Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 307433 - net-ftp/gftp crashes on FTPS connection with not-matching certificate - /usr/bin/gftp-gtk: free(): invalid pointer
Summary: net-ftp/gftp crashes on FTPS connection with not-matching certificate - /usr/...
Status: RESOLVED NEEDINFO
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: [OLD] GNOME (show other bugs)
Hardware: All Linux
: High major (vote)
Assignee: Gentoo Linux Gnome Desktop Team
URL: https://bugzilla.gnome.org/show_bug.c...
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2010-03-02 08:56 UTC by Doktor Notor
Modified: 2010-12-23 19:35 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments
backtrace log (backtrace.log,6.85 KB, text/plain)
2010-03-02 08:58 UTC, Doktor Notor
Details

Note You need to log in before you can comment on or make changes to this bug.
Description Doktor Notor 2010-03-02 08:56:03 UTC
On connecting via FTPS, I only get an immediate crash. :(

# emerge --info net-ftp/gftp dev-libs/openssl
Portage 2.1.7.17 (default/linux/x86/10.0/desktop, gcc-4.4.3, glibc-2.11-r1, 2.6.33-gentoo-ck1 i686)
=================================================================
                        System Settings
=================================================================
System uname: Linux-2.6.33-gentoo-ck1-i686-AMD_Athlon-tm-_XP_2800+-with-gentoo-2.0.1
Timestamp of tree: Tue, 02 Mar 2010 05:45:03 +0000
ccache version 2.4 [enabled]
app-shells/bash:     4.1_p2
dev-java/java-config: 2.1.10
dev-lang/python:     2.6.4-r1, 3.1.1-r1
dev-python/pycrypto: 2.1.0
dev-util/ccache:     2.4-r8
dev-util/cmake:      2.8.0-r2
sys-apps/baselayout: 2.0.1
sys-apps/openrc:     0.6.0-r1
sys-apps/sandbox:    2.2
sys-devel/autoconf:  2.13, 2.65
sys-devel/automake:  1.9.6-r3, 1.10.3, 1.11.1
sys-devel/binutils:  2.20-r1
sys-devel/gcc:       4.4.3
sys-devel/gcc-config: 1.4.1
sys-devel/libtool:   2.2.6b
virtual/os-headers:  2.6.32
ACCEPT_KEYWORDS="x86 ~x86"
ACCEPT_LICENSE="*"
CBUILD="i686-pc-linux-gnu"
CFLAGS="-O2 -march=athlon-xp -pipe -fomit-frame-pointer"
CHOST="i686-pc-linux-gnu"
CONFIG_PROTECT="/etc /usr/share/X11/xkb /var/bind"
CONFIG_PROTECT_MASK="/etc/ca-certificates.conf /etc/env.d /etc/env.d/java/ /etc/fonts/fonts.conf /etc/gconf /etc/gentoo-release /etc/revdep-rebuild /etc/sandbox.d /etc/splash /etc/terminfo"
CXXFLAGS="-O2 -march=athlon-xp -pipe -fomit-frame-pointer"
DISTDIR="/usr/portage/distfiles"
EMERGE_DEFAULT_OPTS="--alphabetical --keep-going --with-bdeps y"
FEATURES="assume-digests buildsyspkg ccache distlocks fakeroot fixpackages metadata-transfer news parallel-fetch protect-owned sandbox sfperms strict unmerge-logs unmerge-orphans userfetch userpriv usersandbox"
GENTOO_MIRRORS="http://gentoo.mirror.web4u.cz/ http://ftp.fi.muni.cz/pub/linux/gentoo/"
LANG="en_US.UTF-8"
LDFLAGS="-Wl,-O1 -Wl,--sort-common -Wl,--as-needed -Wl,--hash-style=gnu"
LINGUAS="cs en"
MAKEOPTS="-j2"
PKGDIR="/usr/portage/packages"
PORTAGE_CONFIGROOT="/"
PORTAGE_RSYNC_EXTRA_OPTS="--prune-empty-dirs --omit-dir-times"
PORTAGE_RSYNC_OPTS="--recursive --links --safe-links --perms --times --compress --force --whole-file --delete --stats --timeout=180 --exclude=/distfiles --exclude=/local --exclude=/packages"
PORTAGE_TMPDIR="/var/tmp"
PORTDIR="/usr/portage"
PORTDIR_OVERLAY="/var/lib/layman/php-testing /var/lib/layman/php-experimental /var/lib/layman/webapps-experimental /var/lib/layman/sunrise /var/lib/layman/enlightenment /usr/local/portage"
SYNC="rsync://rsync.europe.gentoo.org/gentoo-portage"
USE="3dnow 3dnowext X X509 a52 aac aalib acl acpi alsa amr ao bash-completion berkdb bluetooth branding bzip2 cairo caps cdda cddb cdparanoia cdr cleartype cli cracklib crypt css cups curl cvs cxx dbus directfb djvu dri dts dv dvd dvdr encode exif faac faad fam fat fbcon ffmpeg firefox flac flash fontconfig ftp fuse gd gdbm ggi gif git gnome-keyring gnutls gpm gs gsm gstreamer gtk hal iconv icu id3tag idn ieee1394 imagemagick imap ipv6 irda jbig jpeg jpeg2k ladspa lame lcms libcaca libnotify libsamplerate lirc lm_sensors lock lua lzo mad maildir matroska mikmod mmx mmxext mng modules mp3 mp4 mpeg mudflap musepack musicbrainz ncurses network network-cron nfs nfsv3 nfsv4 nls nptl nptlonly nsplugin ntfs offensive ogg openal openexr opengl openmp pam pch pcre pdf perl pkcs11 plotutils png portaudio ppds pppd python quicktime raw readline reflection reiserfs schroedinger sdl session shorten skey sndfile sox speex spell spl sqlite sqlite3 sse ssl startup-notification subversion svg symlink sysfs taglib tcl tcpd theora thunar tiff tk truetype unicode usb v4l v4l2 vcd vorbis wavpack win32codecs wmf wxwidgets x264 x86 xattr xcb xinerama xinetd xml xorg xpm xulrunner xv xvid xvmc zlib" ALSA_CARDS="emu10k1 bt87x" ALSA_PCM_PLUGINS="adpcm alaw asym copy dmix dshare dsnoop empty extplug file hooks iec958 ioplug ladspa lfloat linear meter mmap_emul mulaw multi null plug rate route share shm softvol" APACHE2_MODULES="actions alias auth_basic authn_alias authn_anon authn_dbm authn_default authn_file authz_dbm authz_default authz_groupfile authz_host authz_owner authz_user autoindex cache dav dav_fs dav_lock deflate dir disk_cache env expires ext_filter file_cache filter headers include info log_config logio mem_cache mime mime_magic negotiation rewrite setenvif speling status unique_id userdir usertrack vhost_alias" ELIBC="glibc" INPUT_DEVICES="evdev joystick keyboard lirc mouse vmmouse" KERNEL="linux" LCD_DEVICES="bayrad cfontz cfontz633 glk hd44780 lb216 lcdm001 mtxorb ncurses text" LINGUAS="cs en" LIRC_DEVICES="cph06x devinput" RUBY_TARGETS="ruby18" USERLAND="GNU" VIDEO_CARDS="nouveau nvidia v4l vmware" 
Unset:  CPPFLAGS, CTARGET, FFLAGS, INSTALL_MASK, LC_ALL, PORTAGE_COMPRESS, PORTAGE_COMPRESS_FLAGS

=================================================================
                        Package Settings
=================================================================

net-ftp/gftp-2.0.19-r1 was built with the following:
USE="gtk ssl" 
CFLAGS="-O2 -march=athlon-xp -pipe -ggdb"
CXXFLAGS="-O2 -march=athlon-xp -pipe -ggdb"


dev-libs/openssl-0.9.8l-r2 was built with the following:
USE="-bindist -gmp -kerberos -sse2 -test zlib" 
CFLAGS="-O2 -march=athlon-xp -pipe -ggdb -fno-strict-aliasing -Wa,--noexecstack"
CXXFLAGS="-O2 -march=athlon-xp -pipe -ggdb -fno-strict-aliasing -Wa,--noexecstack"
Comment 1 Doktor Notor 2010-03-02 08:58:26 UTC
Created attachment 221763 [details]
backtrace log
Comment 2 Doktor Notor 2010-03-02 09:28:49 UTC
OK, and here's the actual cause (found out by using gftp-text instead of the GUI)

ERROR: The host in the SSL certificate (foo.example.com) does not match the host that we connected to (bar.example.com). Aborting connection.

Well, that really needs to be handled a whole lot more gracefully, rather than crashing. Plus it doesn't even ask any question whether to use the cert anyway even if it doesn't match, it just aborts. Eh. :/
Comment 3 Pacho Ramos gentoo-dev 2010-09-03 18:22:04 UTC
Can you please try to get a better backtrace following:
http://www.gentoo.org/proj/en/qa/backtraces.xml
?
Comment 4 Pacho Ramos gentoo-dev 2010-12-23 19:35:31 UTC
(In reply to comment #3)
> Can you please try to get a better backtrace following:
> http://www.gentoo.org/proj/en/qa/backtraces.xml
> ?
>