version: opensips 4.0.0-rc2 (x86_64/linux)
flags: STATS: On, DISABLE_NAGLE, USE_MCAST, SHM_MMAP, PKG_MALLOC, Q_MALLOC, F_MALLOC, HP_MALLOC, F_PARALLEL_MALLOC, DBG_MALLOC, CC_O0, FAST_LOCK-ADAPTIVE_WAIT
ADAPTIVE_WAIT_LOOPS=1024, MAX_RECV_BUFFER_SIZE 262144, MAX_LISTEN 16, MAX_URI_SIZE 1024, BUF_SIZE 65535
poll method support: poll, epoll, sigio_rt, select.
git revision: b670774
main.c compiled on with gcc 14
Crash Core Dump
Can't share full dump because of UAC Auth towards carrier.
Program terminated with signal SIGSEGV, Segmentation fault.
#0 0x00007ffff4c929b9 in b2b_get_server_entity_key () from /usr/lib/x86_64-linux-gnu/opensips/modules/b2b_entities.so
Describe the traffic that generated the bug
Receiving Cancel during 180 ringing in a B2B_Logic/ B2B_Entities scenario
To Reproduce
Make inbound call, let it ring once, or twice, then hangup from caller side.
Callee will remain ringing. No proper cancel or bye signaling upstream.
Relevant System Logs
Jul 13 17:13:47 [2824] DBG:core:parse_msg_opt: method: <CANCEL>
Jul 13 17:13:47 [2824] DBG:core:parse_msg_opt: uri: <sip:anon@anon:5080>
Jul 13 17:13:47 [2824] DBG:core:parse_msg_opt: version: <SIP/2.0>
Jul 13 17:13:47 [2824] DBG:core:parse_headers_aux: flags=ffffffffffffffff
Jul 13 17:13:47 [2824] DBG:core:parse_via_param: found param type 232, <branch> = <z9hG4bK02fb.24b4a453.0>; state=16
Jul 13 17:13:47 [2824] DBG:core:parse_via: end of header reached, state=5
Jul 13 17:13:47 [2824] DBG:core:parse_headers_aux: via found, flags=ffffffffffffffff
Jul 13 17:13:47 [2824] DBG:core:parse_headers_aux: this is the first via
Jul 13 17:13:47 [2824] DBG:core:_parse_to: end of header reached, state=10
Jul 13 17:13:47 [2824] DBG:core:_parse_to: display={}, ruri={sip:anon@anon}
Jul 13 17:13:47 [2824] DBG:core:get_hdr_field_aux: <To> [33]; uri=[sip:anon@anon]
Jul 13 17:13:47 [2824] DBG:core:get_hdr_field_aux: to body [<sip:anon@anon>
]
Jul 13 17:13:47 [2824] DBG:core:get_hdr_field_aux: cseq <CSeq>: <102> <CANCEL>
Jul 13 17:13:47 [2824] DBG:core:get_hdr_field_aux: content_length=0
Jul 13 17:13:47 [2824] DBG:core:get_hdr_field_aux: found end of header
Jul 13 17:13:47 [2824] DBG:core:receive_msg: After parse_msg...
Jul 13 17:13:47 [2824] DBG:core:receive_msg: preparing to run routing scripts...
Jul 13 17:13:47 [2824] DBG:core:parse_headers_aux: flags=ffffffffffffffff
Jul 13 17:13:47 [2824] DBG:b2b_entities:b2b_prescript_f: start - method = CANCEL
Jul 13 17:13:47 [2824] DBG:core:parse_to_param: tag=as735a639c
Jul 13 17:13:47 [2824] DBG:core:parse_to_param: end of header reached, state=11
Jul 13 17:13:47 [2824] DBG:core:_parse_to: end of header reached, state=29
Jul 13 17:13:47 [2824] DBG:core:_parse_to: display={"anon"}, ruri={sip:anon@anon.net}
Jul 13 17:13:47 [2824] DBG:tm:t_lookupOriginalT: searching on hash entry 48928
Jul 13 17:13:47 [2824] DBG:tm:matching_3261: RFC3261 transaction matched, tid=02fb.24b4a453.0
Jul 13 17:13:47 [2824] DBG:tm:t_lookupOriginalT: canceled transaction found (0x7ffff51b1e48)!
Jul 13 17:13:47 [2824] DBG:tm:t_lookupOriginalT: REF_UNSAFE:[0x7ffff51b1e48] after is 2
Jul 13 17:13:47 [2824] DBG:tm:t_lookupOriginalT: t_lookupOriginalT completed
Jul 13 17:13:47 [2824] DBG:b2b_entities:b2bl_search_iteratively: Search for record with callid= anon@anon:5060, tag= as735a639c
Jul 13 17:13:47 [2824] DBG:b2b_entities:b2bl_search_iteratively: Found callid= anon@anon:5060, tag= as735a639c
Jul 13 17:13:47 [2824] DBG:tm:t_unref_cell: UNREF_UNSAFE: [0x7ffff51b1e48] after is 1
Jul 13 17:13:47 [2824] DBG:tm:t_newtran: transaction on entrance=0xffffffffffffffff
Jul 13 17:13:47 [2824] DBG:core:parse_headers_aux: flags=ffffffffffffffff
Jul 13 17:13:47 [2824] DBG:core:parse_headers_aux: flags=78
Jul 13 17:13:47 [2824] DBG:tm:t_lookup_request: start searching: hash=48928, isACK=0
Jul 13 17:13:47 [2824] DBG:tm:matching_3261: RFC3261 transaction matching failed
Jul 13 17:13:47 [2824] DBG:tm:t_lookup_request: no transaction found
Jul 13 17:13:47 [2824] DBG:tm:run_any_trans_callbacks: trans=0x7ffff51a3f18, callback type 1, id 0 entered
Jul 13 17:13:47 [2824] DBG:core:MD5StringArray: MD5 calculated: c7d936a27e87ba90e12809336b030c88
Jul 13 17:13:47 [2824] DBG:core:parse_headers_aux: flags=ffffffffffffffff
Jul 13 17:13:47 [2824] DBG:tm:cleanup_uac_timers: RETR/FR timers reset
Jul 13 17:13:47 [2824] DBG:tm:insert_timer_unsafe: [2]: 0x7ffff51a3f98 (41)
Jul 13 17:13:47 [2824] DBG:tm:_reply_light: reply sent out. buf=0x7ffff6e64bc0: SIP/2.0 2..., shmem=0x7ffff51a3968: SIP/2.0 2
Jul 13 17:13:47 [2824] DBG:tm:_reply_light: finished
Jul 13 17:13:47 [2824] DBG:tm:t_unref_cell: UNREF_UNSAFE: [0x7ffff51a3f18] after is 0
Jul 13 17:13:47 [2824] CRITICAL:core:sig_usr: segfault in process pid: 2824, id: 12
Jul 13 17:13:47 [2824] DBG:core:restore_segv_handler: restoring SIGSEGV handler...
Jul 13 17:13:47 [2824] DBG:core:restore_segv_handler: successfully restored system SIGSEGV handler
Jul 13 17:13:47 [2810] DBG:core:handle_sigs: OpenSIPS exit status = 139
Jul 13 17:13:47 [2810] INFO:core:handle_sigs: child process 2824 exited by a signal 11
Jul 13 17:13:47 [2810] INFO:core:handle_sigs: core was generated
Jul 13 17:13:47 [2810] INFO:core:handle_sigs: terminating due to SIGCHLD
OS/environment information
- Operating System: Debian 13
Additional context
Not doing any additional actions on the CANCEL in B2B Script route, simply handled in the b2b_logic route with 'b2b_pass_request'.
version: opensips 4.0.0-rc2 (x86_64/linux)
flags: STATS: On, DISABLE_NAGLE, USE_MCAST, SHM_MMAP, PKG_MALLOC, Q_MALLOC, F_MALLOC, HP_MALLOC, F_PARALLEL_MALLOC, DBG_MALLOC, CC_O0, FAST_LOCK-ADAPTIVE_WAIT
ADAPTIVE_WAIT_LOOPS=1024, MAX_RECV_BUFFER_SIZE 262144, MAX_LISTEN 16, MAX_URI_SIZE 1024, BUF_SIZE 65535
poll method support: poll, epoll, sigio_rt, select.
git revision: b670774
main.c compiled on with gcc 14
Crash Core Dump
Can't share full dump because of UAC Auth towards carrier.
Describe the traffic that generated the bug
Receiving Cancel during 180 ringing in a B2B_Logic/ B2B_Entities scenario
To Reproduce
Make inbound call, let it ring once, or twice, then hangup from caller side.
Callee will remain ringing. No proper cancel or bye signaling upstream.
Relevant System Logs
OS/environment information
Additional context
Not doing any additional actions on the CANCEL in B2B Script route, simply handled in the b2b_logic route with 'b2b_pass_request'.