Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

Agent SIGSEGV on /api/v2|v3/claim — claim_add_user_info_command() calls strchr(NULL) when the lib dir is not writable

Đang mở Phù hợp với người mới
#22,786 1 bình luận 0 reaction 0 người được giao Xem trên GitHub

Maintainer thường phản hồi trong vòng 1 ngày

Chưa có ai nhận issue này.

Đánh giá

Độ khó
2/5
Thời gian dự kiến
1-3 giờ
Mức phù hợp với người mới
72/100
Loại issue
Lỗi
Độ rõ ràng
Đặc tả rõ ràng
Mức độ hoạt động
Ít trao đổi
Công nghệ
c, linux
Lĩnh vực
api, backend, observability

Hướng nghiên cứu

Bắt đầu tại src/web/api/v2/api_v2_claim.c, ở claim_add_user_info_command(), sau đó lần theo netdata_random_session_id_get_filename() và tái hiện bằng yêu cầu curl được cung cấp khi thư mục lib không thể ghi. Xác nhận rằng endpoint claim không còn bị crash khi tên tệp không khả dụng, và kiểm tra system/systemd/netdata.service.in để tìm packaging trigger.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

Summary

A self-hosted (unclaimed) Netdata Agent crashes with SIGSEGV on every GET /api/v2/claim / GET /api/v3/claim request whenever it cannot create its random-session-id file in netdata_configured_varlib_dir (e.g. when that directory is read-only for the agent process). The web UI issues this request on load / when showing the "Sign-in to continue" panel, so the dashboard reliably crashes the agent in a restart loop.

Root cause is a missing NULL check in claim_add_user_info_command():

// src/web/api/v2/api_v2_claim.c
static void claim_add_user_info_command(BUFFER *wb) {
    const char *filename = netdata_random_session_id_get_filename(); // may be NULL
    ...
    os_filename = filename;          // NULL
    ...
    if(strchr(os_filename, ' '))     // <-- strchr(NULL) => SIGSEGV

netdata_random_session_id_get_filename() returns NULL when netdata_random_session_id_generate() failed (its open(O_WRONLY|O_CREAT...) returned -1 and netdata_random_session_id_filename was left NULL). The caller dereferences it unconditionally.

gdb backtrace (v2.10.3, official Debian .deb)

#0  __strchr_avx2 () at ../sysdeps/x86_64/multiarch/strchr-avx2.S:67
#1  0x... in claim_add_user_info_command (wb=0x...) at src/web/api/v2/api_v2_claim.c:131
#2  claim_json_response (wb=..., response=CLAIM_RESP_INFO, msg=...) at src/web/api/v2/api_v2_claim.c:158
#3  0x... in api_claim (version=..., w=..., url=...) at src/web/api/v2/api_v2_claim.c:230
#4  0x... in web_client_api_request_v3 (...) at src/web/api/web_api_v3.c:269
#5  web_client_api_request (...) at src/web/server/web_client.c:576
#6  check_host_and_call (...) at src/web/server/web_client.c:542
#7  web_client_process_url (... filename = "/api/v3/claim_info" ...) at src/web/server/web_client.c:1163
#8  web_client_process_request_from_web_server (...) 
#9  web_server_rcv_callback (...) at src/web/server/static/static-threaded.c:196
...

bt full for frame #1 shows os_message = "We need to verify this server is yours. SSH to this server and run this command. ...", os_prefix = "sudo cat", and os_filename resolving from the (NULL) session-id filename.

How the file creation fails (the trigger on the official .deb)

netdata_random_session_id_generate() does:

snprintfz(filename, FILENAME_MAX, "%s/netdata_random_session_id", netdata_configured_varlib_dir);
...
int fd = open(filename, O_WRONLY|O_CREAT|O_TRUNC|O_CLOEXEC, 640);
if(fd == -1) { netdata_log_error(...); ret = false; }   // filename stays NULL

On the official Debian package, the shipped systemd unit (system/systemd/netdata.service.in) runs with:

ProtectSystem=full
ProtectHome=read-only
ReadWriteDirectories=/run/netdata
ReadWriteDirectories=-/var/spool/postfix/maildrop

With this sandbox the agent process cannot write to /var/lib/netdata (verified by entering the service's mount namespace):

$ sudo nsenter -t <netdata-pid> -m -- touch /var/lib/netdata/__t
touch: cannot touch '/var/lib/netdata/__t': Read-only file system

So open() returns -1 (EROFS) → netdata_random_session_id_filename stays NULL → get_filename() returns NULL → strchr(NULL) → SIGSEGV. (The same crash would occur on any system where the lib dir is non-writable: full disk, wrong ownership, etc.)

Reproduction

On a v2.10.3 Debian .deb install (agent running as a streaming parent, unclaimed, self-hosted):

# crashes the agent every time:
curl -s -o /dev/null -w '%{http_code}\n' http://127.0.0.1:19999/api/v3/claim
# -> empty reply / 000, journal shows: netdata.service: Main process exited, code=killed, status=11/SEGV

systemctl then restart-loops the agent (Restart=on-failure). Opening the dashboard or clicking "Sign in anonymously" triggers the same request and the same crash.

Suggested fixes

1. Code (the actual crash) — add a NULL guard in claim_add_user_info_command() so the agent never dereferences a NULL session-id filename. (PR incoming.)

2. Packaging (the trigger) — let the agent write its lib dir. Add the lib directory to the unit's writable paths, e.g. in system/systemd/netdata.service.in:

ReadWritePaths=/var/lib/netdata

I verified that adding this drop-in alone makes /api/v3/claim return 200 and the session-id file gets created normally — but the NULL guard is still needed so other "lib dir not writable" conditions can't crash the agent.

Environment

  • Netdata v2.10.3, official .deb (repository.netdata.cloud, stable channel)
  • Debian 12 (bookworm), x86_64, kernel 6.12
  • Agent role: streaming parent for 3 nodes, unclaimed / self-hosted (no Netdata Cloud)
  • netdatacli aclk-state → ACLK Available: Yes

Happy to also send the full bt full / a coredump if useful.

Ngôn ngữ chính
Go
Star
80.6k
Fork
6.6k
Merge trung bình
15 giờ 35 phút
Pull request đã merge (30 ngày)
305

Chuẩn bị môi trường

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của netdata/netdata

Tất cả issue của netdata/netdata

Issue tương tự

Thêm issue về Go

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.