Return-Path: <marmstrong@google.com>
X-Original-To: notmuch@notmuchmail.org
Delivered-To: notmuch@notmuchmail.org
Received: from localhost (localhost [127.0.0.1])
 by arlo.cworth.org (Postfix) with ESMTP id E814D6DE12A7
 for <notmuch@notmuchmail.org>; Tue, 15 Aug 2017 10:37:35 -0700 (PDT)
X-Virus-Scanned: Debian amavisd-new at cworth.org
X-Spam-Flag: NO
X-Spam-Score: -0.313
X-Spam-Level: 
X-Spam-Status: No, score=-0.313 tagged_above=-999 required=5
 tests=[AWL=-0.182, DKIM_SIGNED=0.1, DKIM_VALID=-0.1,
 DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_NONE=-0.0001,
 RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_PASS=-0.001,
 T_RP_MATCHES_RCVD=-0.01] autolearn=disabled
Received: from arlo.cworth.org ([127.0.0.1])
 by localhost (arlo.cworth.org [127.0.0.1]) (amavisd-new, port 10024)
 with ESMTP id ku27nnxkexMu for <notmuch@notmuchmail.org>;
 Tue, 15 Aug 2017 10:37:35 -0700 (PDT)
Received: from mail-pg0-f49.google.com (mail-pg0-f49.google.com [74.125.83.49])
 by arlo.cworth.org (Postfix) with ESMTPS id 435A36DE11B5
 for <notmuch@notmuchmail.org>; Tue, 15 Aug 2017 10:37:35 -0700 (PDT)
Received: by mail-pg0-f49.google.com with SMTP id u185so9665016pgb.1
 for <notmuch@notmuchmail.org>; Tue, 15 Aug 2017 10:37:35 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20161025;
 h=from:to:subject:date:message-id:mime-version;
 bh=VedPzk3OTotcA/KVY1zzVdjBjvQ8aQRM6Ch+wz6WJkU=;
 b=Fbth/C0ossaETKfo7b5Qey4T5ytSFpJjecrITQE+Dy1WXbUczJoK+Qbw2cdcES1c56
 yC84XC+rDYHlYMb2DakTfs0E7hLX+uu4J+1KYPIXjVMRYPLLp5Z3Jo4k/khskI3AlZF0
 N0ccmQX1I4ekmI08NlebhWypS5RQf5sgBCrsheR8CfLGjz8Bh0kY6c+6W7biJQ7W82uw
 PnD6NalUhvwHsWVyIpbQk2BnIMRlnwb7FifDQVJxYtyO9HO2yevxqcmhLJBV0gG8O/Xf
 qZivVza3T/CZ5cv6JT82fejbxF/z56/blY6hG1f4ZI0IIyAuZ+M5t3pcWy+DB+iznNO7
 VMZQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
 d=1e100.net; s=20161025;
 h=x-gm-message-state:from:to:subject:date:message-id:mime-version;
 bh=VedPzk3OTotcA/KVY1zzVdjBjvQ8aQRM6Ch+wz6WJkU=;
 b=b3HMGFm6gKg4SZOyoRfhzZX1/Ssl85JoVY3BZNCdqS6X1my6w+KqQfJSUwB5NyrpV0
 Lnyka0Lb1HkIwC857lkRgGxVFoBCFUN6MqwrJdC87JqDELzG3bpq/LqsCnTdOXxzZ+Pk
 kppF1M0ZPwl/EWOfhTdFuWeX9tbGkMRuDMOGTPNbdQbSvQvbet2vZDQFnIJnfiycYMZ8
 WERK5jakG7Gx+q6SykZGYQQOU1eeuWZPT81Z5Y/aMkMT0tHP1ZfdLxkP6/Vy/cdfqMfq
 BbIeSZqryJdiVYI5PzBeuuOOZ9SpBqjEax+r5XjZFy+mettRj6tepnsArjGqy9wbUzS2
 e/bg==
X-Gm-Message-State: AHYfb5h1X+ADNw9Gi6/o8OVRu6yHAIupiFrOD/qc0PqrUL8Z3wlxx4+e
 z8DIUiWq8N+T6I5jAQwrcw==
X-Received: by 10.84.229.7 with SMTP id b7mr32639098plk.357.1502818654097;
 Tue, 15 Aug 2017 10:37:34 -0700 (PDT)
Received: from marmstrong-linux.kir.corp.google.com
 ([2620:0:1008:11:1db9:5f8c:2f6f:521a])
 by smtp.gmail.com with ESMTPSA id 73sm17764286pfj.136.2017.08.15.10.37.32
 for <notmuch@notmuchmail.org>
 (version=TLS1_2 cipher=AES128-SHA bits=128/128);
 Tue, 15 Aug 2017 10:37:32 -0700 (PDT)
From: Matt Armstrong <marmstrong@google.com>
To: notmuch@notmuchmail.org
Subject: bug: notmuch show --decrypt leads to SIGSEGV
Date: Tue, 15 Aug 2017 10:37:31 -0700
Message-ID: <qf5d17wzq90.fsf@google.com>
MIME-Version: 1.0
Content-Type: text/plain
X-BeenThere: notmuch@notmuchmail.org
X-Mailman-Version: 2.1.23
Precedence: list
List-Id: "Use and development of the notmuch mail system."
 <notmuch.notmuchmail.org>
List-Unsubscribe: <https://notmuchmail.org/mailman/options/notmuch>,
 <mailto:notmuch-request@notmuchmail.org?subject=unsubscribe>
List-Archive: <http://notmuchmail.org/pipermail/notmuch/>
List-Post: <mailto:notmuch@notmuchmail.org>
List-Help: <mailto:notmuch-request@notmuchmail.org?subject=help>
List-Subscribe: <https://notmuchmail.org/mailman/listinfo/notmuch>,
 <mailto:notmuch-request@notmuchmail.org?subject=subscribe>
X-List-Received-Date: Tue, 15 Aug 2017 17:37:36 -0000
Status: O
Content-Length: 2332
Lines: 61

I've been able to diagnose a SIGSEGV, and I have a workaround that
satisfies me.  I'm unsure how to fix it, so I'll describe the problem
and leave it at that.

Repro:

% notmuch --version
notmuch 0.25+22~g0967e46 (a recent git @HEAD)
% notmuch show --format=sexp --decrypt thread:000000000002ad2c
-> SIGSEGV

Workaround:

Don't pass --decrypt.  In Emacs, configure notmuch-crypto-process-mime
to shut off crypto processing, or C-u before in notmuch-show before
viewing a problematic thread.

Diagnosis:

mime-node.c's _mime_node_create() can return NULL in various scenarios
yet few to none of its callers appear to handle it properly.  In this
particular case, the NULL is returned here:

#if (GMIME_MAJOR_VERSION < 3)
    if ((GMIME_IS_MULTIPART_ENCRYPTED (part) && node->ctx->crypto->decrypt)
	|| (GMIME_IS_MULTIPART_SIGNED (part) && node->ctx->crypto->verify)) {
	GMimeContentType *content_type = g_mime_object_get_content_type (part);
	const char *protocol = g_mime_content_type_get_parameter (content_type, "protocol");
	cryptoctx = notmuch_crypto_get_context (node->ctx->crypto, protocol);
	if (!cryptoctx) {
	    return NULL;
	}
    }
#endif

Note above a missing call to talloc_free(node) before the return, which
suggests a kind of bit-rot has set in for the GMIME_MAJOR_VERSION<3
case?  Anyway...

mime_node_child() calls _mime_node_create() and will SIGSEGV:

    node = _mime_node_create (parent, sub);

    if (child == parent->next_child && parent->next_part_num != -1) {
	/* We're traversing in depth-first order.  Record the child's
	 * depth-first numbering. */
	node->part_num = parent->next_part_num;
	node->next_part_num = node->part_num + 1;


If I address that by returning NULL from mime_node_child() when
_mime_node_create() does, then the problem cascades to callers.  None of
the callers of mime_node_child() explicitly handle the NULL return case:

mime-node.c:		mime_node_t *child = mime_node_child (node, i);
notmuch-show.c:571:	format_part_text (ctx, sp, mime_node_child (node, i), indent, params);
notmuch-show.c:622:	    format_part_sprinter (ctx, sp, mime_node_child (node, 0), first, TRUE, include_html);
notmuch-show.c:724:	format_part_sprinter (ctx, sp, mime_node_child (node, i), i == 0, TRUE, include_html);

..._mime_node_seek_dfs_walk will proceed to SIGSEGV, and so will
format_part_...().
