Hello, 
We've been experiencing bird crashes while using the radv protocol with enabled tracing on v2.19.2 (master branch is also affected). I've found that wrong struct is casted and forwarded into RADV_TRACE macro causing "bug("unknown network type")" and SIGABRT at the end.

Patch:

diff --git a/proto/radv/radv.c b/proto/radv/radv.c

index 7c2e8953..db2910b6 100644

--- a/proto/radv/radv.c

+++ b/proto/radv/radv.c

@@ -291,29 +291,30 @@ radv_prune_neighbors(struct radv_proto *p)

     {

       /* Only process routes from our protocol */

       if (e->src != p->p.main_source)

-       continue;

+        continue;

 

       /* Get the expiration time EA */

       eattr *expires_ea = ea_find(e->attrs->eattrs, EA_RA_LIFETIME);

       if (!expires_ea)

-       continue;

+        continue;

 

       btime expires = expires_ea->u.data S;

 

       if (expires <= now)

       {

-       /* Neighbor has expired, add to withdrawal list */

-       net_addr_nbr *nbr = (net_addr_nbr *) e->net;

+        /* Neighbor has expired, add to withdrawal list */

+        net_addr_nbr *nbr = (net_addr_nbr *) n->n.addr;

 

-       struct expired_nbr *ep = tmp_allocz(sizeof(struct expired_nbr));

-       net_copy_nbr(&ep->n, nbr);

-       ep->next = expired_list;

-       expired_list = ep;

+        struct expired_nbr *ep = tmp_allocz(sizeof(struct expired_nbr));

+        net_copy_nbr(&ep->n, nbr);

+        ep->next = expired_list;

+        expired_list = ep;

 

-       RADV_TRACE(D_EVENTS, "Router %N expired", nbr);

+        RADV_TRACE(D_EVENTS, "Router %N expired", nbr);

+      }

+      else {

+        next = MIN(next, expires);

       }

-      else

-       next = MIN(next, expires);

     }

   }

   FIB_WALK_END;


Regards, Michal