[1638] in athena10

home help back first fref pref prev next nref lref last post

[DRAFT] Important information for owl users on linerva

daemon@ATHENA.MIT.EDU (Anders Kaseorg)
Fri Mar 13 22:50:01 2009

From: Anders Kaseorg <andersk@MIT.EDU>
To: linerva@mit.edu
Content-Type: text/plain
Date: Fri, 13 Mar 2009 22:49:03 -0400
Message-Id: <1236998943.7405.6.camel@balanced-tree>
Mime-Version: 1.0
Content-Transfer-Encoding: 7bit

This message is being sent to the 7 users who have been running owl on
Linerva (linux.mit.edu) during the last week.

As you may have noticed, your owl session probably has a pattern of
crashing periodically with the error message
  Killed
This is due to a known bug in owl that causes it to consume extremely
excessive CPU resources [1], which surpass the resource limits that have
been set on Linerva to ensure acceptable performance for all users.
Because owl has not been maintained by its author since 2005, this bug
is unlikely to ever be fixed in owl, along with other critical bugs such
as the security vulnerability CVE-2009-0363 [2].

The Linerva maintainers urge you to consider switching from owl to
BarnOwl, the SIPB-developed fork of owl that fixes these bugs.  BarnOwl
can be used as a drop-in replacement for owl with no configuration
changes on your part.  You can run it from the barnowl locker:

% add barnowl
% barnowl

BarnOwl also includes new features such as Jabber and IRC support, if
you choose to enable them.  For more information about BarnOwl, visit
<http://barnowl.mit.edu/>.  Feel free to send any questions about
BarnOwl to the developers <barnowl@mit.edu>, or zephyr -c barnowl.

Anders
SIPB Linerva team <linerva@mit.edu>


[1] Technical details: Instead of going to sleep to wait for input, owl
uses a timer to poll the kernel 100000 times per second.  This bug is
exacerbated by the new kernel 2.6.26 (installed on Linerva during the
upgrade to Debian Lenny last week), which is capable of trying to
service such a fast timer, and so owl processes are woken up about as
often as the CPU can handle.  The kernel automatically detects and kills
all user processes that have consumed 12 hours of CPU time.
<http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=433027>

[2] owl is vulnerable to multiple buffer overflows that may allow
attackers to gain control of your Athena account by sending you
maliciously crafted messages.  These bugs have all been fixed in
BarnOwl. <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0363>


home help back first fref pref prev next nref lref last post