• All submissions to this site are governed by Second Life Project Contribution Agreement. By submitting patches and other information using this site, you acknowledge that you have read, understood, and agreed to those terms.
Issue Details (XML | Word | Printable)

Key: SVC-3505
Type: Bug Bug
Status: Resolved Resolved
Resolution: Needs More Info
Priority: Critical Critical
Assignee: Unassigned
Reporter: Charlette Proto
Votes: 0
Watchers: 1
Operations

If you were logged in you would be able to see more operations.
2. Second Life Service - SVC

Inventory items missing following recent asset server upgrades or resulting from griefer attacks

Created: 09/Dec/08 10:59 AM   Updated: 21/Dec/08 02:13 PM
Return to search
Component/s: Inventory
Affects Version/s: None
Fix Version/s: None

Environment:
About Second Life:

Second Life 1.22.2 (104576) Dec 2 2008 12:04:44 (Second Life Release Candidate)
Release Notes

You are at 284985.5, 278645.2, 35.9 in Iwaki located at sim4162.agni.lindenlab.com (63.210.157.66:13002)
Second Life Server 1.24.9.98659
Release Notes

CPU: Intel Pentium III/Pentium III Xeon (0.25 micron process) with external L2 cache (2527 MHz)
Memory: 3069 MB
OS Version: Microsoft Windows Vista Service Pack 1 (Build 6001)
Graphics Card Vendor: NVIDIA Corporation
Graphics Card: GeForce 9600M GT/PCI/SSE2
OpenGL Version: 2.1.2

libcurl Version: libcurl/7.16.4 OpenSSL/0.9.7c zlib/1.2.3
J2C Decoder Version: KDU
LLMozLib Version: [LLMediaImplLLMozLib] - 2.01.20156 (Mozilla GRE version 1.8.1.13_0000000000)
Packets Lost: 6/109851 (0.0%)

Connection Details:

ADSL2+
Edit > Preferences > Network > Maximum Bandwidth 1500 kbps
Issue Links:
Relates
 

Last Triaged: 15/Dec/08 02:13 PM


 Description  « Hide
MISSING INVENTORY ITEMS

The user has experience a number of problems with missing items in the inventory in the last few days and while some copies of the items have been recovered following the earlier errors all shapes and shape related parts (shoe bases, bald heads etc) and skins as well as many texture based clothing items are unrecoverable or have gone missing a number of times.

THE ENCOUNTERED ERROR SITUATION

The situation experienced when the problem was encountered on the last occasion (similar situation was encountered on a previous recent occasion following the upgrade of the asset server and unconnected to it griefing attacks)

Error dialogs (centre of screen) for each missing item worn (5) upon login:

"Unable to save to central asset store. This is usually a temporary failure. Please customize and save the wearable again in a few minutes.
If this problem persists, please click on the 'Tools|Report Bug' pulldown menu and provide detail about your network setup."

Error dialogs (top right) for each missing item worn (5) upon login:

"Failed to find body part in database."

Corresponding Local Chat message for each missing item (5) upon login:
[7:58] Replaced missing clothing/body part with default.

For each item lost a "New ???..." eg New Shape entry is made in the "Lost And Found" folder of the inventory.

Error dialog when an attempting to wear any of the missing items:

"Failed to find part named Damselfly Bald Head in database."
the "Damselfly Bald Head" is obviously a part of the dialog which varies depending on what item is chosen.

These errors are still persisting after a 3 hours. The shape used is replaced with the default shape of the newbie avatar and the skin is replaced with that of a negro complexion never used by this avatar (see griefer comments). The missing clothing and tattooes (textures) are replaced with plain white textures at maximum extent in all dimensions of the given garment.

GRIEFING ATTACK SCENARIOS

A number of direct references to the user (avatar) in question had been made by the same griefer using different accounts on previous occasions.

Statement by the griefer during latest attack on 081209 (repeated many times) before crash:

Deleted per ToS and not posting chat logs

Chat text during attack (first line repeated many times):

7:37] Object: Unable to give inventory: 'No item named ''.'.
[7:37] Object: too many errors... dropping further messages until the flood stops

Griefer avatar identity:

Deleted per ToS and not posting chat logs

Previous statements by the griefer:

Occasion 1:

Deleted per ToS and not posting chat logs

Occasion 2:

Deleted per ToS and not posting chat logs
...
Deleted per ToS and not posting chat logs



 All   Comments   Change History      Sort Order: Ascending order - Click to sort in descending order
meni kaiousei added a comment - 09/Dec/08 01:02 PM
Changed priority, as per http://jira.secondlife.com/secure/ShowConstantsHelp.jspa?decorator=popup#PriorityLevels

Showstopper
ONLY the most severe, confirmed issues which demand immediate attention from Linden Lab. For example, inability for many Residents to login. IMPORTANT: Abusing this setting will cause revocation of Issue Tracker access. If in doubt, mark "Critical" instead.

Critical
Generally, most crashes (particularly if they're easy to reproduce and affect many), content loss, significant memory leaks, greatly reduced performance, etc.


Maggie Darwin added a comment - 10/Dec/08 10:56 AM - edited
Should this item be moved to SEC? I see clues in this report as to a vulnerability that can be used to attack the asset server. Of course, it appears to already be in the (PN) wild...

Soft Linden added a comment - 10/Dec/08 11:39 AM
If you see another incident similar to this please email security@lindenlab.com or create a JIRA in the SEC- category as it happens. It would be helpful to investigate this close to when it happened.

Charlette Proto added a comment - 11/Dec/08 02:04 PM - edited
– Comment deleted as chat logs should not be posted and this is a PG site. – Alexa Linden

Soft Linden added a comment - 15/Dec/08 12:21 PM
Please reopen only if you see the missing items aspect - not just text spam.

Alexa Linden added a comment - 15/Dec/08 02:16 PM
When being griefed, please file an abuse report. Do not post logs in Pjira and please remember that Pjira is also used by the teen grid and therefore all posts should toned appropriately. Issues of a security nature should be opened as SEC. This will keep all information posted private and viewable by only the poster and Linden Lab.

Please read the following to see if this helps you: http://wiki.secondlife.com/wiki/Inventory_Page
For our support info or to file a ticket for your "specific instance of inventory loss", please go to http://secondlife.com/support