# possible bug

**URL:** <https://community.zeek.org/t/possible-bug/624>\
**Category:** Zeek\
**Created:** [November 5, 2004, 2:11pm UTC](https://community.zeek.org/t/possible-bug/624 "2004-11-05T14:11:28Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![john\_mcnicholas](https://avatars.discourse-cdn.com/v4/letter/j/fbc32d/32.png) [@john\_mcnicholas](https://community.zeek.org/u/john_mcnicholas)\
**Post date:** [November 5, 2004, 2:11pm UTC](https://community.zeek.org/t/possible-bug/624/1 "2004-11-05T14:11:28Z")

</div>

Hi,

I believe I came across a minor bug in the 0.94 and 0.97 bro code. I'm still new to this project, so it is possible the problem is a user error.

In short, when TCP\_Connection::SetContentsFile is called with the CONTENTS\_BOTH value as the direction, the BroFile object reference counter needs to be incremented else one will encounter an internal reference count error. (or something similar, I don't recall the exact message). In the 0.94 build the program would immediately exit.

Notes:

- below is a temporary work around that i added. I'm not that familiar with the bro code so I imagine there are other solutions and I'm not recommending one over another.  
- here is an outline/fragment of a bro script to generate the error.

event connection\_established( c: connection )  
{  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;# 1. see if appropriate protocol/port is being used

&nbsp;&nbsp;local filename: string;  
&nbsp;&nbsp;local f : file;

&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;# 2. NOTE: construct appropriate filename here

&nbsp;&nbsp;f = open(filename);  
&nbsp;&nbsp;set\_contents\_file(c$id,CONTENTS\_BOTH,f);  
}

Please let me know if you'd like additional information.

John

//-----------------------------------------------------------------------

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:37pm UTC](https://community.zeek.org/t/possible-bug/624/2 "2022-05-06T15:37:14Z")

</div>


