Bug 1205072

Summary: [abrt] libreoffice-core: SwListImpl::~SwListImpl(): soffice.bin killed by SIGSEGV
Product: [Fedora] Fedora Reporter: Nik Zbugz <nixbugz>
Component: libreofficeAssignee: Michael Stahl <mstahl>
Status: CLOSED ERRATA QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: 20CC: caolanm, dtardon, erack, ifoolb, ltinkl, mstahl, sbergman
Target Milestone: ---   
Target Release: ---   
Hardware: x86_64   
OS: Unspecified   
URL: https://retrace.fedoraproject.org/faf/reports/bthash/681d4162db659d5b5117aea5c23f3f57619305de
Whiteboard: abrt_hash:069bf2559c899faaf0edc7f28885d9c9842d6a7b
Fixed In Version: libreoffice-4.3.7.2-4.fc21 Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2015-05-12 20:40:14 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Attachments:
Description Flags
File: backtrace
none
File: cgroup
none
File: core_backtrace
none
File: dso_list
none
File: environ
none
File: exploitable
none
File: limits
none
File: maps
none
File: open_fds
none
File: proc_pid_status
none
File: var_log_messages none

Description Nik Zbugz 2015-03-24 08:15:31 UTC
Description of problem:
II dragged a URL from Firefox's address bar into a document, wanting to paste a link.
The Insert Section box came up.  Not what I expected but the Link box is ticked, so untick Protect & click insert.
See that it has inserted most of the web page into the document.  Not what I wanted.  Also see the Undo button is greyed-out so select most of what had just been pasted & press the delete key.
Collapse of soffice.bin.

Version-Release number of selected component:
libreoffice-core-4.2.8.2-6.fc20

Additional info:
reporter:       libreport-2.2.3
backtrace_rating: 4
cmdline:        /usr/lib64/libreoffice/program/soffice.bin --writer '/home/nick/Documents/Michael\'s New PC/Specifications for Michael\'s PC.odt' --splash-pipe=5
crash_function: SwListImpl::~SwListImpl
executable:     /usr/lib64/libreoffice/program/soffice.bin
kernel:         3.18.7-100.fc20.x86_64
runlevel:       N 5
type:           CCpp
uid:            1000

Truncated backtrace:
Thread no. 1 (10 frames)
 #0 SwListImpl::~SwListImpl at /usr/src/debug/libreoffice-4.2.8.2/sw/source/core/doc/list.cxx:109
 #1 SwList::~SwList at /usr/src/debug/libreoffice-4.2.8.2/sw/source/core/doc/list.cxx:232
 #2 SwDoc::~SwDoc at /usr/src/debug/libreoffice-4.2.8.2/sw/source/core/doc/docnew.cxx:676
 #4 SwDocShell::RemoveLink at /usr/src/debug/libreoffice-4.2.8.2/sw/source/ui/app/docshini.cxx:450
 #5 SwDocShell::~SwDocShell at /usr/src/debug/libreoffice-4.2.8.2/sw/source/ui/app/docshini.cxx:369
 #7 Clear at /usr/src/debug/libreoffice-4.2.8.2/include/sfx2/objsh.hxx:757
 #8 SwTransferable::~SwTransferable at /usr/src/debug/libreoffice-4.2.8.2/sw/source/ui/dochdl/swdtflvr.cxx:254
 #10 ~Reference at /usr/src/debug/libreoffice-4.2.8.2/include/com/sun/star/uno/Reference.hxx:106
 #11 x11::X11Clipboard::setContents at /usr/src/debug/libreoffice-4.2.8.2/vcl/unx/generic/dtrans/X11_clipboard.cxx:166
 #12 TransferableHelper::ClearSelection at /usr/src/debug/libreoffice-4.2.8.2/svtools/source/misc/transfer.cxx:1164

Comment 1 Nik Zbugz 2015-03-24 08:15:35 UTC
Created attachment 1005718 [details]
File: backtrace

Comment 2 Nik Zbugz 2015-03-24 08:15:36 UTC
Created attachment 1005719 [details]
File: cgroup

Comment 3 Nik Zbugz 2015-03-24 08:15:37 UTC
Created attachment 1005720 [details]
File: core_backtrace

Comment 4 Nik Zbugz 2015-03-24 08:15:38 UTC
Created attachment 1005721 [details]
File: dso_list

Comment 5 Nik Zbugz 2015-03-24 08:15:40 UTC
Created attachment 1005722 [details]
File: environ

Comment 6 Nik Zbugz 2015-03-24 08:15:41 UTC
Created attachment 1005723 [details]
File: exploitable

Comment 7 Nik Zbugz 2015-03-24 08:15:42 UTC
Created attachment 1005724 [details]
File: limits

Comment 8 Nik Zbugz 2015-03-24 08:15:44 UTC
Created attachment 1005725 [details]
File: maps

Comment 9 Nik Zbugz 2015-03-24 08:15:45 UTC
Created attachment 1005726 [details]
File: open_fds

Comment 10 Nik Zbugz 2015-03-24 08:15:47 UTC
Created attachment 1005727 [details]
File: proc_pid_status

Comment 11 Nik Zbugz 2015-03-24 08:15:48 UTC
Created attachment 1005728 [details]
File: var_log_messages

Comment 12 Michael Stahl 2015-04-27 12:15:47 UTC
impossible to tell from the backtrace what the problem is;
something about a clipboard document.

to create the linked section, you have to drag not from the address
but from the globe on the left of the address.

can reproduce crashes in 4.2.8.2 with this page:
http://en.wikipedia.org/wiki/Magic_SysRq_key

cannot reproduce this crash with current 4.3 or 4.4 builds,
but something showed up in valgrind.

while testing this i've found and fixed 2 different a11y
crashes on master and 4.4.

fixed in upstream master commit c55599fd0e7198773087c6433031f7119aaaca36
fixed in upstream libreoffice-4-4 for 4.4.4 commit 8f570028b0871dbaaaa99722cca76c0d1179e06c

added patch to F21 package

Comment 13 Michael Stahl 2015-04-27 16:46:51 UTC
*** Bug 1209734 has been marked as a duplicate of this bug. ***

Comment 14 Fedora Update System 2015-05-03 20:01:21 UTC
libreoffice-4.3.7.2-4.fc21 has been submitted as an update for Fedora 21.
https://admin.fedoraproject.org/updates/libreoffice-4.3.7.2-4.fc21

Comment 15 Fedora Update System 2015-05-08 07:44:48 UTC
Package libreoffice-4.3.7.2-4.fc21:
* should fix your issue,
* was pushed to the Fedora 21 testing repository,
* should be available at your local mirror within two days.
Update it with:
# su -c 'yum update --enablerepo=updates-testing libreoffice-4.3.7.2-4.fc21'
as soon as you are able to.
Please go to the following url:
https://admin.fedoraproject.org/updates/FEDORA-2015-7549/libreoffice-4.3.7.2-4.fc21
then log in and leave karma (feedback).

Comment 16 Fedora Update System 2015-05-12 20:40:14 UTC
libreoffice-4.3.7.2-4.fc21 has been pushed to the Fedora 21 stable repository.  If problems still persist, please make note of it in this bug report.