Bug 1260350
Summary: | [abrt] gimp: gimp_id_table_remove(): gimp-2.8 killed by SIGSEGV | ||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Product: | [Fedora] Fedora | Reporter: | Brandon Amaro <omega13a> | ||||||||||||||||||||||||||
Component: | gimp | Assignee: | Nils Philippsen <nphilipp> | ||||||||||||||||||||||||||
Status: | CLOSED INSUFFICIENT_DATA | QA Contact: | Fedora Extras Quality Assurance <extras-qa> | ||||||||||||||||||||||||||
Severity: | unspecified | Docs Contact: | |||||||||||||||||||||||||||
Priority: | unspecified | ||||||||||||||||||||||||||||
Version: | 22 | CC: | nphilipp, omega13a, phracek | ||||||||||||||||||||||||||
Target Milestone: | --- | ||||||||||||||||||||||||||||
Target Release: | --- | ||||||||||||||||||||||||||||
Hardware: | x86_64 | ||||||||||||||||||||||||||||
OS: | Unspecified | ||||||||||||||||||||||||||||
URL: | https://retrace.fedoraproject.org/faf/reports/bthash/e735394a7e8a7beb51a1bb2a7ccf8f973e33433e | ||||||||||||||||||||||||||||
Whiteboard: | abrt_hash:866414a78faffd72be38adf7691a05d6fa1273cf | ||||||||||||||||||||||||||||
Fixed In Version: | Doc Type: | Bug Fix | |||||||||||||||||||||||||||
Doc Text: | Story Points: | --- | |||||||||||||||||||||||||||
Clone Of: | Environment: | ||||||||||||||||||||||||||||
Last Closed: | 2016-06-03 11:55:55 UTC | Type: | --- | ||||||||||||||||||||||||||
Regression: | --- | Mount Type: | --- | ||||||||||||||||||||||||||
Documentation: | --- | CRM: | |||||||||||||||||||||||||||
Verified Versions: | Category: | --- | |||||||||||||||||||||||||||
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||||||||||||||||||||||||
Cloudforms Team: | --- | Target Upstream Version: | |||||||||||||||||||||||||||
Embargoed: | |||||||||||||||||||||||||||||
Attachments: |
|
Description
Brandon Amaro
2015-09-06 06:38:08 UTC
Created attachment 1070645 [details]
File: backtrace
Created attachment 1070646 [details]
File: cgroup
Created attachment 1070647 [details]
File: core_backtrace
Created attachment 1070648 [details]
File: dso_list
Created attachment 1070649 [details]
File: environ
Created attachment 1070650 [details]
File: limits
Created attachment 1070651 [details]
File: maps
Created attachment 1070652 [details]
File: mountinfo
Created attachment 1070653 [details]
File: namespaces
Created attachment 1070654 [details]
File: open_fds
Created attachment 1070655 [details]
File: proc_pid_status
Created attachment 1070656 [details]
File: var_log_messages
What did you do when this crash happened? Can you reproduce it? Note to self: The id_table pointer in this function call looks very suspicious (2^33, "8 Giga"). Thread 1 (Thread 0x7fa2448c6980 (LWP 6018)): #0 0x00005644acf04065 in gimp_id_table_remove (id_table=0x200000000, id=152) at gimpidtable.c:231 __inst = 0x200000000 __t = 94852996996928 __r = <optimized out> __func__ = "gimp_id_table_remove" The affected gimp->item_table member is only ever written directly in two places: app/core/gimp.c:226: gimp->item_table = gimp_id_table_new (); app/core/gimp.c:419: g_object_unref (gimp->item_table); app/core/gimp.c:420: gimp->item_table = NULL; So it's probably one of these, but it's nigh impossible to debug without being able to reproduce it: - something overwrites the struct member through bad boundary checking or whatever - one bit flipped in memory (HW fault) The needinfo request[s] on this closed bug have been removed as they have been unresolved for 1000 days |