Bug 1384739 - gnome-shell segv in wl_resource_post_event
Summary: gnome-shell segv in wl_resource_post_event
Keywords:
Status: CLOSED EOL
Alias: None
Product: Fedora
Classification: Fedora
Component: gnome-shell
Version: 25
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
Assignee: Owen Taylor
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2016-10-14 03:00 UTC by Zbigniew Jędrzejewski-Szmek
Modified: 2017-12-12 10:58 UTC (History)
2 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2017-12-12 10:58:21 UTC
Type: Bug


Attachments (Terms of Use)

Description Zbigniew Jędrzejewski-Szmek 2016-10-14 03:00:57 UTC
This started happening regularly after today's update:
gnome-shell-3.22.0-1.fc25.x86_64
It happens a few seconds after I switch to a different console and back.

Unfortunately abrt does not report the backtrace for some reason. I'm providing the bactrace from coredumpctl instead:

Core was generated by `/usr/bin/gnome-shell'.
Program terminated with signal SIGSEGV, Segmentation fault.
#0  0x00007f33b3412e19 in wl_resource_post_event (resource=resource@entry=0xffffffffffffffe0, opcode=opcode@entry=2) at src/wayland-server.c:194
194		wl_argument_from_va_list(object->interface->events[opcode].signature,
[Current thread is 1 (Thread 0x7f33bd759b80 (LWP 7139))]

(gdb) bt
#0  0x00007f33b3412e19 in wl_resource_post_event (resource=resource@entry=0xffffffffffffffe0, opcode=opcode@entry=2) at src/wayland-server.c:194
#1  0x00007f33b84663b7 in wl_pointer_send_motion (surface_y=<optimized out>, surface_x=<optimized out>, time=5528744, resource_=0xffffffffffffffe0) at /usr/include/wayland-server-protocol.h:3423
#2  0x00007f33b84663b7 in meta_wayland_pointer_send_motion (pointer=0x5575427eb1b0 [MetaWaylandPointer], event=0x7f336c00d5c0) at wayland/meta-wayland-pointer.c:339
#3  0x00007f33b8466b3a in notify_motion (event=0x7f336c00d5c0, pointer=0x5575427eb1b0 [MetaWaylandPointer]) at wayland/meta-wayland-pointer.c:558
#4  0x00007f33b8466b3a in handle_motion_event (event=0x7f336c00d5c0, pointer=0x5575427eb1b0 [MetaWaylandPointer]) at wayland/meta-wayland-pointer.c:565
#5  0x00007f33b8466b3a in meta_wayland_pointer_handle_event (pointer=0x5575427eb1b0 [MetaWaylandPointer], event=event@entry=0x7f336c00d5c0) at wayland/meta-wayland-pointer.c:711
#6  0x00007f33b846a40a in meta_wayland_seat_handle_event (seat=<optimized out>, event=event@entry=0x7f336c00d5c0) at wayland/meta-wayland-seat.c:360
#7  0x00007f33b845da4a in meta_wayland_compositor_handle_event (compositor=compositor@entry=0x7f33b86e0080 <_meta_wayland_compositor>, event=event@entry=0x7f336c00d5c0) at wayland/meta-wayland.c:208
#8  0x00007f33b8428dbf in meta_display_handle_event (event=0x7f336c00d5c0, display=0x557542928080 [MetaDisplay]) at core/events.c:386
#9  0x00007f33b8428dbf in event_callback (event=0x7f336c00d5c0, data=0x557542928080) at core/events.c:401
#10 0x00007f33b74d922d in _clutter_event_process_filters (event=event@entry=0x7f336c00d5c0) at clutter-event.c:1913
#11 0x00007f33b74ebb13 in emit_pointer_event (device=0x5575428570b0 [ClutterInputDeviceEvdev], event=0x7f336c00d5c0) at clutter-main.c:2011
#12 0x00007f33b74ebb13 in _clutter_process_event_details (context=0x55754270eef0, event=0x7f336c00d5c0, stage=<optimized out>) at clutter-main.c:2372
#13 0x00007f33b74ebb13 in _clutter_process_event (event=event@entry=0x7f336c00d5c0) at clutter-main.c:2548
#14 0x00007f33b7501fa9 in _clutter_stage_process_queued_events (stage=0x557542853810 [MetaStage]) at clutter-stage.c:1026
#15 0x00007f33b74edc99 in master_clock_process_events (master_clock=0x55754287b700 [ClutterMasterClockDefault], stages=<optimized out>) at clutter-master-clock-default.c:364
#16 0x00007f33b74edc99 in clutter_clock_dispatch (source=<optimized out>, callback=<optimized out>, user_data=<optimized out>) at clutter-master-clock-default.c:561
#17 0x00007f33b3a85e82 in g_main_dispatch (context=0x5575426afde0) at gmain.c:3201
#18 0x00007f33b3a85e82 in g_main_context_dispatch (context=context@entry=0x5575426afde0) at gmain.c:3854
#19 0x00007f33b3a86200 in g_main_context_iterate (context=0x5575426afde0, block=block@entry=1, dispatch=dispatch@entry=1, self=<optimized out>) at gmain.c:3927
#20 0x00007f33b3a86522 in g_main_loop_run (loop=0x557542880110) at gmain.c:4123
#21 0x00007f33b842fc9c in meta_run () at core/main.c:572
#22 0x00005575408fb657 in main (argc=<optimized out>, argv=<optimized out>) at main.c:471


(gdb) bt full
#0  0x00007f33b3412e19 in wl_resource_post_event (resource=resource@entry=0xffffffffffffffe0, opcode=opcode@entry=2) at src/wayland-server.c:194
        args = {{i = -1744756160, u = 2550211136, f = -1744756160, s = 0x7f3398012240 "\360\210\207BuU", o = 0x7f3398012240, n = 2550211136, a = 0x7f3398012240, h = -1744756160}, {i = -1219840513, u = 3075126783, f = -1219840513, s = 0x7f33b74ab5ff <_clutter_actor_transform_and_project_box+127> "H\213L$8dH3\f%(", o = 0x7f33b74ab5ff <_clutter_actor_transform_and_project_box+127>, n = 3075126783, a = 0x7f33b74ab5ff <_clutter_actor_transform_and_project_box+127>, h = -1219840513}, {i = 0, u = 0, f = 0, s = 0x0, o = 0x0, n = 0, a = 0x0, h = 0}, {i = 0, u = 0, f = 0, s = 0x448d400000000000 <error: Cannot access memory at address 0x448d400000000000>, o = 0x448d400000000000, n = 0, a = 0x448d400000000000, h = 0}, {i = 0, u = 0, f = 0, s = 0x0, o = 0x0, n = 0, a = 0x0, h = 0}, {i = 0, u = 0, f = 0, s = 0x4455800000000000 <error: Cannot access memory at address 0x4455800000000000>, o = 0x4455800000000000, n = 0, a = 0x4455800000000000, h = 0}, {i = 0, u = 0, f = 0, s = 0x448d400000000000 <error: Cannot access memory at address 0x448d400000000000>, o = 0x448d400000000000, n = 0, a = 0x448d400000000000, h = 0}, {i = 1146454016, u = 1146454016, f = 1146454016, s = 0x44558000 <error: Cannot access memory at address 0x44558000>, o = 0x44558000, n = 1146454016, a = 0x44558000, h = 1146454016}, {i = 1116095520, u = 1116095520, f = 1116095520, s = 0x557542864420 "", o = 0x557542864420, n = 1116095520, a = 0x557542864420, h = 1116095520}, {i = -810830848, u = 3484136448, f = -810830848, s = 0xf8a7686acfabb400 <error: Cannot access memory at address 0xf8a7686acfabb400>, o = 0xf8a7686acfabb400, n = 3484136448, a = 0xf8a7686acfabb400, h = -810830848}, {i = 1158645872, u = 1158645872, f = 1158645872, s = 0x5575450f8870 "", o = 0x5575450f8870, n = 1158645872, a = 0x5575450f8870, h = 1158645872}, {i = -1219840232, u = 3075127064, f = -1219840232, s = 0x7f33b74ab718 <clutter_actor_get_abs_allocation_vertices+248> "\351c\377\377\377\350\006N\376\377\017\037@", o = 0x7f33b74ab718 <clutter_actor_get_abs_allocation_vertices+248>, n = 3075127064, a = 0x7f33b74ab718 <clutter_actor_get_abs_allocation_vertices+248>, h = -1219840232}, {i = 0, u = 0, f = 0, s = 0x0, o = 0x0, n = 0, a = 0x0, h = 0}, {i = 1150107648, u = 1150107648, f = 1150107648, s = 0x44558000448d4000 <error: Cannot access memory at address 0x44558000448d4000>, o = 0x44558000448d4000, n = 1150107648, a = 0x44558000448d4000, h = 1150107648}, {i = 1116095600, u = 1116095600, f = 1116095600, s = 0x557542864470 " \204\207BuU", o = 0x557542864470, n = 1116095600, a = 0x557542864470, h = 1116095600}, {i = -810830848, u = 3484136448, f = -810830848, s = 0xf8a7686acfabb400 <error: Cannot access memory at address 0xf8a7686acfabb400>, o = 0xf8a7686acfabb400, n = 3484136448, a = 0xf8a7686acfabb400, h = -810830848}, {i = 1158646672, u = 1158646672, f = 1158646672, s = 0x5575450f8b90 "\200\220\210BuU", o = 0x5575450f8b90, n = 1158646672, a = 0x5575450f8b90, h = 1158646672}, {i = 1158645872, u = 1158645872, f = 1158645872, s = 0x5575450f8870 "", o = 0x5575450f8870, n = 1158645872, a = 0x5575450f8870, h = 1158645872}, {i = 464558148, u = 464558148, f = 464558148, s = 0x7ffc1bb09844 "SJ\034D", o = 0x7ffc1bb09844, n = 464558148, a = 0x7ffc1bb09844, h = 464558148}, {i = -1219837101, u = 3075130195, f = -1219837101, s = 0x7f33b74ac353 <clutter_actor_transform_stage_point+179> "\363\017,Ѕ\333\017\204\241\003", o = 0x7f33b74ac353 <clutter_actor_transform_stage_point+179>, n = 3075130195, a = 0x7f33b74ac353 <clutter_actor_transform_stage_point+179>, h = -1219837101}}
        object = 0xffffffffffffffe0
        ap = {{gp_offset = 464557936, fp_offset = 32764, overflow_arg_area = 0x7ffc1bb09840, reg_save_area = 0x1}}
#1  0x00007f33b84663b7 in wl_pointer_send_motion (surface_y=<optimized out>, surface_x=<optimized out>, time=5528744, resource_=0xffffffffffffffe0) at /usr/include/wayland-server-protocol.h:3423
        resource = 0xffffffffffffffe0
        time = 5528744
        sx = 133.328918
        sy = 625.161316
        event = 0x7f336c00d5c0
        pointer = 0x5575427eb1b0 [MetaWaylandPointer]
#2  0x00007f33b84663b7 in meta_wayland_pointer_send_motion (pointer=0x5575427eb1b0 [MetaWaylandPointer], event=0x7f336c00d5c0) at wayland/meta-wayland-pointer.c:339
        resource = 0xffffffffffffffe0
        time = 5528744
        sx = 133.328918
        sy = 625.161316
        event = 0x7f336c00d5c0
        pointer = 0x5575427eb1b0 [MetaWaylandPointer]
#3  0x00007f33b8466b3a in notify_motion (event=0x7f336c00d5c0, pointer=0x5575427eb1b0 [MetaWaylandPointer]) at wayland/meta-wayland-pointer.c:558
#4  0x00007f33b8466b3a in handle_motion_event (event=0x7f336c00d5c0, pointer=0x5575427eb1b0 [MetaWaylandPointer]) at wayland/meta-wayland-pointer.c:565
#5  0x00007f33b8466b3a in meta_wayland_pointer_handle_event (pointer=0x5575427eb1b0 [MetaWaylandPointer], event=event@entry=0x7f336c00d5c0) at wayland/meta-wayland-pointer.c:711
#6  0x00007f33b846a40a in meta_wayland_seat_handle_event (seat=<optimized out>, event=event@entry=0x7f336c00d5c0) at wayland/meta-wayland-seat.c:360
#7  0x00007f33b845da4a in meta_wayland_compositor_handle_event (compositor=compositor@entry=0x7f33b86e0080 <_meta_wayland_compositor>, event=event@entry=0x7f336c00d5c0) at wayland/meta-wayland.c:208
#8  0x00007f33b8428dbf in meta_display_handle_event (event=0x7f336c00d5c0, display=0x557542928080 [MetaDisplay]) at core/events.c:386
        bypass_clutter = 1
        bypass_wayland = <optimized out>
        tracker = <optimized out>
        sequence = <optimized out>
        source = <optimized out>
        compositor = 0x7f33b86e0080 <_meta_wayland_compositor>
        display = 0x557542928080 [MetaDisplay]
#9  0x00007f33b8428dbf in event_callback (event=0x7f336c00d5c0, data=0x557542928080) at core/events.c:401
        display = 0x557542928080 [MetaDisplay]
#10 0x00007f33b74d922d in _clutter_event_process_filters (event=event@entry=0x7f336c00d5c0) at clutter-event.c:1913
        event_filter = <optimized out>
        context = <optimized out>
        l = <optimized out>
        next = 0x0
#11 0x00007f33b74ebb13 in emit_pointer_event (device=0x5575428570b0 [ClutterInputDeviceEvdev], event=0x7f336c00d5c0) at clutter-main.c:2011
        context = <optimized out>
        actor = <optimized out>
        x = 107.328941
        y = 668.161316
        device = 0x5575428570b0 [ClutterInputDeviceEvdev]
        context = 0x55754270eef0
        stage = <optimized out>
#12 0x00007f33b74ebb13 in _clutter_process_event_details (context=0x55754270eef0, event=0x7f336c00d5c0, stage=<optimized out>) at clutter-main.c:2372
        actor = <optimized out>
        x = 107.328941
        y = 668.161316
        device = 0x5575428570b0 [ClutterInputDeviceEvdev]
        context = 0x55754270eef0
        stage = <optimized out>
#13 0x00007f33b74ebb13 in _clutter_process_event (event=event@entry=0x7f336c00d5c0) at clutter-main.c:2548
        context = 0x55754270eef0
        stage = <optimized out>
#14 0x00007f33b7501fa9 in _clutter_stage_process_queued_events (stage=0x557542853810 [MetaStage]) at clutter-stage.c:1026
        next_event = <optimized out>
        device = <optimized out>
        event = 0x7f336c00d5c0
        next_device = <optimized out>
        check_device = 0
        priv = 0x557542853210
        events = 0x557542b4fec0 = {0x7f336c00d5c0}
        l = 0x557542b4fec0 = {0x7f336c00d5c0}
        __func__ = "_clutter_stage_process_queued_events"
#15 0x00007f33b74edc99 in master_clock_process_events (master_clock=0x55754287b700 [ClutterMasterClockDefault], stages=<optimized out>) at clutter-master-clock-default.c:364
        l = 0x557543d69ca0 = {0x557542853810}
        clock_source = <optimized out>
        master_clock = 0x55754287b700 [ClutterMasterClockDefault]
        stages_updated = 0
#16 0x00007f33b74edc99 in clutter_clock_dispatch (source=<optimized out>, callback=<optimized out>, user_data=<optimized out>) at clutter-master-clock-default.c:561
        clock_source = <optimized out>
        master_clock = 0x55754287b700 [ClutterMasterClockDefault]
        stages_updated = 0
#17 0x00007f33b3a85e82 in g_main_dispatch (context=0x5575426afde0) at gmain.c:3201
        dispatch = 0x7f33b74edbe0 <clutter_clock_dispatch>
        prev_source = 0x0
        was_in_call = 0
        user_data = 0x0
        callback = 0x0
        cb_funcs = 0x0
        cb_data = 0x0
        need_destroy = <optimized out>
        source = 0x557542880630
        current = 0x5575426be830
        i = 0
#18 0x00007f33b3a85e82 in g_main_context_dispatch (context=context@entry=0x5575426afde0) at gmain.c:3854
#19 0x00007f33b3a86200 in g_main_context_iterate (context=0x5575426afde0, block=block@entry=1, dispatch=dispatch@entry=1, self=<optimized out>) at gmain.c:3927
        max_priority = 150
        timeout = 0
        some_ready = 1
        nfds = 17
        allocated_nfds = 17
        fds = <optimized out>
#20 0x00007f33b3a86522 in g_main_loop_run (loop=0x557542880110) at gmain.c:4123
        __func__ = "g_main_loop_run"
#21 0x00007f33b842fc9c in meta_run () at core/main.c:572
#22 0x00005575408fb657 in main (argc=<optimized out>, argv=<optimized out>) at main.c:471
        ctx = <optimized out>
        error = 0x0
        ecode = <optimized out>
        sender = 0x7f3398011d70 [TpDebugSender]

$ lspci | grep VGA
01:00.0 VGA compatible controller: Advanced Micro Devices, Inc. [AMD/ATI] RV620/M82 [Mobility Radeon HD 3450/3470]
$ uname -r
4.8.0-0.rc7.git0.1.fc25.x86_64

Comment 1 Zbigniew Jędrzejewski-Szmek 2016-10-14 03:15:56 UTC
Same with gnome-shell-3.22.1-1.fc25.x86_64.

Comment 2 Fedora End Of Life 2017-11-16 18:57:25 UTC
This message is a reminder that Fedora 25 is nearing its end of life.
Approximately 4 (four) weeks from now Fedora will stop maintaining
and issuing updates for Fedora 25. It is Fedora's policy to close all
bug reports from releases that are no longer maintained. At that time
this bug will be closed as EOL if it remains open with a Fedora  'version'
of '25'.

Package Maintainer: If you wish for this bug to remain open because you
plan to fix it in a currently maintained version, simply change the 'version'
to a later Fedora version.

Thank you for reporting this issue and we are sorry that we were not
able to fix it before Fedora 25 is end of life. If you would still like
to see this bug fixed and are able to reproduce it against a later version
of Fedora, you are encouraged  change the 'version' to a later Fedora
version prior this bug is closed as described in the policy above.

Although we aim to fix as many bugs as possible during every release's
lifetime, sometimes those efforts are overtaken by events. Often a
more recent Fedora release includes newer upstream software that fixes
bugs or makes them obsolete.

Comment 3 Fedora End Of Life 2017-12-12 10:58:21 UTC
Fedora 25 changed to end-of-life (EOL) status on 2017-12-12. Fedora 25 is
no longer maintained, which means that it will not receive any further
security or bug fix updates. As a result we are closing this bug.

If you can reproduce this bug against a currently maintained version of
Fedora please feel free to reopen this bug against that version. If you
are unable to reopen this bug, please file a new report against the
current release. If you experience problems, please add a comment to this
bug.

Thank you for reporting this bug and we are sorry it could not be fixed.


Note You need to log in before you can comment on or make changes to this bug.