Bug 238580 - New libX11 triggers seg fault in rdesktop
New libX11 triggers seg fault in rdesktop
Status: CLOSED WONTFIX
Product: Fedora
Classification: Fedora
Component: rdesktop (Show other bugs)
5
All Linux
medium Severity medium
: ---
: ---
Assigned To: David Zeuthen
:
Depends On: 236006
Blocks:
  Show dependency treegraph
 
Reported: 2007-05-01 12:34 EDT by David Zeuthen
Modified: 2013-03-05 22:50 EST (History)
6 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2008-02-18 11:13:14 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description David Zeuthen 2007-05-01 12:34:35 EDT
+++ This bug was initially created as a clone of Bug #236006 +++

Description of problem:
I have just updated to libX11-1.0.3-7.fc6 from libX11-1.0.3-6.fc6 and rdesktop
has stopped working, giving a Segmentation fault when I log in to the remote
system. I have obtained a core dump
#0  0x4820a2b2 in XPutImage () from /usr/lib/libX11.so.6
#1  0x0805155c in ui_desktop_restore (offset=0, x=303, y=144, cx=417, cy=263)
    at xwin.c:3226
#2  0x080633d0 in process_orders (s=0x80b5f20, num_orders=152) at orders.c:375
#3  0x080685f9 in rdp5_process (s=0x80b5f20) at rdp5.c:85
#4  0x08060311 in rdp_recv (type=0xbff77ceb "") at rdp.c:99
#5  0x080608d8 in rdp_loop (deactivated=0xbff78084, ext_disc_reason=0xbff78080)
    at rdp.c:1378
#6  0x080614ec in rdp_main_loop (deactivated=0xbff78084, 
    ext_disc_reason=0xbff78080) at rdp.c:1363
#7  0x0804d2f5 in main (argc=1, argv=Cannot access memory at address 0x5
) at rdesktop.c:912
which suggests the problem is in XPutImage.

-- Additional comment from mcepl@redhat.com on 2007-04-11 11:23 EST --
Thanks for the bug report.  We have reviewed the information you have provided
above, and there is some additional information we require that will be helpful
in our diagnosis of this issue.

Please attach your X server config file (/etc/X11/xorg.conf) and X server log
file (/var/log/Xorg.*.log) to the bug report as individual uncompressed file
attachments using the bugzilla file attachment link below.

Could you please also try to run without any /etc/X11/xorg.conf whatsoever and
let X11 autodetect your display and video card? Attach to this bug
/var/log/Xorg.0.log from this attempt as well, please.

We will review this issue again once you've had a chance to attach this information.

Thanks in advance.


-- Additional comment from M.A.Young@durham.ac.uk on 2007-04-11 12:22 EST --
Created an attachment (id=152285)
xorg.conf that triggers the bug

Here are the files you asked for. My testing while generating these files
indicates that the seg fault occurs when the colour depth is 16-bit, but
rdesktop runs successfully when the colour depth is 24-bit. Running without an
xorg.conf doesn't work as X isn't started.

-- Additional comment from M.A.Young@durham.ac.uk on 2007-04-11 12:23 EST --
Created an attachment (id=152286)
Xorg.0.log when the bug is triggered


-- Additional comment from M.A.Young@durham.ac.uk on 2007-04-11 12:24 EST --
Created an attachment (id=152287)
Xorg.0.log when X is run without an xorg.conf file (fails to start)


-- Additional comment from M.A.Young@durham.ac.uk on 2007-04-11 12:35 EST --
Note that the remote desktop being contacted is 16-bit, as the WARNING message
WARNING: Remote desktop does not support colour depth 24; falling back to 16
is displayed when rdesktop is run from a 24-bit colour X session.

-- Additional comment from ajackson@redhat.com on 2007-04-13 09:35 EST --
Can you install libX11-debuginfo and repeat the backtrace from gdb please? 
Would be good to see exactly what's segfaulting in libX11.

Since 1.0.3-7 was a security fix only relative to -6, I rather suspect that this
is a bug in rdesktop that's always been there and is only now exposed.

-- Additional comment from M.A.Young@durham.ac.uk on 2007-04-13 09:49 EST --
With libX11-debuginfo installed #0 of the above core is now
#0  0x4820a2b2 in XPutImage (dpy=0x8f606a0, d=41943045, gc=0x8f73688, 
    image=0x0, req_xoffset=0, req_yoffset=0, x=303, y=144, req_width=417, 
    req_height=263) at PutImage.c:967

-- Additional comment from M.A.Young@durham.ac.uk on 2007-04-13 10:10 EST --
As image=0x0 (ie. null pointer), it might be useful to note that the code in
rdesktop (xwin.c) leading up to this call to the library is
ui_desktop_restore(uint32 offset, int x, int y, int cx, int cy)
{
        XImage *image;
        uint8 *data;

        offset *= g_bpp / 8;
        data = cache_get_desktop(offset, cx, cy, g_bpp / 8);
        if (data == NULL)
                return;

        image = XCreateImage(g_display, g_visual, g_depth, ZPixmap, 0,
                             (char *) data, cx, cy, BitmapPad(g_display), cx *
g_bpp / 8);

        if (g_ownbackstore)
        {
                XPutImage(g_display, g_backstore, g_gc, image, 0, 0, x, y, cx, cy);

-- Additional comment from bitmage@bellsouth.net on 2007-04-20 09:46 EST --
Happening here too on FC5 after updating to libX11.i386 1.0.0-4.fc5.  Core dumps
after the colour depth warning.  Let me know if you want me to open this as a
separate bug against FC5.



-- Additional comment from bitmage@bellsouth.net on 2007-04-20 10:11 EST --
The problem may be related to this?
http://www.nabble.com/Bug-418098:--PATCH--rdesktop-segfault-with-libx11-6-1.0.3-7-t3560107.html

-- Additional comment from ajackson@redhat.com on 2007-04-24 14:25 EST --
Looks like it to me.  Reassigning to rdesktop.

-- Additional comment from davidz@redhat.com on 2007-04-26 12:52 EST --
rdesktop-1.5.0-2.fc6 packages are on it's way as soon as rel-eng gets around to
pushing them.

-- Additional comment from updates@fedora.redhat.com on 2007-04-27 01:59 EST --
rdesktop-1.5.0-2.fc6 has been pushed for fc6, which should resolve this issue. 
If these problems are still present in this version, then please make note of it
in this bug report.

-- Additional comment from bitmage@bellsouth.net on 2007-05-01 11:10 EST --
Will there be any fix for FC5 users?
Comment 1 Adam Jackson 2008-02-18 11:13:14 EST
Couldn't build anything for FC5 if I wanted to anymore.  Closing. 

Note You need to log in before you can comment on or make changes to this bug.