Bug 487534 - reproducible crash: *** glibc detected *** /usr/bin/Xorg: double free or corruption (!prev): 0x09485 8b0 ***
Summary: reproducible crash: *** glibc detected *** /usr/bin/Xorg: double free or corr...
Keywords:
Status: CLOSED WONTFIX
Alias: None
Product: Fedora
Classification: Fedora
Component: xorg-x11-drv-ati
Version: 10
Hardware: All
OS: Linux
low
high
Target Milestone: ---
Assignee: Dave Airlie
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2009-02-26 16:08 UTC by Charles R. Anderson
Modified: 2009-12-18 08:03 UTC (History)
2 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2009-12-18 08:03:48 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)
full Xorg backtrace from glibc (3.93 KB, text/plain)
2009-02-26 16:08 UTC, Charles R. Anderson
no flags Details
Xorg.0.log from crash (180.84 KB, text/plain)
2009-02-26 16:10 UTC, Charles R. Anderson
no flags Details
xorg.conf (725 bytes, text/plain)
2009-02-26 16:12 UTC, Charles R. Anderson
no flags Details
Xorg.0.log from session that crashed (42.71 KB, application/octet-stream)
2009-04-13 13:08 UTC, Basil Mohamed Gohar
no flags Details
.xsession-errors.old also seems to have some information related to the crash (81.22 KB, application/octet-stream)
2009-04-13 13:10 UTC, Basil Mohamed Gohar
no flags Details

Description Charles R. Anderson 2009-02-26 16:08:20 UTC
Created attachment 333343 [details]
full Xorg backtrace from glibc

Description of problem:

Xorg crashes when resizing all columns in a OpenOffice Calc sheet.  I'm using the radeon driver with KMS modesetting in dual-head mode, two 1600x1200 LCD monitors side-by-side connected to DVI ports of a Radeon X600 PCI Express card.

Version-Release number of selected component (if applicable):
xorg-x11-drv-ati-6.10.0-2.fc10.i386
xorg-x11-server-Xorg-1.5.3-13.fc10.i386
openoffice.org-calc-3.0.1-15.2.fc10.i386

How reproducible:
always

Steps to Reproduce:
1. Open OpenOffice Calc with a new blank document (oocalc)
2. Click the box at the upper left to select the entire sheet's cells
3. Double-click the resize-bar between the "A" and "B" column headers
[This causes oocalc to resize all columns to fit the contents of the widest cell in each column.  The fact that the sheet is completely empty is irrelevant for this reproduction.]
4. Xorg crashes.
  
Actual results:

On the tty where Xorg had been running, I see these error messages (cut and pasted using gpm, then cleaned up stair stepping):

*** glibc detected *** /usr/bin/Xorg: double free or corruption (!prev): 0x094858b0 ***
                                                                                       
======= Backtrace: =========
/lib/libc.so.6[0x3003a4]
/lib/libc.so.6(cfree+0x96)[0x302356]
/usr/bin/Xorg(Xfree+0x21)[0x812fd91]
/usr/lib/xorg/modules/drivers//radeon_drv.so(RADEONCSReleaseIndirect+0x4a)[0x5d34da]
/usr/lib/xorg/modules/drivers//radeon_drv.so(RADEONCPReleaseIndirect+0xa0)[0x5d35d0]
/usr/lib/xorg/modules/drivers//radeon_drv.so[0x61f573]
/usr/lib/xorg/modules/extensions//libdri.so(DRIDoBlockHandler+0xe0)[0xd1db30]
/usr/lib/xorg/modules/extensions//libdri.so(DRIBlockHandler+0x6b)[0xd1cccb]
/usr/bin/Xorg(BlockHandler+0x94)[0x8089b04]
/usr/bin/Xorg(WaitForSomething+0x10d)[0x812901d]
/usr/bin/Xorg(Dispatch+0x7e)[0x8085bce]
/usr/bin/Xorg(main+0x47d)[0x806b71d]
/lib/libc.so.6(__libc_start_main+0xe5)[0x2a76e5]
/usr/bin/Xorg[0x806ab01]


Expected results:
no crash

Additional info:

01:00.1 Display controller: ATI Technologies Inc RV380 [Radeon X600]

Comment 1 Charles R. Anderson 2009-02-26 16:10:04 UTC
Created attachment 333344 [details]
Xorg.0.log from crash

Comment 2 Charles R. Anderson 2009-02-26 16:12:49 UTC
Created attachment 333345 [details]
xorg.conf

Comment 3 Charles R. Anderson 2009-02-26 16:13:36 UTC
Possibly interesting kernel messages:

Feb 26 10:35:47 dustpuppy kernel: mtrr: base(0xe2f2b000) is not aligned on a size(0x1388000) boundary
Feb 26 10:39:04 dustpuppy kernel: [drm] TMDS-10: set mode 1600x1200 22
Feb 26 10:39:04 dustpuppy kernel: mtrr: base(0xe2f2b000) is not aligned on a size(0x1388000) boundary

Comment 4 Basil Mohamed Gohar 2009-04-13 13:05:12 UTC
I've had the exact same problem happen to me.  I'll upload some files that are, hopefully, helpful.

Comment 5 Basil Mohamed Gohar 2009-04-13 13:08:56 UTC
Created attachment 339314 [details]
Xorg.0.log from session that crashed

This is the Xorg.0.log file from the session that crashed.  You can see all the action at the end of the file.

Comment 6 Basil Mohamed Gohar 2009-04-13 13:10:02 UTC
Created attachment 339315 [details]
.xsession-errors.old also seems to have some information related to the crash

Comment 7 Basil Mohamed Gohar 2009-04-13 13:11:41 UTC
By the way, this is happening on rawhide today.  I just updated a few hours ago.  Here is my video card:

01:00.0 VGA compatible controller: ATI Technologies Inc RV350 [Mobility Radeon 9600 M10]

Comment 8 Bug Zapper 2009-11-18 09:53:05 UTC
This message is a reminder that Fedora 10 is nearing its end of life.
Approximately 30 (thirty) days from now Fedora will stop maintaining
and issuing updates for Fedora 10.  It is Fedora's policy to close all
bug reports from releases that are no longer maintained.  At that time
this bug will be closed as WONTFIX if it remains open with a Fedora 
'version' of '10'.

Package Maintainer: If you wish for this bug to remain open because you
plan to fix it in a currently maintained version, simply change the 'version' 
to a later Fedora version prior to Fedora 10's end of life.

Bug Reporter: Thank you for reporting this issue and we are sorry that 
we may not be able to fix it before Fedora 10 is end of life.  If you 
would still like to see this bug fixed and are able to reproduce it 
against a later version of Fedora please change the 'version' of this 
bug to the applicable version.  If you are unable to change the version, 
please add a comment here and someone will do it for you.

Although we aim to fix as many bugs as possible during every release's 
lifetime, sometimes those efforts are overtaken by events.  Often a 
more recent Fedora release includes newer upstream software that fixes 
bugs or makes them obsolete.

The process we are following is described here: 
http://fedoraproject.org/wiki/BugZappers/HouseKeeping

Comment 9 Bug Zapper 2009-12-18 08:03:48 UTC
Fedora 10 changed to end-of-life (EOL) status on 2009-12-17. Fedora 10 is 
no longer maintained, which means that it will not receive any further 
security or bug fix updates. As a result we are closing this bug.

If you can reproduce this bug against a currently maintained version of 
Fedora please feel free to reopen this bug against that version.

Thank you for reporting this bug and we are sorry it could not be fixed.


Note You need to log in before you can comment on or make changes to this bug.