Bug 531083 - Segmentation fault upon compose new mail message
Summary: Segmentation fault upon compose new mail message
Keywords:
Status: CLOSED WONTFIX
Alias: None
Product: Fedora
Classification: Fedora
Component: thunderbird
Version: 11
Hardware: All
OS: Linux
low
high
Target Milestone: ---
Assignee: Martin Stransky
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
: 558112 (view as bug list)
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2009-10-26 20:15 UTC by Edwin ten Brink
Modified: 2018-04-11 11:45 UTC (History)
4 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2010-06-28 15:19:53 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)
gdb backtrace of segmentation fault (21.12 KB, text/plain)
2009-10-26 20:15 UTC, Edwin ten Brink
no flags Details
Output of valgrind as requested (1.29 KB, text/plain)
2009-10-27 19:20 UTC, Edwin ten Brink
no flags Details
Output of valgrind rerun with --leak-check=full (60.63 KB, text/plain)
2009-10-27 19:21 UTC, Edwin ten Brink
no flags Details
Output of valgrind rerun with --trace-children=yes --leak-check=full (48.35 KB, text/plain)
2009-11-12 18:13 UTC, Edwin ten Brink
no flags Details

Description Edwin ten Brink 2009-10-26 20:15:08 UTC
Created attachment 366153 [details]
gdb backtrace of segmentation fault

Description of problem:
Thunderbird crashes when a new message is composed.


Version-Release number of selected component (if applicable):
$ rpm -qa *xulrun* *thunderbird* *mozilla* *flash* *plugin* | sort
alsa-plugins-pulseaudio-1.0.21-2.fc11.i586
anaconda-yum-plugins-1.0-4.fc11.noarch
flash-plugin-10.0.32.18-release.i386
gedit-plugins-2.26.1-1.fc11.i586
gstreamer-plugins-base-0.10.25-1.fc11.i586
gstreamer-plugins-good-0.10.15-4.fc11.i586
java-1.6.0-openjdk-plugin-1.6.0.0-29.b16.fc11.i586
java-1.6.0-sun-plugin-1.6.0.14-1jpp.i586
mozilla-filesystem-1.9-4.fc11.i586
PackageKit-yum-plugin-0.4.9-1.fc11.i586
plymouth-plugin-label-0.7.0-0.2009.05.15.1.fc11.i586
plymouth-plugin-space-flares-0.7.0-0.2009.05.15.1.fc11.i586
plymouth-plugin-two-step-0.7.0-0.2009.05.15.1.fc11.i586
setroubleshoot-plugins-2.0.18-5.fc11.noarch
thunderbird-3.0-2.8.b4.fc11.i586
xulrunner-1.9.1.3-1.fc11.i586
xulrunner-debuginfo-1.9.1.2-1.fc11.i586
yum-plugin-fastestmirror-1.1.23-1.fc11.noarch


How reproducible:
Always.


Steps to Reproduce:
1. Open thunderbird
2. Click on button "Write"
3. Click in the message body area


Actual results:
$ thunderbird
/usr/lib/thunderbird-3.0b4/run-mozilla.sh: line 131:  3721 Segmentation fault      "$prog" ${1+"$@"}


Expected results:
Ability to compose the new message.


Additional info:
-

Comment 1 Edwin ten Brink 2009-10-26 20:17:12 UTC
BTW: I hope gdb caught the exception in the output, since at the crash I got:

Program received signal SIGSEGV, Segmentation fault.
[Switching to Thread 0xa4fffb70 (LWP 4009)]

Comment 2 Martin Stransky 2009-10-27 08:31:02 UTC
Looks like a crash in JS engine (JIT) - nanojit::LirBufWriter::ins0

Comment 3 Martin Stransky 2009-10-27 09:09:38 UTC
Hm, I can't reproduce it with the same package...can you provide more precise steps how to reproduce it? Or try to run thunderbird inside gdb and attach the backtrace here. I'll attach instructions...

Comment 4 Martin Stransky 2009-10-27 09:11:38 UTC
There are the steps there:
--------------------------

Please install thunderbird-debuginfo (debuginfo-install is from
yum-utils package).

 debuginfo-install thunderbird

Then run thunderbird with a parameter -g. That will start thunderbird running inside of gdb debugger. Then use command run and do whatever you did to make thunderbird crash. When it happens, you should go back to the gdb and run

 (gdb) thread apply all backtrace

This produces usually many screens of the text. Copy all of them into a text
editor and attach the file to the bug as an uncompressed attachment.

We will review this issue again once you've had a chance to attach this
information.

Thanks in advance.

Comment 5 Martin Stransky 2009-10-27 09:26:05 UTC
Additionally, please try to run thunderbird inside valgrind (a debugging tool).

1) install valgrind
2) run "valgrind --trace-children=yes /usr/bin/thunderbird"

You may get some error messages before the crash so please attach them here.

Comment 6 Matěj Cepl 2009-10-27 17:30:56 UTC
Thanks for the bug report.  We have reviewed the information you have provided above, and there is some additional information we require that will be helpful in our diagnosis of this issue.

First of all, could we get output of the command

	rpm -qa *xulrun* *firefox* *mozilla* *flash* *plugin*

Please also install firefox-debuginfo (debuginfo-install is from
yum-utils package).

	debuginfo-install firefox

Then run firefox with a parameter -g. That will start firefox running inside of gdb debugger. Then use command run and do whatever you did to make firefox crash. When it happens, you should go back to the gdb and run

	(gdb) thread apply all backtrace

This produces usually many screens of the text. Copy all of them into a text editor and attach the file to the bug as an uncompressed attachment.

Please, install also valgrind (from valgrind package) and run

	valgrind --trace-children=yes --log-file=/tmp/firefox-valgrind-log.txt /usr/bin/firefox

(that's one line command, browser breaking this line into two notwithstanding)

Please, attach the file /tmp/firefox-valgrind-log.txt to this bug as an attachment as well.

We will review this issue again once you've had a chance to attach this information.

Thanks in advance.

Comment 7 Matěj Cepl 2009-10-27 17:32:06 UTC
sorry, the message got included by mistake ... it doesn't mean any additional requirements on your side aside from comment 4 and comment 5

Comment 8 Edwin ten Brink 2009-10-27 19:19:18 UTC
(In reply to comment #4)
>  (gdb) thread apply all backtrace
> 
> This produces usually many screens of the text. Copy all of them into a text
> editor and attach the file to the bug as an uncompressed attachment.

See attachment in original comment #0.

(In reply to comment #5)
> Additionally, please try to run thunderbird inside valgrind (a debugging tool).

I assume you meant s/firefox/thunderbird/.

Upon start-up, I got:
$ valgrind --trace-children=yes --log-file=/tmp/thunderbird-valgrind-log.txt /usr/bin/thunderbird
Assertion 'pthread_mutex_unlock(&m->mutex) == 0' failed at pulsecore/mutex-posix.c:108, function pa_mutex_unlock(). Aborting.
/usr/lib/thunderbird-3.0b4/run-mozilla.sh: line 131:  2478 Killed                  "$prog" ${1+"$@"}

Since it did not get any further than just starting thunderbird (crashing as soon as the application fully started), I reran with --leak-check=full as well as suggested by valgrind's output.

Comment 9 Edwin ten Brink 2009-10-27 19:20:34 UTC
Created attachment 366326 [details]
Output of valgrind as requested

Comment 10 Edwin ten Brink 2009-10-27 19:21:37 UTC
Created attachment 366327 [details]
Output of valgrind rerun with --leak-check=full

Comment 11 Martin Stransky 2009-11-12 08:45:46 UTC
You didn't run it with "--trace-children=yes" valgrind options so we get the debug info only from a loader. Please run the valgrind session again and add the --trace-children=yes command line argument.

Comment 12 Edwin ten Brink 2009-11-12 18:13:42 UTC
Created attachment 369284 [details]
Output of valgrind rerun with --trace-children=yes --leak-check=full

Comment 13 Chris Campbell 2010-01-23 19:39:45 UTC
*** Bug 558112 has been marked as a duplicate of this bug. ***

Comment 14 Bug Zapper 2010-04-28 10:58:53 UTC
This message is a reminder that Fedora 11 is nearing its end of life.
Approximately 30 (thirty) days from now Fedora will stop maintaining
and issuing updates for Fedora 11.  It is Fedora's policy to close all
bug reports from releases that are no longer maintained.  At that time
this bug will be closed as WONTFIX if it remains open with a Fedora 
'version' of '11'.

Package Maintainer: If you wish for this bug to remain open because you
plan to fix it in a currently maintained version, simply change the 'version' 
to a later Fedora version prior to Fedora 11's end of life.

Bug Reporter: Thank you for reporting this issue and we are sorry that 
we may not be able to fix it before Fedora 11 is end of life.  If you 
would still like to see this bug fixed and are able to reproduce it 
against a later version of Fedora please change the 'version' of this 
bug to the applicable version.  If you are unable to change the version, 
please add a comment here and someone will do it for you.

Although we aim to fix as many bugs as possible during every release's 
lifetime, sometimes those efforts are overtaken by events.  Often a 
more recent Fedora release includes newer upstream software that fixes 
bugs or makes them obsolete.

The process we are following is described here: 
http://fedoraproject.org/wiki/BugZappers/HouseKeeping

Comment 15 Bug Zapper 2010-06-28 15:19:53 UTC
Fedora 11 changed to end-of-life (EOL) status on 2010-06-25. Fedora 11 is 
no longer maintained, which means that it will not receive any further 
security or bug fix updates. As a result we are closing this bug.

If you can reproduce this bug against a currently maintained version of 
Fedora please feel free to reopen this bug against that version.

Thank you for reporting this bug and we are sorry it could not be fixed.


Note You need to log in before you can comment on or make changes to this bug.