Bug 981959 - [abrt] libreoffice-core-4.1.0.1-8.fc19: SIGSEGV in orfolite4ooo.uno.so extension
Summary: [abrt] libreoffice-core-4.1.0.1-8.fc19: SIGSEGV in orfolite4ooo.uno.so extension
Keywords:
Status: CLOSED INSUFFICIENT_DATA
Alias: None
Product: Fedora
Classification: Fedora
Component: libreoffice
Version: 19
Hardware: i686
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
Assignee: Caolan McNamara
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard: abrt_hash:ad32af8155f204349e289b51df4...
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2013-07-07 10:23 UTC by Mikhail
Modified: 2013-07-29 10:14 UTC (History)
7 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2013-07-29 10:14:10 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)
File: backtrace (2.34 KB, text/plain)
2013-07-07 10:24 UTC, Mikhail
no flags Details
File: cgroup (140 bytes, text/plain)
2013-07-07 10:24 UTC, Mikhail
no flags Details
File: core_backtrace (1.96 KB, text/plain)
2013-07-07 10:24 UTC, Mikhail
no flags Details
File: dso_list (28.47 KB, text/plain)
2013-07-07 10:24 UTC, Mikhail
no flags Details
File: environ (3.55 KB, text/plain)
2013-07-07 10:24 UTC, Mikhail
no flags Details
File: limits (1.29 KB, text/plain)
2013-07-07 10:24 UTC, Mikhail
no flags Details
File: maps (87.65 KB, text/plain)
2013-07-07 10:24 UTC, Mikhail
no flags Details
File: open_fds (533 bytes, text/plain)
2013-07-07 10:24 UTC, Mikhail
no flags Details
File: proc_pid_status (803 bytes, text/plain)
2013-07-07 10:24 UTC, Mikhail
no flags Details
File: var_log_messages (339 bytes, text/plain)
2013-07-07 10:24 UTC, Mikhail
no flags Details
file which occured this crash (60.00 KB, application/msword)
2013-07-07 10:26 UTC, Mikhail
no flags Details

Description Mikhail 2013-07-07 10:23:55 UTC
Description of problem:
open 4f6b7323c4f666_04963788 (2).doc file

Version-Release number of selected component:
libreoffice-core-4.1.0.1-8.fc19

Additional info:
reporter:       libreport-2.1.5
backtrace_rating: 4
cmdline:        /usr/lib/libreoffice/program/soffice.bin --calc file:///home/mikhail/.cache/evolution/tmp/evolution-mikhail-VEZulz/%D0%9F%D1%80%D0%B8%D0%BB%D0%BE%D0%B6%D0%B5%D0%BD%D0%B8%D0%B5%202%201%20%20Anketa_%D0%A4%D0%9B.xlsx --splash-pipe=5
executable:     /usr/lib/libreoffice/program/soffice.bin
kernel:         3.9.9-301.fc19.i686.PAE
runlevel:       N 5
uid:            1000
xsession_errors: 

Truncated backtrace:
[New LWP 10585]
[New LWP 10588]
[New LWP 10885]
[New LWP 10586]
[New LWP 10591]
[New LWP 10589]
[New LWP 24427]
[New LWP 24428]
[New LWP 18979]
[New LWP 24429]
[New LWP 10590]
[Thread debugging using libthread_db enabled]
Using host libthread_db library "/lib/libthread_db.so.1".
Core was generated by `/usr/lib/libreoffice/program/soffice.bin --calc file:///home/mikhail/.cache/evo'.
Program terminated with signal 11, Segmentation fault.
#0  0xaf382325 in utf16towcs(wchar_t*, unsigned short const*, unsigned int) () from /home/mikhail/.config/libreoffice/4/user/uno_packages/cache/uno_packages/luq0mqw6.tmp_/orfo4ooo-linux.oxt/Linux_x86/orfolite4ooo.uno.so

Thread 11 (Thread 0xb3dffb40 (LWP 10590)):
#0  0xb774a424 in __kernel_vsyscall ()
No symbol table info available.
#1  0x4234b2fb in poll () at ../sysdeps/unix/syscall-template.S:81
No locals.
#2  0xb6a4b5a5 in poll (__timeout=-1, __nfds=2, __fds=0xb50401c4) at /usr/include/bits/poll2.h:46
No locals.
#3  ICEConnectionWorker (data=0x99505c0) at /usr/src/debug/libreoffice-4.1.0.1/vcl/unx/generic/app/sm.cxx:634
        nConnectionsBefore = 1
        bWakeup = <optimized out>
        g = <optimized out>
        t = <optimized out>
        pLocalFD = 0xb50401c4
        nRet = <optimized out>
        pThis = <optimized out>
#4  0x433bdc51 in osl_thread_start_Impl (pData=0x9eaf8c8) at /usr/src/debug/libreoffice-4.1.0.1/sal/osl/unx/thread.c:251
        terminate = 0
        pImpl = 0x9eaf8c8
#5  0x4242d9da in start_thread (arg=0xb3dffb40) at pthread_create.c:308
        __res = <optimized out>
        pd = 0xb3dffb40
        now = <optimized out>
        unwind_buf = {cancel_jmp_buf = {{jmp_buf = {1111744512, -1277166784, 4001536, -1277168728, 462592379, 566741144}, mask_was_saved = 0}}, priv = {pad = {0x0, 0x0, 0x0, 0x0}, data = {prev = 0x0, cleanup = 0x0, canceltype = 0}}}
        not_first_call = <optimized out>
        pagesize_m1 = <optimized out>
        sp = <optimized out>
        freesize = <optimized out>
#6  0x4235792e in clone () at ../sysdeps/unix/sysv/linux/i386/clone.S:131
No locals.

Thread 10 (Thread 0xa8ff0b40 (LWP 24429)):
#0  0xb774a424 in __kernel_vsyscall ()

Timeout exceeded: 240 seconds, killing gdb.
Looks like gdb hung while generating backtrace.
This may be a bug in gdb. Consider submitting a bug report to gdb developers.
Please attach coredump from this crash to the bug report if you do.

Comment 1 Mikhail 2013-07-07 10:24:01 UTC
Created attachment 769920 [details]
File: backtrace

Comment 2 Mikhail 2013-07-07 10:24:05 UTC
Created attachment 769921 [details]
File: cgroup

Comment 3 Mikhail 2013-07-07 10:24:11 UTC
Created attachment 769922 [details]
File: core_backtrace

Comment 4 Mikhail 2013-07-07 10:24:16 UTC
Created attachment 769923 [details]
File: dso_list

Comment 5 Mikhail 2013-07-07 10:24:20 UTC
Created attachment 769924 [details]
File: environ

Comment 6 Mikhail 2013-07-07 10:24:23 UTC
Created attachment 769925 [details]
File: limits

Comment 7 Mikhail 2013-07-07 10:24:27 UTC
Created attachment 769926 [details]
File: maps

Comment 8 Mikhail 2013-07-07 10:24:33 UTC
Created attachment 769927 [details]
File: open_fds

Comment 9 Mikhail 2013-07-07 10:24:38 UTC
Created attachment 769928 [details]
File: proc_pid_status

Comment 10 Mikhail 2013-07-07 10:24:45 UTC
Created attachment 769929 [details]
File: var_log_messages

Comment 11 Mikhail 2013-07-07 10:26:55 UTC
Created attachment 769931 [details]
file which occured this crash

Comment 12 David Tardon 2013-07-08 10:27:21 UTC
If the crash is reproducible, could you attach the .doc file here?

Comment 13 Michael Stahl 2013-07-10 15:01:52 UTC
David, the document is already attached, see comment #11.

but it doesn't crash for me, and i guess i know why:
the (otherwise uselessly truncated) backtrace shows that the
crash happens in an extension:

  uno_packages/cache/uno_packages/luq0mqw6.tmp_/orfo4ooo-linux.oxt/Linux_x86/orfolite4ooo.uno.so

is it this thing: http://www.informatic.ru/

the only word on there i recognize is LibreOffice;
guess it's a commercial spelling checker.

i wonder if we can do anything here... certainly not if we don't
have a full backtrace of where it's crashing (but likely more debugging
would be needed).  is there a trial version or something like that
of the extension?


Note You need to log in before you can comment on or make changes to this bug.