unity-2d-panel crashed with SIGSEGV in QConfSchema::findKey()

Bug #834045 reported by Destain Duckert
670
This bug affects 79 people
Affects Status Importance Assigned to Milestone
dconf-qt
New
Undecided
auto-desrt
unity-2d
Fix Released
Critical
Alberto Mardegan
unity-2d (Ubuntu)
Fix Released
High
Alberto Mardegan
Oneiric
Fix Released
High
Alberto Mardegan

Bug Description

fresh reboot from updates dated 8.25.11. Had just launched the new Software Center.

ProblemType: Crash
DistroRelease: Ubuntu 11.10
Package: unity-2d-panel 4.2.0-0ubuntu1
ProcVersionSignature: Ubuntu 3.0.0-9.14-generic 3.0.3
Uname: Linux 3.0.0-9-generic i686
Architecture: i386
Date: Thu Aug 25 14:34:26 2011
ExecutablePath: /usr/bin/unity-2d-panel
InstallationMedia: Ubuntu 11.10 "Oneiric Ocelot" - Alpha i386 (20110817)
ProcCmdline: unity-2d-panel
ProcEnviron:
 PATH=(custom, no user)
 LANG=en_US.UTF-8
 SHELL=/bin/bash
SegvAnalysis:
 Segfault happened at: 0x181937 <_ZNK11QConfSchema7findKeyEPKc+39>: mov 0x8(%eax),%edx
 PC (0x00181937) ok
 source "0x8(%eax)" (0xffff95c0) not located in a known VMA region (needed readable region)!
 destination "%edx" ok
SegvReason: reading unknown VMA
Signal: 11
SourcePackage: unity-2d
StacktraceTop:
 QConfSchema::findKey(char const*) const () from /usr/lib/libdconf-qt.so.0
 QConf::notify(char const*) () from /usr/lib/libdconf-qt.so.0
 ?? () from /usr/lib/libdconf-qt.so.0
 ?? () from /usr/lib/libdconf-dbus-1.so.0
 ?? () from /lib/i386-linux-gnu/libdbus-1.so.3
Title: unity-2d-panel crashed with SIGSEGV in QConfSchema::findKey()
UpgradeStatus: Upgraded to oneiric on 2011-08-23 (2 days ago)
UserGroups: adm admin cdrom dialout lpadmin plugdev sambashare

Related branches

Revision history for this message
Destain Duckert (dduckert) wrote :
Revision history for this message
Apport retracing service (apport) wrote :

StacktraceTop:
 QConfSchema::findKey(char const*) const () from /tmp/tmp080XGq/usr/lib/libdconf-qt.so.0
 QConf::notify(char const*) () from /tmp/tmp080XGq/usr/lib/libdconf-qt.so.0
 ?? () from /tmp/tmp080XGq/usr/lib/libdconf-qt.so.0
 add_match_done (pending=0x9cc8350, user_data=0x9c44180) at dconf-dbus-1.c:569
 ?? () from /tmp/tmp080XGq/lib/i386-linux-gnu/libdbus-1.so.3

Revision history for this message
Apport retracing service (apport) wrote : Stacktrace.txt
Revision history for this message
Apport retracing service (apport) wrote : ThreadStacktrace.txt
Changed in unity-2d (Ubuntu):
importance: Undecided → Medium
tags: removed: need-i386-retrace
Revision history for this message
Robert Roth (evfool) wrote :

Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privilege boundaries nor directly cause loss of data/privacy. Please feel free to report any other bugs you may find.

visibility: private → public
Changed in unity-2d (Ubuntu):
status: New → Confirmed
Robert Roth (evfool)
Changed in unity-2d (Ubuntu):
importance: Medium → High
Changed in unity-2d (Ubuntu Oneiric):
assignee: nobody → Canonical Desktop Experience Team (canonical-dx-team)
Revision history for this message
streetpunk234 (spatiegames) wrote :

Got the same after a dist-upgrade from the update manager yesterday (27-08-2011) and rebooting, then I logged in and this popped up. I'm not sure wether I opened an application but I don't think it has anything to do with this crash.

Changed in unity-2d (Ubuntu Oneiric):
milestone: none → ubuntu-11.10-beta-1
Revision history for this message
Alberto Mardegan (mardy) wrote :

The crash is reproducible from revision 658 onwards. Probably something is wrong with the panel plugins dconf schema.

Changed in unity-2d (Ubuntu Oneiric):
assignee: Canonical Desktop Experience Team (canonical-dx-team) → Alberto Mardegan (mardy)
status: Confirmed → In Progress
Alberto Mardegan (mardy)
Changed in unity-2d:
status: New → In Progress
importance: Undecided → Critical
assignee: nobody → Alberto Mardegan (mardy)
milestone: none → 4.4
Revision history for this message
Alberto Mardegan (mardy) wrote :

The QConf object we allocate when instantiating the panel gets destroyed before we enter the main loop, but its destructor doesn't remove the connection to DConf's notify signal, which later gets emitted from the main loop. At that point our QConf instance is already destroyed, and hence the crash.
We can work around it in the panel, by simply not destroying the QConf instance, but we can hopefully get it fixed in QConf as well.

tags: added: iso-testing
Changed in unity-2d:
status: In Progress → Fix Committed
Changed in unity-2d (Ubuntu Oneiric):
status: In Progress → Fix Committed
Revision history for this message
streetpunk234 (spatiegames) wrote :

Happened after first boot of daily build in Virtual Box.

Martin Pitt (pitti)
Changed in unity-2d (Ubuntu):
milestone: ubuntu-11.10-beta-1 → ubuntu-11.10-beta-2
Changed in unity-2d:
status: Fix Committed → Fix Released
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package unity-2d - 4.4.0-0ubuntu1

---------------
unity-2d (4.4.0-0ubuntu1) oneiric; urgency=low

  * New upstream release:
    - unity-2d-panel crashed with SIGSEGV in QConfSchema::findKey()
      (LP: #834045)
    - unity-2d-panel crashed with SIGSEGV in QConf::notify() (LP: #834001)
    - [panel] Implement whitelisting for legacy tray applet (LP: #707354)
    - [launcher] stops automatically hiding after some time using it
      (LP: #821180)
    - [panel] Empathy displays icon in deprecated systray (LP: #830017)
    - [dash] Invalid UTF-8 in the dash (LP: #836587)
    - [dash] Home buttons 'Media' and 'Internet' apps should not only take you
      to the apps lens but also activate the right filter (LP: #837360)
    - [dash] Drag&drop application from dash to launcher is broken
      (LP: #837361)
    - [launcher] contextual menu's corner has a blue line (LP: #828386)
    - [dash] Lens bar graphical layout glitches (LP: #833805)
    - [dash] Rating Filter: All button not clearing star highlighting
      (LP: #834640)
    - [dash] should be falling back to the default renderer if the renderer
      requested by the lens is not found (LP: #837356)
    - [dash] Gwibber lens icon doesn't show up in 2d unity (LP: #830728)
    - [dash] Lacks horizontal renderer used by lenses such as Gwibber
      (LP: #837712)
    - [dash] See %1 more result inconsistency (LP: #834226)
    - [launcher] When application has no icon, a question mark icon should be
      displayed (LP: #837351)
    - unity places should return a default icon when no matching icon is found
      (LP: #711200)
    - spacing between indicators should be 5 pixels (LP: #734010)
  * debian/control:
    - require current nux and unity
 -- Didier Roche <email address hidden> Thu, 01 Sep 2011 17:41:00 +0200

Changed in unity-2d (Ubuntu Oneiric):
status: Fix Committed → Fix Released
Changed in unity-2d:
status: Fix Released → Fix Committed
Gerry Boland (gerboland)
Changed in unity-2d:
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.