[apport] gnome-search-tool crashed with SIGSEGV in free()

Bug #95700 reported by Detlef Lechner
2
Affects Status Importance Assigned to Milestone
gnome-utils (Ubuntu)
Invalid
Medium
Ubuntu Desktop Bugs

Bug Description

Binary package hint: gnome-utils

My error report is simiar to 94497. 93818, 91143. Gnome Panel 2.18.0.

ProblemType: Crash
Architecture: i386
Date: Sat Mar 24 23:28:57 2007
DistroRelease: Ubuntu 7.04
ExecutablePath: /usr/bin/gnome-search-tool
Package: gnome-utils 2.18.0-0ubuntu1
PackageArchitecture: i386
ProcCmdline: gnome-search-tool
ProcCwd: /home/detlef
ProcEnviron:
 LANGUAGE=de_DE.UTF-8
 PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/usr/games
 LANG=de_DE.UTF-8
 SHELL=/bin/bash
Signal: 11
SourcePackage: gnome-utils
StacktraceTop:
 free () from /lib/tls/i686/cmov/libc.so.6
 g_free () from /usr/lib/libglib-2.0.so.0
 ?? () from /usr/lib/libgnomevfs-2.so.0
 ?? ()
 free () from /lib/tls/i686/cmov/libc.so.6
Uname: Linux MD97600 2.6.20-12-generic #2 SMP Wed Mar 21 20:55:46 UTC 2007 i686 GNU/Linux
UserGroups: adm admin audio cdrom dialout dip floppy lpadmin netdev plugdev powerdev scanner video

Revision history for this message
Detlef Lechner (detlef-lechner) wrote :
Revision history for this message
Sebastien Bacher (seb128) wrote :
Download full text (11.4 KiB)

Debug backtrace for the crash:

#0 0xb7314dcc in free () from /lib/tls/i686/cmov/libc.so.6
(gdb) thread apply all bt full

Thread 8 (process 23718):
#0 0xffffe410 in __kernel_vsyscall ()
No symbol table info available.
#1 0xb736b932 in unlink () from /lib/tls/i686/cmov/libc.so.6
No symbol table info available.
#2 0xb743138d in IA__g_unlink (filename=0x809ce00 "/tmp/orbit-detlef/linc-5ca6-0-5101c8bc703e") at gstdio.c:741
No locals.
#3 0xb7c0469d in link_protocol_unix_destroy (fd=12, dummy=0x809cdf0 "localhost",
    pathname=0x809ce00 "/tmp/orbit-detlef/linc-5ca6-0-5101c8bc703e") at linc-protocols.c:1019
No locals.
#4 0xb7c04a6b in link_protocol_destroy_cnx (proto=0xb7c193b0, fd=12, host=0x809cdf0 "localhost",
    service=0x809ce00 "/tmp/orbit-detlef/linc-5ca6-0-5101c8bc703e") at linc-protocols.c:1122
        __PRETTY_FUNCTION__ = "link_protocol_destroy_cnx"
#5 0xb7c059f3 in link_server_dispose (obj=0x8082590) at linc-server.c:103
        l = <value optimized out>
#6 0xb74948db in IA__g_object_unref (_object=0x8082590) at gobject.c:1760
        object = (GObject *) 0x8082590
        __PRETTY_FUNCTION__ = "IA__g_object_unref"
#7 0xb7430b31 in IA__g_slist_foreach (list=0x808fb00, func=0x80511c8 <g_object_unref@plt>, user_data=0x0) at gslist.c:468
        next = (GSList *) 0x0
#8 0xb7be6762 in CORBA_ORB_shutdown (orb=0x8097318, wait_for_completion=1 '\001', ev=0xbfeb5958) at corba-orb.c:174
No locals.
#9 0xb7be684d in CORBA_ORB_destroy (orb=0x8097318, ev=0xbfeb5958) at corba-orb.c:1257
        __PRETTY_FUNCTION__ = "CORBA_ORB_destroy"
#10 0xb7be7f4f in shutdown_orb () at corba-orb.c:306
        orb = (CORBA_ORB) 0x8097318
        ev = {_id = 0x0, _major = 0, _any = {_type = 0x0, _value = 0x0, _release = 0 '\0'}}
#11 0xb72d69d9 in exit () from /lib/tls/i686/cmov/libc.so.6
No symbol table info available.
#12 0xb72bfec4 in __libc_start_main () from /lib/tls/i686/cmov/libc.so.6
No symbol table info available.
#13 0x08051851 in _start ()
No symbol table info available.

Thread 7 (process 25782):
#0 0xffffe410 in __kernel_vsyscall ()
No symbol table info available.
#1 0xb7bb384c in pthread_cond_timedwait@@GLIBC_2.3.2 () from /lib/tls/i686/cmov/libpthread.so.0
No symbol table info available.
#2 0xb7bc4133 in g_cond_timed_wait_posix_impl (cond=0x8136008, entered_mutex=0x0, abs_time=0x58) at gthread-posix.c:242
        result = <value optimized out>
        end_time = {tv_sec = 1174775337, tv_nsec = 500177000}
        __PRETTY_FUNCTION__ = "g_cond_timed_wait_posix_impl"
#3 0xb73fbc81 in g_async_queue_pop_intern_unlocked (queue=0x8097860, try=<value optimized out>, end_time=0xb6412384)
    at gasyncqueue.c:341
---Type <return> to continue, or q <return> to quit---
        retval = <value optimized out>
        __PRETTY_FUNCTION__ = "g_async_queue_pop_intern_unlocked"
#4 0xb74386d3 in g_thread_pool_thread_proxy (data=0x8097828) at gthreadpool.c:220
        task = <value optimized out>
        pool = (GRealThreadPool *) 0x8097828
#5 0xb7436b7f in g_thread_create_proxy (data=0x82bf460) at gthread.c:591
        __PRETTY_FUNCTION__ = "g_thread_create_proxy"
#6 0xb7baf31b in start_thread () from /lib/tls/i686/cmov/libpthread.so.0
No symbol tab...

Revision history for this message
Apport retracing service (apport) wrote : Symbolic stack trace

StacktraceTop:free () from /lib/tls/i686/cmov/libc.so.6
IA__g_free (mem=0x5) at gmem.c:187
remove_one_stack (key=0x5, value=0x31, callback_data=0x0) at gnome-vfs-module-callback.c:362
g_hash_table_foreach_remove_or_steal (hash_table=0x813a5a0, func=0xb7d809a0 <remove_one_stack>, user_data=0x0, notify=1) at ghash.c:605
clear_stack_table (stack_table=0xfffffffd) at gnome-vfs-module-callback.c:389

Revision history for this message
Apport retracing service (apport) wrote : Symbolic threaded stack trace
Revision history for this message
Sebastien Bacher (seb128) wrote :

Thanks for your bug report. The crash looks like a memory corruption. Could you try to get a valgrind log for it (you can follow the instructions from https://wiki.ubuntu.com/Valgrind for that)?

Changed in gnome-utils:
assignee: nobody → desktop-bugs
importance: Undecided → Medium
status: Unconfirmed → Needs Info
Revision history for this message
Daniel Holbach (dholbach) wrote :

Thanks for the bug report. This particular bug has already been reported, but feel free to report any other bugs you find.

Changed in gnome-utils:
status: Needs Info → Rejected
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.