← Back to team overview

touch-packages team mailing list archive

[Bug 1418771] Re: gjs-console assert failure: *** Error in `/usr/bin/gjs-console': free(): invalid next size (fast): 0x00007f74a804b240 ***

 

** Description changed:

- crash under wayland session
+ [Impact]
+ gnome-documents search provider crashes due to a buffer overrun in libunistring handling.
  
- ProblemType: Crash
- DistroRelease: Ubuntu 15.04
- Package: gjs 1.43.3-0ubuntu1~vivid1 [origin: LP-PPA-gnome3-team-gnome3-staging]
- ProcVersionSignature: Ubuntu 3.18.0-12.13-generic 3.18.4
- Uname: Linux 3.18.0-12-generic x86_64
- ApportVersion: 2.15.1-0ubuntu4
- Architecture: amd64
- AssertionMessage: *** Error in `/usr/bin/gjs-console': free(): invalid next size (fast): 0x00007f74a804b240 ***
- CrashCounter: 1
- CurrentDesktop: GNOME
- Date: Fri Feb  6 09:04:55 2015
- ExecutablePath: /usr/bin/gjs-console
- ProcCmdline: /usr/bin/gjs-console -I /usr/share/gnome-documents/js -c const\ Main\ =\ imports.main;\ Main.start(); --gapplication-service
- Signal: 6
- SourcePackage: gjs
- StacktraceTop:
-  __libc_message (do_abort=do_abort@entry=1, fmt=fmt@entry=0x7f74d0bf9b00 "*** Error in `%s': %s: 0x%s ***\n") at ../sysdeps/posix/libc_fatal.c:175
-  _int_free (ptr=<optimised out>, str=0x7f74d0bf9ca0 "free(): invalid next size (fast)", action=1) at malloc.c:4996
-  _int_free (av=<optimised out>, p=<optimised out>, have_lock=0) at malloc.c:3840
-  () at /usr/lib/x86_64-linux-gnu/libsqlite3.so.0
-  () at /usr/lib/x86_64-linux-gnu/libsqlite3.so.0
- Title: gjs-console assert failure: *** Error in `/usr/bin/gjs-console': free(): invalid next size (fast): 0x00007f74a804b240 ***
- UpgradeStatus: Upgraded to vivid on 2015-01-09 (27 days ago)
- UserGroups: adm admin cdrom dialout lpadmin plugdev sambashare systemd-journal
+ I have also included a few other patches cherry-picked from the upstream
+ tracker-1.4 branch, that deal with crashes mishandling gcancellables.
+ 
+ [Test Case]
+ 
+ - in one terminal run /usr/bin/gnome-documents --gapplication-service
+ - within 10 seconds of the above, in another terminal run dbus-send --print-reply --dest=org.gnome.Documents /org/gnome/Documents/SearchProvider org.gnome.Shell.SearchProvider2.GetInitialResultSet array:string:"search"
+ 
+ [Regression Potential]
+  Low, these are all simple patches from the upstream stable branch

** Changed in: tracker (Ubuntu)
       Status: New => Fix Committed

-- 
You received this bug notification because you are a member of Ubuntu
Touch seeded packages, which is subscribed to tracker in Ubuntu.
https://bugs.launchpad.net/bugs/1418771

Title:
  gjs-console assert failure: *** Error in `/usr/bin/gjs-console':
  free(): invalid next size (fast): 0x00007f74a804b240 ***

Status in gjs:
  Fix Released
Status in Ubuntu GNOME:
  Confirmed
Status in tracker package in Ubuntu:
  Fix Committed
Status in gjs source package in Wily:
  New
Status in tracker source package in Wily:
  New
Status in gjs package in Debian:
  Fix Released

Bug description:
  [Impact]
  gnome-documents search provider crashes due to a buffer overrun in libunistring handling.

  I have also included a few other patches cherry-picked from the
  upstream tracker-1.4 branch, that deal with crashes mishandling
  gcancellables.

  [Test Case]

  - in one terminal run /usr/bin/gnome-documents --gapplication-service
  - within 10 seconds of the above, in another terminal run dbus-send --print-reply --dest=org.gnome.Documents /org/gnome/Documents/SearchProvider org.gnome.Shell.SearchProvider2.GetInitialResultSet array:string:"search"

  [Regression Potential]
   Low, these are all simple patches from the upstream stable branch

To manage notifications about this bug go to:
https://bugs.launchpad.net/gjs/+bug/1418771/+subscriptions