** Description changed: - crash under wayland session + [Impact] + gnome-documents search provider crashes due to a buffer overrun in libunistring handling. - ProblemType: Crash - DistroRelease: Ubuntu 15.04 - Package: gjs 1.43.3-0ubuntu1~vivid1 [origin: LP-PPA-gnome3-team-gnome3-staging] - ProcVersionSignature: Ubuntu 3.18.0-12.13-generic 3.18.4 - Uname: Linux 3.18.0-12-generic x86_64 - ApportVersion: 2.15.1-0ubuntu4 - Architecture: amd64 - AssertionMessage: *** Error in `/usr/bin/gjs-console': free(): invalid next size (fast): 0x00007f74a804b240 *** - CrashCounter: 1 - CurrentDesktop: GNOME - Date: Fri Feb 6 09:04:55 2015 - ExecutablePath: /usr/bin/gjs-console - ProcCmdline: /usr/bin/gjs-console -I /usr/share/gnome-documents/js -c const\ Main\ =\ imports.main;\ Main.start(); --gapplication-service - Signal: 6 - SourcePackage: gjs - StacktraceTop: - __libc_message (do_abort=do_abort@entry=1, fmt=fmt@entry=0x7f74d0bf9b00 "*** Error in `%s': %s: 0x%s ***\n") at ../sysdeps/posix/libc_fatal.c:175 - _int_free (ptr=<optimised out>, str=0x7f74d0bf9ca0 "free(): invalid next size (fast)", action=1) at malloc.c:4996 - _int_free (av=<optimised out>, p=<optimised out>, have_lock=0) at malloc.c:3840 - () at /usr/lib/x86_64-linux-gnu/libsqlite3.so.0 - () at /usr/lib/x86_64-linux-gnu/libsqlite3.so.0 - Title: gjs-console assert failure: *** Error in `/usr/bin/gjs-console': free(): invalid next size (fast): 0x00007f74a804b240 *** - UpgradeStatus: Upgraded to vivid on 2015-01-09 (27 days ago) - UserGroups: adm admin cdrom dialout lpadmin plugdev sambashare systemd-journal + I have also included a few other patches cherry-picked from the upstream + tracker-1.4 branch, that deal with crashes mishandling gcancellables. + + [Test Case] + + - in one terminal run /usr/bin/gnome-documents --gapplication-service + - within 10 seconds of the above, in another terminal run dbus-send --print-reply --dest=org.gnome.Documents /org/gnome/Documents/SearchProvider org.gnome.Shell.SearchProvider2.GetInitialResultSet array:string:"search" + + [Regression Potential] + Low, these are all simple patches from the upstream stable branch
** Changed in: tracker (Ubuntu) Status: New => Fix Committed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1418771 Title: gjs-console assert failure: *** Error in `/usr/bin/gjs-console': free(): invalid next size (fast): 0x00007f74a804b240 *** To manage notifications about this bug go to: https://bugs.launchpad.net/gjs/+bug/1418771/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs