Note: This is a beta release of Red Hat Bugzilla 5.0. The data contained within is a snapshot of the live data so any changes you make will not be reflected in the production Bugzilla. Also email is disabled so feel free to test any aspect of the site that you want. File any problems you find or give feedback here.
Bug 231025 - evolution segv in mail_msg_free
Summary: evolution segv in mail_msg_free
Status: CLOSED DUPLICATE of bug 220714
Alias: None
Product: Fedora
Classification: Fedora
Component: evolution
Version: 7
Hardware: i386
OS: Linux
Target Milestone: ---
Assignee: Matthew Barnes
QA Contact:
: 221760 (view as bug list)
Depends On:
TreeView+ depends on / blocked
Reported: 2007-03-05 17:38 UTC by Peter Jones
Modified: 2018-04-11 15:16 UTC (History)
2 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Last Closed: 2007-12-11 15:39:26 UTC

Attachments (Terms of Use)
traceback (deleted)
2007-03-05 17:38 UTC, Peter Jones
no flags Details
patch that seems to make evo work again for me (deleted)
2007-03-05 17:40 UTC, Peter Jones
no flags Details | Diff

Description Peter Jones 2007-03-05 17:38:37 UTC
Description of problem:

I start evo, and I get a traceback immediately from a duplicate free() from
mail_msg_free() in evolution/mail/mail-ts.c .

Comment 1 Peter Jones 2007-03-05 17:38:37 UTC
Created attachment 149273 [details]

Comment 2 Peter Jones 2007-03-05 17:40:57 UTC
Created attachment 149274 [details]
patch that seems to make evo work again for me

This patch seems to mitigate it, but I'm kindof stabbing in the dark here, so
I'm not sure that the patch is actually _correct_.

Comment 3 Matthew Barnes 2007-03-05 17:45:16 UTC
Thanks for the patch.  Can I ask you to attach another backtrace of evolution
crashing in this way?  The attachment in comment #1 just shows a memory map.

Comment 4 Peter Jones 2007-03-05 19:14:33 UTC
So here's the backtrace from gdb:

(gdb) bt
#0  0x00fe0402 in __kernel_vsyscall ()
#1  0x06d398de in __lll_mutex_lock_wait () from /lib/
#2  0x06cc970e in _L_lock_14400 () from /lib/
#3  0x06cc8c34 in *__GI___libc_free (mem=0x9546750) at malloc.c:3564
#4  0x00934081 in _dl_map_object_deps (map=0x9547000, preloads=0x0, 
    npreloads=<value optimized out>, trace_mode=0, open_mode=-2147483648)
    at dl-deps.c:495
#5  0x009389c8 in dl_open_worker (a=0xbfd52268) at dl-open.c:284
#6  0x00934ee6 in _dl_catch_error (objname=0xbfd52290, errstring=0xbfd5228c, 
    mallocedp=0xbfd52297, operate=0x938880 <dl_open_worker>, args=0xbfd52268)
    at dl-error.c:178
#7  0x009384a2 in _dl_open (file=0x6d7fd92 "", 
    mode=<value optimized out>, caller_dlopen=0x0, nsid=-2, argc=1, 
    argv=0xbfd52f84, env=0xbfd52f8c) at dl-open.c:557
#8  0x06d62fd2 in do_dlopen (ptr=0xbfd523c0) at dl-libc.c:86
#9  0x00934ee6 in _dl_catch_error (objname=0xbfd523d0, errstring=0xbfd523cc, 
    mallocedp=0xbfd523d7, operate=0x6d62f70 <do_dlopen>, args=0xbfd523c0)
    at dl-error.c:178
#10 0x06d63185 in *__GI___libc_dlopen_mode (name=0x6d7fd92 "", 
    mode=-2147483647) at dl-libc.c:47
#11 0x06d3fec9 in init () at ../sysdeps/i386/backtrace.c:43
#12 0x00bfb2bb in pthread_once () from /lib/
#13 0x06d400a5 in *__GI___backtrace (array=0xbfd529a0, size=64)
---Type <return> to continue, or q <return> to quit---
    at ../sysdeps/i386/backtrace.c:116
#14 0x06cbd821 in __libc_message (do_abort=2, 
    fmt=0x6d82c04 "*** glibc detected *** %s: %s: 0x%s ***\n")
    at ../sysdeps/unix/sysv/linux/libc_fatal.c:150
#15 0x06cc55ed in _int_free (av=0x6dad120, mem=0x8e99708) at malloc.c:5788
#16 0x06cc8c40 in *__GI___libc_free (mem=0x8e99708) at malloc.c:3566
#17 0x0052f6e1 in IA__g_free (mem=0x8e99708) at gmem.c:187
#18 0x0152ec20 in free_user_message (mm=0x899eb70) at mail-session.c:358
#19 0x015275e6 in mail_msg_free (msg=0x899eb70) at mail-mt.c:188
#20 0x015279f8 in periodic_processing () at mail-mt.c:458
#21 0x00528a16 in g_timeout_dispatch (source=0x8a7c880, callback=0, 
    user_data=0x0) at gmain.c:3422
#22 0x00528442 in IA__g_main_context_dispatch (context=0x88f8530)
    at gmain.c:2045
#23 0x0052b41f in g_main_context_iterate (context=0x88f8530, block=1, 
    dispatch=1, self=0x88d5660) at gmain.c:2677
#24 0x0052b7c9 in IA__g_main_loop_run (loop=0x892da58) at gmain.c:2881
#25 0x044c07c3 in bonobo_main () at bonobo-main.c:311
#26 0x0805ef8c in main (argc=1, argv=0xbfd52f84) at main.c:611

Comment 5 Matthew Barnes 2007-03-05 19:29:25 UTC
Thanks, this should be very helpful in tracking down the problem.

Comment 6 Tom "spot" Callaway 2007-03-05 19:51:50 UTC
*** Bug 221760 has been marked as a duplicate of this bug. ***

Comment 7 Matthew Barnes 2007-03-11 20:56:12 UTC
The backtrace in comment #4 looks familiar.  What's the version/release of the
evolution package you're using?

Comment 8 Matthew Barnes 2007-03-15 04:18:25 UTC
Is this bug still present in evolution-2.10.0-1.fc7 or later?

I'm trying to determine if this is a dupe of bug #220714, which was recently
fixed.  Neither this bug nor bug #221760 states which version of evolution was
being used.

Comment 9 Matěj Cepl 2007-08-31 19:50:18 UTC
Reporter, could you please reply to the previous question?

Comment 10 Matěj Cepl 2007-11-14 15:03:02 UTC
Reporter, could you please reply to the previous question? If you won't reply in
one month, I will have to close this bug as INSUFFICIENT_DATA. Thank you.

Comment 11 Matthew Barnes 2007-12-11 15:39:26 UTC
I know this is fixed now and I'm pretty sure it's a dupe of bug #220714, so
marking it as such.

*** This bug has been marked as a duplicate of 220714 ***

Note You need to log in before you can comment on or make changes to this bug.