From mboxrd@z Thu Jan 1 00:00:00 1970 Path: news.gmane.org!not-for-mail From: Eli Zaretskii Newsgroups: gmane.emacs.bugs Subject: bug#17771: 24.3.91; SIGSEGV in cleanup_vector Date: Fri, 13 Jun 2014 16:58:32 +0300 Message-ID: <83lht0x65z.fsf@gnu.org> References: <874mzp896b.fsf@rosalinde.fritz.box> <83vbs5w3h7.fsf@gnu.org> <87zjhh6su4.fsf@rosalinde.fritz.box> <83tx7pvw61.fsf@gnu.org> <87ppid6l0x.fsf@rosalinde.fritz.box> <83ppidvsyx.fsf@gnu.org> <87lht16ii3.fsf@rosalinde.fritz.box> <83mwdgx6t4.fsf@gnu.org> <87ha3o7w68.fsf@rosalinde.fritz.box> Reply-To: Eli Zaretskii NNTP-Posting-Host: plane.gmane.org X-Trace: ger.gmane.org 1402667965 6589 80.91.229.3 (13 Jun 2014 13:59:25 GMT) X-Complaints-To: usenet@ger.gmane.org NNTP-Posting-Date: Fri, 13 Jun 2014 13:59:25 +0000 (UTC) Cc: 17771@debbugs.gnu.org To: Stephen Berman Original-X-From: bug-gnu-emacs-bounces+geb-bug-gnu-emacs=m.gmane.org@gnu.org Fri Jun 13 15:59:17 2014 Return-path: Envelope-to: geb-bug-gnu-emacs@m.gmane.org Original-Received: from lists.gnu.org ([208.118.235.17]) by plane.gmane.org with esmtp (Exim 4.69) (envelope-from ) id 1WvS0j-0005cE-E3 for geb-bug-gnu-emacs@m.gmane.org; Fri, 13 Jun 2014 15:59:17 +0200 Original-Received: from localhost ([::1]:59293 helo=lists.gnu.org) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1WvS0j-0004qW-1z for geb-bug-gnu-emacs@m.gmane.org; Fri, 13 Jun 2014 09:59:17 -0400 Original-Received: from eggs.gnu.org ([2001:4830:134:3::10]:48464) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1WvS0a-0004pG-9v for bug-gnu-emacs@gnu.org; Fri, 13 Jun 2014 09:59:14 -0400 Original-Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1WvS0U-0008Bt-DN for bug-gnu-emacs@gnu.org; Fri, 13 Jun 2014 09:59:08 -0400 Original-Received: from debbugs.gnu.org ([140.186.70.43]:55581) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1WvS0U-0008Bp-A9 for bug-gnu-emacs@gnu.org; Fri, 13 Jun 2014 09:59:02 -0400 Original-Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.80) (envelope-from ) id 1WvS0U-0002Vx-10 for bug-gnu-emacs@gnu.org; Fri, 13 Jun 2014 09:59:02 -0400 X-Loop: help-debbugs@gnu.org Resent-From: Eli Zaretskii Original-Sender: "Debbugs-submit" Resent-CC: bug-gnu-emacs@gnu.org Resent-Date: Fri, 13 Jun 2014 13:59:01 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: followup 17771 X-GNU-PR-Package: emacs X-GNU-PR-Keywords: Original-Received: via spool by 17771-submit@debbugs.gnu.org id=B17771.14026679339644 (code B ref 17771); Fri, 13 Jun 2014 13:59:01 +0000 Original-Received: (at 17771) by debbugs.gnu.org; 13 Jun 2014 13:58:53 +0000 Original-Received: from localhost ([127.0.0.1]:46731 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.80) (envelope-from ) id 1WvS0K-0002VT-E0 for submit@debbugs.gnu.org; Fri, 13 Jun 2014 09:58:52 -0400 Original-Received: from mtaout29.012.net.il ([80.179.55.185]:55676) by debbugs.gnu.org with esmtp (Exim 4.80) (envelope-from ) id 1WvS0H-0002V6-K1 for 17771@debbugs.gnu.org; Fri, 13 Jun 2014 09:58:50 -0400 Original-Received: from conversion-daemon.mtaout29.012.net.il by mtaout29.012.net.il (HyperSendmail v2007.08) id <0N74008000ZTQC00@mtaout29.012.net.il> for 17771@debbugs.gnu.org; Fri, 13 Jun 2014 16:58:59 +0300 (IDT) Original-Received: from HOME-C4E4A596F7 ([87.69.4.28]) by mtaout29.012.net.il (HyperSendmail v2007.08) with ESMTPA id <0N74004QT1IAV460@mtaout29.012.net.il>; Fri, 13 Jun 2014 16:58:59 +0300 (IDT) In-reply-to: <87ha3o7w68.fsf@rosalinde.fritz.box> X-012-Sender: halo1@inter.net.il X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.15 Precedence: list X-detected-operating-system: by eggs.gnu.org: GNU/Linux 3.x X-Received-From: 140.186.70.43 X-BeenThere: bug-gnu-emacs@gnu.org List-Id: "Bug reports for GNU Emacs, the Swiss army knife of text editors" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: bug-gnu-emacs-bounces+geb-bug-gnu-emacs=m.gmane.org@gnu.org Original-Sender: bug-gnu-emacs-bounces+geb-bug-gnu-emacs=m.gmane.org@gnu.org Xref: news.gmane.org gmane.emacs.bugs:90334 Archived-At: > From: Stephen Berman > Cc: 17771@debbugs.gnu.org > Date: Fri, 13 Jun 2014 15:53:35 +0200 > > On Fri, 13 Jun 2014 16:44:39 +0300 Eli Zaretskii wrote: > > >> From: Stephen Berman > >> Cc: 17771@debbugs.gnu.org > >> Date: Fri, 13 Jun 2014 15:34:12 +0200 > >> > >> On Fri, 13 Jun 2014 16:28:54 +0300 Eli Zaretskii wrote: > >> > >> >> From: Stephen Berman > >> >> Cc: 17771@debbugs.gnu.org > >> >> Date: Fri, 13 Jun 2014 14:39:42 +0200 > >> >> > >> >> Program received signal SIGSEGV, Segmentation fault. > >> >> 0x00000000005aa564 in cleanup_vector (vector=0x413c318) > >> >> at ../../../../bzr/emacs/emacs-24/src/alloc.c:2929 > >> >> 2929 ((struct font *) vector)->driver->close ((struct font *) vector); > >> >> (gdb) p vector > >> >> $1 = (struct Lisp_Vector *) 0x413c318 > >> >> (gdb) p vector->driver > >> >> There is no member named driver. > >> >> (gdb) p vector->driver->close > >> >> There is no member named driver. > >> > > >> > (gdb) p ((struct font *) vector)->driver > >> > (gdb) p ((struct font *) vector)->driver->close > >> > >> (gdb) p ((struct font *) vector)->driver > >> $4 = (struct font_driver *) 0x0 > >> (gdb) p ((struct font *) vector)->driver->close > >> Cannot access memory at address 0x40 > > > > IOW, the font driver is NULL. > > Could that be due to my typing `C-g'? It evidently is. My current theory is that the font driver was not fully set up, before Emacs got interrupted by C-g. > If I don't do that, the file does get displayed. But `C-g' > shouldn't make Emacs crash. Do you see what the problem is, or can > I provide further information? The immediate problem is clearly that we dereference a NULL pointer. I installed a trivial workaround for that in r117235 on the emacs-24 branch. The diffs are below. Can you try this and see if the problem is solved? It's possible that the real problem is somewhere else, in which case you will probably see it when you apply the patch. Thanks. === modified file 'src/alloc.c' --- src/alloc.c 2014-05-30 20:19:29 +0000 +++ src/alloc.c 2014-06-13 13:53:24 +0000 @@ -2924,9 +2924,16 @@ cleanup_vector (struct Lisp_Vector *vect && ((vector->header.size & PSEUDOVECTOR_SIZE_MASK) == FONT_OBJECT_MAX)) { - /* Attempt to catch subtle bugs like Bug#16140. */ - eassert (valid_font_driver (((struct font *) vector)->driver)); - ((struct font *) vector)->driver->close ((struct font *) vector); + struct font_driver *drv = ((struct font *) vector)->driver; + + /* The font driver might sometimes be NULL, e.g. if Emacs was + interrupted before it had time to set it up. */ + if (drv) + { + /* Attempt to catch subtle bugs like Bug#16140. */ + eassert (valid_font_driver (drv)); + drv->close ((struct font *) vector); + } } }