bluetoothd crashed with SIGSEGV in magazine_chain_pop_head()

Bug #818354 reported by Alex Mayorga
12
This bug affects 1 person
Affects Status Importance Assigned to Milestone
bluez (Ubuntu)
Invalid
Medium
Unassigned

Bug Description

Crashed while sending a file to a phone over Bluetooth.

ProblemType: Crash
DistroRelease: Ubuntu 11.10
Package: bluez 4.95-0ubuntu1
ProcVersionSignature: Ubuntu 3.0.0-7.8-generic 3.0.0
Uname: Linux 3.0.0-7-generic x86_64
Architecture: amd64
Date: Fri Jul 29 22:48:27 2011
ExecutablePath: /usr/sbin/bluetoothd
InstallationMedia: Ubuntu 10.04.1 LTS "Lucid Lynx" - Release amd64 (20100816.1)
InterestingModules: bnep rfcomm btusb bluetooth
MachineType: Sony Corporation VPCCW1FFX
ProcCmdline: /usr/sbin/bluetoothd
ProcEnviron: PATH=(custom, no user)
ProcKernelCmdLine: BOOT_IMAGE=/boot/vmlinuz-3.0.0-7-generic root=UUID=f415c990-a34d-451b-b69c-2070c5d53e47 ro quiet splash vt.handoff=7
SegvAnalysis:
 Segfault happened at: 0x7f671b71dc58 <g_slice_alloc+280>: mov 0x8(%rax),%rbx
 PC (0x7f671b71dc58) ok
 source "0x8(%rax)" (0x100100000021) not located in a known VMA region (needed readable region)!
 destination "%rbx" ok
SegvReason: reading unknown VMA
Signal: 11
SourcePackage: bluez
StacktraceTop:
 magazine_chain_pop_head (mem_size=16) at /build/buildd/glib2.0-2.29.14/./glib/gslice.c:488
 thread_memory_magazine1_alloc (mem_size=16) at /build/buildd/glib2.0-2.29.14/./glib/gslice.c:795
 g_slice_alloc (mem_size=16) at /build/buildd/glib2.0-2.29.14/./glib/gslice.c:833
 g_slist_prepend (list=0x7f671cf1ab10, data=0x7f671c096600) at /build/buildd/glib2.0-2.29.14/./glib/gslist.c:302
 ?? ()
Title: bluetoothd crashed with SIGSEGV in magazine_chain_pop_head()
UpgradeStatus: Upgraded to oneiric on 2011-07-06 (23 days ago)
UserGroups:

dmi.bios.date: 09/22/2009
dmi.bios.vendor: American Megatrends Inc.
dmi.bios.version: R0190Y5
dmi.board.asset.tag: N/A
dmi.board.name: VAIO
dmi.board.vendor: Sony Corporation
dmi.board.version: N/A
dmi.chassis.asset.tag: N/A
dmi.chassis.type: 10
dmi.chassis.vendor: Sony Corporation
dmi.chassis.version: N/A
dmi.modalias: dmi:bvnAmericanMegatrendsInc.:bvrR0190Y5:bd09/22/2009:svnSonyCorporation:pnVPCCW1FFX:pvrR5785054:rvnSonyCorporation:rnVAIO:rvrN/A:cvnSonyCorporation:ct10:cvrN/A:
dmi.product.name: VPCCW1FFX
dmi.product.version: R5785054
dmi.sys.vendor: Sony Corporation
hciconfig:
 hci0: Type: BR/EDR Bus: USB
  BD Address: 00:26:43:A9:97:5F ACL MTU: 1021:8 SCO MTU: 64:1
  UP RUNNING
  RX bytes:467 acl:0 sco:0 events:19 errors:0
  TX bytes:88 acl:0 sco:0 commands:19 errors:0

Revision history for this message
Alex Mayorga (alex-mayorga) wrote :
Revision history for this message
Apport retracing service (apport) wrote :

StacktraceTop:
 magazine_chain_pop_head (mem_size=16) at /build/buildd/glib2.0-2.29.14/./glib/gslice.c:488
 thread_memory_magazine1_alloc (mem_size=16) at /build/buildd/glib2.0-2.29.14/./glib/gslice.c:795
 g_slice_alloc (mem_size=16) at /build/buildd/glib2.0-2.29.14/./glib/gslice.c:833
 g_slist_prepend (list=0x7f671cf1ab10, data=0x7f671c096600) at /build/buildd/glib2.0-2.29.14/./glib/gslist.c:302
 probe_driver (adapter=0x7f671cf18470, user_data=0x7f671c096600) at src/adapter.c:2132

Revision history for this message
Apport retracing service (apport) wrote : Stacktrace.txt
Revision history for this message
Apport retracing service (apport) wrote : ThreadStacktrace.txt
Changed in bluez (Ubuntu):
importance: Undecided → Medium
tags: removed: need-amd64-retrace
visibility: private → public
Revision history for this message
Alex Mayorga (alex-mayorga) wrote :

hci.log when I tried to reproduce, it no longer crashes, but it fails to send to both a phone and another laptop until I pair the phone.

Revision history for this message
dino99 (9d9) wrote :

This version has expired long ago; no more supported

Changed in bluez (Ubuntu):
status: New → Invalid
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.