#0 0x00007ffb9a423267 in __GI_raise (sig=sig@entry=6) at ../sysdeps/unix/sysv/linux/raise.c:55 resultvar = 0 pid = 2951 selftid = 2961 #1 0x00007ffb9a424eca in __GI_abort () at abort.c:89 save_stage = 2 act = {__sigaction_handler = {sa_handler = 0x7ffb97d0e958, sa_sigaction = 0x7ffb97d0e958}, sa_mask = {__val = {128, 140718093936144, 140718623768352, 140718093936048, 0, 0, 140718093951152, 140718601324736, 140718601873564, 140718093951296, 140718093951296, 0, 3893693555, 0, 0, 0}}, sa_flags = 2080413184, sa_restorer = 0x1} sigs = {__val = {32, 0 }} #2 0x00007ffb97d0548c in talloc_abort (reason=0x7ffb97d0e958 "Bad talloc magic value - access after free") at ../talloc.c:340 No locals. #3 0x00007ffb97d04c0f in talloc_abort_access_after_free () at ../talloc.c:359 No locals. #4 talloc_chunk_from_ptr (ptr=ptr@entry=0x7ffb7c00a610) at ../talloc.c:380 No locals. #5 0x00007ffb97d091bf in talloc_chunk_from_ptr (ptr=0x7ffb7c00a610) at ../talloc.c:378 pp = 0x7ffb7c00a610 "P\276" tc = 0x7ffb7c00a5b0 #6 __talloc_with_prefix (prefix_len=32, size=837, context=0x7ffb7c00a610) at ../talloc.c:595 tc = 0x0 limit = 0x0 total_len = 965 #7 _talloc_pool (size=837, context=0x7ffb7c00a610) at ../talloc.c:668 No locals. #8 _talloc_pooled_object (ctx=, type_size=type_size@entry=128, type_name=type_name@entry=0x7ffb967c23b4 "struct tevent_req", num_subobjects=3, num_subobjects@entry=2, total_subobjects_size=total_subobjects_size@entry=280) at ../talloc.c:737 poolsize = 837 subobjects_slack = 429 tmp = 837 #9 0x00007ffb967bd82e in _tevent_req_create (mem_ctx=, pdata=0x7ffb87ffe2c8, data_size=200, type=0x7ffb98ddfcd6 "struct nb_packet_reader_state", location=0x7ffb98ddfa18 "../source3/libsmb/unexpected.c:481") at ../tevent_req.c:66 req = ppdata = 0x7ffb87ffe2c8 data = #10 0x00007ffb98dd0b07 in nb_packet_reader_send (mem_ctx=0xb87, ev=0x7ffb7c00be50, type=NMB_PACKET, trn_id=16910, mailslot_name=0x0) at ../source3/libsmb/unexpected.c:480 req = 0x7ffb7c00be50 subreq = 0x7ffb7c00a480 state = 0x0 path = 0x7ffb7c00a480 "" #11 0x00007ffb98dd5bb3 in nb_trans_send (mem_ctx=, ev=ev@entry=0x7ffb7c00be50, my_addr=0x7ffb7c00c950, dst_addr=0x7ffb7c00c9d0, bcast=bcast@entry=true, buf=0x7ffb7c00ca51 "B\016\001\020", buflen=50, trn_id=16910, validator=0x7ffb98dd4af0 , private_data=0x7ffb7c00c950, type=NMB_PACKET) at ../source3/libsmb/namequery.c:567 req = 0x7ffb7c00a480 subreq = state = 0x7ffb7c00a610 #12 0x00007ffb98dd7504 in name_query_send (mem_ctx=, ev=0x7ffb7c00be50, name=, name_type=29, bcast=, recurse=, addr=0x7ffb7c00c340) at ../source3/libsmb/namequery.c:1266 req = 0x7ffb7c00c7c0 subreq = state = 0x7ffb7c00c950 p = {next = 0x0, prev = 0x0, locked = false, ip = {s_addr = 0}, port = 0, recv_fd = 0, send_fd = 0, timestamp = 0, packet_type = NMB_PACKET, packet = {nmb = {header = {name_trn_id = 16910, opcode = 0, response = false, nm_flags = {bcast = true, recursion_available = false, recursion_desired = true, trunc = false, authoritative = false}, rcode = 0, qdcount = 1, ancount = 0, nscount = 0, arcount = 0}, question = {question_name = {name = "WORKGROUP\000\000\000\000\000\000", scope = '\000' , name_type = 29}, question_type = 32, question_class = 1}, answers = 0x0, nsrecs = 0x0, additional = 0x0}, dgram = {header = {msg_type = 16910, flags = {node_type = B_NODE, first = false, more = true}, dgm_id = 0, source_ip = {s_addr = 0}, source_port = 1, dgm_length = 0, packet_offset = 0}, source_name = {name = "\000\000\000\000WORKGROUP\000\000", scope = '\000' , name_type = 0}, dest_name = {name = "\035\000\000\000 \000\000\000\001\000\000\000\000\000\000", scope = '\000' , name_type = 0}, datasize = 0, data = '\000' }}} nmb = 0x7ffb87ffe3e8 in_addr = __FUNCTION__ = "name_query_send" #13 0x00007ffb98dd7f66 in name_queries_send (bcast=, recurse=, wait_msec=, timeout_msec=, num_addrs=, addrs=, name_type=, name=, ev=, mem_ctx=) at ../source3/libsmb/namequery.c:1630 req = 0x7ffb7c00c460 state = 0x7ffb7c00c5f0 #14 name_resolve_bcast_send (mem_ctx=0xb87, mem_ctx@entry=0x7ffb7c00bc80, ev=0x7ffb7c00be50, name=0x6 , name@entry=0x7ffb7c01c500 "WORKGROUP", name_type=-1, name_type@entry=29) at ../source3/libsmb/namequery.c:1830 req = 0x7ffb7c00c140 state = 0x7ffb7c00c2d0 bcast_addrs = 0x7ffb7c00c340 i = 1 num_addrs = 2080425056 num_bcast_addrs = 1 __FUNCTION__ = "name_resolve_bcast_send" #15 0x00007ffb98dd8287 in name_resolve_bcast (name=name@entry=0x7ffb7c01c500 "WORKGROUP", name_type=name_type@entry=29, mem_ctx=0x7ffb7c00bb60, return_iplist=return_iplist@entry=0x7ffb87ffe880, return_count=return_count@entry=0x7ffb87ffe984) at ../source3/libsmb/namequery.c:1888 frame = 0x7ffb7c00bc80 ev = 0x7ffb7c00be50 req = status = {v = 3221225495} #16 0x00007ffb98dd969c in internal_resolve_name (name=name@entry=0x7ffb7c01c500 "WORKGROUP", name_type=name_type@entry=29, sitename=sitename@entry=0x0, return_iplist=return_iplist@entry=0x7ffb87ffe988, return_count=return_count@entry=0x7ffb87ffe984, resolve_order=) at ../source3/libsmb/namequery.c:2708 ss_list = 0x0 tok = 0x7ffb7c002e00 "bcast" status = i = frame = 0x7ffb7c00bb60 __FUNCTION__ = "internal_resolve_name" #17 0x00007ffb98dd974b in resolve_name (name=0x7ffb7c01c500 "WORKGROUP", return_ss=0x7ffb87ffeab0, name_type=29, prefer_ipv4=) at ../source3/libsmb/namequery.c:2804 sitename = 0x0 count = 0 status = #18 0x00007ffb9b724abc in SMBC_opendir_ctx (context=0x7ffb7c003490, fname=0x7ffb7c0036b0 "smb://WORKGROUP/") at ../source3/libsmb/libsmb_dir.c:648 saved_errno = 2080397024 server = 0x7ffb7c01c500 "WORKGROUP" share = 0x7ffb7c0056d0 "" user = 0x7ffb7c013ab0 "chris" password = 0x7ffb7c00baf0 "" options = 0x7ffb7c013b20 "" workgroup = 0x7ffb7c006a10 "WORKGROUP" path = 0x7ffb7c009d20 "" mode = 32 port = 0 dir = 0x7ffb7c0056e0 rem_ss = {ss_family = 1, __ss_align = 140718601873564, __ss_padding = "$\000\000\000\000\000\000\000`\354\377\207\373\177\000\000$\000\000\000\000\000\000\000\220\354\377\207\373\177\000\000\001\000\000\000\000\000\000\000#\000\000\000\000\000\000\000#\000\000\000\000\000\000\000`\354\377\207\373\177\000\000p1\000|\373\177\000\000lgP\232\373\177\000\000\000\200\255\373\000\000\000\000p1\000|\373\177\000\000p1\000|\373\177\000\000p1\000|\373\177\000"} frame = 0x7ffb7c0031d0 __FUNCTION__ = "SMBC_opendir_ctx" #19 0x0000000000405bef in do_mount (backend=0x17c62e0, job=0xb91, mount_spec=0x6, mount_source=0x7ffb87fff690, is_automount=2080413184) at gvfsbackendsmbbrowse.c:987 op_backend = 0x17c62e0 smb_context = 0x7ffb7c003490 dir = 0x17c62e0 display_name = 0x7ffb7c00a060 "\260\066" debug = 0x0 debug_val = 2961 uri = 0x7ffb7c00a060 res = 2080490480 browse_mount_spec = 0x7ffb7c01c3f0 #20 0x00007ffb9b504fea in g_vfs_job_run (job=0x17c9ca0) at gvfsjob.c:197 class = 0x17d2f40 #21 0x00007ffb9b4ff73f in job_handler_callback (data=, user_data=) at gvfsdaemon.c:208 job = 0x17c9ca0 #22 0x00007ffb9aa472e8 in g_thread_pool_thread_proxy (data=) at /build/buildd/glib2.0-2.43.92/./glib/gthreadpool.c:307 task = 0x17c9ca0 pool = 0x17be0a0 #23 0x00007ffb9aa46955 in g_thread_proxy (data=0x17bb140) at /build/buildd/glib2.0-2.43.92/./glib/gthread.c:764 thread = 0x17bb140 #24 0x00007ffb9a7bf6aa in start_thread (arg=0x7ffb87fff700) at pthread_create.c:333 __res = pd = 0x7ffb87fff700 now = unwind_buf = {cancel_jmp_buf = {{jmp_buf = {140718295217920, 5774919086878009118, 0, 140727179143023, 140718295218624, 24895648, -5777082926244255970, -5777108249104439522}, mask_was_saved = 0}}, priv = {pad = {0x0, 0x0, 0x0, 0x0}, data = {prev = 0x0, cleanup = 0x0, canceltype = 0}}} not_first_call = pagesize_m1 = sp = freesize = __PRETTY_FUNCTION__ = "start_thread" #25 0x00007ffb9a4f4eed in clone () at ../sysdeps/unix/sysv/linux/x86_64/clone.S:109 No locals.