rekonq crashed with SIGSEGV in JSC::JSArray::shiftCountWithArrayStorage()

Bug #1158271 reported by Balaam's Miracle
14
This bug affects 2 people
Affects Status Importance Assigned to Milestone
rekonq (Ubuntu)
Invalid
Medium
Unassigned

Bug Description

Rekonq was minimized at the time of the crash. A few tabs were open, but none displayed exceptionally heavy pages.

Description: Ubuntu Raring Ringtail (development branch)
Release: 13.04

rekonq Version 2.2.1

ProblemType: Crash
DistroRelease: Ubuntu 13.04
Package: rekonq 2.2.1-0ubuntu1
ProcVersionSignature: Ubuntu 3.8.0-12.21-generic 3.8.2
Uname: Linux 3.8.0-12-generic i686
NonfreeKernelModules: nvidia
ApportVersion: 2.9.2-0ubuntu1
Architecture: i386
CrashCounter: 1
Date: Wed Mar 20 14:46:49 2013
ExecutablePath: /usr/bin/rekonq
InstallationDate: Installed on 2012-08-13 (220 days ago)
InstallationMedia: Kubuntu 12.04 LTS "Precise Pangolin" - Release i386 (20120423)
MarkForUpload: True
ProcCmdline: /usr/bin/rekonq
ProcEnviron:
 PATH=(custom, no user)
 XDG_RUNTIME_DIR=<set>
 LANG=en_US.UTF-8
 SHELL=/bin/bash
 LANGUAGE=
SegvAnalysis:
 Segfault happened at: 0xb6a6761b <_ZN3JSC7JSArray26shiftCountWithArrayStorageEjjPNS_12ArrayStorageE+107>: testb $0x1,0x18(%ebp)
 PC (0xb6a6761b) ok
 source "$0x1" ok
 destination "0x18(%ebp)" (0x47ae1493) not located in a known VMA region (needed writable region)!
SegvReason: writing unknown VMA
Signal: 11
SourcePackage: rekonq
StacktraceTop:
 JSC::JSArray::shiftCountWithArrayStorage(unsigned int, unsigned int, JSC::ArrayStorage*) () from /usr/lib/i386-linux-gnu/libQtWebKit.so.4
 JSC::JSArray::shiftCountForShift(JSC::ExecState*, unsigned int, unsigned int) () from /usr/lib/i386-linux-gnu/libQtWebKit.so.4
 void JSC::shift<(JSC::JSArray::ShiftCountMode)0>(JSC::ExecState*, JSC::JSObject*, unsigned int, unsigned int, unsigned int, unsigned int) () from /usr/lib/i386-linux-gnu/libQtWebKit.so.4
 JSC::arrayProtoFuncShift(JSC::ExecState*) () from /usr/lib/i386-linux-gnu/libQtWebKit.so.4
 ?? ()
Title: rekonq crashed with SIGSEGV in JSC::JSArray::shiftCountWithArrayStorage()
UpgradeStatus: Upgraded to raring on 2013-03-15 (5 days ago)
UserGroups: adm cdrom dip floppy lpadmin mail plugdev sambashare scanner sudo vboxsf vboxusers

Revision history for this message
Balaam's Miracle (balaam-balaamsmiracle) wrote :
Revision history for this message
Apport retracing service (apport) wrote :

StacktraceTop:
 JSC::JSArray::shiftCountWithArrayStorage(unsigned int, unsigned int, JSC::ArrayStorage*) () from /tmp/apport_sandbox_SW7zbF/usr/lib/i386-linux-gnu/libQtWebKit.so.4
 JSC::JSArray::shiftCountForShift(JSC::ExecState*, unsigned int, unsigned int) () from /tmp/apport_sandbox_SW7zbF/usr/lib/i386-linux-gnu/libQtWebKit.so.4
 void JSC::shift<(JSC::JSArray::ShiftCountMode)0>(JSC::ExecState*, JSC::JSObject*, unsigned int, unsigned int, unsigned int, unsigned int) () from /tmp/apport_sandbox_SW7zbF/usr/lib/i386-linux-gnu/libQtWebKit.so.4
 JSC::arrayProtoFuncShift(JSC::ExecState*) () from /tmp/apport_sandbox_SW7zbF/usr/lib/i386-linux-gnu/libQtWebKit.so.4
 ?? ()

Revision history for this message
Apport retracing service (apport) wrote : Stacktrace.txt
Revision history for this message
Apport retracing service (apport) wrote : StacktraceSource.txt
Revision history for this message
Apport retracing service (apport) wrote : ThreadStacktrace.txt
Changed in rekonq (Ubuntu):
importance: Undecided → Medium
tags: removed: need-i386-retrace
Rohan Garg (rohangarg)
information type: Private → Public
Revision history for this message
Launchpad Janitor (janitor) wrote :

Status changed to 'Confirmed' because the bug affects multiple users.

Changed in rekonq (Ubuntu):
status: New → Confirmed
Revision history for this message
Shawn Peterson (shawnpeterson77) wrote :

So, not sure if it is happening for the same reason or not, but both rekonq and qupzilla (both of these use webkit) are crashing consistently for me on two different machines. On the one machine, I upgraded to 13.04. The other one is a fresh install of 13.04.

Here is a website that will cause them to crash everytime: http://www.webupd8.org/2013/04/7-things-to-do-after-installing-ubuntu.html

Revision history for this message
Rohan Garg (rohangarg) wrote :

Please file bugs against rekonq in the KDE bugtracker at https://bugs.kde.org

Changed in rekonq (Ubuntu):
status: Confirmed → Invalid
Revision history for this message
Shawn Peterson (shawnpeterson77) wrote :

https://bugs.kde.org/show_bug.cgi?id=318639 . Done, although I don't think it is specific to rekonq, as it also happens in qupzilla.

Revision history for this message
Rohan Garg (rohangarg) wrote :

Best to leave it to the Rekonq developers to decipher if that's an issue with qtwebkit since I have no idea how the qtwebkit stuff works.

If this does turn out to be a bug in QtWebkit, best to file it at the Webkit bug tracer at https://bugs.webkit.org

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.