| Summary: | Konqueror crash on vote submit | ||
|---|---|---|---|
| Product: | [Applications] konqueror | Reporter: | Miharu Amakase <miharu.amakase> |
| Component: | khtml renderer | Assignee: | Konqueror Bugs <konqueror-bugs-null> |
| Status: | RESOLVED WORKSFORME | ||
| Severity: | crash | CC: | justin.zobel |
| Priority: | NOR | ||
| Version First Reported In: | 4.3.4 | ||
| Target Milestone: | --- | ||
| Platform: | Ubuntu | ||
| OS: | Linux | ||
| Latest Commit: | Version Fixed/Implemented In: | ||
| Sentry Crash Report: | |||
|
Description
Miharu Amakase
2010-05-24 04:27:37 UTC
==10659== Invalid read of size 4 ==10659== at 0xBA27592: khtml::RenderCanvas::staticRegion() const (render_canvas.cpp:332) ==10659== by 0xB85A71E: KHTMLView::scrollContentsBy(int, int) (khtmlview.cpp:3995) ==10659== by 0x5EB79A5: QAbstractScrollAreaPrivate::_q_vslide(int) (qabstractscrollarea.cpp:1310) ==10659== by 0x5EB7E58: QAbstractScrollArea::qt_metacall(QMetaObject::Call, int, void**) (moc_qabstractscrollarea.cpp:85) ==10659== by 0x60F026E: QScrollArea::qt_metacall(QMetaObject::Call, int, void**) (moc_qscrollarea.cpp:69) ==10659== by 0xB85B6F9: KHTMLView::qt_metacall(QMetaObject::Call, int, void**) (khtmlview.moc:90) ==10659== by 0x5497E19: QMetaObject::metacall(QObject*, QMetaObject::Call, int, void**) (qmetaobject.cpp:237) ==10659== by 0x54A9EEE: QMetaObject::activate(QObject*, QMetaObject const*, int, void**) (qobject.cpp:3290) ==10659== by 0x60E956D: QAbstractSlider::valueChanged(int) (moc_qabstractslider.cpp:182) ==10659== by 0x5DC489C: QAbstractSlider::setValue(int) (qabstractslider.cpp:542) ==10659== by 0xB848A37: KHTMLView::setContentsPos(int, int) (khtmlview.cpp:752) ==10659== by 0xBB20FDA: KJS::WindowFunc::callAsFunction(KJS::ExecState*, KJS::JSObject*, KJS::List const&) (kjs_window.cpp:2004) ==10659== by 0xBB22705: KJS::JSObject::call(KJS::ExecState*, KJS::JSObject*, KJS::List const&) (object.h:616) ==10659== by 0xC470D00: KJS::Machine::runBlock(KJS::ExecState*, WTF::Vector<unsigned char, 0u> const&, KJS::ExecState*) (codes.def:1209) ==10659== by 0xC44C409: KJS::FunctionImp::callAsFunction(KJS::ExecState*, KJS::JSObject*, KJS::List const&) (function.cpp:172) ==10659== by 0xBB22705: KJS::JSObject::call(KJS::ExecState*, KJS::JSObject*, KJS::List const&) (object.h:616) ==10659== by 0xC42DDD3: KJS::FunctionProtoFunc::callAsFunction(KJS::ExecState*, KJS::JSObject*, KJS::List const&) (function_object.cpp:139) ==10659== by 0xBB22705: KJS::JSObject::call(KJS::ExecState*, KJS::JSObject*, KJS::List const&) (object.h:616) ==10659== by 0xC470D00: KJS::Machine::runBlock(KJS::ExecState*, WTF::Vector<unsigned char, 0u> const&, KJS::ExecState*) (codes.def:1209) ==10659== by 0xC44C409: KJS::FunctionImp::callAsFunction(KJS::ExecState*, KJS::JSObject*, KJS::List const&) (function.cpp:172) ==10659== by 0xBB22705: KJS::JSObject::call(KJS::ExecState*, KJS::JSObject*, KJS::List const&) (object.h:616) ==10659== by 0xBB45BD9: KJS::JSEventListener::handleEvent(DOM::Event&) (kjs_events.cpp:106) ==10659== by 0xBB51D6D: KJS::XMLHttpRequest::changeState(KJS::XMLHttpRequestState) (xmlhttprequest.cpp:366) ==10659== by 0xBB52567: KJS::XMLHttpRequest::slotFinished(KJob*) (xmlhttprequest.cpp:747) ==10659== by 0xBB525C6: KJS::XMLHttpRequestQObject::slotFinished(KJob*) (xmlhttprequest.cpp:93) ==10659== by 0xBB5275E: KJS::XMLHttpRequestQObject::qt_metacall(QMetaObject::Call, int, void**) (xmlhttprequest.moc:78) ==10659== by 0x5497E19: QMetaObject::metacall(QObject*, QMetaObject::Call, int, void**) (qmetaobject.cpp:237) ==10659== by 0x54A9EEE: QMetaObject::activate(QObject*, QMetaObject const*, int, void**) (qobject.cpp:3290) ==10659== by 0x5105E22: KJob::result(KJob*) (kjob.moc:194) ==10659== by 0x5106298: KJob::emitResult() (kjob.cpp:312) ==10659== by 0x44AF07E: KIO::SimpleJob::slotFinished() (job.cpp:522) ==10659== by 0x44AF942: KIO::TransferJob::slotFinished() (job.cpp:1111) ==10659== by 0x44B6392: KIO::TransferJob::qt_metacall(QMetaObject::Call, int, void**) (jobclasses.moc:367) ==10659== by 0x5497E19: QMetaObject::metacall(QObject*, QMetaObject::Call, int, void**) (qmetaobject.cpp:237) ==10659== by 0x54A9EEE: QMetaObject::activate(QObject*, QMetaObject const*, int, void**) (qobject.cpp:3290) ==10659== by 0x455D3B6: KIO::SlaveInterface::finished() (slaveinterface.moc:171) ==10659== by 0x455F0A1: KIO::SlaveInterface::dispatch(int, QByteArray const&) (slaveinterface.cpp:175) ==10659== by 0x455FC59: KIO::SlaveInterface::dispatch() (slaveinterface.cpp:91) ==10659== by 0x4552AD3: KIO::Slave::gotInput() (slave.cpp:344) ==10659== by 0x455400A: KIO::Slave::qt_metacall(QMetaObject::Call, int, void**) (slave.moc:82) ==10659== by 0x5497E19: QMetaObject::metacall(QObject*, QMetaObject::Call, int, void**) (qmetaobject.cpp:237) ==10659== by 0x54A9EEE: QMetaObject::activate(QObject*, QMetaObject const*, int, void**) (qobject.cpp:3290) ==10659== by 0x4479A36: KIO::Connection::readyRead() (connection.moc:92) ==10659== by 0x447AA55: KIO::ConnectionPrivate::dequeue() (connection.cpp:82) ==10659== by 0x447B8D5: KIO::Connection::qt_metacall(QMetaObject::Call, int, void**) (connection.moc:79) ==10659== by 0x5497E19: QMetaObject::metacall(QObject*, QMetaObject::Call, int, void**) (qmetaobject.cpp:237) ==10659== by 0x54A48F6: QMetaCallEvent::placeMetaCall(QObject*) (qobject.cpp:561) ==10659== by 0x54A65A4: QObject::event(QEvent*) (qobject.cpp:1245) ==10659== by 0x5984DE9: QApplicationPrivate::notify_helper(QObject*, QEvent*) (qapplication.cpp:4304) ==10659== by 0x59826A9: QApplication::notify(QObject*, QEvent*) (qapplication.cpp:3708) ==10659== Address 0xc743af8 is 8 bytes inside a block of size 140 free'd ==10659== at 0x4023996: free (vg_replace_malloc.c:325) ==10659== by 0xB9EC2D5: khtml::RenderArena::free(unsigned int, void*) (render_arena.cpp:122) ==10659== by 0xB9CA712: khtml::RenderObject::arenaDelete(khtml::RenderArena*, void*) (render_object.cpp:2400) ==10659== by 0xB9CA7D7: khtml::RenderObject::detach() (render_object.cpp:2385) ==10659== by 0xB9E299A: khtml::RenderBox::detach() (render_box.cpp:224) ==10659== by 0xB9E531A: khtml::RenderFlow::detach() (render_flow.cpp:362) ==10659== by 0xB9028FB: DOM::NodeImpl::detach() (dom_nodeimpl.cpp:976) ==10659== by 0xB90297F: DOM::NodeBaseImpl::detach() (dom_nodeimpl.cpp:1966) ==10659== by 0xB912081: DOM::ElementImpl::detach() (dom_elementimpl.cpp:914) ==10659== by 0xB902965: DOM::NodeBaseImpl::detach() (dom_nodeimpl.cpp:1964) ==10659== by 0xB912081: DOM::ElementImpl::detach() (dom_elementimpl.cpp:914) ==10659== by 0xB902965: DOM::NodeBaseImpl::detach() (dom_nodeimpl.cpp:1964) ==10659== by 0xB912081: DOM::ElementImpl::detach() (dom_elementimpl.cpp:914) ==10659== by 0xB902965: DOM::NodeBaseImpl::detach() (dom_nodeimpl.cpp:1964) ==10659== by 0xB912081: DOM::ElementImpl::detach() (dom_elementimpl.cpp:914) ==10659== by 0xB902965: DOM::NodeBaseImpl::detach() (dom_nodeimpl.cpp:1964) ==10659== by 0xB912081: DOM::ElementImpl::detach() (dom_elementimpl.cpp:914) ==10659== by 0xB902965: DOM::NodeBaseImpl::detach() (dom_nodeimpl.cpp:1964) ==10659== by 0xB912081: DOM::ElementImpl::detach() (dom_elementimpl.cpp:914) ==10659== by 0xB902965: DOM::NodeBaseImpl::detach() (dom_nodeimpl.cpp:1964) ==10659== by 0xB912081: DOM::ElementImpl::detach() (dom_elementimpl.cpp:914) ==10659== by 0xB911CFD: DOM::ElementImpl::recalcStyle(DOM::NodeImpl::StyleChange) (dom_elementimpl.cpp:988) ==10659== by 0xB9619A8: DOM::HTMLElementImpl::recalcStyle(DOM::NodeImpl::StyleChange) (html_elementimpl.cpp:237) ==10659== by 0xB911DEE: DOM::ElementImpl::recalcStyle(DOM::NodeImpl::StyleChange) (dom_elementimpl.cpp:1019) ==10659== by 0xB9619A8: DOM::HTMLElementImpl::recalcStyle(DOM::NodeImpl::StyleChange) (html_elementimpl.cpp:237) ==10659== by 0xB911DEE: DOM::ElementImpl::recalcStyle(DOM::NodeImpl::StyleChange) (dom_elementimpl.cpp:1019) ==10659== by 0xB9619A8: DOM::HTMLElementImpl::recalcStyle(DOM::NodeImpl::StyleChange) (html_elementimpl.cpp:237) ==10659== by 0xB911DEE: DOM::ElementImpl::recalcStyle(DOM::NodeImpl::StyleChange) (dom_elementimpl.cpp:1019) ==10659== by 0xB9619A8: DOM::HTMLElementImpl::recalcStyle(DOM::NodeImpl::StyleChange) (html_elementimpl.cpp:237) ==10659== by 0xB911DEE: DOM::ElementImpl::recalcStyle(DOM::NodeImpl::StyleChange) (dom_elementimpl.cpp:1019) ==10659== by 0xB9619A8: DOM::HTMLElementImpl::recalcStyle(DOM::NodeImpl::StyleChange) (html_elementimpl.cpp:237) ==10659== by 0xB8F0476: DOM::DocumentImpl::recalcStyle(DOM::NodeImpl::StyleChange) (dom_docimpl.cpp:1443) ==10659== by 0xB8E96C8: DOM::DocumentImpl::updateRendering() (dom_docimpl.cpp:1472) ==10659== by 0xB8F0054: DOM::DocumentImpl::updateDocumentsRendering() (dom_docimpl.cpp:1485) ==10659== by 0xB9085F2: DOM::NodeImpl::dispatchGenericEvent(DOM::EventImpl*, int&) (dom_nodeimpl.cpp:544) ==10659== by 0xB906D3A: DOM::NodeImpl::dispatchEvent(DOM::EventImpl*, int&, bool) (dom_nodeimpl.cpp:454) ==10659== by 0xB908C57: DOM::NodeImpl::dispatchHTMLEvent(int, bool, bool) (dom_nodeimpl.cpp:553) ==10659== by 0xB978F73: DOM::HTMLFormElementImpl::reset() (html_formimpl.cpp:726) ==10659== by 0xBAFD754: KJS::HTMLElementFunction::callAsFunction(KJS::ExecState*, KJS::JSObject*, KJS::List const&) (kjs_html.cpp:2136) ==10659== by 0xBB22705: KJS::JSObject::call(KJS::ExecState*, KJS::JSObject*, KJS::List const&) (object.h:616) ==10659== by 0xC470D00: KJS::Machine::runBlock(KJS::ExecState*, WTF::Vector<unsigned char, 0u> const&, KJS::ExecState*) (codes.def:1209) ==10659== by 0xC44C409: KJS::FunctionImp::callAsFunction(KJS::ExecState*, KJS::JSObject*, KJS::List const&) (function.cpp:172) ==10659== by 0xBB22705: KJS::JSObject::call(KJS::ExecState*, KJS::JSObject*, KJS::List const&) (object.h:616) ==10659== by 0xC470D00: KJS::Machine::runBlock(KJS::ExecState*, WTF::Vector<unsigned char, 0u> const&, KJS::ExecState*) (codes.def:1209) ==10659== by 0xC44C409: KJS::FunctionImp::callAsFunction(KJS::ExecState*, KJS::JSObject*, KJS::List const&) (function.cpp:172) ==10659== by 0xBB22705: KJS::JSObject::call(KJS::ExecState*, KJS::JSObject*, KJS::List const&) (object.h:616) ==10659== by 0xC42DDD3: KJS::FunctionProtoFunc::callAsFunction(KJS::ExecState*, KJS::JSObject*, KJS::List const&) (function_object.cpp:139) ==10659== by 0xBB22705: KJS::JSObject::call(KJS::ExecState*, KJS::JSObject*, KJS::List const&) (object.h:616) ==10659== by 0xC470D00: KJS::Machine::runBlock(KJS::ExecState*, WTF::Vector<unsigned char, 0u> const&, KJS::ExecState*) (codes.def:1209) ==10659== by 0xC44C409: KJS::FunctionImp::callAsFunction(KJS::ExecState*, KJS::JSObject*, KJS::List const&) (function.cpp:172) Thank you for the report, Miharu. As it has been a while since this was reported, can you please test and confirm if this issue is still occurring or if this bug report can be marked as resolved. I have set the bug status to "needsinfo" pending your response, please change back to "reported" or "resolved/worksforme" when you respond, thank you. Hi Justin, You can change this to "resolved/worksforme". > Gesendet: Donnerstag, 03. Dezember 2020 um 23:54 Uhr > Von: "Justin Zobel" <bugzilla_noreply@kde.org> > An: miharu.amakase@gmx.net > Betreff: [konqueror] [Bug 238645] Konqueror crash on vote submit > > https://bugs.kde.org/show_bug.cgi?id=238645 > > Justin Zobel <justin.zobel@gmail.com> changed: > > What |Removed |Added > ---------------------------------------------------------------------------- > Status|CONFIRMED |NEEDSINFO > Resolution|--- |WAITINGFORINFO > CC| |justin.zobel@gmail.com > > --- Comment #2 from Justin Zobel <justin.zobel@gmail.com> --- > Thank you for the report, Miharu. > > As it has been a while since this was reported, can you please test and confirm > if this issue is still occurring or if this bug report can be marked as > resolved. > > I have set the bug status to "needsinfo" pending your response, please change > back to "reported" or "resolved/worksforme" when you respond, thank you. > > -- > You are receiving this mail because: > You reported the bug. |