Bug 205967 - Konqueror crashed on www.bahn.de, probably due to AJAX request
Summary: Konqueror crashed on www.bahn.de, probably due to AJAX request
Status: RESOLVED FIXED
Alias: None
Product: konqueror
Classification: Applications
Component: general (show other bugs)
Version: unspecified
Platform: Unlisted Binaries Linux
: NOR crash
Target Milestone: ---
Assignee: Konqueror Developers
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2009-09-02 11:02 UTC by Stefan Gründel
Modified: 2009-09-27 02:13 UTC (History)
1 user (show)

See Also:
Latest Commit:
Version Fixed In:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Stefan Gründel 2009-09-02 11:02:09 UTC
Application that crashed: konqueror
Version of the application: 4.3.1 (KDE 4.3.1)
KDE Version: 4.3.1 (KDE 4.3.1)
Qt Version: 4.5.2
Operating System: Linux 2.6.31-020631rc6-generic x86_64
Distribution: Ubuntu 9.04

What I was doing when the application crashed:
Crash while entering my destination train station on www.bahn.de, which should result in an AJAX autocompletion list.  After restarting konqueror and restoring the session, it worked.

 -- Backtrace:
Application: Konqueror (kdeinit4), signal: Aborted
[Current thread is 0 (LWP 4725)]

Thread 3 (Thread 0x7f1dd3183950 (LWP 4726)):
#0  __lll_lock_wait_private () at ../nptl/sysdeps/unix/sysv/linux/x86_64/lowlevellock.S:91
#1  0x00007f1de4c4c025 in _L_lock_4783 () from /lib/libc.so.6
#2  0x00007f1de4c4826b in *__GI___libc_free (mem=0x7f1de4f3ba00) at malloc.c:3623
#3  0x00007f1de431db2a in ?? () from /usr/lib/libglib-2.0.so.0
#4  0x00007f1de82eea52 in ~QEventDispatcherGlib (this=0x1a1bd10) at kernel/qeventdispatcher_glib.cpp:289
#5  0x00007f1de81dadfc in QThreadPrivate::finish (arg=<value optimized out>) at thread/qthread_unix.cpp:212
#6  0x00007f1de81dad3d in QThreadPrivate::start (arg=0x1a20760) at /usr/include/pthread.h:533
#7  0x00007f1de40cf3ba in start_thread (arg=<value optimized out>) at pthread_create.c:297
#8  0x00007f1de4cb3fcd in clone () at ../sysdeps/unix/sysv/linux/x86_64/clone.S:112
#9  0x0000000000000000 in ?? ()

Thread 2 (Thread 0x7f1dd289f950 (LWP 15582)):
#0  __lll_lock_wait_private () at ../nptl/sysdeps/unix/sysv/linux/x86_64/lowlevellock.S:91
#1  0x00007f1de4c4c025 in _L_lock_4783 () from /lib/libc.so.6
#2  0x00007f1de4c4826b in *__GI___libc_free (mem=0x7f1de4f3ba00) at malloc.c:3623
#3  0x00007f1de431db2a in ?? () from /usr/lib/libglib-2.0.so.0
#4  0x00007f1de82eea52 in ~QEventDispatcherGlib (this=0x1b06bf0) at kernel/qeventdispatcher_glib.cpp:289
#5  0x00007f1de81dadfc in QThreadPrivate::finish (arg=<value optimized out>) at thread/qthread_unix.cpp:212
#6  0x00007f1de81dad3d in QThreadPrivate::start (arg=0x283ed80) at /usr/include/pthread.h:533
#7  0x00007f1de40cf3ba in start_thread (arg=<value optimized out>) at pthread_create.c:297
#8  0x00007f1de4cb3fcd in clone () at ../sysdeps/unix/sysv/linux/x86_64/clone.S:112
#9  0x0000000000000000 in ?? ()

Thread 1 (Thread 0x7f1de87a2750 (LWP 4725)):
[KCrash Handler]
#5  0x00007f1de4c00fb5 in *__GI_raise (sig=<value optimized out>) at ../nptl/sysdeps/unix/sysv/linux/raise.c:64
#6  0x00007f1de4c02bc3 in *__GI_abort () at abort.c:88
#7  0x00007f1de4c40228 in __libc_message (do_abort=2, fmt=0x7f1de4d0a488 "*** glibc detected *** %s: %s: 0x%s ***\n") at ../sysdeps/unix/sysv/linux/libc_fatal.c:170
#8  0x00007f1de4c45cb8 in malloc_printerr (action=2, str=0x7f1de4d07a26 "corrupted double-linked list", ptr=<value optimized out>) at malloc.c:5994
#9  0x00007f1de4c48048 in _int_free (av=0x7f1de4f3ba00, mem=0xb324d80) at malloc.c:4726
#10 0x00007f1de4c48276 in *__GI___libc_free (mem=0x7f1de4d008a0) at malloc.c:3625
#11 0x00007f1dd5f51cd3 in ~NodeListImpl (this=0xb17cbc0) at /build/buildd/kde4libs-4.3.1/khtml/misc/shared.h:65
#12 0x00007f1dd5f53006 in ~TagNodeListImpl (this=0xb17cbc0) at /build/buildd/kde4libs-4.3.1/khtml/xml/dom_nodelistimpl.h:168
#13 0x00007f1dd60effeb in ~DOMNodeList (this=0x7f1dd1ded200) at /build/buildd/kde4libs-4.3.1/khtml/misc/shared.h:41
#14 0x00007f1dd5a52bba in KJS::Collector::collect () at /build/buildd/kde4libs-4.3.1/kjs/collector.cpp:720
#15 0x00007f1dd5a52ffe in KJS::Collector::allocate (s=64) at /build/buildd/kde4libs-4.3.1/kjs/collector.cpp:330
#16 0x00007f1dd5a6e573 in KJS::StringImp::toObject (this=0x7f1dd1da6b00, exec=<value optimized out>) at /build/buildd/kde4libs-4.3.1/kjs/internal.cpp:99
#17 0x00007f1dd5a96e7c in KJS::Machine::runBlock (exec=0x7fffc03465a0, codeBlock=<value optimized out>, parentExec=0x7fffc0347090) at /build/buildd/kde4libs-4.3.1/kjs/value.h:495
#18 0x00007f1dd5a7fd1f in KJS::FunctionImp::callAsFunction (this=0x7f1dd1ffb140, exec=0x7fffc0347090, thisObj=<value optimized out>, args=@0x7fffc0346fe0)
    at /build/buildd/kde4libs-4.3.1/kjs/function.cpp:144
#19 0x00007f1dd5a837b9 in KJS::JSObject::call (this=0x1275, exec=0x7f1de4d008a0, thisObj=0x6, args=@0xffffffffffffffff) at /build/buildd/kde4libs-4.3.1/kjs/object.cpp:69
#20 0x00007f1dd5a9e831 in KJS::Machine::runBlock (exec=0x7fffc0347090, codeBlock=<value optimized out>, parentExec=0x40694a0) at codes.def:1192
#21 0x00007f1dd5a7fd1f in KJS::FunctionImp::callAsFunction (this=0x7f1dd1ffa800, exec=0x40694a0, thisObj=<value optimized out>, args=@0x7fffc03472b0)
    at /build/buildd/kde4libs-4.3.1/kjs/function.cpp:144
#22 0x00007f1dd5a837b9 in KJS::JSObject::call (this=0x1275, exec=0x7f1de4d008a0, thisObj=0x6, args=@0xffffffffffffffff) at /build/buildd/kde4libs-4.3.1/kjs/object.cpp:69
#23 0x00007f1dd615455d in KJS::JSEventListener::handleEvent (this=0xb18b910, evt=@0x7fffc0347330) at /build/buildd/kde4libs-4.3.1/khtml/ecma/kjs_events.cpp:106
#24 0x00007f1dd5f4da58 in DOM::NodeImpl::handleLocalEvents (this=<value optimized out>, evt=0xb5dec80, useCapture=false) at /build/buildd/kde4libs-4.3.1/khtml/xml/dom_nodeimpl.cpp:718
#25 0x00007f1dd5f4df21 in DOM::NodeImpl::dispatchGenericEvent (this=0x37aba30, evt=0xb5dec80) at /build/buildd/kde4libs-4.3.1/khtml/xml/dom_nodeimpl.cpp:501
#26 0x00007f1dd5f4dfae in DOM::NodeImpl::dispatchEvent (this=0x37aba30, evt=0xb5dec80, exceptioncode=@0x7fffc0347434, tempEvent=true) at /build/buildd/kde4libs-4.3.1/khtml/xml/dom_nodeimpl.cpp:453
#27 0x00007f1dd5f4e930 in DOM::NodeImpl::dispatchKeyEvent (this=0x37aba30, key=0x7fffc0347e00, keypress=<value optimized out>) at /build/buildd/kde4libs-4.3.1/khtml/xml/dom_nodeimpl.cpp:694
#28 0x00007f1dd5eb1695 in KHTMLView::dispatchKeyEvent (this=0x23db3b0, _ke=0x7fffc0347e00) at /build/buildd/kde4libs-4.3.1/khtml/khtmlview.cpp:1650
#29 0x00007f1dd5eb94a0 in KHTMLView::keyReleaseEvent (this=0x23db3b0, _ke=0x7fffc0347e00) at /build/buildd/kde4libs-4.3.1/khtml/khtmlview.cpp:1987
#30 0x00007f1de58dc27c in QWidget::event (this=0x23db3b0, event=0x7fffc0347e00) at kernel/qwidget.cpp:7610
#31 0x00007f1de5c4ef0b in QFrame::event (this=0x23db3b0, e=0x7fffc0347e00) at widgets/qframe.cpp:559
#32 0x00007f1de5ce0639 in QAbstractScrollArea::event (this=0x23db3b0, e=0x7fffc0347e00) at widgets/qabstractscrollarea.cpp:918
#33 0x00007f1dd5eb8bf1 in KHTMLView::event (this=0x23db3b0, e=0x7fffc0347e00) at /build/buildd/kde4libs-4.3.1/khtml/khtmlview.cpp:546
#34 0x00007f1de588af4d in QApplicationPrivate::notify_helper (this=0x1a1c5a0, receiver=0x23db3b0, e=0x7fffc0347e00) at kernel/qapplication.cpp:4056
#35 0x00007f1de58940cf in QApplication::notify (this=<value optimized out>, receiver=0x23db3b0, e=0x7fffc0347e00) at kernel/qapplication.cpp:3662
#36 0x00007f1de699ddeb in KApplication::notify (this=0x7fffc034a1e0, receiver=0x9e06180, event=0x7fffc0347e00) at /build/buildd/kde4libs-4.3.1/kdeui/kernel/kapplication.cpp:302
#37 0x00007f1de82c46ac in QCoreApplication::notifyInternal (this=0x7fffc034a1e0, receiver=0x9e06180, event=0x7fffc0347e00) at kernel/qcoreapplication.cpp:610
#38 0x00007f1de59206a4 in QKeyMapper::sendKeyEvent (keyWidget=0x9e06180, grab=<value optimized out>, type=QEvent::KeyRelease, code=87, modifiers={i = -1070301136}, text=@0x7fffc0348020, 
    autorepeat=false, count=1, nativeScanCode=25, nativeVirtualKey=119, nativeModifiers=0) at kernel/qkeymapper_x11.cpp:1675
#39 0x00007f1de5922a02 in QKeyMapperPrivate::translateKeyEvent (this=0x1a51580, keyWidget=0x9e06180, event=0x7fffc0349c30, grab=117) at kernel/qkeymapper_x11.cpp:1645
#40 0x00007f1de58fb0e6 in QApplication::x11ProcessEvent (this=0x7fffc034a1e0, event=0x7fffc0349c30) at kernel/qapplication_x11.cpp:3443
#41 0x00007f1de5924454 in x11EventSourceDispatch (s=0x1a201e0, callback=0, user_data=0x0) at kernel/qguieventdispatcher_glib.cpp:146
#42 0x00007f1de431e20a in g_main_context_dispatch () from /usr/lib/libglib-2.0.so.0
#43 0x00007f1de43218e0 in ?? () from /usr/lib/libglib-2.0.so.0
#44 0x00007f1de4321a7c in g_main_context_iteration () from /usr/lib/libglib-2.0.so.0
#45 0x00007f1de82eda8f in QEventDispatcherGlib::processEvents (this=0x1995e70, flags=<value optimized out>) at kernel/qeventdispatcher_glib.cpp:327
#46 0x00007f1de5923bdf in QGuiEventDispatcherGlib::processEvents (this=0x1275, flags=<value optimized out>) at kernel/qguieventdispatcher_glib.cpp:202
#47 0x00007f1de82c2f42 in QEventLoop::processEvents (this=<value optimized out>, flags={i = -1070293216}) at kernel/qeventloop.cpp:149
#48 0x00007f1de82c3314 in QEventLoop::exec (this=0x7fffc0349f60, flags={i = -1070293136}) at kernel/qeventloop.cpp:201
#49 0x00007f1de82c55e4 in QCoreApplication::exec () at kernel/qcoreapplication.cpp:888
#50 0x00007f1ddcf124e2 in kdemain () from /usr/lib/libkdeinit4_konqueror.so
#51 0x0000000000407215 in launch (argc=3, _name=0x19d6108 "konqueror", args=<value optimized out>, cwd=0x0, envc=1, envs=0x19d613c "", reset_env=false, tty=0x0, avoid_loops=false, 
    startup_id_str=0x40a3a1 "0") at /build/buildd/kde4libs-4.3.1/kinit/kinit.cpp:677
#52 0x0000000000407a38 in handle_launcher_request (sock=7, who=<value optimized out>) at /build/buildd/kde4libs-4.3.1/kinit/kinit.cpp:1169
#53 0x0000000000407fe5 in handle_requests (waitForPid=0) at /build/buildd/kde4libs-4.3.1/kinit/kinit.cpp:1362
#54 0x0000000000408b26 in main (argc=2, argv=0x7fffc034b8c8, envp=0x7fffc034b8e0) at /build/buildd/kde4libs-4.3.1/kinit/kinit.cpp:1793

Reported using DrKonqi
Comment 1 Dario Andres 2009-09-02 14:26:33 UTC
This could be related to bug 186539 / bug 195547. Thanks
Comment 2 Maksim Orlovich 2009-09-27 02:12:28 UTC
SVN commit 1028401 by orlovich:

Handle reentry of setFocusNode via blur event.
Fixes crashes on bahn.de
BUG:201159
BUG:207952
BUG:201208
BUG:204050
BUG:195710
BUG:177689
BUG:205967
BUG:186539


 M  +12 -4     dom_docimpl.cpp  


WebSVN link: http://websvn.kde.org/?view=rev&revision=1028401
Comment 3 Maksim Orlovich 2009-09-27 02:13:34 UTC
SVN commit 1028402 by orlovich:

Merged revision:r1028401 | orlovich | 2009-09-26 20:12:19 -0400 (Sat, 26 Sep 2009) | 11 lines

Handle reentry of setFocusNode via blur event.
Fixes crashes on bahn.de
BUG:201159
BUG:207952
BUG:201208
BUG:204050
BUG:195710
BUG:177689
BUG:205967
BUG:186539

 M  +12 -4     dom_docimpl.cpp  


WebSVN link: http://websvn.kde.org/?view=rev&revision=1028402