Bug 49775

Summary: CRASH when FILEOPEN particular .rtf
Product: LibreOffice Reporter: Carlo Di Dato <shinnai>
Component: WriterAssignee: Miklos Vajna <vmiklos>
Status: RESOLVED DUPLICATE    
Severity: major CC: jbfaure, LibreOffice, robinson.libreoffice, serval2412, s-joyemusequna, vmiklos
Priority: medium Keywords: regression
Version: 3.5.3 release   
Hardware: x86 (IA32)   
OS: Windows (All)   
Whiteboard: bibisected35
Crash report or crash signature: Regression By:
Attachments: Proof of concept
crash.gz
console msgs + bt
bt + console msg on 3.5 updated
Bug 49775 - WinDbg session

Description Carlo Di Dato 2012-05-11 00:06:56 UTC
Created attachment 61418 [details]
Proof of concept

Hi, 
attached you can find a compressed file containing:

1) crash.rtf (poc)
2) fault_soffice_bin.txt (registers status atm of crash)
3) fault_soffice_exe.txt (registers status atm of crash)
4) fault_swriter.txt (registers status atm of crash)

Regards
Comment 1 Rainer Bielefeld Retired 2012-05-11 02:21:27 UTC
[Reproducible] with reporter's sample "LibreOffice 3.5.3.2 (RC2) German UI/Locale [Build-ID: 235ab8a-3802056-4a8fed3-2d66ea8-e241b80] on German WIN7 Home Premium (64bit) 
Still a problem with parallel installation of Master "LOdev 3.6.0alpha0+  – WIN7 Home Premium (64bit) ENGLISH UI [Build ID: 7f3f6e4]" (tinderbox: Win-x86@6-fast, pull time 2012-05-08 21:43:52)

No Crash with 3.4.5, so Regression

We had some RTF crash fixes some days ago, I will check with latest Master.
Comment 2 Rainer Bielefeld Retired 2012-05-11 04:27:55 UTC
Still [Reproducible] with parallel installation of Master "LOdev 3.6.0alpha0+  – WIN7 Home Premium (64bit) ENGLISH UI [Build ID: 9980e69]" (tinderbox: Win-x86@6-fast, pull time 2012-05-10 09:36:56)

@Miklós:
Please set Status to ASSIGNED and add yourself to "Assigned To" if you accept this Bug
Comment 3 Rainer Bielefeld Retired 2012-05-11 04:29:09 UTC
@Carlo Di Dato 
Is this the only crashing document or is that a problem for a bigger number of documents?
Comment 4 Carlo Di Dato 2012-05-11 05:20:29 UTC
@Rainer Bielefeld
at the moment I have just this file
Comment 5 Julien Nabet 2012-05-11 23:42:11 UTC
On pc x86-64 Debian testing, unrar package can't open the archive you attached.
Could you please use an open format to compress the files ? (zip, gzip, ...)
Comment 6 Carlo Di Dato 2012-05-13 23:48:08 UTC
Created attachment 61593 [details]
crash.gz

@Julien Nabet
Here it is
Comment 7 Julien Nabet 2012-05-15 12:54:59 UTC
Created attachment 61684 [details]
console msgs + bt

On pc Debian x86-64, master updated today, I reproduced the problem.
I attached console messages + bt with symbols.

carlo: thank you for having resent the file compressed with gzip.
Comment 8 Robinson Tryon (qubit) 2012-05-20 22:50:50 UTC
On Ubuntu 11.10 (x86_64), no crash with 3.5.4 rc1 or with oldest/latest from bibisect tool:

LibreOffice 3.5.4.1 Build ID: 7306755-f4f605c-738527d-1cf4bc1-9930dc8
LibreOffice 3.5.0 Build ID: d6cde02
LibreOffice 3.5.0 Build ID: 85c6244

@Julien Nabet -- could you try a 3.5.4.1 build?

(If the bug is reproducible under Debian, should the platform be changed to 'All' ?)
Comment 9 Julien Nabet 2012-05-21 12:19:07 UTC
Created attachment 61927 [details]
bt + console msg on 3.5 updated

Still on pc Debian x86-64, I reproduced this problem on 3.5 and master both updated today and each time by resetting LO profile.
I attached the console + bt messages from 3.5 Almost the same logs than before except the lines which slightly differ.
Comment 10 bfoman (inactive) 2012-05-31 04:25:21 UTC
Created attachment 62327 [details]
Bug 49775 - WinDbg session

Confirmed with:
LO 3.5.4.2 
Build ID: own W7 debug build
Windows 7 Professional SP1 64 bit

Crash while loading.
Attached full WinDbg session with mini dump file loaded generated by procdump  soffice.bin -h.
Comment 11 s-joyemusequna 2012-06-15 03:19:35 UTC
It works with LOdev 3.7 (master - 2012-06-14, Win-x86@6-fast; Build ID: 5af60dc) under Windows XP and Vista 64.

It crashes with LibO 3.6 Beta 1 though.

Shall I close the bug?
Comment 12 Miklos Vajna 2012-06-15 03:26:14 UTC
Hi,

Yes, let's close, based on the bt I think this is a duplicate of bug 49178.

Thanks,

Miklos

*** This bug has been marked as a duplicate of bug 49178 ***