Bug 149548 - CRASH: copying and pasting tracked content
Summary: CRASH: copying and pasting tracked content
Status: VERIFIED FIXED
Alias: None
Product: LibreOffice
Classification: Unclassified
Component: Writer (show other bugs)
Version:
(earliest affected)
5.0.0.5 release
Hardware: All All
: medium normal
Assignee: Not Assigned
URL:
Whiteboard: target:7.5.0 target:7.4.1
Keywords: bibisected, bisected, haveBacktrace, regression
Depends on:
Blocks: Paste DOCX-Track-Changes Crash
  Show dependency treegraph
 
Reported: 2022-06-13 10:43 UTC by Xisco Faulí
Modified: 2022-09-06 03:59 UTC (History)
5 users (show)

See Also:
Crash report or crash signature: ["BigPtrArray::Index2Block(long)"]
Regression By: Noel Grandin


Attachments
sample file (134.40 KB, application/vnd.openxmlformats-officedocument.wordprocessingml.document)
2022-06-13 10:43 UTC, Xisco Faulí
Details
Backtrace (24.63 KB, text/plain)
2022-06-13 21:13 UTC, Aron Budea
Details

Note You need to log in before you can comment on or make changes to this bug.
Description Xisco Faulí 2022-06-13 10:43:07 UTC
Created attachment 180723 [details]
sample file

Steps to reproduce:
1. Open attached document
2. Select all
3. Copy
4. Paste

Reproduced in

Version: 7.4.0.0.alpha1+ / LibreOffice Community
Build ID: d4123356c61db269651e950a0a2cc93e6d801c90
CPU threads: 8; OS: Linux 5.10; UI render: default; VCL: x11
Locale: es-ES (es_ES.UTF-8); UI: en-US
Calc: threaded
Comment 1 Xisco Faulí 2022-06-13 10:49:14 UTC
Regression introduced by:

author	Aron Budea <aron.budea@collabora.com>	2018-03-25 08:33:16 +0200
committer	Aron Budea <aron.budea@collabora.com>	2018-03-26 15:44:07 +0200
commit 7b1d50e97eaa00855152e74f42b789fc643e0bac (patch)
tree 66d4e710ba020e3bc18533a464e356ca07619ea7
parent 4f268695787ff6c7052269058f7ae6de34abfd5d (diff)
tdf#106746: pDelPam is a bit special

Bisected with: bibisect-linux64-6.1

Adding Cc: to Aron Budea
Comment 2 Aron Budea 2022-06-13 14:41:18 UTC
For the record, my change simply reintroduced the behavior before the regressing commit identified in bug 106746 (hash: db17d3c17c40d6b0e92392cf3c6e343d1d17b771), and indeed, the crash is present at the commit preceding that (also eg. in 5.1.0.3).

But it's still a regression, and could be bibisected to the following commit using repo bibisect-50max. Same commit as found in bug 143276, bug 143215, bug 143278 and bug 144270. Adding CC: to Michael Stahl.

https://cgit.freedesktop.org/libreoffice/core/commit/?id=c4cf85766453982f1aa94a7f2cb22af19ed100be
author		Michael Stahl <mstahl@redhat.com>	2015-05-05 23:15:20 +0200
committer	Michael Stahl <mstahl@redhat.com>	2015-05-06 00:10:17 +0200

sw: fix crash due to redlines on tables on ooo121112-2.docx
Comment 3 Aron Budea 2022-06-13 21:13:19 UTC
Created attachment 180738 [details]
Backtrace

Attaching backtrace taken with LO 7.5.0.0.alpha0+ (3ad12672e924f7aef394119f9fe5f0b06a900b9e) debug build.

Also saw this on the console:

/usr/include/c++/9/debug/array:155:
In function:
    constexpr std::__debug::array<_Tp, _Nm>::value_type& 
    std::__debug::array<_Tp, _Nm>::operator[](std::__debug::array<_Tp, 
    _Nm>::size_type) [with _Tp = BigPtrEntry*; long unsigned int _Nm = 1000; 
    std::__debug::array<_Tp, _Nm>::reference = BigPtrEntry*&; 
    std::__debug::array<_Tp, _Nm>::value_type = BigPtrEntry*; 
    std::__debug::array<_Tp, _Nm>::size_type = long unsigned int]

Error: attempt to subscript container with out-of-bounds index 32450, but 
container only holds 1000 elements.

Objects involved in the operation:
    sequence "this" @ 0x0x1b {
      type = std::__debug::array<BigPtrEntry*, 1000ul>;
    }
Comment 4 Commit Notification 2022-07-18 08:59:03 UTC
Michael Stahl committed a patch related to this issue.
It has been pushed to "master":

https://git.libreoffice.org/core/commit/de49e1c55dc10ce1b59345af5cc49fde3adf65b7

tdf#149548 sw: don't rely on binary search in SplitRedline()

It will be available in 7.5.0.

The patch should be included in the daily builds available at
https://dev-builds.libreoffice.org/daily/ in the next 24-48 hours. More
information about daily builds can be found at:
https://wiki.documentfoundation.org/Testing_Daily_Builds

Affected users are encouraged to test the fix and report feedback.
Comment 5 Aron Budea 2022-07-18 13:12:00 UTC
Michael, thanks for fixing! Does the following mean that there is a problem with the bugdoc and such documents should normally not be created?

"The problem is that for this bugdoc overlapping redlines are created by
writerfilter"
Comment 6 Michael Stahl (allotropia) 2022-07-19 15:58:53 UTC
(In reply to Aron Budea from comment #5)
> Michael, thanks for fixing! Does the following mean that there is a problem
> with the bugdoc and such documents should normally not be created?
> 
> "The problem is that for this bugdoc overlapping redlines are created by
> writerfilter"

mainly it means that Writer shouldn't create such redlines, probably by splitting them up differently, but it looks like quite some work to fix that.
Comment 7 Xisco Faulí 2022-07-27 12:56:12 UTC
Hi Michael,
unfortunately the issue is still reproducible in

Version: 7.5.0.0.alpha0+ / LibreOffice Community
Build ID: c4f7043c593823b8c5605e779371ff430659eb20
CPU threads: 8; OS: Linux 5.10; UI render: default; VCL: gtk3
Locale: es-ES (es_ES.UTF-8); UI: en-US
Calc: threaded

following the steps in the description.
Comment 8 Michael Stahl (allotropia) 2022-08-10 14:46:54 UTC
bibisect finds that it worked on my commit but started to crash with this:

commit 2fe4de5167eb70e40a7d2f6e9c68247d2b151775
Author: Jenkins Build User <tdf@pollux.tdf>
Date:   Tue Jul 19 19:14:42 2022 +0200

    source sha:4701d17bfe785f00958ad58a63dc0ece4c5c3281


...i'm afraid there are some long-standing problems such as overlapping SwRangeRedlines that prevent optimizing this stuff.

for me reverting this commit makes it not crash on paste, see:
https://gerrit.libreoffice.org/c/core/+/138094


(i found an unrelated crash that happens when you copy all, then close the document, then copy anything else (clearing the first clipboard document), looks like an SfxItemPool UAF)
Comment 9 Commit Notification 2022-08-12 19:30:20 UTC
Michael Stahl committed a patch related to this issue.
It has been pushed to "master":

https://git.libreoffice.org/core/commit/656ff63ed045dfaedff7f34dc4adc0b203850543

tdf#149548 Revert "tdf#119840 loop backwards in ...

It will be available in 7.5.0.

The patch should be included in the daily builds available at
https://dev-builds.libreoffice.org/daily/ in the next 24-48 hours. More
information about daily builds can be found at:
https://wiki.documentfoundation.org/Testing_Daily_Builds

Affected users are encouraged to test the fix and report feedback.
Comment 10 Xisco Faulí 2022-08-16 14:07:32 UTC
(In reply to Michael Stahl (allotropia) from comment #8)
> (i found an unrelated crash that happens when you copy all, then close the
> document, then copy anything else (clearing the first clipboard document),
> looks like an SfxItemPool UAF)

Reported in bug 150441
Comment 11 Commit Notification 2022-08-18 08:13:11 UTC
Michael Stahl committed a patch related to this issue.
It has been pushed to "libreoffice-7-4":

https://git.libreoffice.org/core/commit/fa5838b018a5f1e5b1616bbacbb242eb4fac998a

tdf#149548 sw: don't rely on binary search in SplitRedline()

It will be available in 7.4.1.

The patch should be included in the daily builds available at
https://dev-builds.libreoffice.org/daily/ in the next 24-48 hours. More
information about daily builds can be found at:
https://wiki.documentfoundation.org/Testing_Daily_Builds

Affected users are encouraged to test the fix and report feedback.
Comment 12 Gabor Kelemen (allotropia) 2022-08-18 13:03:21 UTC
Verified in

Version: 7.5.0.0.alpha0+ (x64) / LibreOffice Community
Build ID: 8475b367298de73aec6abc60a159cc015baf9734
CPU threads: 14; OS: Windows 10.0 Build 19044; UI render: Skia/Raster; VCL: win
Locale: en-US (hu_HU); UI: en-US
Calc: threaded

Copy-paste of the whole document content does not crash.
Comment 13 Gabor Kelemen (allotropia) 2022-08-18 13:05:45 UTC
Oh no - Copy all and close LO does crash :(.
Comment 14 Telesto 2022-08-18 13:19:11 UTC
(In reply to Gabor Kelemen (allotropia) from comment #13)
> Oh no - Copy all and close LO does crash :(.

Crash or Assert. Assert is reported in bug 147731 & as duplicate of bug 147731
Comment 15 Gabor Kelemen (allotropia) 2022-08-18 14:01:44 UTC
(In reply to Telesto from comment #14)
> (In reply to Gabor Kelemen (allotropia) from comment #13)
> > Oh no - Copy all and close LO does crash :(.
> 
> Crash or Assert. Assert is reported in bug 147731 & as duplicate of bug
> 147731

Crash. Seems to have started in 6.1 or 6.2, so probably not a duplicate of the above. Will bibisect and file a new one.