thunderbird 2.0.16 (from mozilla.org) crash with invalid pointer in munmap_chunk

RESOLVED WORKSFORME

Status

--
critical
RESOLVED WORKSFORME
10 years ago
9 years ago

People

(Reporter: wharms, Unassigned)

Tracking

({crash})

x86
Linux
crash

Firefox Tracking Flags

(Not tracked)

Details

(Reporter)

Description

10 years ago
User-Agent:       Mozilla/5.0 (X11; U; Linux i686; de; rv:1.9.0.1) Gecko/2008070400 SUSE/3.0.1-0.1 Firefox/3.0.1
Build Identifier: thunderbird-bin: munmap_chunk(): invalid pointer: 0x09e118f8 ***

After running thunderbird for sometime random crashes occur.
(see also:bug 453956)

Reproducible: Always

Steps to Reproduce:
1.Start thunderbird
2.Connect to IMAP
3.Keep it running for some days (sometimes is crashes faster)

Actual Results:  
Crash with back trace



this bug is reported already to opensuse fro thunderbird 2.0.12. I did not get any feedback for now but i think this type of bug points to a larger problem that should be investigated.
(Reporter)

Comment 1

10 years ago
backtrace since start, the "Couldn't load XPCOM" are produced when i tried to
start firefox directly from thunderbird. 

/opt/thunderbird-2.0.16/thunderbird 
Couldn't load XPCOM.
Couldn't load XPCOM.
Gtk-Message: (for origin information, set GTK_DEBUG): failed to retrieve property `GtkTreeView::odd-row-color' of type `GdkColor' from rc file value "((GString*) 0xa234c40)" of type `GString'
Couldn't load XPCOM.

(eog:6887): EOG-CRITICAL **: eog_list_store_get_pos_by_image: assertion `EOG_IS_IMAGE (image)' failed

(eog:6887): EOG-CRITICAL **: eog_list_store_get_pos_by_image: assertion `EOG_IS_IMAGE (image)' failed
Couldn't load XPCOM.
*** glibc detected *** /opt/thunderbird-2.0.16/thunderbird-bin: munmap_chunk(): invalid pointer: 0x09e118f8 ***
======= Backtrace: =========
/lib/libc.so.6[0xb72c1fc4]
/lib/libc.so.6[0xb72c3059]
/usr/lib/libstdc++.so.5(_ZdlPv+0x21)[0xb7440bd1]
/opt/thunderbird-2.0.16/libxpcom_core.so[0xb7e78650]
/opt/thunderbird-2.0.16/libxpcom_core.so(PL_DHashTableRawRemove+0x20)[0xb7e6d180]
/opt/thunderbird-2.0.16/libxpcom_core.so(PL_DHashTableEnumerate+0x188)[0xb7e6d338]
/opt/thunderbird-2.0.16/libxpcom_core.so(_ZN11nsHashtable5ResetEPFiP9nsHashKeyPvS2_ES2_+0x4c)[0xb7e78dcc]
/opt/thunderbird-2.0.16/thunderbird-bin[0x89074cb]
/opt/thunderbird-2.0.16/thunderbird-bin[0x8906efe]
/opt/thunderbird-2.0.16/libxpcom_core.so(_ZN13nsCOMPtr_baseD2Ev+0x18)[0xb7e6d3f8]
/opt/thunderbird-2.0.16/thunderbird-bin[0x88f02e2]
/opt/thunderbird-2.0.16/thunderbird-bin[0x88da20d]
/opt/thunderbird-2.0.16/thunderbird-bin[0x89a680e]
/opt/thunderbird-2.0.16/libxpcom_core.so(_ZN13nsCOMPtr_base18assign_with_AddRefEP11nsISupports+0x2c)[0xb7e6d44c]
/opt/thunderbird-2.0.16/libxpcom_core.so(_ZN8nsThread4MainEPv+0x44)[0xb7eb9c54]
/opt/thunderbird-2.0.16/libnspr4.so[0xb7e178f1]
/lib/libpthread.so.0[0xb7dc2175]
/lib/libc.so.6(clone+0x5e)[0xb7323dce]
======= Memory map: ========
08048000-08d0e000 r-xp 00000000 08:13 39498      /opt/thunderbird-2.0.16/thunderbird-bin
08d0e000-08d27000 rwxp 00cc5000 08:13 39498      /opt/thunderbird-2.0.16/thunderbird-bin
08d27000-0ba08000 rwxp 08d27000 00:00 0          [heap]
aa7de000-aa7df000 ---p aa7de000 00:00 0 
aa7df000-aafdf000 rwxp aa7df000 00:00 0 
aafdf000-aba63000 r-xp 00000000 08:13 31081      /opt/kde3/share/icons/hicolor/icon-theme.cache
aba63000-ac34a000 r-xp 00000000 08:12 126398     /usr/share/icons/hicolor/icon-theme.cache
ac34a000-ac56b000 r-xp 00000000 08:13 29469      /etc/opt/kde3/share/icons/crystalsvg/icon-theme.cache
ac56b000-ad675000 r-xp 00000000 08:13 29473      /opt/kde3/share/icons/crystalsvg/icon-theme.cache
ad675000-ad676000 ---p ad675000 00:00 0 
ad676000-ade76000 rwxp ad676000 00:00 0 
ade76000-ade77000 ---p ade76000 00:00 0 
ade77000-ae677000 rwxp ade77000 00:00 0 
ae677000-ae678000 ---p ae677000 00:00 0 
ae678000-aee78000 rwxp ae678000 00:00 0 
aee78000-aee79000 ---p aee78000 00:00 0 
aee79000-af679000 rwxp aee79000 00:00 0 
af679000-af67a000 ---p af679000 00:00 0 
af67a000-afe7a000 rwxp af67a000 00:00 0 
afe7a000-afe7b000 ---p afe7a000 00:00 0 
afe7b000-b0e7d000 rwxp afe7b000 00:00 0 
b1200000-b1300000 rwxp b1200000 00:00 0 
b13bd000-b13be000 rwxp b13bd000 00:00 0 
b13c0000-b14a5000 r-xp 00000000 08:12 16725      /usr/lib/libstdc++.so.6.0.10
b14a5000-b14a9000 r-xp 000e5000 08:12 16725      /usr/lib/libstdc++.so.6.0.10
b14a9000-b14aa000 rwxp 000e9000 08:12 16725      /usr/lib/libstdc++.so.6.0.10
b14aa000-b14b0000 rwxp b14aa000 00:00 0 
b14b0000-b1bb4000 r-xp 00000000 08:12 314106     /usr/share/icons/gnome/icon-theme.cache
b1bbf000-b1bc0000 ---p b1bbf000 00:00 0 
b1bc0000-b23c0000 rwxp b1bc0000 00:00 0 
b23c0000-b23c4000 r-xp 00000000 08:13 38584      /opt/thunderbird-2.0.16/components/libmozgnome.so
b23c4000-b23c5000 rwxp 00003000 08:13 38584      /opt/thunderbird-2.0.16/components/libmozgnome.so
b23c5000-b2402000 r-xp 00000000 08:13 39363      /opt/thunderbird-2.0.16/libnssckbi.so
b2402000-b240c000 rwxp 0003d000 08:13 39363      /opt/thunderbird-2.0.16/libnssckbi.so
b240c000-b2448000 r-xp 00000000 08:13 39140      /opt/thunderbird-2.0.16/libfreebl3.so
b2448000-b2449000 rwxp 0003c000 08:13 39140      /opt/thunderbird-2.0.16/libfreebl3.so
b2449000-b244a000 ---p b2449000 00:00 0 
b244a000-b2c4a000 rwxp b244a000 00:00 0 
b2c4a000-b2c4b000 ---p b2c4a000 00:00 0 
b2c4b000-b344b000 rwxp b2c4b000 00:00 0 
b344b000-b34ab000 rwxs 00000000 00:09 111476743  /SYSV00000000 (deleted)
b34d5000-b34d7000 r-xp 00000000 08:12 109451     /usr/lib/pango/1.6.0/modules/pango-basic-fc.so
b34d7000-b34d8000 r-xp 00001000 08:12 109451     /usr/lib/pango/1.6.0/modules/pango-basic-fc.so
b34d8000-b34d9000 rwxp 00002000 08:12 109451     /usr/lib/pango/1.6.0/modules/pango-basic-fc.so
b34d9000-b3503000 r-xp 00000000 08:12 20724      /usr/share/fonts/truetype/albw.ttf
b352d000-b353d0/opt/thunderbird-2.0.16/run-mozilla.sh: line 131:   856 Abgebrochen             "$prog" ${1+"$@"}
(Reporter)

Comment 2

10 years ago
after the last anoying crash i used valgrind2 to find the bug. here are the highlights of the valgrind output. (Mismatched free() / delete / delete [])

==17848== Syscall param writev(vector[...]) points to uninitialised byte(s)
==17848==    at 0x1B8E47D2: (within /lib/ld-2.8.so)
==17848==    by 0x1E121992: (within /usr/lib/libORBit-2.so.0.1.0)
==17848==    by 0x1E122E9F: link_connection_writev (in /usr/lib/libORBit-2.so.0.1.0)
==17848==    by 0x1E101BC7: giop_send_buffer_write (in /usr/lib/libORBit-2.so.0.1.0)
==17848==    by 0x1E1068A5: (within /usr/lib/libORBit-2.so.0.1.0)
==17848==    by 0x1E107EAE: ORBit_small_invoke_stub (in /usr/lib/libORBit-2.so.0.1.0)
==17848==    by 0x1E108108: ORBit_small_invoke_stub_n (in /usr/lib/libORBit-2.so.0.1.0)
==17848==    by 0x1E114DA9: ORBit_c_stub_invoke (in /usr/lib/libORBit-2.so.0.1.0)
==17848==    by 0x1E0D7F4D: ConfigServer_ping (in /usr/lib/libgconf-2.so.4.1.5)
==17848==    by 0x1E0C0CAF: gconf_activate_server (in /usr/lib/libgconf-2.so.4.1.5)
==17848==    by 0x1E0CB198: (within /usr/lib/libgconf-2.so.4.1.5)
==17848==    by 0x1E0CC125: (within /usr/lib/libgconf-2.so.4.1.5)
==17848==  Address 0x1DFBB5F2 is 10 bytes inside a block of size 2048 alloc'd
==17848==    at 0x1B90A2B6: malloc (in /usr/lib/valgrind2/vgpreload_memcheck.so)
==17848==    by 0x1C0BC583: g_malloc (in /usr/lib/libglib-2.0.so.0.1600.3)
==17848==    by 0x1E101125: (within /usr/lib/libORBit-2.so.0.1.0)
==17848==    by 0x1E1011CD: (within /usr/lib/libORBit-2.so.0.1.0)
==17848==    by 0x1E1019E7: giop_send_buffer_use_request (in /usr/lib/libORBit-2.so.0.1.0)
==17848==    by 0x1E106844: (within /usr/lib/libORBit-2.so.0.1.0)
==17848==    by 0x1E107EAE: ORBit_small_invoke_stub (in /usr/lib/libORBit-2.so.0.1.0)
==17848==    by 0x1E108108: ORBit_small_invoke_stub_n (in /usr/lib/libORBit-2.so.0.1.0)
==17848==    by 0x1E114DA9: ORBit_c_stub_invoke (in /usr/lib/libORBit-2.so.0.1.0)
==17848==    by 0x1E0D7F4D: ConfigServer_ping (in /usr/lib/libgconf-2.so.4.1.5)
==17848==    by 0x1E0C0CAF: gconf_activate_server (in /usr/lib/libgconf-2.so.4.1.5)
==17848==    by 0x1E0CB198: (within /usr/lib/libgconf-2.so.4.1.5)

==17848== 
==17848== Mismatched free() / delete / delete []
==17848==    at 0x1B90A7D7: free (in /usr/lib/valgrind2/vgpreload_memcheck.so)
==17848==    by 0x1BAE0A96: PR_Free (in /usr/lib/libnspr4.so)
==17848==    by 0x898F937: (within /usr/lib/thunderbird/thunderbird-bin)
==17848==    by 0x8989BED: (within /usr/lib/thunderbird/thunderbird-bin)
==17848==    by 0x8991085: (within /usr/lib/thunderbird/thunderbird-bin)
==17848==    by 0x8986FD7: (within /usr/lib/thunderbird/thunderbird-bin)
==17848==    by 0x89855C0: (within /usr/lib/thunderbird/thunderbird-bin)
==17848==    by 0x898C27A: (within /usr/lib/thunderbird/thunderbird-bin)
==17848==    by 0x8986FD7: (within /usr/lib/thunderbird/thunderbird-bin)
==17848==    by 0x8999942: (within /usr/lib/thunderbird/thunderbird-bin)
==17848==    by 0x891B540: (within /usr/lib/thunderbird/thunderbird-bin)
==17848==    by 0x894978C: (within /usr/lib/thunderbird/thunderbird-bin)
==17848==  Address 0x203245A0 is 0 bytes inside a block of size 64 alloc'd
==17848==    at 0x1B90A42E: operator new(unsigned) (in /usr/lib/valgrind2/vgpreload_memcheck.so)
==17848==    by 0x898F4CA: (within /usr/lib/thunderbird/thunderbird-bin)
==17848==    by 0x898BFDA: (within /usr/lib/thunderbird/thunderbird-bin)
==17848==    by 0x8997C64: (within /usr/lib/thunderbird/thunderbird-bin)
==17848==    by 0x891C147: (within /usr/lib/thunderbird/thunderbird-bin)
==17848==    by 0x891C6F7: (within /usr/lib/thunderbird/thunderbird-bin)
==17848==    by 0x891CA35: (within /usr/lib/thunderbird/thunderbird-bin)
==17848==    by 0x8176289: (within /usr/lib/thunderbird/thunderbird-bin)
==17848==    by 0x8969E1E: (within /usr/lib/thunderbird/thunderbird-bin)
==17848==    by 0x87F8510: (within /usr/lib/thunderbird/thunderbird-bin)
==17848==    by 0x87F9F0D: (within /usr/lib/thunderbird/thunderbird-bin)
==17848==    by 0x87FA0ED: (within /usr/lib/thunderbird/thunderbird-bin)
==17848== 
==17848== Conditional jump or move depends on uninitialised value(s)
==17848==    at 0x82E948F: (within /usr/lib/thunderbird/thunderbird-bin)
==17848==    by 0x82E99D5: (within /usr/lib/thunderbird/thunderbird-bin)
==17848==    by 0x82E9D0C: (within /usr/lib/thunderbird/thunderbird-bin)
==17848==    by 0x82EA230: (within /usr/lib/thunderbird/thunderbird-bin)
==17848==    by 0x82EA5C4: (within /usr/lib/thunderbird/thunderbird-bin)
==17848==    by 0x82EB657: (within /usr/lib/thunderbird/thunderbird-bin)
==17848==    by 0x82ECCDA: (within /usr/lib/thunderbird/thunderbird-bin)
==17848==    by 0x82E8092: (within /usr/lib/thunderbird/thunderbird-bin)
==17848==    by 0x82E9DE6: (within /usr/lib/thunderbird/thunderbird-bin)
==17848==    by 0x82EA5C4: (within /usr/lib/thunderbird/thunderbird-bin)
==17848==    by 0x82EB657: (within /usr/lib/thunderbird/thunderbird-bin)
==17848==    by 0x82F3218: (within /usr/lib/thunderbird/thunderbird-bin)
==17881== 
==17881== ERROR SUMMARY: 80 errors from 11 contexts (suppressed: 0 from 0)
==17881== malloc/free: in use at exit: 30099782 bytes in 156492 blocks.
==17881== malloc/free: 777068 allocs, 620576 frees, 213936769 bytes allocated.
==17881== For counts of detected errors, rerun with: -v
==17881== searching for pointers to 156492 not-freed blocks.
==17881== checked 30910092 bytes.
==17881== 
==17881== LEAK SUMMARY:
==17881==    definitely lost: 93856 bytes in 3336 blocks.
==17881==      possibly lost: 733872 bytes in 10505 blocks.
==17881==    still reachable: 29272054 bytes in 142651 blocks.
==17881==         suppressed: 0 bytes in 0 blocks.
==17881== Use --leak-check=full to see details of leaked memory.
--17848-- WARNING: unhandled syscall: 250
--17848-- Do not panic.  You may be able to fix this easily.
--17848-- Read the file README_MISSING_SYSCALL_OR_IOCTL.
--17848-- WARNING: unhandled syscall: 250

==17848== 
==17848== Mismatched free() / delete / delete []
==17848==    at 0x1B90A7D7: free (in /usr/lib/valgrind2/vgpreload_memcheck.so)
==17848==    by 0x1BAE0A96: PR_Free (in /usr/lib/libnspr4.so)
==17848==    by 0x898F937: (within /usr/lib/thunderbird/thunderbird-bin)
==17848==    by 0x89855FE: (within /usr/lib/thunderbird/thunderbird-bin)
==17848==    by 0x898E153: (within /usr/lib/thunderbird/thunderbird-bin)
==17848==    by 0x8986FD7: (within /usr/lib/thunderbird/thunderbird-bin)
==17848==    by 0x89855C0: (within /usr/lib/thunderbird/thunderbird-bin)
==17848==    by 0x898C27A: (within /usr/lib/thunderbird/thunderbird-bin)
==17848==    by 0x8986FD7: (within /usr/lib/thunderbird/thunderbird-bin)
==17848==    by 0x8999942: (within /usr/lib/thunderbird/thunderbird-bin)
==17848==    by 0x891B540: (within /usr/lib/thunderbird/thunderbird-bin)
==17848==    by 0x894978C: (within /usr/lib/thunderbird/thunderbird-bin)
==17848==  Address 0x234FC060 is 0 bytes inside a block of size 64 alloc'd
==17848==    at 0x1B90A42E: operator new(unsigned) (in /usr/lib/valgrind2/vgpreload_memcheck.so)
==17848==    by 0x898F4CA: (within /usr/lib/thunderbird/thunderbird-bin)
==17848==    by 0x898BFDA: (within /usr/lib/thunderbird/thunderbird-bin)
==17848==    by 0x8997C64: (within /usr/lib/thunderbird/thunderbird-bin)
==17848==    by 0x891C147: (within /usr/lib/thunderbird/thunderbird-bin)
==17848==    by 0x891C6F7: (within /usr/lib/thunderbird/thunderbird-bin)
==17848==    by 0x891CA35: (within /usr/lib/thunderbird/thunderbird-bin)
==17848==    by 0x8176289: (within /usr/lib/thunderbird/thunderbird-bin)
==17848==    by 0x8969E1E: (within /usr/lib/thunderbird/thunderbird-bin)
==17848==    by 0x894959F: (within /usr/lib/thunderbird/thunderbird-bin)
==17848==    by 0x1BA87088: XPTC_InvokeByIndex (in /usr/lib/thunderbird/libxpcom_core.so)
==17848==    by 0x80B48FC: (within /usr/lib/thunderbird/thunderbird-bin)
For reporting crashes, always try mozilla.org builds, and give the talkback crash id. See http://kb.mozillazine.org/Talkback
(Reporter)

Comment 4

10 years ago
i know but i found the matter serious enough to report also this result.

btw: talkback does not work for me and the Opensuse build and Mozilla build show the same problems

Comment 5

10 years ago
walter, can you try trunk build to get a crash report?  http://kb.mozillazine.org/Breakpad
Of course, protect your profile and data when using trunk.

Comment 6

10 years ago
walter, if you're going to use valgrind, you need debugging symbols. Either build thunderbird yourself or try to get them from opensuse
(Reporter)

Comment 7

10 years ago
i am aware of that. The whole valgrind2-idea was a test to see what will happen.
the problem is as always 'time'. I am wondering that noone else is reporting this problem, for me it happens rather frequently, maybe because i do *not* run fancy plug-ins ?
Walter, Thunderbird 2.0.0.18 is out now -- does the crash still occur?

Also, as timeless mentions, you'd need a debug build with symbols for valgrind usage to make sense.
(Reporter)

Comment 9

10 years ago
no


thunderbird 
Registering Enigmail account manager extension.
Enigmail account manager extension registered.
*** glibc detected *** /usr/lib/thunderbird/thunderbird-bin: free(): invalid next size (fast): 0x0a35e030 
***
======= Backtrace: =========
/lib/libc.so.6[0xb70c5fc4]
/lib/libc.so.6(cfree+0x9c)[0xb70c795c]
/usr/lib/thunderbird/libxpcom_core.so(_ZN14nsStringBuffer7ReleaseEv+0x2d)[0xb7ea08d3]
/usr/lib/thunderbird/libxpcom_core.so(_ZN12nsCSubstring8FinalizeEv+0x25)[0xb7ea09bf]
/usr/lib/thunderbird/libxpcom_core.so(_ZN19nsACString_internalD2Ev+0x27)[0xb7ea6269]
/usr/lib/thunderbird/thunderbird-bin[0x8885003]
/usr/lib/thunderbird/thunderbird-bin[0x894962b]
/usr/lib/thunderbird/thunderbird-bin[0x888469e]
/usr/lib/thunderbird/libxpcom_core.so(_ZN13nsCOMPtr_base18assign_with_AddRefEP11nsISupports+0x2c)[0xb7e3d3
c0]
/usr/lib/thunderbird/libxpcom_core.so(_ZN12nsPipeEventsD1Ev+0x38)[0xb7e65b68]
/usr/lib/thunderbird/libxpcom_core.so(_ZN6nsPipe18AdvanceWriteCursorEj+0xee)[0xb7e66648]
/usr/lib/thunderbird/libxpcom_core.so(_ZN18nsPipeOutputStream13WriteSegmentsEPFjP15nsIOutputStreamPvPcjjPj
ES2_jS4_+0x156)[0xb7e66c84]
/usr/lib/thunderbird/libxpcom_core.so(_ZN16nsStreamCopierOB6DoCopyEPjS0_+0x4d)[0xb7e67e23]
/usr/lib/thunderbird/libxpcom_core.so(_ZN15nsAStreamCopier23HandleContinuationEventEP7PLEvent+0x44)[0xb7e6
8084]
/usr/lib/thunderbird/libxpcom_core.so(PL_HandleEvent+0x27)[0xb7e8276b]
/usr/lib/thunderbird/thunderbird-bin[0x81698a0]
/usr/lib/thunderbird/thunderbird-bin[0x8169ddd]
/usr/lib/thunderbird/libxpcom_core.so(_ZN8nsThread4MainEPv+0x35)[0xb7e85fe5]
/usr/lib/libnspr4.so[0xb7da9ad1]
/lib/libpthread.so.0[0xb7d6e175]
/lib/libc.so.6(clone+0x5e)[0xb7127dce]
======= Memory map: ========
08048000-08c72000 r-xp 00000000 08:12 56015      /usr/lib/thunderbird/thunderbird-bin
08c72000-08c74000 r--p 00c2a000 08:12 56015      /usr/lib/thunderbird/thunderbird-bin
08c74000-08c89000 rw-p 00c2c000 08:12 56015      /usr/lib/thunderbird/thunderbird-bin
08c89000-0b24e000 rw-p 08c89000 00:00 0          [heap]
ad3f2000-ad3f3000 ---p ad3f2000 00:00 0 
ad3f3000-adbf3000 rw-p ad3f3000 00:00 0 
adbf3000-adbf4000 ---p adbf3000 00:00 0 
adbf4000-ae3f4000 rw-p adbf4000 00:00 0 
ae3f4000-ae3f5000 ---p ae3f4000 00:00 0 
ae3f5000-aebf5000 rw-p ae3f5000 00:00 0 
aebf5000-aebf6000 ---p aebf5000 00:00 0 
<cut>

Comment 10

10 years ago
does it happen if you disable enigmail?

(if necessary, safemode should let you start w/o it)
(Reporter)

Comment 11

10 years ago
i will give it a try,
NTL i have not installed anything strange.
The way i produce the bug is simply let run for sometime.
(Reporter)

Comment 12

10 years ago
safe-mode does not change anything

$ thunderbird -safe-mode

*** glibc detected *** /usr/lib/thunderbird/thunderbird-bin: free(): invalid next size (fast): 0x0b1e5d88 ***
======= Backtrace: =========
/lib/libc.so.6[0xb71c8fc4]
/lib/libc.so.6(cfree+0x9c)[0xb71ca95c]
/usr/lib/thunderbird/libxpcom_core.so(_ZN14nsStringBuffer7ReleaseEv+0x2d)[0xb7fa38d3]
/usr/lib/thunderbird/libxpcom_core.so(_ZN12nsCSubstring8FinalizeEv+0x25)[0xb7fa39bf]
/usr/lib/thunderbird/libxpcom_core.so(_ZN19nsACString_internalD2Ev+0x27)[0xb7fa9269]
/usr/lib/thunderbird/thunderbird-bin[0x8885003]
/usr/lib/thunderbird/thunderbird-bin[0x894962b]
/usr/lib/thunderbird/thunderbird-bin[0x888469e]
/usr/lib/thunderbird/libxpcom_core.so(_ZN13nsCOMPtr_base18assign_with_AddRefEP11nsISupports+0x2c)[0xb7f403c0]
/usr/lib/thunderbird/libxpcom_core.so(_ZN8nsThread4MainEPv+0x42)[0xb7f88ff2]
/usr/lib/libnspr4.so[0xb7eacad1]
/lib/libpthread.so.0[0xb7e71175]
/lib/libc.so.6(clone+0x5e)[0xb722adce]
======= Memory map: ========
08048000-08c72000 r-xp 00000000 08:12 56015      /usr/lib/thunderbird/thunderbird-bin
08c72000-08c74000 r--p 00c2a000 08:12 56015      /usr/lib/thunderbird/thunderbird-bin
08c74000-08c89000 rw-p 00c2c000 08:12 56015      /usr/lib/thunderbird/thunderbird-bin
08c89000-0bb6d000 rw-p 08c89000 00:00 0          [heap]
aa6c5000-aa6c6000 ---p aa6c5000 00:00 0 
aa6c6000-aaec6000 rw-p aa6c6000 00:00 0 
aaec6000-ab94a000 r--p 00000000 08:13 31081      /opt/kde3/share/icons/hicolor/icon-theme.cache
ab94a000-ac235000 r--p 00000000 08:12 258080     /usr/share/icons/hicolor/icon-theme.cache
ac235000-ac456000 r--p 00000000 08:13 29469      /etc/opt/kde3/share/icons/crystalsvg/icon-theme.cache
ac456000-ad560000 r--p 00000000 08:13 29473      /opt/kde3/share/icons/crystalsvg/icon-theme.cache
ad560000-adc64000 r--p 00000000 08:12 319126     /usr/share/icons/gnome/icon-theme.cache
adc64000-adc65000 ---p adc64000 00:00 0 
adc65000-ae465000 rw-p adc65000 00:00 0 
ae465000-ae466000 ---p ae465000 00:00 0 
ae466000-aec66000 rw-p ae466000 00:00 0 
<cut>

Comment 13

9 years ago
walter, do you still see problem if you use 3.0 beta (almost released)?
 http://download.opensuse.org/repositories/mozilla:/beta/

note: backup your profile first, and be prepared for changes
 http://kb.mozillazine.org/Thunderbird_3.0_-_New_Features_and_Changes
Keywords: crash
Version: unspecified → 2.0
(Reporter)

Comment 14

9 years ago
Hi,
unfortuately the computer that i was using died, my current system is 64bit instead of 32, has plenty of RAM etc. except for one (unreproduceable) crash
thunderbird now runs stable. I suspect that the 6G ram i have now buffer
most of the problems. sorry.
Status: UNCONFIRMED → RESOLVED
Last Resolved: 9 years ago
Resolution: --- → INCOMPLETE

Comment 15

9 years ago
thanks for closing.
we use WORKSFORME when cause of fixing is known.
ref: https://bugzilla.mozilla.org/page.cgi?id=fields.html#status
Resolution: INCOMPLETE → WORKSFORME
You need to log in before you can comment on or make changes to this bug.