Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 398097 - =media-sound/pulseaudio-1.1 w/ =net-wireless/bluez-4.97 on hardened: Crashing with bluetooth headset
Summary: =media-sound/pulseaudio-1.1 w/ =net-wireless/bluez-4.97 on hardened: Crashing...
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Hardened (show other bugs)
Hardware: All Linux
: Normal normal
Assignee: Arun Raghavan (RETIRED)
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2012-01-07 23:13 UTC by Aidan Thornton
Modified: 2012-05-11 15:17 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Aidan Thornton 2012-01-07 23:13:10 UTC
When trying to use a Bluetooth headset with PulseAudio 1.1 and Bluez 4.97 on hardened, the pulseaudio daemon consistently crashes with an error "*** stack smashing detected ***: pulseaudio - terminated". I can't figure out a way to get any kind of backtrace for this because the stack smashing protection uses SIGKILL. Downgrading to Bluez 4.96 appears to prevent the crash.

Reproducible: Always

Steps to Reproduce:
1. Install PulseAudio 1.1 and Bluez 4.97 with stack smashing protection enabled
2. Connect a Bluetooth headset
Actual Results:  
PulseAudio crashes with a message "stack smashing detected"

Expected Results:  
PulseAudio actually plays audio through Bluetooth.

Portage 2.1.10.44 (hardened/linux/amd64, gcc-4.5.3, glibc-2.14.1-r2, 3.1.5-gentoo x86_64)
=================================================================
System uname: Linux-3.1.5-gentoo-x86_64-AMD_Athlon-tm-_II_X2_245_Processor-with-gentoo-2.1
Timestamp of tree: Sat, 07 Jan 2012 00:45:01 +0000
app-shells/bash:          4.2_p20
dev-java/java-config:     2.1.11-r3
dev-lang/python:          2.7.2-r3, 3.2.2
dev-util/cmake:           2.8.6-r4
dev-util/pkgconfig:       0.26
sys-apps/baselayout:      2.1
sys-apps/openrc:          0.9.7
sys-apps/sandbox:         2.5
sys-devel/autoconf:       2.13, 2.68
sys-devel/automake:       1.11.2
sys-devel/binutils:       2.22-r1
sys-devel/gcc:            4.5.3-r2, 4.6.2
sys-devel/gcc-config:     1.5-r2
sys-devel/libtool:        2.4.2
sys-devel/make:           3.82-r3
sys-kernel/linux-headers: 3.1 (virtual/os-headers)
sys-libs/glibc:           2.14.1-r2
Repositories: gentoo x-crossdev x-makomk pcsx2 Techwolf x11 c1pher bitcoin
ACCEPT_KEYWORDS="amd64 ~amd64"
ACCEPT_LICENSE="* -@EULA AdobeFlash-10.1 skype-eula google-chrome"
CBUILD="x86_64-pc-linux-gnu"
CFLAGS="-O2 -mtune=barcelona -pipe"
CHOST="x86_64-pc-linux-gnu"
CONFIG_PROTECT="/etc /usr/share/config /usr/share/gnupg/qualified.txt /usr/share/maven-bin-3.0/conf"
CONFIG_PROTECT_MASK="/etc/ca-certificates.conf /etc/env.d /etc/env.d/java/ /etc/fonts/fonts.conf /etc/gconf /etc/gentoo-release /etc/php/apache2-php5.4/ext-active/ /etc/php/cgi-php5.4/ext-active/ /etc/php/cli-php5.4/ext-active/ /etc/revdep-rebuild /etc/sandbox.d /etc/terminfo /etc/texmf/language.dat.d /etc/texmf/language.def.d /etc/texmf/updmap.d /etc/texmf/web2c"
CXXFLAGS="-O2 -mtune=barcelona -pipe"
DISTDIR="/var/portage/distfiles"
FEATURES="assume-digests binpkg-logs distlocks ebuild-locks fixlafiles news parallel-fetch protect-owned sandbox sfperms splitdebug strict unknown-features-warn unmerge-logs unmerge-orphans userfetch userpriv usersandbox webrsync-gpg"
FFLAGS=""
GENTOO_MIRRORS="http://mirror.bytemark.co.uk/gentoo/"
LANG="en_GB.UTF-8"
LDFLAGS="-Wl,-O1 -Wl,--as-needed"
MAKEOPTS="-j2"
PKGDIR="/usr/portage/packages"
PORTAGE_CONFIGROOT="/"
PORTAGE_RSYNC_OPTS="--recursive --links --safe-links --perms --times --compress --force --whole-file --delete --stats --timeout=180 --exclude=/distfiles --exclude=/local --exclude=/packages"
PORTAGE_TMPDIR="/var/tmp"
PORTDIR="/usr/portage"
PORTDIR_OVERLAY="/usr/local/portage/crossdev /usr/local/portage/makomk /var/lib/layman/pcsx2-overlay /var/lib/layman/techwolf /var/lib/layman/x11 /var/lib/layman/c1pher /var/lib/layman/bitcoin"
SYNC="rsync://rsync.gentoo.org/gentoo-portage"
USE="X acl alsa amd64 berkdb bluetooth bzip2 cli cracklib crypt cups cxx dbus dri dvb gdbm gif gpm hal hardened iconv ipv6 jpeg justify kipi mmx modules mudflap multilib mysql ncurses nls nptl nptlonly opengl openmp pam pax_kernel pcre pdf png pppd pulseaudio qt3support readline scanner semantic-desktop session sse sse2 ssl sysfs tcpd unicode urandom xorg zlib" ALSA_CARDS="ali5451 als4000 atiixp atiixp-modem bt87x ca0106 cmipci emu10k1x ens1370 ens1371 es1938 es1968 fm801 hda-intel intel8x0 intel8x0m maestro3 trident usb-audio via82xx via82xx-modem ymfpci" ALSA_PCM_PLUGINS="adpcm alaw asym copy dmix dshare dsnoop empty extplug file hooks iec958 ioplug ladspa lfloat linear meter mmap_emul mulaw multi null plug rate route share shm softvol" APACHE2_MODULES="actions alias auth_basic authn_alias authn_anon authn_dbm authn_default authn_file authz_dbm authz_default authz_groupfile authz_host authz_owner authz_user autoindex cache cgi cgid dav dav_fs dav_lock deflate dir disk_cache env expires ext_filter file_cache filter headers include info log_config logio mem_cache mime mime_magic negotiation rewrite setenvif speling status unique_id userdir usertrack vhost_alias" CALLIGRA_FEATURES="kexi words flow plan stage tables krita karbon braindump" CAMERAS="ptp2" COLLECTD_PLUGINS="df interface irq load memory rrdtool swap syslog" DVB_CARDS="usb-dib0700" ELIBC="glibc" GPSD_PROTOCOLS="ashtech aivdm earthmate evermore fv18 garmin garmintxt gpsclock itrax mtk3301 nmea ntrip navcom oceanserver oldstyle oncore rtcm104v2 rtcm104v3 sirf superstar2 timing tsip tripmate tnt ubx" INPUT_DEVICES="keyboard mouse evdev" KERNEL="linux" LCD_DEVICES="bayrad cfontz cfontz633 glk hd44780 lb216 lcdm001 mtxorb ncurses text" PHP_TARGETS="php5-3" QEMU_SOFTMMU_TARGETS="i386 x86_64" QEMU_USER_TARGETS="i386 x86_64" RUBY_TARGETS="ruby18" USERLAND="GNU" VIDEO_CARDS="fbdev vesa radeon" XTABLES_ADDONS="quota2 psd pknock lscan length2 ipv4options ipset ipp2p iface geoip fuzzy condition tee tarpit sysrq steal rawnat logmark ipmark dhcpmac delude chaos account"
Unset:  CPPFLAGS, CTARGET, EMERGE_DEFAULT_OPTS, INSTALL_MASK, LC_ALL, LINGUAS, PORTAGE_BUNZIP2_COMMAND, PORTAGE_COMPRESS, PORTAGE_COMPRESS_FLAGS, PORTAGE_RSYNC_EXTRA_OPTS
Comment 1 Pacho Ramos gentoo-dev 2012-03-08 09:50:57 UTC
Still valid with bluez-4.99?
Comment 2 Aidan Thornton 2012-03-14 21:44:03 UTC
Still seeing this with bluez-4.99, yeah.
Comment 3 Aidan Thornton 2012-04-28 21:13:48 UTC
Still seeing this with PulseAudio 1.99.2 and bluez 4.99. Have finally figured out how to debug this with gdb and traced the crash to a bug within endpoint_set_configuration in the PulseAudio bluetooth code. It calls dbus_message_iter_get_basic with a pointer to a stack variable of type pa_bool_t when it should be passing a pointer to a dbus_bool_t. On my system sizeof(pa_bool_t) is 1 whereas sizeof(dbus_bool_t) is 4, causing the call to dbus_message_iter_get_basic to overwrite the stack canary and crash PulseAudio.
Comment 4 Arun Raghavan (RETIRED) gentoo-dev 2012-05-11 12:02:52 UTC
Thanks for the bug report and investigation! I'll push a fix for this upstream which will be available Real Soon Now™ in PulseAudio 2.0.
Comment 5 Arun Raghavan (RETIRED) gentoo-dev 2012-05-11 15:17:13 UTC
Told you it'd be real soon, now. :)