the hue of death: setting color property crashes application
"gregory benison" <[email protected]> Mon, 28 Jul 2008 08:43:51 -0700
| Newsgroups | gmane.lisp.guile.gtk |
|---|---|
| Message-ID | <[email protected]> |
In the latest guile-gnome, setting a "color" property can cause a crash: G_SLICE=debug-blocks guile-gnome-2 > (use-modules (oop goops)(gnome gtk)) > (set (make <gtk-color-button>) 'color "red") GSlice: MemChecker: attempt to release non-allocated block: 0x81a50a8 size=12 Aborted Without 'debug-blocks', the crash is delayed, but will happen eventually because the heap is corrupted. The cause is a GdkColor* being allocated with g_new0(), but freed with g_slice_free1() rather than g_free(): - scm_scm_to_gdk_color() allocates a GdkColor* using g_new0(). - The new GdkColor* is packaged into a GValue* - g_object_set_property() is called - scm_set_gobject_property calls g_value_unset() on the GValue* - g_value_unset() calls gdk_color_free() which calls g_slice_free1() gdk_color_free() switched from using g_free() to g_slice_free1() with gtk+-2.10. Changing scm_scm_to_gdk_color() to use g_slice_new0() makes the bug go away, but I don't like that solution because it sets things up for another bug if future versions of GDK switch to use g_frobnitz_free() or whatever. It would be better to use a gdk_color_new() function, but unfortunately there is none in GDK. One can easily be made, though, from gdk_color_copy(). The attached patch does that (and fixes the crash). A similar issue may affect scm_scm_to_gdk_rectangle(). -- ====================== Gregory Benison Oregon State University gbenison at gmail dot com ====================== _______________________________________________ guile-gtk-general mailing list [email protected] http://lists.gnu.org/mailman/listinfo/guile-gtk-general
gdk_color.patch
(text/x-patch, 2.3 KB)
# Bazaar merge directive format 2 (Bazaar 0.90) # revision_id: [email protected] # target_branch: http://arch.gna.org/guile-gnome/bzr/gtk/ # testament_sha1: 1dd74795aba452934a0810f47bfe1ad34b958e4b # timestamp: 2008-07-28 08:36:30 -0700 # base_revision_id: [email protected] # # Begin patch === modified file 'gnome/gw/gdk-support.c' --- gnome/gw/gdk-support.c 2008-04-24 11:17:07 +0000 +++ gnome/gw/gdk-support.c 2008-07-28 15:30:14 +0000 @@ -228,11 +228,22 @@ return ret; } +/* + * Allocate a new GdkColor* which must be freed using + * gdk_color_free(). + */ +static GdkColor* +gdk_color_new() +{ + GdkColor tmp; + return gdk_color_copy(&tmp); +} + GdkColor* scm_scm_to_gdk_color (SCM scm) #define FUNC_NAME "%scm->gdk-rectangle" { - GdkColor *ret = g_new0 (GdkColor, 1); + GdkColor *ret = gdk_color_new(); if (scm_is_string (scm)) { char *chars; # Begin bundle IyBCYXphYXIgcmV2aXNpb24gYnVuZGxlIHY0CiMKQlpoOTFBWSZTWZjPJ74AAbHfgEAQUXP//3qA AAC////6UAPZV7KKmigbBkSKemTJNjQBMKepo9RkZNGQ00MAAAABoAAAAAEomgmgaCTNBR6NQHpD 0TTT1GjDAAAAAaAAAAABJIQ0j0TBJ5JiGmAppkZBoZHetMt0dHeL+Zs1essYZwmiipWtmW5noD6t JP2bTdtsv1JJPzNyeehztVVSPROr6m0YKZQFaOWu+z06Rud5U/7D6/HzSd7loXjOuOtTyhUB1+CF uquimbPJylUSYlaqGEDm3OnfJaLqj2yQ6r3QgKpKtA0pmW2HITLziKOTjm/fVLt6fxQHZtkGFTeB FuHcCiRWzsuJDoOcpYPAVFiEB8InMDl4naQHikc4a1XMxmYpaVYnPm2xrL3exYl0MEuEnlJO+JM5 UFYwKS8BCwsgYhIWS2kuWGPMseMJO8ncXBIuJJ/X3ZRKMVCSIGaSULHRgmhOe9tGooKytZCskgmJ VS3QycULqKoxuNQ40lJoxtNxRyHHy7M0nUOE7BicXaUrMD5NrgsTCJtL8C5FPpE4MOJhg9nMJwT3 DIsLzYUpCYlqPMWnEscKgQYSs2YjyQ6qxhXiYYlgxArte4UW+sCwwi2FpYQLks5oURZypVRHaVFP pJwmgV89TYjcTRROinDCUijL3O+eY5U1957/RoOIq5mRPALX3Kin8fYD/w9R85hVuGpzKzOiC8oV dPSyI6qB4jHE1b13nz11zltZaFSX1tLIcaRTqymf46deB05hZeUhBjGBqRcFZ2XkTb8hmPQXCMP0 tfrRiWC4H2BiBEq5zGkSOGJoLiorU6aBWik6E8Rdxl/gYWG3ds790ppnbBuHeVHwr+HA0EfQlKAc q/E8AntpuJ1obUmOUEnfKYWm3NSt+oNhgoiNKKE+jOcy30xMx7eHGTLe33vIVOBzpxG8omhwPoNo PUmADruvHqaAVsAj5wgV2JksOsiBgWJZJ5ceoZqpB76oTzAbgKgLn8+qwLOWhwi4O5KK3uWHx6y8 xGhbXvEVnkl2qk3YyJxYRuKNpjChsznCTyZ4PfeDxdm8DFXuCDIZbZWg3Yr6/kuYYAypBkmDrMiE 4iIZlSOUreq0/wTGBllkoFAYcVIzkYjT/nQq/MW2bYwSTILXX3uG2etAsP61m91rJ9MZK6x94QmG YZNAZtZGfFMR1gOijgJD1tiHFaPr3/XjtiadSQ2LOpiSg+seT5OMoANJeQvIZNTBh4134wCOLGE6 SCzdOZStqOnvfsWpi8GtD3xaP8XckU4UJCYzye+A