Package: qemu-kvm
Version: 0.14.0+dfsg-1~tls
Severity: important
I'm running a 32-bit guest (Xubuntu 10.04 to be precise) on a
64-bit host with the command line:
kvm -drive file=xubuntu.img,if=virtio,format=qcow2,boot=on -net
nic,model=virtio -net user -m 1024 -vga vmware -usbdevice tablet -smp 2 -vnc :1
and after a while, kvm crashes. I get the following traceback from gdb:
Program received signal SIGSEGV, Segmentation fault.
0x7494aaf1 in memcpy () from /lib/libc.so.6
(gdb) bt
#0 0x7494aaf1 in memcpy () from /lib/libc.so.6
#1 0x004c0381 in buffer_append (buffer=0x184d2d8, data=0x1da6000,
len=4294427045)
at /usr/include/bits/string3.h:52
#2 0x004c9bff in tight_compress_data (vs=0x1843230, stream_id=,
bytes=4294967717, level=, strategy=)
at ui/vnc-enc-tight.c:864
#3 0x004c9d2d in send_full_color_rect (vs=0x1843230, x=,
y=, w=, h=48) at
ui/vnc-enc-tight.c:925
#4 0x004cb9cf in send_sub_rect_nojpeg (vs=0x1843230, x=432, y=441,
w=,
h=) at ui/vnc-enc-tight.c:1462
#5 send_sub_rect (vs=0x1843230, x=432, y=441, w=,
h=)
at ui/vnc-enc-tight.c:1530
#6 0x004ccd95 in tight_send_framebuffer_update (vs=0x1843230, x=,
y=, w=, h=)
at ui/vnc-enc-tight.c:1675
#7 0x004cec90 in vnc_job_add_rect (job=0x184d480, x=31088640,
y=-540251, w=33525740, h=0)
at ui/vnc-jobs-sync.c:64
#8 0x004c07fa in vnc_update_client (vs=,
has_dirty=)
at ui/vnc.c:909
#9 0x004c0a2f in vnc_refresh (opaque=0x17ba9b0) at ui/vnc.c:2326
#10 0x004d017e in qemu_run_timers (clock=) at
qemu-timer.c:503
#11 0x004d01f6 in qemu_run_all_timers () at qemu-timer.c:634
#12 0x0041edc9 in main_loop_wait (nonblocking=)
at /home/roland/qemu-kvm-0.14.0+dfsg/vl.c:1401
#13 0x00438747 in kvm_main_loop () at
/home/roland/qemu-kvm-0.14.0+dfsg/qemu-kvm.c:1589
#14 0x0041fe8a in main_loop (argc=17, argv=,
envp=)
at /home/roland/qemu-kvm-0.14.0+dfsg/vl.c:1429
#15 main (argc=17, argv=, envp=)
at /home/roland/qemu-kvm-0.14.0+dfsg/vl.c:3201
I notice that the len values look like they are negative numbers
that have become huge unsigned 32-bit values...
-- Package-specific info:
/proc/cpuinfo:
processor : 0
vendor_id : GenuineIntel
cpu family : 6
model : 44
model name : Intel(R) Xeon(R) CPU X5650 @ 2.67GHz
stepping: 2
cpu MHz : 2667.171
cache size : 12288 KB
physical id : 0
siblings: 12
core id : 0
cpu cores : 6
apicid : 0
initial apicid : 0
fpu : yes
fpu_exception : yes
cpuid level : 11
wp : yes
flags : fpu vme de pse tsc msr pae mce cx8 apic sep mtrr pge mca cmov
pat pse36 clflush dts acpi mmx fxsr sse sse2 ss ht tm pbe syscall nx pdpe1gb
rdtscp lm constant_tsc arch_perfmon pebs bts rep_good nopl xtopology
nonstop_tsc aperfmperf pni pclmulqdq dtes64 monitor ds_cpl vmx smx est tm2
ssse3 cx16 xtpr pdcm dca sse4_1 sse4_2 popcnt aes lahf_lm ida arat epb dts
tpr_shadow vnmi flexpriority ept vpid
bogomips: 5334.34
clflush size: 64
cache_alignment : 64
address sizes : 40 bits physical, 48 bits virtual
power management:
processor : 1
vendor_id : GenuineIntel
cpu family : 6
model : 44
model name : Intel(R) Xeon(R) CPU X5650 @ 2.67GHz
stepping: 2
cpu MHz : 2667.171
cache size : 12288 KB
physical id : 0
siblings: 12
core id : 1
cpu cores : 6
apicid : 2
initial apicid : 2
fpu : yes
fpu_exception : yes
cpuid level : 11
wp : yes
flags : fpu vme de pse tsc msr pae mce cx8 apic sep mtrr pge mca cmov
pat pse36 clflush dts acpi mmx fxsr sse sse2 ss ht tm pbe syscall nx pdpe1gb
rdtscp lm constant_tsc arch_perfmon pebs bts rep_good nopl xtopology
nonstop_tsc aperfmperf pni pclmulqdq dtes64 monitor ds_cpl vmx smx est tm2
ssse3 cx16 xtpr pdcm dca sse4_1 sse4_2 popcnt aes lahf_lm ida arat epb dts
tpr_shadow vnmi flexpriority ept vpid
bogomips: 5333.47
clflush size: 64
cache_alignment : 64
address sizes : 40 bits physical, 48 bits virtual
power management:
processor : 2
vendor_id : GenuineIntel
cpu family : 6
model : 44
model name : Intel(R) Xeon(R) CPU X5650 @ 2.67GHz
stepping: 2
cpu MHz : 2667.171
cache size : 12288 KB
physical id : 0
siblings: 12
core id : 2
cpu cores : 6
apicid : 4
initial apicid : 4
fpu : yes
fpu_exception : yes
cpuid level : 11
wp : yes
flags : fpu vme de pse tsc msr pae mce cx8 apic sep mtrr pge mca cmov
pat pse36 clflush dts acpi mmx fxsr sse sse2 ss ht tm pbe syscall nx pdpe1gb
rdtscp lm constant_tsc arch_perfmon pebs bts rep_good nopl xtopology
nonstop_tsc aperfmperf pni pclmulqdq dtes64 monitor ds_cpl vmx smx est tm2
ssse3