Tk Source Code

View Ticket
Login
Ticket UUID: 434c8dd8046ba3c0a7307fa8dc3a8e3a64e005bd
Title: Crash in Tk_ConfigureWidget when a default value of a canvas item option is invalid
Type: Bug Version: 8.6.18, 9.0.5, 9.1b1
Submitter: serhiy.storchaka Created on: 2026-09-25 16:32:57
Subsystem: 05. Canvas Items Assigned To: jan.nijtmans
Priority: 5 Medium Severity: Critical
Status: Closed Last Modified: 2026-10-08 12:53:35
Resolution: Fixed Closed By: jan.nijtmans
    Closed on: 2026-10-08 12:53:35
Description:

If the default value of a canvas item option cannot be applied, Tk_ConfigureWidget() crashes while formatting the error message

(default value for "%.50s" in widget "%.50s")

because it passes specPtr->dbName, which is NULL for all canvas item options. This happens, for example, if fontconfig finds no fonts: since [1440417fff] widgets report "failed to allocate font due to internal system font engine problem", but .c create text 10 10 -text abc segfaults instead. Reproduced on Linux with an empty fontconfig configuration (FONTCONFIG_FILE pointing to a file without font directories) in 8.6.18, 9.0.5 and 9.1.

User Comments: jan.nijtmans added on 2026-10-08 12:53:35:

Fixed in [a2791cb1444037f5|trunk], backported to core-9-0-branch and core-8-6-branch

Many thanks!


serhiy.storchaka added on 2026-09-25 16:34:01:

Proposed fix in [dc71571171] (branch canvas-default-error-crash): use the option name in the error message if the option has no database name. Now .c create text reports the error with (default value for "-font" in widget ".c") instead of crashing.