| Ticket UUID: | a0c1a9c6c632be8b2272bb84eed1ae93da49c74c | |||
| Title: | The fn RemoveFromBaseChunk is not thread safe | |||
| Type: | Bug | Version: | 8.6.15, 8.6.18, 9.0.5, 9.1b1 | |
| Submitter: | anonymous | Created on: | 2024-12-12 08:49:46 | |
| Subsystem: | 18. [text] | Assigned To: | nobody | |
| Priority: | 5 Medium | Severity: | Severe | |
| Status: | Open | Last Modified: | 2026-09-29 13:09:29 | |
| Resolution: | None | Closed By: | nobody | |
| Closed on: | ||||
| Description: |
tkTextDisp.c:8157 If TK_LAYOUT_WITH_BASE_CHUNKS is defined (deafult on macosx), the fn CharUndisplayProc may invoke the function RemoveFromBaseChunk. tkTextDisp.c:9094 The fn RemoveFromBaseChunk stores the pointer to the Tcl_DString into a global variable baseCharChunkPtr defined in tkTextDisp.c:478: /* TODO: Thread safety */ static TkTextDispChunk *baseCharChunkPtr = NULL; tkTextDisp.c:8965 If the Tk library was compiled with --enable-threads (default on macosx) the fn FreeBaseChunk may free baseCharChunkPtr and set it to NULL. tkTextDisp.c:9110 The freed Tcl_DString is passed to Tcl_DStringSetLength and causes a crash: EXC_BAD_ACCESS (SIGSEGV) KERN_INVALID_ADDRESS at 0x0000000000000024 Proposed fix: Disable TK_LAYOUT_WITH_BASE_CHUNKS when compiled with --enable-threads | |||
| User Comments: |
serhiy.storchaka added on 2026-09-29 13:09:29:
The attached script wish a0c1a9c6c6_sample.tcl ?nthreads? ?seconds? On Linux/X11 with 4 threads, trunk crashed in all 40 runs, in Xft on its own is not thread safe: threads crash in serhiy.storchaka added on 2026-09-24 11:53:03:
Confirmed, and it is now worse on 9.1: since [8ce823d20c] base chunks are also used on Windows and X11, not only on macOS. On X11, four threads laying out text widgets crash in Fix on text-basechunk-threads: keep | |||
Attachments:
- a0c1a9c6c6_sample.tcl [download] added by serhiy.storchaka on 2026-09-29 13:07:28. [details]
