Q: Messages crashing / ichat video crashing
For the last few days, iChat video sessions have been crashing. One end, or the other end, of virtually all video chat sessions crashes hard.
In /var/log/system.log, we see the typical:
Jul 15 07:44:06 dhcp95.priv.bungi.com Messages[55814]: detected buffer overflow
Jul 15 07:44:06 dhcp95 com.apple.launchd.peruser.501[269] (com.apple.iChat.18430
4[55814]): Job appears to have crashed: Abort trap: 6
This "detected buffer overflow" happens very, very repeatedly.
In the crash log, we see this thread as the culprit:
Thread 17 Crashed:
0 libsystem_kernel.dylib 0x00007fff99720ce2 __pthread_kill + 10
1 libsystem_c.dylib 0x00007fff983307d2 pthread_kill + 95
2 libsystem_c.dylib 0x00007fff98321b4a __abort + 159
3 libsystem_c.dylib 0x00007fff982f389f __chk_fail + 91
4 libsystem_c.dylib 0x00007fff982f36d9 __sprintf_chk + 173
5 com.apple.viceroy.framework 0x00007fff8d2f67df ProbeRecvProc + 594
6 libsystem_c.dylib 0x00007fff9832e8bf _pthread_start + 335
7 libsystem_c.dylib 0x00007fff98331b75 thread_start + 13
Thread 17 crashed with X86 Thread State (64-bit):
rax: 0x0000000000000000 rbx: 0x0000000000000006 rcx: 0x000000011e9553d8 rdx: 0x0000000000000000
rdi: 0x0000000000016713 rsi: 0x0000000000000006 rbp: 0x000000011e955400 rsp: 0x000000011e9553d8
r8: 0x00007fff7e28dfb8 r9: 0x00007ff98b6e8c10 r10: 0x00007fff99720d0a r11: 0xffffff80002dad60
r12: 0x0000000000000138 r13: 0x000000011e956000 r14: 0x000000011e956000 r15: 0x000000000000137c
rip: 0x00007fff99720ce2 rfl: 0x0000000000000246 cr2: 0x000000010b9df000
Logical CPU: 0
This has been happening with Jabber peers (I'm using gmail).
Of note, this happens with IPv6-connected hosts, so I'm suspecting that is the root cause. IPv4 hosts seem to connect without a problem.
My guess is a buffer containing an address is too small.
I've even tried this on a freshly-installed system, connecting only one jabber account; fails reliably.
This was all working fine a few days ago...
Messages, OS X Mavericks (10.9.5)
Posted on Jul 15, 2015 8:18 AM





