FS#13060 - Seeking in long opus files leads to crash on Sansa Clip+

Attached to Project: Rockbox
Opened by Stephan Lohse (sloh) - Monday, 26 October 2015, 16:24 GMT
Last edited by Solomon Peachy (pizza) - Sunday, 23 December 2018, 22:39 GMT
Task Type Bugs
Category Codecs
Status Closed
Assigned To No-one
Operating System Sansa Clip+
Severity Medium
Priority Normal
Reported Version Daily build (which?)
Due in Version Undecided
Due Date Undecided
Percent Complete 100%
Votes 0
Private No


possibly related to FS#12851.

When seeking in large opus files, rockbox crashes.
Using git bisect, I found commit 9b7ec42 to be the first one showing this behavior.

The crash screen for the latest git revision d57e651 looks as follows:

Stkov codec
pc:3006008C sp:30803B{cut of due to screenspace ending. Next character could possibly be a '3'}
A: 3008728C
bt end

If I interpret the map-file correctly (and I totally might not), that would put the Program Counter somewhere in cancel_cpu_boost (thread.o).

for 9b7ec42 it is pc:3005E264, A: 3005E2BC. Stackpointer is the same.
Here the pc appears to be in check_tmo_threads (thread.o)

I haven't quite figured out where exactly "large" starts, but it does happen with 4 hour long files (~60MB), but not with 1 hour long files (~20MB). It also does not happen in the Simulator, only on the actual hardware.

Example files:
error occurs:
error does not occur:
This task depends upon

Closed by  Solomon Peachy (pizza)
Sunday, 23 December 2018, 22:39 GMT
Reason for closing:  Accepted
Additional comments about closing:  The workaround patch was committed a while back, so I think we can close this ticket.
Comment by thrd (thrdhes) - Tuesday, 16 February 2016, 13:38 GMT
i can confirm this behaviour for version bc56811 from 2016-02-16.
the following file reliably crashes rb here if searching more than about 1 minutes into the file: (
Comment by Stephan Lohse (sloh) - Monday, 27 March 2017, 10:09 GMT
Update: it no longer crashes when seeking manually, but still crashes when resuming a bookmark (version bfd04df from 2017-03-22)
pc: 30064618
sp: 30803B{again cut of due to screenspace ending. Next character could still possibly be a '3'}
A: 3008C020
Comment by Martin Nowak (dawg) - Sunday, 19 August 2018, 05:52 GMT
Stil happens to me while seeking with the latest dev release 91500e1.
pc: 30065418
Comment by Martin Nowak (dawg) - Sunday, 19 August 2018, 08:06 GMT
Build a debug version of rockbox and could map the crash pc (30066970) to thread_panicf¹ using addr2line.
Most likely this is simply a stack overflow as detected by checking the bottom of the stack².


I fiddled a bit with the stack size of the decoder thread³ and bumping it by just another 1KiB resolves the issue for me.
As memory is quite limited on this device it would be better to save stack space if possible, but that required a lot more effort at understanding seeking in the opus codec.

Comment by Martin Nowak (dawg) - Sunday, 19 August 2018, 08:53 GMT
Submitted as patch to gerrit (