# Crash during SDL\_UnlockSurface

**URL:** <https://discourse.libsdl.org/t/crash-during-sdl-unlocksurface/11688>\
**Category:** SDL Development\
**Created:** [December 29, 2004, 4:07am UTC](https://discourse.libsdl.org/t/crash-during-sdl-unlocksurface/11688 "2004-12-29T04:07:02Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![aardvark\_joe](https://discourse.libsdl.org/letter_avatar_proxy/v4/letter/a/ecc23a/32.png) [@aardvark\_joe](https://discourse.libsdl.org/u/aardvark_joe)\
**Post date:** [December 29, 2004, 4:07am UTC](https://discourse.libsdl.org/t/crash-during-sdl-unlocksurface/11688/1 "2004-12-29T04:07:02Z")

</div>

I’ve been running into a problem that I think is a bug in SDL. The  
situation is:

I have a surface (surface A) with SDL\_SRCALPHA and SDL\_RLEACCEL set. I blit  
from that to surface B. (and use it for various things, never touching A).  
I then free surface B. Afterwards, I do some direct manipulation of surface  
A, and so I lock the surface, do my stuff, and then unlock it. During the  
call to SDL\_UnlockSurface, I get a crash.

It turns out that it crashes at SDL\_RLEaccel.c, line 1433, which is  
masksum = df-\>Rmask | df-\>Gmask | df-\>Bmask;

df is some junk pointer (usually null).

It looks to me like what happens is that A-\>map-\>dst gets set to B when I do  
the blit, and then when B is freed that pointer is left dangling. When it  
tries to access the fields of A-\>map-\>dst in RLEAlphaSurface, it crashes.

So, is this a known issue? Could someone with more knowledge of SDL  
internals than me verify that this is the bug?

I’m including a short test case that illustrates the situation and behavior.  
(Actually, this one doesn’t crash on my system, but Valgrind complains  
loudly about reading from previously freed memory at the same point.) I  
found the problem while using SDL 1.2.6; 1.2.8 seems to have the same  
problem.

Thanks

Jared Minch

/\* crash.c \*/

#include “SDL.h”

int main( int argc, char \*\*argv )  
{  
SDL\_Surface \*screen;  
SDL\_Surface \*s1, \*s2;

/\* Initialize SDL \*/  
SDL\_Init(SDL\_INIT\_VIDEO);

screen = SDL\_SetVideoMode(640, 480, 16, SDL\_SWSURFACE);

/\* Create two surfaces \*/  
s1 = SDL\_CreateRGBSurface(SDL\_SWSURFACE, 64, 64, 32,  
0x000000ff, 0x0000ff00, 0x00ff0000, 0xff000000);  
s2 = SDL\_CreateRGBSurface(SDL\_SWSURFACE, 64, 64, 32,  
0x000000ff, 0x0000ff00, 0x00ff0000, 0xff000000);

SDL\_SetAlpha(s1, SDL\_SRCALPHA | SDL\_RLEACCEL, 0xff);

/\* Blit from s1 to s2 \*/  
SDL\_BlitSurface(s1, NULL, s2, NULL);

/\* Free s2 \*/  
SDL\_FreeSurface(s2);

/\* Now lock and unlock s1 \*/  
SDL\_LockSurface(s1);  
SDL\_UnlockSurface(s1);

SDL\_Quit();

return 0;  
}

---

<div class="post-metadata">

**Author:** ![slouken](https://discourse.libsdl.org/letter_avatar_proxy/v4/letter/s/ec9cab/32.png) [@slouken](https://discourse.libsdl.org/u/slouken)\
**Post date:** [January 2, 2005, 4:52am UTC](https://discourse.libsdl.org/t/crash-during-sdl-unlocksurface/11688/2 "2005-01-02T04:52:57Z")

</div>

> I’ve been running into a problem that I think is a bug in SDL. The  
> situation is:

> I have a surface (surface A) with SDL\_SRCALPHA and SDL\_RLEACCEL set. I blit  
> from that to surface B. (and use it for various things, never touching A).  
> I then free surface B. Afterwards, I do some direct manipulation of surface  
> A, and so I lock the surface, do my stuff, and then unlock it. During the  
> call to SDL\_UnlockSurface, I get a crash.

> It turns out that it crashes at SDL\_RLEaccel.c, line 1433, which is  
> masksum = df-\>Rmask | df-\>Gmask | df-\>Bmask;

Sounds like a bug to me. Can you put together a small test case and post  
a link to it?

Thanks!  
-Sam Lantinga, Software Engineer, Blizzard Entertainment
