<html>
    <head>
      <base href="https://bugs.freedesktop.org/" />
    </head>
    <body><table border="1" cellspacing="0" cellpadding="8">
        <tr>
          <th>Bug ID</th>
          <td><a class="bz_bug_link 
          bz_status_NEW "
   title="NEW - [HD Graphics 4000] Crash"
   href="https://bugs.freedesktop.org/show_bug.cgi?id=91577">91577</a>
          </td>
        </tr>

        <tr>
          <th>Summary</th>
          <td>[HD Graphics 4000] Crash
          </td>
        </tr>

        <tr>
          <th>Product</th>
          <td>xorg
          </td>
        </tr>

        <tr>
          <th>Version</th>
          <td>unspecified
          </td>
        </tr>

        <tr>
          <th>Hardware</th>
          <td>x86-64 (AMD64)
          </td>
        </tr>

        <tr>
          <th>OS</th>
          <td>Linux (All)
          </td>
        </tr>

        <tr>
          <th>Status</th>
          <td>NEW
          </td>
        </tr>

        <tr>
          <th>Severity</th>
          <td>normal
          </td>
        </tr>

        <tr>
          <th>Priority</th>
          <td>medium
          </td>
        </tr>

        <tr>
          <th>Component</th>
          <td>Driver/intel
          </td>
        </tr>

        <tr>
          <th>Assignee</th>
          <td>chris@chris-wilson.co.uk
          </td>
        </tr>

        <tr>
          <th>Reporter</th>
          <td>fdo-bugs.aspseka@xoxy.net
          </td>
        </tr>

        <tr>
          <th>QA Contact</th>
          <td>intel-gfx-bugs@lists.freedesktop.org
          </td>
        </tr></table>
      <p>
        <div>
        <pre>I experience reproducable crashed with trunk
(bc063c9f4af90542297877281b1b9f4692dafde4).

Steps to reproduce on my machine:
1. Open Links (on X)
2. Navigate to <a href="http://www.x.org/wiki/Development/Documentation/ServerDebugging/">http://www.x.org/wiki/Development/Documentation/ServerDebugging/</a>
3. Scroll down to the script "Debugging with one machine", "Version 1"
4. Select/deselect it using pointer repeatedly

After a short while, intel_drv.so crashes:

[119917.095] (EE) 
[119917.095] (EE) Backtrace:
[119917.102] (EE) 0: /usr/bin/Xorg (OsSigHandler+0x29) [0x5a34a9]
[119917.173] (EE) 1: /lib64/libc.so.6 (killpg+0x40) [0x7f60c968252f]
[119917.241] (EE) 2: /usr/lib64/xorg/modules/drivers/intel_drv.so
(_init+0x166e6) [0x7f60c7645786]
[119917.307] (EE) 3: /usr/lib64/xorg/modules/drivers/intel_drv.so
(_init+0x108094) [0x7f60c7828974]
[119917.371] (EE) 4: /usr/lib64/xorg/modules/drivers/intel_drv.so
(_init+0x2d925) [0x7f60c7673b25]
[119917.435] (EE) 5: /usr/lib64/xorg/modules/drivers/intel_drv.so
(_init+0x5169c) [0x7f60c76bb0bc]
[119917.435] (EE) 6: /usr/bin/Xorg (damagePolyFillRect+0x7b) [0x52451b]
[119917.435] (EE) 7: /usr/bin/Xorg (ProcPolyFillRectangle+0xe0) [0x436630]
[119917.435] (EE) 8: /usr/bin/Xorg (Dispatch+0x287) [0x439ed7]
[119917.435] (EE) 9: /usr/bin/Xorg (dix_main+0x3f5) [0x43e0a5]
[119917.499] (EE) 10: /lib64/libc.so.6 (__libc_start_main+0xf0)
[0x7f60c966f730]
[119917.500] (EE) 11: /usr/bin/Xorg (_start+0x29) [0x427e59]
[119917.568] (EE) 12: ? (?+0x29) [0x29]
[119917.568] (EE) 
[119917.568] (EE) Segmentation fault at address 0x80
[119917.568] (EE) 
Fatal server error:
[119917.568] (EE) Caught signal 11 (Segmentation fault). Server aborting</pre>
        </div>
      </p>
      <hr>
      <span>You are receiving this mail because:</span>
      
      <ul>
          <li>You are the QA Contact for the bug.</li>
      </ul>
    </body>
</html>