Re: free(): double free detected in tcache 2
Denis Corbin <[email protected]>
| Newsgroups | gmane.comp.sysutils.backup.dar.support |
|---|---|
| Message-ID | <[email protected]> |
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
On 27/02/2020 11:34, Graham Cobb wrote:
> On 26/02/2020 21:05, Graham Cobb wrote:
>>> Difficult to know what caused this without more info
>>>
[...]
>>
>> I will see if I get anything tonight.
>
> It crashed again last night. I had turned on -v, here is the log:
>
> ############ DARsystem: ### Thu, 27 Feb 2020 02:20:01 +0000 ###
> DARsystem: Current backup information (Size in 1024 bytes
> blocks.): DARsystem: ..DARsystemFull: 36509724. DARsystem:
> ..DARsystemDiff: 3198896: DARsystem: ....DARsystemDiff01: 3198896.
> ############ DARsystem: Preparing to Create DARsystemDiff02.
> ############ DARsystem: creating DARsystemDiff02. Please wait. ###
> No terminal found for user interaction. All questions will be
> assumed a negative answer (less destructive choice), which most of
> the time will abort the program. No user target found on command
> line Opening archive DARsystemDiff01 ... Opening the archive using
> the multi-slice abstraction layer... free(): double free detected
> in tcache 2 sh: line 1: 419867 Aborted (core
> dumped)
>
> As you can see, the last message was "Opening the archive using
> the multi-slice abstraction layer..."
>
> I asked gdb for a backtrace and got this...
>
> #0 __GI_raise (sig=sig@entry=6) at
> ../sysdeps/unix/sysv/linux/raise.c:50 #1 0x00007f152f655535 in
> __GI_abort () at abort.c:79 #2 0x00007f152f6abdc8 in
> __libc_message (action=action@entry=do_abort,
> fmt=fmt@entry=0x7f152f7b6aae "%s\n") at
> ../sysdeps/posix/libc_fatal.c:181 #3 0x00007f152f6b249a in
> malloc_printerr (str=str@entry=0x7f152f7b8768 "free(): double free
> detected in tcache 2") at malloc.c:5361 #4 0x00007f152f6b3e5d in
> _int_free (av=0x7f152f7e9c40 <main_arena>, p=0x559fd8a95de0,
> have_lock=<optimized out>) at malloc.c:4215 #5 0x0000559fd838a831
> in std::deque<std::__cxx11::basic_string<char,
> std::char_traits<char>, std::allocator<char> >,
> std::allocator<std::__cxx11::basic_string<char,
> std::char_traits<char>, std::allocator<char> > >
>> ::_M_destroy_data_aux(std::_Deque_iterator<std::__cxx11::basic_string
<char,
>
>>
std::char_traits<char>, std::allocator<char> >,
> std::__cxx11::basic_string<char, std::char_traits<char>,
> std::allocator<char> >&, std::__cxx11::basic_string<char,
> std::char_traits<char>, std::allocator<char> >*>,
> std::_Deque_iterator<std::__cxx11::basic_string<char,
> std::char_traits<char>, std::allocator<char> >,
> std::__cxx11::basic_string<char, std::char_traits<char>,
> std::allocator<char> >&, std::__cxx11::basic_string<char,
> std::char_traits<char>, std::allocator<char> >*>) () #6
> 0x00007f152fbb1dd0 in
> libdar::etage::etage(libdar::user_interaction&, char const*,
> libdar::datetime const&, libdar::datetime const&, bool, bool) ()
> from /usr/lib/x86_64-linux-gnu/libdar64.so.6000 #7
> 0x00007f152fba8999 in libdar::entrepot_local::read_dir_reset()
> const () from /usr/lib/x86_64-linux-gnu/libdar64.so.6000 #8
> 0x00007f152fc1f24e in
> libdar::sar_tools_get_higher_number_in_dir(libdar::entrepot&,
> std::__cxx11::basic_string<char, std::char_traits<char>,
> std::allocator<char> > const&, libdar::limitint<unsigned long>
> const&, std::__cxx11::basic_string<char, std::char_traits<char>,
> std::allocator<char> > const&, libdar::limitint<unsigned long>&)
> () from /usr/lib/x86_64-linux-gnu/libdar64.so.6000 #9
> 0x00007f152fc1e4f0 in libdar::sar::open_last_file(bool) () from
> /usr/lib/x86_64-linux-gnu/libdar64.so.6000 #10 0x00007f152fc1ea00
> in libdar::sar::skip_to_eof() () from
> /usr/lib/x86_64-linux-gnu/libdar64.so.6000 #11 0x00007f152fc1ee9f
> in libdar::sar::sar(std::shared_ptr<libdar::user_interaction>
> const&, std::__cxx11::basic_string<char, std::char_traits<char>,
> std::allocator<char> > const&, std::__cxx11::basic_string<char,
> std::char_traits<char>, std::allocator<char> > const&,
> std::shared_ptr<libdar::entrepot> const&, bool,
> libdar::limitint<unsigned long> const&, bool,
> std::__cxx11::basic_string<char, std::char_traits<char>,
> std::allocator<char> > const&) () from
> /usr/lib/x86_64-linux-gnu/libdar64.so.6000 #12 0x00007f152fc07aeb
> in
> libdar::macro_tools_open_archive(std::shared_ptr<libdar::user_interact
ion>
>
>
const&, std::shared_ptr<libdar::entrepot> const&,
> std::__cxx11::basic_string<char, std::char_traits<char>,
> std::allocator<char> > const&, libdar::limitint<--Type <RET> for
> more, q to quit, c to continue without paging--c unsigned long>
> const&, std::__cxx11::basic_string<char, std::char_traits<char>,
> std::allocator<char> > const&, libdar::crypto_algo,
> libdar::secu_string const&, unsigned int, libdar::pile&,
> libdar::header_version&, std::__cxx11::basic_string<char,
> std::char_traits<char>, std::allocator<char> > const&,
> std::__cxx11::basic_string<char, std::char_traits<char>,
> std::allocator<char> > const&, std::__cxx11::basic_string<char,
> std::char_traits<char>, std::allocator<char> > const&,
> libdar::limitint<unsigned long>&, bool, bool, bool, bool,
> std::__cxx11::list<libdar::signator,
> std::allocator<libdar::signator>
>> &, libdar::slice_layout&, bool, bool) () from
> /usr/lib/x86_64-linux-gnu/libdar64.so.6000 #13 0x00007f152fbe7e92
> in
> libdar::archive::i_archive::i_archive(std::shared_ptr<libdar::user_int
eraction>
>
>
const&, libdar::path const&, std::__cxx11::basic_string<char,
> std::char_traits<char>, std::allocator<char> > const&,
> std::__cxx11::basic_string<char, std::char_traits<char>,
> std::allocator<char> > const&, libdar::archive_options_read const&)
> () from /usr/lib/x86_64-linux-gnu/libdar64.so.6000 #14
> 0x00007f152fb58d3b in
> libdar::archive::archive(std::shared_ptr<libdar::user_interaction>
> const&, libdar::path const&, std::__cxx11::basic_string<char,
> std::char_traits<char>, std::allocator<char> > const&,
> std::__cxx11::basic_string<char, std::char_traits<char>,
> std::allocator<char> > const&, libdar::archive_options_read const&)
> () from /usr/lib/x86_64-linux-gnu/libdar64.so.6000 #15
> 0x0000559fd8394069 in ?? () #16 0x0000559fd839d097 in ?? () #17
> 0x0000559fd8371971 in ?? () #18 0x00007f152f656bbb in
> __libc_start_main (main=0x559fd8371930, argc=246,
> argv=0x7ffc901fbec8, init=<optimized out>, fini=<optimized out>,
> rtld_fini=<optimized out>, stack_end=0x7ffc901fbeb8) at
> ../csu/libc-start.c:308 #19 0x0000559fd8371aea in ?? ()
Thanks for that!
>
> That is hard to read due to email wrapping. The last call inside
> libdar (#6) claims to be: libdar::etage::etage. Apparently that
> called (#7) std::deque, which did the free.
yep, this code has not changed for years... The problem occurs at etage
object construction. Its field "fichier" should be initalized by default
before the etage constructor code is ran. The first thing that is done
is to invoke the std::deque::clear() method on this one, which seems to
be the #5 in the stack.
If you recompile dar and still have the problem, can compile and run
this very simple C++ code. It would let me validate this hypothesis
which is about lack of initialization of class std::deque
# cat test1.cpp
// -----
#include <string>
#include <deque>
int main()
{
std::deque<std::string> fichier;
fichier.clear();
}
// -----
# g++ test1.cpp -o test1
# ./test1
>
> In case it is at all useful, I have made the core file (and the
> corresponding dar image) available at http://cobb.uk.net/denis.tgz
> (https won't work).
>
I got it thanks, but is was not more useful than the stack info you
provided
> I will let you know when I have been able to try with a debugging
> image. In the meantime, you might find you could reproduce with a
> vm running the most recent debian testing.
OK, won't be able to play with that until this week-end but that's
good to know!
>
> Regards Graham
>
Regards,
Denis
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCAAdFiEEOzEprx3d76WjfYGPCDGwvQPYsYIFAl5Xst0ACgkQCDGwvQPY
sYLVMRAAu9noD6TDUza5OZsSJ4V3K/YT5NuBs5uaQ/ZoGb6SsFqXDBA7M1gF0vZh
TzsrjT2JnZKIeWPC/83u4sNHDcYTOk2dCCiGan+oSHhMGPYglsAbOzUB4VFQyopS
GTFGKSOWCcF7Uj7siMeqT7f3r8PPwz+2YYydAk5wqZCvpKZ1+CH8SX3xOUkF/GAZ
nbblkxCM7l7ImpGxb4T8n4Uc38FyBqY2p5r1RfJC/V7jmow10cYahYtTZM6K5nGi
QnlMrpij9S6CJqdXi0RcL/3CJrPb9i/4/L5vTcOmWhwq4tuYB0uMJL+ZUM69zWoX
BDLskGQyppKzf7H/XJ5H6TbxjX40zNZNvJkErQ8IdzZr2Oxt8UcxsSLmGht/Dwt4
qAHLH7sc7fakRaGREzjfZRRPfu3A5i0tXlYXOCJJOVfRBCw2ZpMNv5B39iH/5JaA
wm8W4pQz6zPxN8Z/IZk3RU1UIIsDs4L9knAIn35TXW7P2WjrBOOFFETT3rv7Yj1h
P0LAufpQ3mx9HbCO3rqdRV2Aabbtj0WPe08iQUboNG2T3SBoWSjaGXLW89AZv89Y
x/3UEbmmvwEx/6KTJZeUvr2y4tsGOgKwFLejJuKMItMz60n9USO/xhQxJa1kZWpe
YrDPZCwtUIhzJ456HZv0SI3yzJYO51AIsa6YEa0vQWRZUEiiZcA=
=LQsg
-----END PGP SIGNATURE-----