[PATCH v4] malloc: Improve malloc initialization

Konrad Kleine konrad.kleine@posteo.de
Fri May 23 12:29:08 GMT 2025


Hi Florian,

On 23/05/2025 09:39, Florian Weimer wrote:
 > * Tulio Magno Quites Machado Filho:
 >
 >> Wilco Dijkstra <Wilco.Dijkstra@arm.com> writes:
 >>
 >>> v4: Remove remaining uses of __malloc_initialized.
 >>>
 >>> Move malloc initialization to __libc_early_init.  Use a hidden 
__ptmalloc_init
 >>> for initialization and a weak call to avoid pulling in the system 
malloc in a
 >>> static binary.  All previous initialization checks can now be removed.
 >>>
 >>> Passes regress, OK for commit?
 >>
 >> I bisected crashes on 32-bit x86 to this commit.
 >> It's still unclear to me what is causing the issue, but one thing caught
 >> my attention: malloc() started to return addresses from mmap'ed areas
 >> while it used to return addresses from the software break for this
 >> particular program (dynamically linked llvm-objdump).
 >
 > That part (the switch to mmap) I can explain.  The order in
 > __libc_early_init is currently this:
 >
 >    /* Initialize system malloc.  */
 >    call_function_static_weak (__ptmalloc_init);
 >
 >    /* Initialize ctype data.  */
 >    __ctype_init ();
 >
 >    /* Only the outer namespace is marked as single-threaded.  */
 >    __libc_single_threaded = initial;
 >
 > So __libc_single_threaded is false when __ptmalloc_init is called, and
 > we disable the use of brk.
 >
 >> It looks like that even glibc memory allocations are not using the
 >> software break anymore (see the first lines calling brk() without a call
 >> from the other libraries).
 >
 > Still the switch to mmap is not supposed to result in crashes.  This
 > could point to a completely different bug.  What is the nature of the
 > crashes?

The nature of the crash is that it occurred on 32-bit rawhide when 
building LLVM and especially running this test from an LLVM-LIT file:

https://github.com/llvm/llvm-project/blob/5c3a99760274a06f8cb7e7247ce69c2fde5fbf2a/llvm/test/Object/macho-invalid.test#L287-L288

Here's the crash (segfault) when running in GDB:

$ gdb --quiet --args \
  
/builddir/build/BUILD/llvm-20.1.4-build/llvm-project-20.1.4.src/llvm/redhat-linux-build/bin/llvm-objdump 
\
     --macho \
     --private-headers \
  
/builddir/build/BUILD/llvm-20.1.4-build/llvm-project-20.1.4.src/llvm/test/Object/Inputs/macho-invalid-dylib-cmdsize-past-eof
Reading symbols from 
/builddir/build/BUILD/llvm-20.1.4-build/llvm-project-20.1.4.src/llvm/redhat-linux-build/bin/llvm-objdump...
(gdb) r
Starting program: 
/builddir/build/BUILD/llvm-20.1.4-build/llvm-project-20.1.4.src/llvm/redhat-linux-build/bin/llvm-objdump 
--macho --private-headers 
/builddir/build/BUILD/llvm-20.1.4-build/llvm-project-20.1.4.src/llvm/test/Object/Inputs/macho-invalid-dylib-cmdsize-past-eof
Function(s) ^std::(move|forward|as_const|(__)?addressof) will be skipped 
when stepping.
Function(s) ^std::(shared|unique)_ptr<.*>::(get|operator) will be 
skipped when stepping.
Function(s) 
^std::(basic_string|vector|array|deque|(forward_)?list|(unordered_|flat_)?(multi)?(map|set)|span)<.*>::(c?r?(begin|end)|front|back|data|size|empty) 
will be skipped when stepping.
Function(s) ^std::(basic_string|vector|array|deque|span)<.*>::operator.] 
will be skipped when stepping.
[Thread debugging using libthread_db enabled]
Using host libthread_db library "/lib/libthread_db.so.1".

Program received signal SIGSEGV, Segmentation fault.
checkDylibCommand () at 
/builddir/build/BUILD/llvm-20.1.4-build/llvm-project-20.1.4.src/llvm/lib/Object/MachOObjectFile.cpp:760
760         if (P[i] == '\0')
Missing rpms, try: dnf --enablerepo='*debug*' install 
libstdc++-debuginfo-15.1.1-1.fc43.i686 
libgcc-debuginfo-15.1.1-1.fc43.i686 
glibc-debuginfo-2.41.9000-13.fc43.i686 
libffi-debuginfo-3.4.8-1.fc43.i686 
libedit-debuginfo-3.1-55.20250104cvs.fc42.i686 
zlib-ng-compat-debuginfo-2.2.4-2.fc43.i686 
libzstd-debuginfo-1.5.7-1.fc43.i686 
libxml2-debuginfo-2.12.10-1.fc43.i686 
ncurses-libs-debuginfo-6.5-5.20250125.fc42.i686 
xz-libs-debuginfo-5.8.1-1.fc43.i686
(gdb) bt
#0  checkDylibCommand () at 
/builddir/build/BUILD/llvm-20.1.4-build/llvm-project-20.1.4.src/llvm/lib/Object/MachOObjectFile.cpp:760
#1  0xf159206e in MachOObjectFile () at 
/builddir/build/BUILD/llvm-20.1.4-build/llvm-project-20.1.4.src/llvm/lib/Object/MachOObjectFile.cpp:1435
#2  0xf15af0f1 in create () at 
/builddir/build/BUILD/llvm-20.1.4-build/llvm-project-20.1.4.src/llvm/lib/Object/MachOObjectFile.cpp:1258
#3  createMachOObjectFile () at 
/builddir/build/BUILD/llvm-20.1.4-build/llvm-project-20.1.4.src/llvm/lib/Object/MachOObjectFile.cpp:5330
#4  0xf15b91f5 in createObjectFile () at 
/builddir/build/BUILD/llvm-20.1.4-build/llvm-project-20.1.4.src/llvm/lib/Object/ObjectFile.cpp:193
#5  0xf15bf3b7 in createSymbolicFile () at 
/builddir/build/BUILD/llvm-20.1.4-build/llvm-project-20.1.4.src/llvm/lib/Object/SymbolicFile.cpp:71
#6  0xf14ee817 in createBinary () at 
/builddir/build/BUILD/llvm-20.1.4-build/llvm-project-20.1.4.src/llvm/lib/Object/Binary.cpp:78
#7  0xf14eea37 in createBinary () at 
/builddir/build/BUILD/llvm-20.1.4-build/llvm-project-20.1.4.src/llvm/lib/Object/Binary.cpp:116
#8  0x565c017d in parseInputMachO () at 
/builddir/build/BUILD/llvm-20.1.4-build/llvm-project-20.1.4.src/llvm/tools/llvm-objdump/MachODump.cpp:2538
#9  0x56563d01 in dumpInput () at 
/builddir/build/BUILD/llvm-20.1.4-build/llvm-project-20.1.4.src/llvm/tools/llvm-objdump/llvm-objdump.cpp:3392
#10 
for_each<__gnu_cxx::__normal_iterator<std::__cxx11::basic_string<char, 
std::char_traits<char>, std::allocator<char> >*, 
std::vector<std::__cxx11::basic_string<char, std::char_traits<char>, 
std::allocator<char> >, std::allocator<std::__cxx11::basic_string<char, 
std::char_traits<char>, std::allocator<char> > > > >, void 
(*)(llvm::StringRef)> () at 
/usr/lib/gcc/i686-redhat-linux/15/../../../../include/c++/15/bits/stl_algo.h:3798
#11 for_each<std::vector<std::__cxx11::basic_string<char, 
std::char_traits<char>, std::allocator<char> >, 
std::allocator<std::__cxx11::basic_string<char, std::char_traits<char>, 
std::allocator<char> > > >&, void (*)(llvm::StringRef)> ()
     at 
/builddir/build/BUILD/llvm-20.1.4-build/llvm-project-20.1.4.src/llvm/include/llvm/ADT/STLExtras.h:1733
#12 llvm_objdump_main () at 
/builddir/build/BUILD/llvm-20.1.4-build/llvm-project-20.1.4.src/llvm/tools/llvm-objdump/llvm-objdump.cpp:3748
#13 0x56621227 in main () at 
/builddir/build/BUILD/llvm-20.1.4-build/llvm-project-20.1.4.src/llvm/redhat-linux-build/tools/llvm-objdump/llvm-objdump-driver.cpp:17
(gdb)

I hope this helps.

Konrad

 >
 > Thanks,
 > Florian
 >



More information about the Libc-alpha mailing list