[PATCH v4] malloc: Improve malloc initialization
Konrad Kleine
konrad.kleine@posteo.de
Fri May 23 12:29:08 GMT 2025
Hi Florian,
On 23/05/2025 09:39, Florian Weimer wrote:
> * Tulio Magno Quites Machado Filho:
>
>> Wilco Dijkstra <Wilco.Dijkstra@arm.com> writes:
>>
>>> v4: Remove remaining uses of __malloc_initialized.
>>>
>>> Move malloc initialization to __libc_early_init. Use a hidden
__ptmalloc_init
>>> for initialization and a weak call to avoid pulling in the system
malloc in a
>>> static binary. All previous initialization checks can now be removed.
>>>
>>> Passes regress, OK for commit?
>>
>> I bisected crashes on 32-bit x86 to this commit.
>> It's still unclear to me what is causing the issue, but one thing caught
>> my attention: malloc() started to return addresses from mmap'ed areas
>> while it used to return addresses from the software break for this
>> particular program (dynamically linked llvm-objdump).
>
> That part (the switch to mmap) I can explain. The order in
> __libc_early_init is currently this:
>
> /* Initialize system malloc. */
> call_function_static_weak (__ptmalloc_init);
>
> /* Initialize ctype data. */
> __ctype_init ();
>
> /* Only the outer namespace is marked as single-threaded. */
> __libc_single_threaded = initial;
>
> So __libc_single_threaded is false when __ptmalloc_init is called, and
> we disable the use of brk.
>
>> It looks like that even glibc memory allocations are not using the
>> software break anymore (see the first lines calling brk() without a call
>> from the other libraries).
>
> Still the switch to mmap is not supposed to result in crashes. This
> could point to a completely different bug. What is the nature of the
> crashes?
The nature of the crash is that it occurred on 32-bit rawhide when
building LLVM and especially running this test from an LLVM-LIT file:
https://github.com/llvm/llvm-project/blob/5c3a99760274a06f8cb7e7247ce69c2fde5fbf2a/llvm/test/Object/macho-invalid.test#L287-L288
Here's the crash (segfault) when running in GDB:
$ gdb --quiet --args \
/builddir/build/BUILD/llvm-20.1.4-build/llvm-project-20.1.4.src/llvm/redhat-linux-build/bin/llvm-objdump
\
--macho \
--private-headers \
/builddir/build/BUILD/llvm-20.1.4-build/llvm-project-20.1.4.src/llvm/test/Object/Inputs/macho-invalid-dylib-cmdsize-past-eof
Reading symbols from
/builddir/build/BUILD/llvm-20.1.4-build/llvm-project-20.1.4.src/llvm/redhat-linux-build/bin/llvm-objdump...
(gdb) r
Starting program:
/builddir/build/BUILD/llvm-20.1.4-build/llvm-project-20.1.4.src/llvm/redhat-linux-build/bin/llvm-objdump
--macho --private-headers
/builddir/build/BUILD/llvm-20.1.4-build/llvm-project-20.1.4.src/llvm/test/Object/Inputs/macho-invalid-dylib-cmdsize-past-eof
Function(s) ^std::(move|forward|as_const|(__)?addressof) will be skipped
when stepping.
Function(s) ^std::(shared|unique)_ptr<.*>::(get|operator) will be
skipped when stepping.
Function(s)
^std::(basic_string|vector|array|deque|(forward_)?list|(unordered_|flat_)?(multi)?(map|set)|span)<.*>::(c?r?(begin|end)|front|back|data|size|empty)
will be skipped when stepping.
Function(s) ^std::(basic_string|vector|array|deque|span)<.*>::operator.]
will be skipped when stepping.
[Thread debugging using libthread_db enabled]
Using host libthread_db library "/lib/libthread_db.so.1".
Program received signal SIGSEGV, Segmentation fault.
checkDylibCommand () at
/builddir/build/BUILD/llvm-20.1.4-build/llvm-project-20.1.4.src/llvm/lib/Object/MachOObjectFile.cpp:760
760 if (P[i] == '\0')
Missing rpms, try: dnf --enablerepo='*debug*' install
libstdc++-debuginfo-15.1.1-1.fc43.i686
libgcc-debuginfo-15.1.1-1.fc43.i686
glibc-debuginfo-2.41.9000-13.fc43.i686
libffi-debuginfo-3.4.8-1.fc43.i686
libedit-debuginfo-3.1-55.20250104cvs.fc42.i686
zlib-ng-compat-debuginfo-2.2.4-2.fc43.i686
libzstd-debuginfo-1.5.7-1.fc43.i686
libxml2-debuginfo-2.12.10-1.fc43.i686
ncurses-libs-debuginfo-6.5-5.20250125.fc42.i686
xz-libs-debuginfo-5.8.1-1.fc43.i686
(gdb) bt
#0 checkDylibCommand () at
/builddir/build/BUILD/llvm-20.1.4-build/llvm-project-20.1.4.src/llvm/lib/Object/MachOObjectFile.cpp:760
#1 0xf159206e in MachOObjectFile () at
/builddir/build/BUILD/llvm-20.1.4-build/llvm-project-20.1.4.src/llvm/lib/Object/MachOObjectFile.cpp:1435
#2 0xf15af0f1 in create () at
/builddir/build/BUILD/llvm-20.1.4-build/llvm-project-20.1.4.src/llvm/lib/Object/MachOObjectFile.cpp:1258
#3 createMachOObjectFile () at
/builddir/build/BUILD/llvm-20.1.4-build/llvm-project-20.1.4.src/llvm/lib/Object/MachOObjectFile.cpp:5330
#4 0xf15b91f5 in createObjectFile () at
/builddir/build/BUILD/llvm-20.1.4-build/llvm-project-20.1.4.src/llvm/lib/Object/ObjectFile.cpp:193
#5 0xf15bf3b7 in createSymbolicFile () at
/builddir/build/BUILD/llvm-20.1.4-build/llvm-project-20.1.4.src/llvm/lib/Object/SymbolicFile.cpp:71
#6 0xf14ee817 in createBinary () at
/builddir/build/BUILD/llvm-20.1.4-build/llvm-project-20.1.4.src/llvm/lib/Object/Binary.cpp:78
#7 0xf14eea37 in createBinary () at
/builddir/build/BUILD/llvm-20.1.4-build/llvm-project-20.1.4.src/llvm/lib/Object/Binary.cpp:116
#8 0x565c017d in parseInputMachO () at
/builddir/build/BUILD/llvm-20.1.4-build/llvm-project-20.1.4.src/llvm/tools/llvm-objdump/MachODump.cpp:2538
#9 0x56563d01 in dumpInput () at
/builddir/build/BUILD/llvm-20.1.4-build/llvm-project-20.1.4.src/llvm/tools/llvm-objdump/llvm-objdump.cpp:3392
#10
for_each<__gnu_cxx::__normal_iterator<std::__cxx11::basic_string<char,
std::char_traits<char>, std::allocator<char> >*,
std::vector<std::__cxx11::basic_string<char, std::char_traits<char>,
std::allocator<char> >, std::allocator<std::__cxx11::basic_string<char,
std::char_traits<char>, std::allocator<char> > > > >, void
(*)(llvm::StringRef)> () at
/usr/lib/gcc/i686-redhat-linux/15/../../../../include/c++/15/bits/stl_algo.h:3798
#11 for_each<std::vector<std::__cxx11::basic_string<char,
std::char_traits<char>, std::allocator<char> >,
std::allocator<std::__cxx11::basic_string<char, std::char_traits<char>,
std::allocator<char> > > >&, void (*)(llvm::StringRef)> ()
at
/builddir/build/BUILD/llvm-20.1.4-build/llvm-project-20.1.4.src/llvm/include/llvm/ADT/STLExtras.h:1733
#12 llvm_objdump_main () at
/builddir/build/BUILD/llvm-20.1.4-build/llvm-project-20.1.4.src/llvm/tools/llvm-objdump/llvm-objdump.cpp:3748
#13 0x56621227 in main () at
/builddir/build/BUILD/llvm-20.1.4-build/llvm-project-20.1.4.src/llvm/redhat-linux-build/tools/llvm-objdump/llvm-objdump-driver.cpp:17
(gdb)
I hope this helps.
Konrad
>
> Thanks,
> Florian
>
More information about the Libc-alpha
mailing list