Public bug reported:
Since 3.0.0 to 3.0.2, pybind11 has a regression causing crashes during
interpreter shutdown with `py::enum_<>` by duplicating late-added
`def_property_static` argument strings and `function_record` heap-type
deallocation to call `PyObject_Free()` and decref the type.
This was first reported in #2163679 where autopkgtest was failing for
ecflow with a `free(): invalid pointer` crash. This can be better seen
in the stacktrace:
...
#7 malloc_printerr (str=<optimized out>) at ./malloc/malloc.c:5341
No locals.
#8 0x00007ffff7cb0b44 in malloc_printerr_tail (str=<optimized out>) at
./malloc/malloc.c:5358
No locals.
#9 0x00007ffff6d47e6c in pybind11::cpp_function::destruct (rec=0xd940e0,
free_strings=true) at /usr/include/pybind11/pybind11.h:769
arg = @0xd94290: {name = 0x7ffff72523e7 "self", descr = 0x0, value =
{<pybind11::detail::object_api<pybind11::handle>> =
{<pybind11::detail::pyobject_tag> = {<No data fields>}, <No data fields>},
m_ptr = 0x0}, convert = true, none = false}
__for_range = std::vector of length 1, capacity 1 = {{name =
0x7ffff72523e7 "self", descr = 0x0, value =
{<pybind11::detail::object_api<pybind11::handle>> =
{<pybind11::detail::pyobject_tag> = {<No data fields>}, <No data fields>},
m_ptr = 0x0}, convert = true, none = false}}
__for_begin = <optimized out>
__for_end = <optimized out>
next = 0x0
#10 pybind11::detail::function_record_PyTypeObject_methods::tp_dealloc_impl
(self=0x7ffff68e97d0) at /usr/include/pybind11/pybind11.h:1250
py_func_rec = 0x7ffff68e97d0
#11 0x0000000000514c33 in _Py_Dealloc ()
No symbol table info available.
#12 0x0000000000537d59 in ?? ()
No symbol table info available.
#13 0x0000000000514c33 in _Py_Dealloc ()
No symbol table info available.
#14 0x0000000000691dc3 in ?? ()
No symbol table info available.
...
** Affects: pybind11 (Ubuntu)
Importance: Critical
Status: New
** Tags: regression-release update-excuse
** Tags added: regression-release
** Description changed:
Since 3.0.0 to 3.0.2, pybind11 has a regression causing crashes during
interpreter shutdown with `py::enum_<>` by duplicating late-added
`def_property_static` argument strings and `function_record` heap-type
deallocation to call `PyObject_Free()` and decref the type.
This was first reported in #2163679 where autopkgtest was failing for
- ecflow with a `free(): invalid pointer` crash.
+ ecflow with a `free(): invalid pointer` crash. This can be better seen
+ in the stacktrace:
+
+ ...
+ #7 malloc_printerr (str=<optimized out>) at ./malloc/malloc.c:5341
+ No locals.
+ #8 0x00007ffff7cb0b44 in malloc_printerr_tail (str=<optimized out>) at
./malloc/malloc.c:5358
+ No locals.
+ #9 0x00007ffff6d47e6c in pybind11::cpp_function::destruct (rec=0xd940e0,
free_strings=true) at /usr/include/pybind11/pybind11.h:769
+ arg = @0xd94290: {name = 0x7ffff72523e7 "self", descr = 0x0, value =
{<pybind11::detail::object_api<pybind11::handle>> =
{<pybind11::detail::pyobject_tag> = {<No data fields>}, <No data fields>},
m_ptr = 0x0}, convert = true, none = false}
+ __for_range = std::vector of length 1, capacity 1 = {{name =
0x7ffff72523e7 "self", descr = 0x0, value =
{<pybind11::detail::object_api<pybind11::handle>> =
{<pybind11::detail::pyobject_tag> = {<No data fields>}, <No data fields>},
m_ptr = 0x0}, convert = true, none = false}}
+ __for_begin = <optimized out>
+ __for_end = <optimized out>
+ next = 0x0
+ #10 pybind11::detail::function_record_PyTypeObject_methods::tp_dealloc_impl
(self=0x7ffff68e97d0) at /usr/include/pybind11/pybind11.h:1250
+ py_func_rec = 0x7ffff68e97d0
+ #11 0x0000000000514c33 in _Py_Dealloc ()
+ No symbol table info available.
+ #12 0x0000000000537d59 in ?? ()
+ No symbol table info available.
+ #13 0x0000000000514c33 in _Py_Dealloc ()
+ No symbol table info available.
+ #14 0x0000000000691dc3 in ?? ()
+ No symbol table info available.
+ ...
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2164501
Title:
regression: free() invalid pointer
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/pybind11/+bug/2164501/+subscriptions
--
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs