DynamoRIO / DynamoRIO/drmemory

CRASH (in drmemory full mode w/ -no_privlib_privheap on simple video page)

Open
#1,085 0 comments 0 reactions 0 assignees View on GitHub
Migrated OpSys-Windows Priority-High
Dominant language
C
Stars
2.7k
Forks
290
PR merge metrics
No merged PRs in 30d

Description

_From [bruen...@google.com](https://code.google.com/u/109494838902877177630/) on November 14, 2012 20:22:35_

# rm -rf /c/users/bruening/AppData/LocalLow/drmemory/D\* && ~/drmemory/git/build_x86_dbg/bin/drmemory -pause_at_assert -suppress c:/src/chromium/src/tools/valgrind/drmemory/suppressions.txt -logdir C:/users/bruening/AppData/LocalLow/drmemory -batch -dr c:/src/dr/git/exports -dr_ops "-no_privlib_privheap -stderr_mask 15 -msgbox_mask 12" -- ./chrome.exe --user-data-dir='C:\cygwin\tmp\chrome' <...> http://www.xbird.net/video/stevejobs-stanford.html # grep -h -A 1 ^Error /c/users/bruening/AppData/LocalLow/drmemory/D_/r_ | grep ^# | sed 's/!.*//' | sort -n | uniq -c

0:000> du dynamorio!debugbox_msg_buf
66a3a8c0 "Application C:\src\chromium\src\"
66a3a900 "out\Debug\chrome.exe (60380). C"
66a3a940 "lient exception at PC 0x02b4049d"
66a3a980 ". Program aborted. .0xc0000005 "
66a3a9c0 "0x00000000 0x02b4049d 0x02b4049d"
66a3aa00 " 0x00000000 0x00000000.Base: 0x6"
66a3aa40 "6920000.Registers: eax=0x0000000"
66a3aa80 "0 ebx=0x2028f000 ecx=0x00000000 "
66a3aac0 "edx=0x2023af80. esi=0x2028eda0 e"
66a3ab00 "di=0x00000001 esp=0x2028e9f4 ebp"
66a3ab40 "=0x2028e9fc. eflags=0x00010212.v"
66a3ab80 "ersion 3.2.1702, custom build.-l"
0:000> kb =2028e9fc 2028e9f4 02b4049d
ChildEBP RetAddr Args to Child
2028e9fc 02d11ca9 2023af80 00000000 00000001 drmemorylib!get_thread_tls_value+0x2d [c:\src\drmemory\git\src\drmemory\readwrite.c @ 515]
2028ea94 02d09b7b 2023af80 26e75214 00000000 drmemorylib!prepare_thread_for_scan+0x5b9 [c:\src\drmemory\git\src\drmemory\leak.c @ 1157]
2028ed74 02ccba34 00000001 2028ed8c 02b3ab83 drmemorylib!leak_scan_for_leaks+0xcab [c:\src\drmemory\git\src\drmemory\leak.c @ 1241]
2028ed80 02b3ab83 00000001 2028edcc 669ad796 drmemorylib!check_reachability+0x34 [c:\src\drmemory\git\src\drmemory\alloc_drmem.c @ 2383]
2028ed8c 669ad796 00000000 00000001 c06d007e drmemorylib!event_exit+0x33 [c:\src\drmemory\git\src\drmemory\drmemory.c @ 399]
2028edb0 6694de35 2258aab4 00000001 669ac263 dynamorio!instrument_exit+0x86 [c:\src\dr\git\src\core\x86\instrument.c @ 669]
2028edbc 669ac263 669ac2e4 2028f000 669bcdca dynamorio!dynamo_process_exit+0x265 [c:\src\dr\git\src\core\dynamo.c @ 1394]
2028ee04 6696cf9e c06d007e 66957180 2023af80 dynamorio!cleanup_and_terminate+0x4b [C:\src\dr\git\build_x86_rel\core\CMakeFiles\dynamorio.dir\x86\x86.asm.obj.s @ 1264]
2028ee0c 66957180 2023af80 00000001 23451acc dynamorio!common_global_heap_alloc+0x1e [c:\src\dr\git\src\core\heap.c @ 2504]
2028ee24 6695762a 2023a740 66957641 2023a740 dynamorio!hashtable_fragment_add+0x20 [c:\src\dr\git\src\core\hashtablex.h @ 805]
2028ee60 6695e910 2023af80 66957180 2023af80 dynamorio!fragment_create_and_add_future+0xfa [c:\src\dr\git\src\core\fragment.c @ 4525]
2028ee80 66957509 2023a6e4 66957520 2023a6e4 dynamorio!link_fragment_outgoing+0x1e0 [c:\src\dr\git\src\core\link.c @ 1809]
2028ee9c 66963049 6696307b 66963099 2023af80 dynamorio!fragment_add+0x79 [c:\src\dr\git\src\core\fragment.c @ 3043]
2028eef0 6696d2d0 21095f48 00000000 6696ea9a dynamorio!emit_fragment_common+0x869 [c:\src\dr\git\src\core\emit.c @ 957]
2028ef24 02d930d8 2023af80 00000029 00000001 dynamorio!heap_free+0x40 [c:\src\dr\git\src\core\heap.c @ 3619]
20295ef4 00000000 00000000 772afc9b 0000002e drmemorylib!drmgr_presyscall_event+0x88 [c:\src\dr\git\src\ext\drmgr\drmgr.c @ 832]
0:000> dv
tls = 0x00000000 ""
drcontext = 0x2023af80
index = 0
0:000> ?? drmemorylib!tls_idx_instru
int 0n6
0:000> ~
. 0 Id: ebdc.d2f4 Suspend: 1 Teb: 7efdd000 Unfrozen
1 Id: ebdc.ec2c Suspend: 2 Teb: 7efda000 Unfrozen
2 Id: ebdc.ec60 Suspend: 2 Teb: 7efd7000 Unfrozen
3 Id: ebdc.ec70 Suspend: 2 Teb: 7efaf000 Unfrozen
4 Id: ebdc.eed4 Suspend: 2 Teb: 7efac000 Unfrozen
5 Id: ebdc.eed8 Suspend: 2 Teb: 7efa9000 Unfrozen
6 Id: ebdc.ef14 Suspend: 2 Teb: 7efa6000 Unfrozen
7 Id: ebdc.ee90 Suspend: 2 Teb: 7efa3000 Unfrozen
8 Id: ebdc.eea4 Suspend: 2 Teb: 7efa0000 Unfrozen
9 Id: ebdc.f088 Suspend: 1 Teb: 7ef9d000 Unfrozen

the issue #547 fix looks broken as it calls:
set_thread_tls_value(drcontext, SPILL_SLOT_1, (ptr_uint_t)teb);
and later calls this which nulls out the whole spill slot region:
instrument_thread_exit(drcontext);

looks like r741 for issue #777 (drmgr refactoring) introduced this.

presumably raw tls is still there and we just want to not set the drmgr
field to NULL, right?

_Original issue: http://code.google.com/p/drmemory/issues/detail?id=1085_

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.