Deallocation hangs -- regression moving from `0.9.1` to `0.10.*`

Open
#70 5 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
25/100
Issue type
Bug
Clarity
Needs clarification
Activity status
Stale
Tech stack
rust

Research direction

Start with src/hole.rs, especially Cursor::try_insert_after at line 547 and the deallocate paths at lines 679 and 438 shown in the backtrace. Compare behavior between linked_list_allocator 0.9.1 and 0.10.1–0.10.3 using the Theseus configuration and Rust nightly 1.64. Done means identifying a reproducible failure condition and resolving or clearly isolating the deallocation hang.

Written by the indexing model from the issue text.

Description

We just ran into a strange issue in Theseus OS where the deallocation path hangs. I'm not yet 100% sure what the precise failure condition is, but I wanted to post this issue sooner rather than later in case anyone else has run across this.

So far it only occurs in an OS execution path that causes more heap allocations than what we normally do, so it could be related to heavy heap usage. Also not sure if it's related to the pending issue #66, which alludes to an issue with fragmentation (?).

Relevant details

Theseus uses linked_list_allocator as its early heap allocator. Through bisection, I've confirmed that this issue only occurred after upgrading from linked_list_allocator 0.9.1 to 0.10.3 (https://github.com/theseus-os/Theseus/pull/646), and I confirmed that the problem is present in both 0.10.1 and 0.10.2 as well. If it's relevant, we're using linked_list_allocator as such:

[dependencies.linked_list_allocator]
version = "0.10.3"
default-features = false
features = [ "const_mut_refs" ]

Using Rust nightly 1.64

$ rustc --version
rustc 1.64.0-nightly (f8588549c 2022-07-18)

Backtrace

I have a partial backtrace from GDB but it isn't complete; will work on improving it as I narrow down the exact cause.

#0  0xffffffff8011e916 in linked_list_allocator::hole::Cursor::try_insert_after (node=..., self=<optimized out>) at src/hole.rs:547
#1  linked_list_allocator::hole::deallocate (list=<optimized out>, addr=0xfffffe80004d1700 "\000", size=4096) at src/hole.rs:679
#2  linked_list_allocator::hole::HoleList::deallocate (self=<optimized out>, ptr=..., layout=...) at src/hole.rs:438

I can also add steps to repro this behavior in Theseus but it probably wouldn't be useful until I can more specifically determine the exact failure condition.

Dominant language
Rust
Stars
242
Forks
56
PR merge metrics
No merged PRs in 30d

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from rust-osdev/linked-list-allocator

All issues in rust-osdev/linked-list-allocator

Similar issues

More Rust issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.