Use of Freed Memory crash.

From: David Gilbert <dgilbert_at_dclg.ca>
Date: Sun, 21 Dec 2003 21:24:09 -0500
I got the following backtrace from a recent crash of current:

(kgdb) bt
#0  doadump () at ../../../kern/kern_shutdown.c:240
#1  0xc0542d42 in boot (howto=256) at ../../../kern/kern_shutdown.c:372
#2  0xc0543098 in panic () at ../../../kern/kern_shutdown.c:550
#3  0xc064fa17 in mtrash_ctor (mem=0xc9d84000, size=0, arg=0x0)
    at ../../../vm/uma_dbg.c:137
#4  0xc064e17b in uma_zalloc_arg (zone=0xc103be40, udata=0x0, flags=2)
    at ../../../vm/uma_core.c:1403
#5  0xc0537a93 in malloc (size=3238248000, type=0xc06f45a0, flags=2)
    at ../../../vm/uma.h:234
#6  0xc056d695 in poll (td=0xc6bb88c0, uap=0xe9f71d14)
    at ../../../kern/sys_generic.c:966
#7  0xc0680db0 in syscall (frame=
      {tf_fs = 47, tf_es = 673775663, tf_ds = -1078001617, tf_edi = 10, tf_esi = 172, tf_ebp = -1077943212, tf_isp = -369681036, tf_ebx = 673797812, tf_edx = 160608256, tf_ecx = 137695232, tf_eax = 209, tf_trapno = 22, tf_err = 2, tf_eip = 674140831, tf_cs = 31, tf_eflags = 658, tf_esp = -1077943272, tf_ss = 47})
    at ../../../i386/i386/trap.c:1010
#8  0xc067292d in Xint0x80_syscall () at {standard input}:136
---Can't read userspace from dump, or kernel process---

... now the panic message was:

panic: Most recently used by temp

The code in question (mtrash_ctor) is:

               printf("Memory modified after free %p(%d) val=%x _at_ %p\n",  
                        mem, size, *p, p);
               panic("Most recently used by %s\n", (*ksp == NULL)?
                        "none" : (*ksp)->ks_shortdesc);

... anyone working on something that affects this?  I have the dump if
someone wants it.

Dave.

-- 
============================================================================
|David Gilbert, Independent Contractor.       | Two things can only be     |
|Mail:       dave_at_daveg.ca                    |  equal if and only if they |
|http://daveg.ca                              |   are precisely opposite.  |
=========================================================GLO================
Received on Sun Dec 21 2003 - 17:24:11 UTC

This archive was generated by hypermail 2.4.0 : Wed May 19 2021 - 11:37:35 UTC