gpt4 book ai didi

c++ - boost::thread::join() 崩溃试图引用销毁的 thread_info

转载 作者:太空宇宙 更新时间:2023-11-04 12:46:12 25 4
gpt4 key购买 nike

编辑:我创建了一个导致问题的独立应用程序。它通常需要超过 1000 次循环迭代(创建/运行/加入线程),有时直到几千次迭代才会崩溃:

#include <boost/thread.hpp>
static void do_nothing() {}

int main() {
int thread_count = 0;
while (true) {
thread_count++;
boost::thread t1(boost::bind(&do_nothing));
if (t1.joinable()) {
t1.join();
}
}
}

下面是地址清理程序捕获到使用释放内存后的转储:

=================================================================
==96437==ERROR: AddressSanitizer: heap-use-after-free on address 0x058526f4 at pc 0x000a22cb bp 0xbffff4a8 sp 0xbffff4a4
WRITE of size 4 at 0x058526f4 thread T0
atos(96439,0x100357380) malloc: enabling scribbling to detect mods to free blocks
#0 0xa22ca in boost::detail::atomic_decrement(int _Atomic*) sp_counted_base_clang.hpp:36
#1 0xa21be in boost::detail::sp_counted_base::release() sp_counted_base_clang.hpp:115
#2 0xa2157 in boost::detail::shared_count::~shared_count() shared_count.hpp:473
#3 0xa115b in boost::detail::shared_count::~shared_count() shared_count.hpp:472
#4 0x1ae8e63 in boost::thread::join_noexcept() shared_ptr.hpp:779
#5 0x989a8c in boost::thread::join() thread.hpp:766
#6 0x989366 in main main.cpp

0x058526f4 is located 4 bytes inside of 16-byte region [0x058526f0,0x05852700)
freed by thread T0 here:
#0 0x35ca20d in wrap__ZdlPv (libclang_rt.asan_osx_dynamic.dylib:i386+0x6520d)
#1 0x9ab89c in boost::detail::sp_counted_impl_p<boost::detail::thread_data<boost::_bi::bind_t<void, void (*)(), boost::_bi::list0> > >::~sp_counted_impl_p() sp_counted_impl.hpp:53
#2 0xa1dd1 in boost::detail::sp_counted_base::destroy() sp_counted_base_clang.hpp:97
#3 0xa23e7 in boost::detail::sp_counted_base::weak_release() sp_counted_base_clang.hpp:131
#4 0xa2262 in boost::detail::sp_counted_base::release() sp_counted_base_clang.hpp:118
#5 0xa2157 in boost::detail::shared_count::~shared_count() shared_count.hpp:473
#6 0xa115b in boost::detail::shared_count::~shared_count() shared_count.hpp:472
#7 0x1ae8e56 in boost::thread::join_noexcept() shared_ptr.hpp:779
#8 0x989a8c in boost::thread::join() thread.hpp:766
#9 0x989366 in main main.cpp

previously allocated by thread T0 here:
#0 0x35c9c0d in wrap__Znwm (libclang_rt.asan_osx_dynamic.dylib:i386+0x64c0d)
#1 0x9ab357 in boost::detail::shared_count::shared_count<boost::detail::thread_data<boost::_bi::bind_t<void, void (*)(), boost::_bi::list0> > >(boost::detail::thread_data<boost::_bi::bind_t<void, void (*)(), boost::_bi::list0> >*) shared_count.hpp:137
#2 0x9ab214 in boost::detail::shared_count::shared_count<boost::detail::thread_data<boost::_bi::bind_t<void, void (*)(), boost::_bi::list0> > >(boost::detail::thread_data<boost::_bi::bind_t<void, void (*)(), boost::_bi::list0> >*) shared_count.hpp:132
#3 0x9aaf88 in void boost::detail::sp_pointer_construct<boost::detail::thread_data_base, boost::detail::thread_data<boost::_bi::bind_t<void, void (*)(), boost::_bi::list0> > >(boost::shared_ptr<boost::detail::thread_data_base>*, boost::detail::thread_data<boost::_bi::bind_t<void, void (*)(), boost::_bi::list0> >*, boost::detail::shared_count&) shared_ptr.hpp:284
#4 0x9aae3b in boost::shared_ptr<boost::detail::thread_data_base>::shared_ptr<boost::detail::thread_data<boost::_bi::bind_t<void, void (*)(), boost::_bi::list0> > >(boost::detail::thread_data<boost::_bi::bind_t<void, void (*)(), boost::_bi::list0> >*) shared_ptr.hpp:362
#5 0x99c804 in boost::shared_ptr<boost::detail::thread_data_base>::shared_ptr<boost::detail::thread_data<boost::_bi::bind_t<void, void (*)(), boost::_bi::list0> > >(boost::detail::thread_data<boost::_bi::bind_t<void, void (*)(), boost::_bi::list0> >*) shared_ptr.hpp:361
#6 0x99c407 in boost::shared_ptr<boost::detail::thread_data_base> boost::thread::make_thread_info<boost::_bi::bind_t<void, void (*)(), boost::_bi::list0> >(boost::_bi::bind_t<void, void (*)(), boost::_bi::list0>, boost::disable_if_c<is_same<boost::decay<boost::_bi::bind_t<void, void (*)(), boost::_bi::list0> >::type, boost::thread>::value, boost::thread::dummy*>::type) thread.hpp:229
#7 0x99c120 in boost::thread::thread<boost::_bi::bind_t<void, void (*)(), boost::_bi::list0> >(boost::_bi::bind_t<void, void (*)(), boost::_bi::list0>, boost::disable_if_c<boost::thread_detail::is_rv<boost::_bi::bind_t<void, void (*)(), boost::_bi::list0> >::value, boost::thread::dummy*>::type) thread.hpp:299
#8 0x989826 in boost::thread::thread<boost::_bi::bind_t<void, void (*)(), boost::_bi::list0> >(boost::_bi::bind_t<void, void (*)(), boost::_bi::list0>, boost::disable_if_c<boost::thread_detail::is_rv<boost::_bi::bind_t<void, void (*)(), boost::_bi::list0> >::value, boost::thread::dummy*>::type) thread.hpp:300
#9 0x989366 in main main.cpp

SUMMARY: AddressSanitizer: heap-use-after-free sp_counted_base_clang.hpp:36 in boost::detail::atomic_decrement(int _Atomic*)
Shadow bytes around the buggy address:
0x20b0a480: fa fa fd fd fa fa fd fd fa fa fd fd fa fa fd fd
0x20b0a490: fa fa fd fd fa fa fd fd fa fa fd fd fa fa fd fd
0x20b0a4a0: fa fa fd fd fa fa fd fd fa fa fd fd fa fa fd fd
0x20b0a4b0: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa
0x20b0a4c0: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa
=>0x20b0a4d0: fa fa fa fa fa fa fa fa fa fa fa fa fa fa[fd]fd
0x20b0a4e0: fa fa fd fd fa fa fd fd fa fa fd fd fa fa fd fd
0x20b0a4f0: fa fa fd fd fa fa fd fd fa fa fd fd fa fa fd fd
0x20b0a500: fa fa fd fd fa fa fd fd fa fa fd fd fa fa fd fd
0x20b0a510: fa fa fd fd fa fa fd fd fa fa fd fd fa fa fd fd
0x20b0a520: fa fa fd fd fa fa fd fd fa fa fd fd fa fa fd fd
Shadow byte legend (one shadow byte represents 8 application bytes):
Addressable: 00
Partially addressable: 01 02 03 04 05 06 07
Heap left redzone: fa
Freed heap region: fd
Stack left redzone: f1
Stack mid redzone: f2
Stack right redzone: f3
Stack after return: f5
Stack use after scope: f8
Global redzone: f9
Global init order: f6
Poisoned by user: f7
Container overflow: fc
Array cookie: ac
Intra object redzone: bb
ASan internal: fe
Left alloca redzone: ca
Right alloca redzone: cb

=================================================================
==96437==ERROR: AddressSanitizer: heap-use-after-free on address 0x058526f4 at pc 0x000a22cb bp 0xbffff4a8 sp 0xbffff4a4
WRITE of size 4 at 0x058526f4 thread T0
#0 0xa22ca in boost::detail::atomic_decrement(int _Atomic*) sp_counted_base_clang.hpp:36
#1 0xa21be in boost::detail::sp_counted_base::release() sp_counted_base_clang.hpp:115
#2 0xa2157 in boost::detail::shared_count::~shared_count() shared_count.hpp:473
#3 0xa115b in boost::detail::shared_count::~shared_count() shared_count.hpp:472
#4 0x1ae8e63 in boost::thread::join_noexcept() shared_ptr.hpp:779
#5 0x989a8c in boost::thread::join() thread.hpp:766
#6 0x989366 in main main.cpp

0x058526f4 is located 4 bytes inside of 16-byte region [0x058526f0,0x05852700)
freed by thread T0 here:
#0 0x35ca20d in wrap__ZdlPv (libclang_rt.asan_osx_dynamic.dylib:i386+0x6520d)
#1 0x9ab89c in boost::detail::sp_counted_impl_p<boost::detail::thread_data<boost::_bi::bind_t<void, void (*)(), boost::_bi::list0> > >::~sp_counted_impl_p() sp_counted_impl.hpp:53
#2 0xa1dd1 in boost::detail::sp_counted_base::destroy() sp_counted_base_clang.hpp:97
#3 0xa23e7 in boost::detail::sp_counted_base::weak_release() sp_counted_base_clang.hpp:131
#4 0xa2262 in boost::detail::sp_counted_base::release() sp_counted_base_clang.hpp:118
#5 0xa2157 in boost::detail::shared_count::~shared_count() shared_count.hpp:473
#6 0xa115b in boost::detail::shared_count::~shared_count() shared_count.hpp:472
#7 0x1ae8e56 in boost::thread::join_noexcept() shared_ptr.hpp:779
#8 0x989a8c in boost::thread::join() thread.hpp:766
#9 0x989366 in main main.cpp

previously allocated by thread T0 here:
#0 0x35c9c0d in wrap__Znwm (libclang_rt.asan_osx_dynamic.dylib:i386+0x64c0d)
#1 0x9ab357 in boost::detail::shared_count::shared_count<boost::detail::thread_data<boost::_bi::bind_t<void, void (*)(), boost::_bi::list0> > >(boost::detail::thread_data<boost::_bi::bind_t<void, void (*)(), boost::_bi::list0> >*) shared_count.hpp:137
#2 0x9ab214 in boost::detail::shared_count::shared_count<boost::detail::thread_data<boost::_bi::bind_t<void, void (*)(), boost::_bi::list0> > >(boost::detail::thread_data<boost::_bi::bind_t<void, void (*)(), boost::_bi::list0> >*) shared_count.hpp:132
#3 0x9aaf88 in void boost::detail::sp_pointer_construct<boost::detail::thread_data_base, boost::detail::thread_data<boost::_bi::bind_t<void, void (*)(), boost::_bi::list0> > >(boost::shared_ptr<boost::detail::thread_data_base>*, boost::detail::thread_data<boost::_bi::bind_t<void, void (*)(), boost::_bi::list0> >*, boost::detail::shared_count&) shared_ptr.hpp:284
#4 0x9aae3b in boost::shared_ptr<boost::detail::thread_data_base>::shared_ptr<boost::detail::thread_data<boost::_bi::bind_t<void, void (*)(), boost::_bi::list0> > >(boost::detail::thread_data<boost::_bi::bind_t<void, void (*)(), boost::_bi::list0> >*) shared_ptr.hpp:362
#5 0x99c804 in boost::shared_ptr<boost::detail::thread_data_base>::shared_ptr<boost::detail::thread_data<boost::_bi::bind_t<void, void (*)(), boost::_bi::list0> > >(boost::detail::thread_data<boost::_bi::bind_t<void, void (*)(), boost::_bi::list0> >*) shared_ptr.hpp:361
#6 0x99c407 in boost::shared_ptr<boost::detail::thread_data_base> boost::thread::make_thread_info<boost::_bi::bind_t<void, void (*)(), boost::_bi::list0> >(boost::_bi::bind_t<void, void (*)(), boost::_bi::list0>, boost::disable_if_c<is_same<boost::decay<boost::_bi::bind_t<void, void (*)(), boost::_bi::list0> >::type, boost::thread>::value, boost::thread::dummy*>::type) thread.hpp:229
#7 0x99c120 in boost::thread::thread<boost::_bi::bind_t<void, void (*)(), boost::_bi::list0> >(boost::_bi::bind_t<void, void (*)(), boost::_bi::list0>, boost::disable_if_c<boost::thread_detail::is_rv<boost::_bi::bind_t<void, void (*)(), boost::_bi::list0> >::value, boost::thread::dummy*>::type) thread.hpp:299
#8 0x989826 in boost::thread::thread<boost::_bi::bind_t<void, void (*)(), boost::_bi::list0> >(boost::_bi::bind_t<void, void (*)(), boost::_bi::list0>, boost::disable_if_c<boost::thread_detail::is_rv<boost::_bi::bind_t<void, void (*)(), boost::_bi::list0> >::value, boost::thread::dummy*>::type) thread.hpp:300
#9 0x989366 in main main.cpp

SUMMARY: AddressSanitizer: heap-use-after-free sp_counted_base_clang.hpp:36 in boost::detail::atomic_decrement(int _Atomic*)
Shadow bytes around the buggy address:
0x20b0a480: fa fa fd fd fa fa fd fd fa fa fd fd fa fa fd fd
0x20b0a490: fa fa fd fd fa fa fd fd fa fa fd fd fa fa fd fd
0x20b0a4a0: fa fa fd fd fa fa fd fd fa fa fd fd fa fa fd fd
0x20b0a4b0: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa
0x20b0a4c0: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa
=>0x20b0a4d0: fa fa fa fa fa fa fa fa fa fa fa fa fa fa[fd]fd
0x20b0a4e0: fa fa fd fd fa fa fd fd fa fa fd fd fa fa fd fd
0x20b0a4f0: fa fa fd fd fa fa fd fd fa fa fd fd fa fa fd fd
0x20b0a500: fa fa fd fd fa fa fd fd fa fa fd fd fa fa fd fd
0x20b0a510: fa fa fd fd fa fa fd fd fa fa fd fd fa fa fd fd
0x20b0a520: fa fa fd fd fa fa fd fd fa fa fd fd fa fa fd fd
Shadow byte legend (one shadow byte represents 8 application bytes):
Addressable: 00
Partially addressable: 01 02 03 04 05 06 07
Heap left redzone: fa
Freed heap region: fd
Stack left redzone: f1
Stack mid redzone: f2
Stack right redzone: f3
Stack after return: f5
Stack use after scope: f8
Global redzone: f9
Global init order: f6
Poisoned by user: f7
Container overflow: fc
Array cookie: ac
Intra object redzone: bb
ASan internal: fe
Left alloca redzone: ca
Right alloca redzone: cb

构建环境:在 macOS LLVM 9.0 下构建的 Boost 1.63 和 libc++(使用相同构建的主机应用程序)。主机正在运行调试版本,因此没有编译器优化。 Boost 可能是在优化的基础上构建的,但我必须研究一下。

有人知道我应该去哪里找吗? TBH,我不确定 join_noexcept() 在 shared_ptr 准确重置的情况下做了什么——为什么有必要?我不认为这是一个 Boost 错误,但我不知道该去哪里找。主机应用程序当然可能会踩到某些东西,但我已经对此进行了广泛的调查,但还没有发现任何东西。当 join() 发生时,崩溃始终发生。

在我创建上面的最小案例示例之前的原始帖子: 在等待通信线程通过 join() 关闭时,我很少看到崩溃。崩溃很少发生,但我可以在打开/关闭通信线程数小时后通过一些压力测试重现它,大约每秒 3 次。

我在启用调试内存选项(僵尸 block 等)的情况下捕获了崩溃,它显示在:

thread::join_noexcept()
{
...
if(thread_info==local_thread_info)
{
thread_info.reset();
}
...
}

条件为 True,因此执行 reset() 导致 thread_data 被销毁,堆栈如下所示:

detail::sp_counted_impl_p<boost::detail::thread_data<CThreadAdapter> >::~sp_counted_impl_p() at sp_counted_impl.hpp:53
detail::sp_counted_base::destroy() at sp_counted_base_clang.hpp:97
detail::sp_counted_base::weak_release() at sp_counted_base_clang.hpp:131
detail::sp_counted_base::release() at sp_counted_base_clang.hpp:118
detail::shared_count::~shared_count() at shared_count.hpp:473
detail::shared_count::~shared_count() at shared_count.hpp:472
shared_ptr<boost::detail::thread_data_base>::~shared_ptr() [inlined] at shared_ptr.hpp:779
shared_ptr<boost::detail::thread_data_base>::~shared_ptr() [inlined] at shared_ptr.hpp:779
shared_ptr<boost::detail::thread_data_base>::reset() [inlined] at shared_ptr.hpp:667
thread::join_noexcept() at thread.cpp:343
thread::join() at thread.hpp:766

(上面不是崩溃,只是内存被释放的地方,稍后会引用)

崩溃然后在同一个 join_noexcept() 调用中发生,当它完成并销毁其局部变量时。它似乎试图访问释放的 thread_data(我认为):

detail::atomic_decrement(int _Atomic*) at sp_counted_base_clang.hpp:36
detail::sp_counted_base::release() at sp_counted_base_clang.hpp:115
detail::shared_count::~shared_count() at shared_count.hpp:473
detail::shared_count::~shared_count() at shared_count.hpp:472
shared_ptr<boost::detail::thread_data_base>::~shared_ptr() [inlined] at shared_ptr.hpp:779
shared_ptr<boost::detail::thread_data_base>::~shared_ptr() [inlined] at shared_ptr.hpp:779
thread::join_noexcept() at thread.cpp:351
thread::join() at thread.hpp:766

最佳答案

添加的独立代码值得一千字。

很明显,错误不在驱动程序代码中,boost 不太可能受到指责。这样就剩下了

  • 资源泄露
  • 由于 ODR/ABI 问题导致的未定义行为

您的信息表明您在使用兼容的编译器、库和标志构建库和测试程序时格外小心。这种排除了 ABI/ODR 问题。

这让我想到了资源泄漏。在我看来,如果围绕“joinable()”存在任何竞争,有条件地加入可能会导致不加入线程。我不认为是这种情况,但在您简单的独立示例中,您可以看到以下其中一项是否消除了崩溃:

  • 移除条件:

    #include <boost/thread.hpp>
    #include <iostream>
    static void do_nothing() {}

    int main() {
    uintmax_t thread_count = 0;
    while (++thread_count) {
    boost::thread(do_nothing).join();
    }
    std::cout << "Done\n";
    }
  • 避免竞争(通过延迟 do_nothing 退出,或使用同步原语来指示线程结束)。公平地说,这在我看来是一种“解决方法”, 表明存在库错误。

关于c++ - boost::thread::join() 崩溃试图引用销毁的 thread_info,我们在Stack Overflow上找到一个类似的问题: https://stackoverflow.com/questions/51438287/

25 4 0
Copyright 2021 - 2024 cfsdn All Rights Reserved 蜀ICP备2022000587号
广告合作:1813099741@qq.com 6ren.com