Overview
| Artifact ID: | d8976b93f918f8a49431c4f3ea75c528d9a271fca5263d520c045cc1a983f291 |
|---|---|
| Ticket: | 43573999cae70c8db2b7a234dd4ba0da63adb37a |
| Date: | 2022-09-27 20:20:58 |
| User: | fvogel |
| Artifact Attached: | 7c58c7da228b944b47d6dbeb8088f08c7b2e6f90db3b93d00417564b46684e24 |
| Filename: | Address sanitizer output.txt |
| Description: | Address sanitizer output on macOS Catalina, for the trimmed down script. |
Content:
==18549==ERROR: AddressSanitizer: heap-use-after-free on address 0x61000009e680 at pc 0x000102f77db8 bp 0x7ffeeccc6790 sp 0x7ffeeccc6788
READ of size 4 at 0x61000009e680 thread T0
#0 0x102f77db7 in MatchPatterns tkBind.c:2824
#1 0x102f737bf in Tk_BindEvent tkBind.c:2385
#2 0x102fa91d3 in TkBindEventProc tkCmds.c:319
#3 0x102fe4669 in Tk_HandleEvent tkEvent.c:1292
#4 0x102fe7a56 in WindowEventProc tkEvent.c:1723
#5 0x103bcfbe9 in Tcl_ServiceEvent tclNotify.c:670
#6 0x103bcff8b in Tcl_DoOneEvent tclNotify.c:903
#7 0x102fe98dd in Tk_MainLoop tkEvent.c:2109
#8 0x103054249 in Tk_MainEx tkMain.c:376
#9 0x102f3dbea in main tkAppInit.c:93
#10 0x7fff7302dcc8 in start+0x0 (libdyld.dylib:x86_64+0x1acc8)
0x61000009e680 is located 64 bytes inside of 192-byte region [0x61000009e640,0x61000009e700)
freed by thread T0 here:
#0 0x103d452c6 in wrap_free+0xa6 (libclang_rt.asan_osx_dynamic.dylib:x86_64h+0x492c6)
#1 0x103a837a4 in TclpFree tclAlloc.c:722
#2 0x103a9f1fb in Tcl_DbCkfree tclCkalloc.c:653
#3 0x102f69590 in FreePatSeq tkBind.c:901
#4 0x102f6eaa3 in DeletePatSeq tkBind.c:1998
#5 0x102f6dbfe in Tk_DeleteBinding tkBind.c:1764
#6 0x102fa7f7c in Tk_BindObjCmd tkCmds.c:212
#7 0x103a934ec in Dispatch tclBasic.c:4467
#8 0x103a8f804 in TclNRRunCallbacks tclBasic.c:4503
#9 0x103a8f593 in Tcl_EvalObjv tclBasic.c:4226
#10 0x103a90de8 in TclEvalEx tclBasic.c:5372
#11 0x103a90185 in Tcl_EvalEx tclBasic.c:5037
#12 0x102f76054 in Tk_BindEvent tkBind.c:2602
#13 0x102fa91d3 in TkBindEventProc tkCmds.c:319
#14 0x102fe4669 in Tk_HandleEvent tkEvent.c:1292
#15 0x102fe7a56 in WindowEventProc tkEvent.c:1723
#16 0x103bcfbe9 in Tcl_ServiceEvent tclNotify.c:670
#17 0x103bd00fa in Tcl_DoOneEvent tclNotify.c:967
#18 0x102fe98dd in Tk_MainLoop tkEvent.c:2109
#19 0x103054249 in Tk_MainEx tkMain.c:376
#20 0x102f3dbea in main tkAppInit.c:93
#21 0x7fff7302dcc8 in start+0x0 (libdyld.dylib:x86_64+0x1acc8)
previously allocated by thread T0 here:
#0 0x103d4517d in wrap_malloc+0x9d (libclang_rt.asan_osx_dynamic.dylib:x86_64h+0x4917d)
#1 0x103a83784 in TclpAlloc tclAlloc.c:699
#2 0x103a9e96f in Tcl_DbCkalloc tclCkalloc.c:409
#3 0x103a9f291 in Tcl_DbCkrealloc tclCkalloc.c:695
#4 0x102f6b4ae in FindSequence tkBind.c:4652
#5 0x102f6a3d7 in Tk_CreateBinding tkBind.c:1641
#6 0x102fa80bf in Tk_BindObjCmd tkCmds.c:225
#7 0x103a934ec in Dispatch tclBasic.c:4467
#8 0x103a8f804 in TclNRRunCallbacks tclBasic.c:4503
#9 0x103a91c7f in TclEvalObjEx tclBasic.c:6068
#10 0x103a8efc9 in Tcl_EvalObjEx tclBasic.c:6049
#11 0x103c02e76 in AfterProc tclTimer.c:1199
#12 0x103c01f6d in TclServiceIdle tclTimer.c:751
#13 0x103bd0128 in Tcl_DoOneEvent tclNotify.c:980
#14 0x102fe98dd in Tk_MainLoop tkEvent.c:2109
#15 0x103054249 in Tk_MainEx tkMain.c:376
#16 0x102f3dbea in main tkAppInit.c:93
#17 0x7fff7302dcc8 in start+0x0 (libdyld.dylib:x86_64+0x1acc8)
SUMMARY: AddressSanitizer: heap-use-after-free tkBind.c:2824 in MatchPatterns
Shadow bytes around the buggy address:
0x1c2000013c80: fa fa fa fa fa fa fa fa fd fd fd fd fd fd fd fd
0x1c2000013c90: fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd
0x1c2000013ca0: fa fa fa fa fa fa fa fa fd fd fd fd fd fd fd fd
0x1c2000013cb0: fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd
0x1c2000013cc0: fa fa fa fa fa fa fa fa fd fd fd fd fd fd fd fd
=>0x1c2000013cd0:[fd]fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd
0x1c2000013ce0: fa fa fa fa fa fa fa fa fd fd fd fd fd fd fd fd
0x1c2000013cf0: fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd
0x1c2000013d00: fa fa fa fa fa fa fa fa 00 00 00 00 00 00 00 00
0x1c2000013d10: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 fa
0x1c2000013d20: fa fa fa fa fa fa fa fa fd fd fd fd fd fd fd fd
Shadow byte legend (one shadow byte represents 8 application bytes):
Addressable: 00
Partially addressable: 01 02 03 04 05 06 07
Heap left redzone: fa
Freed heap region: fd
Stack left redzone: f1
Stack mid redzone: f2
Stack right redzone: f3
Stack after return: f5
Stack use after scope: f8
Global redzone: f9
Global init order: f6
Poisoned by user: f7
Container overflow: fc
Array cookie: ac
Intra object redzone: bb
ASan internal: fe
Left alloca redzone: ca
Right alloca redzone: cb
Shadow gap: cc
==18549==ABORTING
Abort trap: 6
