Arena-escaping values leak 17,800 bytes at exit (xcalloc/xstrdup in arena.c) — pre-existing, and no suite program exercises the shape
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 52/100
Research direction
Start with src/arena.c, especially xcalloc at line 58 and xstrdup at line 79, then run the preserved arena-escape reproduction with ASAN_OPTIONS=detect_leaks=1. Add an equivalent escape-shape program to the suite corpus before addressing the ownership leak. Done means the corpus program passes the ordinary ASan lane without the reported 17,800-byte leak.
Written by the indexing model from the issue text.
Description
A program that lets arena-allocated values escape their arena leaks 17,800 bytes at exit under ASan, and the leak is in src/arena.c's own allocators.
Reproduction
The program is a blind critic's arena-escape probe from the #1183 review (a loop that builds strings inside a scope and returns them outward). Any equivalent shape should do; the exact file is preserved at /tmp/strcrit-r4b/c2_21_arena_escape.eigs.
ASAN_OPTIONS=detect_leaks=1 build/asan/eigenscript c2_21_arena_escape.eigs
Direct leak of 14400 byte(s) in 200 object(s) allocated from:
#1 xcalloc src/arena.c:58
Indirect leak of 3400 byte(s) in 200 object(s) allocated from:
#1 xstrdup src/arena.c:79
SUMMARY: AddressSanitizer: 17800 byte(s) leaked in 400 allocation(s).
Exit code 1.
It is PRE-EXISTING — measured, not assumed
Surfaced while reviewing the string cached-length branch (#1183), so the obvious suspicion was that the change caused it. It does not. Both trees were built ASan from source and run on the identical program:
| tree | result |
|---|---|
main @ adf529c, no change |
17800 byte(s) leaked in 400 allocation(s) |
str-cached-length, with the change |
17800 byte(s) leaked in 400 allocation(s) |
Byte-identical, allocation-count identical. The branch is not implicated, and it is filed here rather than counted against it.
Why the suite does not see it
The full ASan suite is green at 5280/5280 with a leak tally of 0, on the same build that leaks here. So this shape is absent from the suite corpus — a green suite is evidence about the corpus, not about the runtime. The arena's escape path is the part with no program exercising it.
That is the more useful half of this report: lib/ and the test corpus contain no program that lets a meaningful number of arena values escape, so the arena/heap ownership seam has no standing witness. Related prior art in this area: the arena-vs-heap reference asymmetry class, where an arena list holding heap items is the failure mode.
Suggested next step
Add the escape shape to the suite corpus first, so the leak is visible to the ordinary ASan lane, then fix. A fix without a corpus program that fails beforehand is unverifiable by the repo's own gates.
- Dominant language
- C
- Stars
- 3
- Forks
- 7
- Avg merge
- 4h 15m
- Merged PRs (30d)
- 106
Getting set up
Starts the project's dev container in your browser, under your own GitHub account.
- Ships a Dockerfile or Docker Compose file
- Has a pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from InauguralSystems/EigenScript
-
area:lint-tooling bug
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
InauguralSystems/EigenScript#1340 ·
Maintainers usually reply within 1 day
-
area:stdlib found-by:code-review kind:silent-wrong
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
InauguralSystems/EigenScript#1338 ·
Maintainers usually reply within 1 day
-
area:lint-tooling found-by:critic kind:docs-drift
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
InauguralSystems/EigenScript#1335 ·
Maintainers usually reply within 1 day
-
area:ci found-by:critic kind:gate-defect
Difficulty 2/5 1-3 hours Newbie friendliness 86/100
InauguralSystems/EigenScript#1311 ·
Maintainers usually reply within 1 day
-
enrolment: decide test_gc_runner_controls.py (exempt vs enrol) and whether floors need a ratchetOpenarea:gates found-by:critic kind:decision
Difficulty 2/5 1-3 hours Newbie friendliness 65/100
InauguralSystems/EigenScript#1280 · 1 comment ·
Maintainers usually reply within 1 day
All issues in InauguralSystems/EigenScript
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
ARM-software/sysarch-acs#556 · 1 comment ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
Maintainers usually reply within 1 day
-
bug needs triage
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
netdata/netdata#24062 · 1 comment ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 76/100