Arena-escaping values leak 17,800 bytes at exit (xcalloc/xstrdup in arena.c) — pre-existing, and no suite program exercises the shape
维护者通常 1 天内回复
还没有人认领这个 Issue。
评估
调研方向
Start with src/arena.c, especially xcalloc at line 58 and xstrdup at line 79, then run the preserved arena-escape reproduction with ASAN_OPTIONS=detect_leaks=1. Add an equivalent escape-shape program to the suite corpus before addressing the ownership leak. Done means the corpus program passes the ordinary ASan lane without the reported 17,800-byte leak.
由索引模型根据 Issue 内容生成。
描述
A program that lets arena-allocated values escape their arena leaks 17,800 bytes at exit under ASan, and the leak is in src/arena.c's own allocators.
Reproduction
The program is a blind critic's arena-escape probe from the #1183 review (a loop that builds strings inside a scope and returns them outward). Any equivalent shape should do; the exact file is preserved at /tmp/strcrit-r4b/c2_21_arena_escape.eigs.
ASAN_OPTIONS=detect_leaks=1 build/asan/eigenscript c2_21_arena_escape.eigs
Direct leak of 14400 byte(s) in 200 object(s) allocated from:
#1 xcalloc src/arena.c:58
Indirect leak of 3400 byte(s) in 200 object(s) allocated from:
#1 xstrdup src/arena.c:79
SUMMARY: AddressSanitizer: 17800 byte(s) leaked in 400 allocation(s).
Exit code 1.
It is PRE-EXISTING — measured, not assumed
Surfaced while reviewing the string cached-length branch (#1183), so the obvious suspicion was that the change caused it. It does not. Both trees were built ASan from source and run on the identical program:
| tree | result |
|---|---|
main @ adf529c, no change |
17800 byte(s) leaked in 400 allocation(s) |
str-cached-length, with the change |
17800 byte(s) leaked in 400 allocation(s) |
Byte-identical, allocation-count identical. The branch is not implicated, and it is filed here rather than counted against it.
Why the suite does not see it
The full ASan suite is green at 5280/5280 with a leak tally of 0, on the same build that leaks here. So this shape is absent from the suite corpus — a green suite is evidence about the corpus, not about the runtime. The arena's escape path is the part with no program exercising it.
That is the more useful half of this report: lib/ and the test corpus contain no program that lets a meaningful number of arena values escape, so the arena/heap ownership seam has no standing witness. Related prior art in this area: the arena-vs-heap reference asymmetry class, where an arena list holding heap items is the failure mode.
Suggested next step
Add the escape shape to the suite corpus first, so the leak is visible to the ordinary ASan lane, then fix. A fix without a corpus program that fails beforehand is unverifiable by the repo's own gates.
- 主要语言
- C
- 星标
- 3
- 派生
- 7
- 平均合并
- 4 小时 7 分钟
- 30 天内合并 PR
- 112
环境准备
在浏览器里用你自己的 GitHub 账号启动这个项目的开发容器。
- 提供 Dockerfile 或 Docker Compose 文件
- 有 Pull Request 模板
- 阅读贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
InauguralSystems/EigenScript 的其他 Issue
-
area:embed kind:silent-wrong
难度 2/5 1-3 小时 新手友好度 78/100
InauguralSystems/EigenScript#1387 ·
维护者通常 1 天内回复
-
area:stdlib kind:silent-wrong
难度 2/5 1-3 小时 新手友好度 86/100
InauguralSystems/EigenScript#1378 ·
维护者通常 1 天内回复
-
area:gates kind:gate-defect
难度 2/5 1-3 小时 新手友好度 78/100
InauguralSystems/EigenScript#1374 ·
维护者通常 1 天内回复
-
Error carets pad multi-byte UTF-8 byte-for-byte, so the ^ lands right of the token on a terminal未关闭area:lint-tooling kind:silent-wrong
难度 2/5 1-3 小时 新手友好度 84/100
InauguralSystems/EigenScript#1373 ·
维护者通常 1 天内回复
-
area:gates kind:docs-drift
难度 1/5 1 小时以内 新手友好度 88/100
InauguralSystems/EigenScript#1372 ·
维护者通常 1 天内回复
查看 InauguralSystems/EigenScript 的全部 Issue
相似的 Issue
-
难度 2/5 1-3 小时 新手友好度 90/100
BasedHardware/omi#19711 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 85/100
microsoft/ebpf-for-windows#5604 ·
维护者通常 3 天内回复
-
难度 2/5 1-3 小时 新手友好度 68/100
trezor/trezor-firmware#7985 ·
维护者通常 2 天内回复
-
难度 2/5 1-3 小时 新手友好度 84/100
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 70/100
维护者通常 2 天内回复