[Simulation.Core] WorkerThread: fix use-after-free crash with ultra-short Task#6116
Open
fredroy wants to merge 2 commits into
Open
[Simulation.Core] WorkerThread: fix use-after-free crash with ultra-short Task#6116fredroy wants to merge 2 commits into
fredroy wants to merge 2 commits into
Conversation
For an ultra-short task, a worker that's still in its doWork poll loop pops the task, runs it (m_task() runs the lambda + counter increment, microseconds), and the framework calls task->operator delete all before the main thread reaches setMainTaskStatus(task->getStatus())
4a40c3f to
d27afdf
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Got this bug while working with a parallelization of a component, with Claude.
After investigation (not so easy even with Claude 😅), it appears that in WorkerThread,
sofa/Sofa/framework/Simulation/Core/src/sofa/simulation/task/WorkerThread.cpp
Lines 198 to 221 in 12e74ee
if a task is so fast that it finished before the line 216, task has been deleted and is garbage. So it crashes (or some random stuff)
To demonstrate the bug, I asked Claude to write a "unit test" which crashes, at least on my computer (macbook pro m3).
I am wondering if the CI (and its slow multi-threading config, if any) will trigger the bug. 🤔
I will push the fix shortly after in this PR, because we cannot merge a crash 😅
EDIT: It does crash on the macOS CI, most certainly because the CI is bare metal and much faster.
[with-all-tests]
By submitting this pull request, I acknowledge that
I have read, understand, and agree SOFA Developer Certificate of Origin (DCO).
Reviewers will merge this pull-request only if