Crash on exit: double free or corruption #7
Labels
No labels
amd
avatars
bug
builder
crash
epic
feature
from-viewer
gl-removal
known-limitation
monitoring
parity
perf
platform
rendering
rt
ui
upstream
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
backspace119/Slipstream#7
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Viewer sometimes aborts at shutdown with 'double free or corruption (out)' and hangs while dumping core. Suspected boost::wave/spirit static destructors (LSL preprocessor). Binaries are now archived per launch (~/.cache/alchemy-bins) so the next occurrence can be symbolized.
Symbolized occurrence (2026-09-27, build with GL-B8, SIGSEGV exit 139 at logout). It confirms the suspicion:
object_with_id_base_supplyis Boost.Spirit Classic's grammar/rule ID pool, a function-local staticshared_ptrshared by every grammar instance. The only Spirit/Wave user in the viewer is the LSL preprocessor (fslslpreproc / boost::wave). At exit the pool is released during static destruction after (or while) the objects that reference it are torn down, so its mutex is already gone. That's a static-destruction-order problem, and the same mutex family as the old Ctrl+S deadlock (#8).Fix options:
LLAppViewer::cleanup()has finished (settings saved, logs flushed, threads joined), end the process with_exit(0)/std::quick_exit. It removes this whole class of exit crashes (Boost.Spirit, other third-party statics), and the OS reclaims memory anyway. Needs a check that nothing important runs in static dtors (log file close: flush explicitly first).mainreturns (explicit teardown in LLAppViewer::cleanup), so the ID pool isn't released during static destruction. More surgical, but other library statics can still bite.Recommend (1), with (2) if a problem shows up.