Crash with Geometry Nodes and Bake node #119958

Closed
opened 2024-03-27 12:38:00 +01:00 by Thomas Dinges · 13 comments

System Information
Operating system: Windows-10-10.0.19045-SP0 64 Bits
Graphics card: Radeon RX 5500 XT ATI Technologies Inc. 4.6.0 Core Profile Context 23.12.1.231124

Blender Version
Broken: version: 4.1.0, branch: blender-v4.1-release, commit date: 2024-03-25 20:42, hash: 40a5e739e270
Worked: Never.

Short description of error

  • Open attached blend file.
  • Start animation playback in the timeline.
  • Press "Bake" in the Bake node.
    You can try to Clear and Bake multiple time.

=> Blender crashes

Originally found by @TobiasKummerOvermindStudios

**System Information** Operating system: Windows-10-10.0.19045-SP0 64 Bits Graphics card: Radeon RX 5500 XT ATI Technologies Inc. 4.6.0 Core Profile Context 23.12.1.231124 **Blender Version** Broken: version: 4.1.0, branch: blender-v4.1-release, commit date: 2024-03-25 20:42, hash: `40a5e739e270` Worked: Never. **Short description of error** * Open attached blend file. * Start animation playback in the timeline. * Press "Bake" in the Bake node. You can try to Clear and Bake multiple time. => Blender crashes Originally found by @TobiasKummerOvermindStudios
Iliya Katushenock added this to the 4.1 milestone 2024-03-27 12:41:01 +01:00
Iliya Katushenock added
Interest
Nodes & Physics
and removed
Module
Nodes & Physics
labels 2024-03-27 12:41:05 +01:00
Iliya Katushenock changed title from Crash with Geometry Nodes and Bake node to Regression: Crash with Geometry Nodes and Bake node 2024-03-27 12:41:12 +01:00
Iliya Katushenock removed this from the 4.1 milestone 2024-03-27 13:06:39 +01:00
Iliya Katushenock changed title from Regression: Crash with Geometry Nodes and Bake node to Crash with Geometry Nodes and Bake node 2024-03-27 13:08:53 +01:00
Member

I can't reproduce this here.

I can't reproduce this here.

You need to re-click a lot of time.

You need to re-click a lot of time.
Member

asan nabs this one pretty easily.

Read blend: "k:\BlenderGit\2022_lite_msvc\bin\Debug\Dingtotest.blend"
=================================================================
==26996==ERROR: AddressSanitizer: heap-use-after-free on address 0x11a2ffda3708 at pc 0x7ff6847c771f bp 0x002820ff57f0 sp 0x002820ff57f8
READ of size 8 at 0x11a2ffda3708 thread T33
    #0 0x7ff6847c771e in std::_Ptr_base<blender::SharedCache<blender::Array<int,4,blender::GuardedAllocator> >::CacheData>::_Incref k:\Microsoft Visual Studio\2022\Community\VC\Tools\MSVC\14.39.33519\include\memory:1359
    #1 0x7ff6847a6e12 in std::_Ptr_base<blender::SharedCache<blender::Array<int,4,blender::GuardedAllocator> >::CacheData>::_Copy_construct_from<blender::SharedCache<blender::Array<int,4,blender::GuardedAllocator> >::CacheData> k:\Microsoft Visual Studio\2022\Community\VC\Tools\MSVC\14.39.33519\include\memory:1318
    #2 0x7ff6847be762 in std::shared_ptr<blender::SharedCache<blender::Array<int,4,blender::GuardedAllocator> >::CacheData>::shared_ptr<blender::SharedCache<blender::Array<int,4,blender::GuardedAllocator> >::CacheData> k:\Microsoft Visual Studio\2022\Community\VC\Tools\MSVC\14.39.33519\include\memory:1595
    #3 0x7ff6847c118d in std::shared_ptr<blender::SharedCache<blender::Array<int,4,blender::GuardedAllocator> >::CacheData>::operator= k:\Microsoft Visual Studio\2022\Community\VC\Tools\MSVC\14.39.33519\include\memory:1654
    #4 0x7ff6847c0c0f in blender::SharedCache<blender::Array<int,4,blender::GuardedAllocator> >::operator=+0x1f (k:\BlenderGit\2022_asan_debug_ninja\bin\blender.exe+0x1411c0c0f)
    #5 0x7ff68479d103 in mesh_copy_data K:\BlenderGit\blender\source\blender\blenkernel\intern\mesh.cc:152
    #6 0x7ff68456ddd8 in BKE_id_copy_in_lib K:\BlenderGit\blender\source\blender\blenkernel\intern\lib_id.cc:668
    #7 0x7ff68456d934 in BKE_id_copy_ex K:\BlenderGit\blender\source\blender\blenkernel\intern\lib_id.cc:715
    #8 0x7ff68479139c in BKE_mesh_copy_for_eval K:\BlenderGit\blender\source\blender\blenkernel\intern\mesh.cc:863
    #9 0x7ff6859337ea in mesh_calc_modifiers K:\BlenderGit\blender\source\blender\blenkernel\intern\DerivedMesh.cc:659
    #10 0x7ff6859380e6 in mesh_build_data K:\BlenderGit\blender\source\blender\blenkernel\intern\DerivedMesh.cc:1298
    #11 0x7ff68592ae52 in makeDerivedMesh K:\BlenderGit\blender\source\blender\blenkernel\intern\DerivedMesh.cc:1476
    #12 0x7ff6856f26f4 in BKE_object_handle_data_update K:\BlenderGit\blender\source\blender\blenkernel\intern\object_update.cc:160
    #13 0x7ff6856f098d in BKE_object_eval_uber_data K:\BlenderGit\blender\source\blender\blenkernel\intern\object_update.cc:315
    #14 0x7ff68642a917 in `blender::deg::DepsgraphNodeBuilder::build_object_data_geometry'::`2'::<lambda_1>::operator() K:\BlenderGit\blender\source\blender\depsgraph\intern\builder\deg_builder_nodes.cc:1681
    #15 0x7ff68643d281 in std::invoke<`blender::deg::DepsgraphNodeBuilder::build_object_data_geometry'::`2'::<lambda_1> &,Depsgraph *> k:\Microsoft Visual Studio\2022\Community\VC\Tools\MSVC\14.39.33519\include\type_traits:1739
    #16 0x7ff68642ef0f in std::_Func_impl_no_alloc<`blender::deg::DepsgraphNodeBuilder::build_object_data_geometry'::`2'::<lambda_1>,void,Depsgraph *>::_Do_call k:\Microsoft Visual Studio\2022\Community\VC\Tools\MSVC\14.39.33519\include\functional:905
    #17 0x7ff6863b9570 in std::_Func_class<void,Depsgraph *>::operator() k:\Microsoft Visual Studio\2022\Community\VC\Tools\MSVC\14.39.33519\include\functional:951
    #18 0x7ff6863b689a in blender::deg::`anonymous namespace'::evaluate_node K:\BlenderGit\blender\source\blender\depsgraph\intern\eval\deg_eval.cc:101
    #19 0x7ff6863b60ea in blender::deg::`anonymous namespace'::deg_task_run_func K:\BlenderGit\blender\source\blender\depsgraph\intern\eval\deg_eval.cc:118
    #20 0x7ff685ff59b0 in Task::operator() K:\BlenderGit\blender\source\blender\blenlib\intern\task_pool.cc:166
    #21 0x7ff685ff8545 in tbb::internal::function_task<Task>::execute K:\BlenderGit\blender\lib\windows_x64\tbb\include\tbb\task.h:1059
    #22 0x7ffe90188090 in tbb::spin_rw_mutex_v3::internal_release_writer+0x25f1a (k:\BlenderGit\2022_asan_debug_ninja\bin\blender.shared\tbb_debug.dll+0x180028090)
    #23 0x7ffe90186252 in tbb::spin_rw_mutex_v3::internal_release_writer+0x240dc (k:\BlenderGit\2022_asan_debug_ninja\bin\blender.shared\tbb_debug.dll+0x180026252)
    #24 0x7ffe9016df85 in tbb::spin_rw_mutex_v3::internal_release_writer+0xbe0f (k:\BlenderGit\2022_asan_debug_ninja\bin\blender.shared\tbb_debug.dll+0x18000df85)
    #25 0x7ffe90178a0f in tbb::spin_rw_mutex_v3::internal_release_writer+0x16899 (k:\BlenderGit\2022_asan_debug_ninja\bin\blender.shared\tbb_debug.dll+0x180018a0f)
    #26 0x7ffe9017e779 in tbb::spin_rw_mutex_v3::internal_release_writer+0x1c603 (k:\BlenderGit\2022_asan_debug_ninja\bin\blender.shared\tbb_debug.dll+0x18001e779)
    #27 0x7ffe9017eafa in tbb::spin_rw_mutex_v3::internal_release_writer+0x1c984 (k:\BlenderGit\2022_asan_debug_ninja\bin\blender.shared\tbb_debug.dll+0x18001eafa)
    #28 0x7ffe58df300f in register_onexit_function+0x12f (C:\WINDOWS\SYSTEM32\ucrtbased.dll+0x1800b300f)
    #29 0x7ffe25acebde in __asan::AsanThread::ThreadStart D:\a\_work\1\s\src\vctools\asan\llvm\compiler-rt\lib\asan\asan_thread.cpp:299
    #30 0x7ffeaa3e7343 in BaseThreadInitThunk+0x13 (C:\WINDOWS\System32\KERNEL32.DLL+0x180017343)
    #31 0x7ffeac2026b0 in RtlUserThreadStart+0x20 (C:\WINDOWS\SYSTEM32\ntdll.dll+0x1800526b0)

0x11a2ffda3708 is located 392 bytes inside of 568-byte region [0x11a2ffda3580,0x11a2ffda37b8)
freed by thread T30 here:
    #0 0x7ff691bca6f3 in operator delete D:\a\_work\1\s\src\vctools\asan\llvm\compiler-rt\lib\asan\asan_win_delete_scalar_size_thunk.cpp:41
    #1 0x7ff6847c5f70 in blender::bke::MeshRuntime::`scalar deleting destructor'+0x30 (k:\BlenderGit\2022_asan_debug_ninja\bin\blender.exe+0x1411c5f70)
    #2 0x7ff68479dd3f in mesh_free_data K:\BlenderGit\blender\source\blender\blenkernel\intern\mesh.cc:228
    #3 0x7ff68464557c in BKE_libblock_free_datablock K:\BlenderGit\blender\source\blender\blenkernel\intern\lib_id_delete.cc:76
    #4 0x7ff686346b3b in blender::deg::deg_free_eval_copy_datablock K:\BlenderGit\blender\source\blender\depsgraph\intern\eval\deg_eval_copy_on_write.cc:1018
    #5 0x7ff68634688a in blender::deg::deg_update_eval_copy_datablock K:\BlenderGit\blender\source\blender\depsgraph\intern\eval\deg_eval_copy_on_write.cc:897
    #6 0x7ff686346d99 in blender::deg::deg_create_eval_copy K:\BlenderGit\blender\source\blender\depsgraph\intern\eval\deg_eval_copy_on_write.cc:1033
    #7 0x7ff686426dd1 in `blender::deg::DepsgraphNodeBuilder::add_id_node'::`11'::<lambda_1>::operator() K:\BlenderGit\blender\source\blender\depsgraph\intern\builder\deg_builder_nodes.cc:182
    #8 0x7ff68643daf1 in std::invoke<`blender::deg::DepsgraphNodeBuilder::add_id_node'::`11'::<lambda_1> &,Depsgraph *> k:\Microsoft Visual Studio\2022\Community\VC\Tools\MSVC\14.39.33519\include\type_traits:1739
    #9 0x7ff68642cb1f in std::_Func_impl_no_alloc<`blender::deg::DepsgraphNodeBuilder::add_id_node'::`11'::<lambda_1>,void,Depsgraph *>::_Do_call k:\Microsoft Visual Studio\2022\Community\VC\Tools\MSVC\14.39.33519\include\functional:905
    #10 0x7ff6863b9570 in std::_Func_class<void,Depsgraph *>::operator() k:\Microsoft Visual Studio\2022\Community\VC\Tools\MSVC\14.39.33519\include\functional:951
    #11 0x7ff6863b689a in blender::deg::`anonymous namespace'::evaluate_node K:\BlenderGit\blender\source\blender\depsgraph\intern\eval\deg_eval.cc:101
    #12 0x7ff6863b60ea in blender::deg::`anonymous namespace'::deg_task_run_func K:\BlenderGit\blender\source\blender\depsgraph\intern\eval\deg_eval.cc:118
    #13 0x7ff685ff59b0 in Task::operator() K:\BlenderGit\blender\source\blender\blenlib\intern\task_pool.cc:166
    #14 0x7ff685ff8545 in tbb::internal::function_task<Task>::execute K:\BlenderGit\blender\lib\windows_x64\tbb\include\tbb\task.h:1059
    #15 0x7ffe90188090 in tbb::spin_rw_mutex_v3::internal_release_writer+0x25f1a (k:\BlenderGit\2022_asan_debug_ninja\bin\blender.shared\tbb_debug.dll+0x180028090)
    #16 0x7ffe90186252 in tbb::spin_rw_mutex_v3::internal_release_writer+0x240dc (k:\BlenderGit\2022_asan_debug_ninja\bin\blender.shared\tbb_debug.dll+0x180026252)
    #17 0x7ffe9016df85 in tbb::spin_rw_mutex_v3::internal_release_writer+0xbe0f (k:\BlenderGit\2022_asan_debug_ninja\bin\blender.shared\tbb_debug.dll+0x18000df85)
    #18 0x7ffe90178a0f in tbb::spin_rw_mutex_v3::internal_release_writer+0x16899 (k:\BlenderGit\2022_asan_debug_ninja\bin\blender.shared\tbb_debug.dll+0x180018a0f)
    #19 0x7ffe9017e779 in tbb::spin_rw_mutex_v3::internal_release_writer+0x1c603 (k:\BlenderGit\2022_asan_debug_ninja\bin\blender.shared\tbb_debug.dll+0x18001e779)
    #20 0x7ffe9017eafa in tbb::spin_rw_mutex_v3::internal_release_writer+0x1c984 (k:\BlenderGit\2022_asan_debug_ninja\bin\blender.shared\tbb_debug.dll+0x18001eafa)
    #21 0x7ffe58df300f in register_onexit_function+0x12f (C:\WINDOWS\SYSTEM32\ucrtbased.dll+0x1800b300f)
    #22 0x7ffe25acebde in __asan::AsanThread::ThreadStart D:\a\_work\1\s\src\vctools\asan\llvm\compiler-rt\lib\asan\asan_thread.cpp:299
    #23 0x7ffeaa3e7343 in BaseThreadInitThunk+0x13 (C:\WINDOWS\System32\KERNEL32.DLL+0x180017343)
    #24 0x7ffeac2026b0 in RtlUserThreadStart+0x20 (C:\WINDOWS\SYSTEM32\ntdll.dll+0x1800526b0)

previously allocated by thread T28 here:
    #0 0x7ff691bca665 in operator new D:\a\_work\1\s\src\vctools\asan\llvm\compiler-rt\lib\asan\asan_win_new_scalar_thunk.cpp:40
    #1 0x7ff68479c640 in mesh_copy_data K:\BlenderGit\blender\source\blender\blenkernel\intern\mesh.cc:113
    #2 0x7ff68456ddd8 in BKE_id_copy_in_lib K:\BlenderGit\blender\source\blender\blenkernel\intern\lib_id.cc:668
    #3 0x7ff68456d934 in BKE_id_copy_ex K:\BlenderGit\blender\source\blender\blenkernel\intern\lib_id.cc:715
    #4 0x7ff68634963c in blender::deg::`anonymous namespace'::id_copy_inplace_no_main K:\BlenderGit\blender\source\blender\depsgraph\intern\eval\deg_eval_copy_on_write.cc:287
    #5 0x7ff68634cad5 in blender::deg::`anonymous namespace'::deg_expand_eval_copy_datablock K:\BlenderGit\blender\source\blender\depsgraph\intern\eval\deg_eval_copy_on_write.cc:822
    #6 0x7ff68634689f in blender::deg::deg_update_eval_copy_datablock K:\BlenderGit\blender\source\blender\depsgraph\intern\eval\deg_eval_copy_on_write.cc:898
    #7 0x7ff686346d99 in blender::deg::deg_create_eval_copy K:\BlenderGit\blender\source\blender\depsgraph\intern\eval\deg_eval_copy_on_write.cc:1033
    #8 0x7ff686426dd1 in `blender::deg::DepsgraphNodeBuilder::add_id_node'::`11'::<lambda_1>::operator() K:\BlenderGit\blender\source\blender\depsgraph\intern\builder\deg_builder_nodes.cc:182
    #9 0x7ff68643daf1 in std::invoke<`blender::deg::DepsgraphNodeBuilder::add_id_node'::`11'::<lambda_1> &,Depsgraph *> k:\Microsoft Visual Studio\2022\Community\VC\Tools\MSVC\14.39.33519\include\type_traits:1739
    #10 0x7ff68642cb1f in std::_Func_impl_no_alloc<`blender::deg::DepsgraphNodeBuilder::add_id_node'::`11'::<lambda_1>,void,Depsgraph *>::_Do_call k:\Microsoft Visual Studio\2022\Community\VC\Tools\MSVC\14.39.33519\include\functional:905
    #11 0x7ff6863b9570 in std::_Func_class<void,Depsgraph *>::operator() k:\Microsoft Visual Studio\2022\Community\VC\Tools\MSVC\14.39.33519\include\functional:951
    #12 0x7ff6863b689a in blender::deg::`anonymous namespace'::evaluate_node K:\BlenderGit\blender\source\blender\depsgraph\intern\eval\deg_eval.cc:101
    #13 0x7ff6863b60ea in blender::deg::`anonymous namespace'::deg_task_run_func K:\BlenderGit\blender\source\blender\depsgraph\intern\eval\deg_eval.cc:118
    #14 0x7ff685ff59b0 in Task::operator() K:\BlenderGit\blender\source\blender\blenlib\intern\task_pool.cc:166
    #15 0x7ff685ff8545 in tbb::internal::function_task<Task>::execute K:\BlenderGit\blender\lib\windows_x64\tbb\include\tbb\task.h:1059
    #16 0x7ffe90188090 in tbb::spin_rw_mutex_v3::internal_release_writer+0x25f1a (k:\BlenderGit\2022_asan_debug_ninja\bin\blender.shared\tbb_debug.dll+0x180028090)
    #17 0x7ffe90186252 in tbb::spin_rw_mutex_v3::internal_release_writer+0x240dc (k:\BlenderGit\2022_asan_debug_ninja\bin\blender.shared\tbb_debug.dll+0x180026252)
    #18 0x7ffe9016df85 in tbb::spin_rw_mutex_v3::internal_release_writer+0xbe0f (k:\BlenderGit\2022_asan_debug_ninja\bin\blender.shared\tbb_debug.dll+0x18000df85)
    #19 0x7ffe90178a0f in tbb::spin_rw_mutex_v3::internal_release_writer+0x16899 (k:\BlenderGit\2022_asan_debug_ninja\bin\blender.shared\tbb_debug.dll+0x180018a0f)
    #20 0x7ffe9017e779 in tbb::spin_rw_mutex_v3::internal_release_writer+0x1c603 (k:\BlenderGit\2022_asan_debug_ninja\bin\blender.shared\tbb_debug.dll+0x18001e779)
    #21 0x7ffe9017eafa in tbb::spin_rw_mutex_v3::internal_release_writer+0x1c984 (k:\BlenderGit\2022_asan_debug_ninja\bin\blender.shared\tbb_debug.dll+0x18001eafa)
    #22 0x7ffe58df300f in register_onexit_function+0x12f (C:\WINDOWS\SYSTEM32\ucrtbased.dll+0x1800b300f)
    #23 0x7ffe25acebde in __asan::AsanThread::ThreadStart D:\a\_work\1\s\src\vctools\asan\llvm\compiler-rt\lib\asan\asan_thread.cpp:299
    #24 0x7ffeaa3e7343 in BaseThreadInitThunk+0x13 (C:\WINDOWS\System32\KERNEL32.DLL+0x180017343)
    #25 0x7ffeac2026b0 in RtlUserThreadStart+0x20 (C:\WINDOWS\SYSTEM32\ntdll.dll+0x1800526b0)

Thread T33 created by T27 here:
    #0 0x7ffe25ad0897 in __asan_wrap_CreateThread D:\a\_work\1\s\src\vctools\asan\llvm\compiler-rt\lib\asan\asan_win.cpp:163
    #1 0x7ffe58df387e in beginthreadex+0x14e (C:\WINDOWS\SYSTEM32\ucrtbased.dll+0x1800b387e)
    #2 0x7ffe9017ecc8 in tbb::spin_rw_mutex_v3::internal_release_writer+0x1cb52 (k:\BlenderGit\2022_asan_debug_ninja\bin\blender.shared\tbb_debug.dll+0x18001ecc8)
    #3 0x7ffe9017e886 in tbb::spin_rw_mutex_v3::internal_release_writer+0x1c710 (k:\BlenderGit\2022_asan_debug_ninja\bin\blender.shared\tbb_debug.dll+0x18001e886)
    #4 0x7ffe9017eafa in tbb::spin_rw_mutex_v3::internal_release_writer+0x1c984 (k:\BlenderGit\2022_asan_debug_ninja\bin\blender.shared\tbb_debug.dll+0x18001eafa)
    #5 0x7ffe58df300f in register_onexit_function+0x12f (C:\WINDOWS\SYSTEM32\ucrtbased.dll+0x1800b300f)
    #6 0x7ffe25acebde in __asan::AsanThread::ThreadStart D:\a\_work\1\s\src\vctools\asan\llvm\compiler-rt\lib\asan\asan_thread.cpp:299
    #7 0x7ffeaa3e7343 in BaseThreadInitThunk+0x13 (C:\WINDOWS\System32\KERNEL32.DLL+0x180017343)
    #8 0x7ffeac2026b0 in RtlUserThreadStart+0x20 (C:\WINDOWS\SYSTEM32\ntdll.dll+0x1800526b0)

Thread T27 created by T0 here:
    #0 0x7ffe25ad0897 in __asan_wrap_CreateThread D:\a\_work\1\s\src\vctools\asan\llvm\compiler-rt\lib\asan\asan_win.cpp:163
    #1 0x7ffe58df387e in beginthreadex+0x14e (C:\WINDOWS\SYSTEM32\ucrtbased.dll+0x1800b387e)
    #2 0x7ffe9017ecc8 in tbb::spin_rw_mutex_v3::internal_release_writer+0x1cb52 (k:\BlenderGit\2022_asan_debug_ninja\bin\blender.shared\tbb_debug.dll+0x18001ecc8)
    #3 0x7ffe9017734a in tbb::spin_rw_mutex_v3::internal_release_writer+0x151d4 (k:\BlenderGit\2022_asan_debug_ninja\bin\blender.shared\tbb_debug.dll+0x18001734a)
    #4 0x7ff6844ee82d in tbb::interface5::internal::task_base::spawn K:\BlenderGit\blender\lib\windows_x64\tbb\include\tbb\task.h:1125
    #5 0x7ff685ff6f40 in tbb::task_group::run<Task> K:\BlenderGit\blender\lib\windows_x64\tbb\include\tbb\task_group.h:208
    #6 0x7ff685ff5d5a in tbb_task_pool_run K:\BlenderGit\blender\source\blender\blenlib\intern\task_pool.cc:210
    #7 0x7ff685ff6009 in tbb_task_pool_work_and_wait K:\BlenderGit\blender\source\blender\blenlib\intern\task_pool.cc:228
    #8 0x7ff685ff55d4 in BLI_task_pool_work_and_wait K:\BlenderGit\blender\source\blender\blenlib\intern\task_pool.cc:472
    #9 0x7ff6863b82eb in blender::deg::`anonymous namespace'::evaluate_graph_threaded_stage K:\BlenderGit\blender\source\blender\depsgraph\intern\eval\deg_eval.cc:323
    #10 0x7ff6863b5b60 in blender::deg::deg_evaluate_on_refresh K:\BlenderGit\blender\source\blender\depsgraph\intern\eval\deg_eval.cc:428
    #11 0x7ff6862f9dbc in deg_flush_updates_and_refresh K:\BlenderGit\blender\source\blender\depsgraph\intern\depsgraph_eval.cc:47
    #12 0x7ff6862f9c3c in DEG_evaluate_on_refresh K:\BlenderGit\blender\source\blender\depsgraph\intern\depsgraph_eval.cc:80
    #13 0x7ff68459f4cb in scene_graph_update_tagged K:\BlenderGit\blender\source\blender\blenkernel\intern\scene.cc:2532
    #14 0x7ff68458a4cb in BKE_scene_graph_update_tagged K:\BlenderGit\blender\source\blender\blenkernel\intern\scene.cc:2581
    #15 0x7ff68652129b in wm_event_do_depsgraph K:\BlenderGit\blender\source\blender\windowmanager\intern\wm_event_system.cc:478
    #16 0x7ff6864ac566 in wm_file_read_post K:\BlenderGit\blender\source\blender\windowmanager\intern\wm_files.cc:779
    #17 0x7ff6864a520b in wm_homefile_read_post K:\BlenderGit\blender\source\blender\windowmanager\intern\wm_files.cc:1528
    #18 0x7ff68649a363 in WM_init K:\BlenderGit\blender\source\blender\windowmanager\intern\wm_init_exit.cc:356
    #19 0x7ff68370cada in main K:\BlenderGit\blender\source\creator\creator.cc:525
    #20 0x7ff691bcb8a8 in invoke_main D:\a\_work\1\s\src\vctools\crt\vcstartup\src\startup\exe_common.inl:78
    #21 0x7ff691bcb7fd in __scrt_common_main_seh D:\a\_work\1\s\src\vctools\crt\vcstartup\src\startup\exe_common.inl:288
    #22 0x7ff691bcb6bd in __scrt_common_main D:\a\_work\1\s\src\vctools\crt\vcstartup\src\startup\exe_common.inl:330
    #23 0x7ff691bcb91d in mainCRTStartup D:\a\_work\1\s\src\vctools\crt\vcstartup\src\startup\exe_main.cpp:16
    #24 0x7ffeaa3e7343 in BaseThreadInitThunk+0x13 (C:\WINDOWS\System32\KERNEL32.DLL+0x180017343)
    #25 0x7ffeac2026b0 in RtlUserThreadStart+0x20 (C:\WINDOWS\SYSTEM32\ntdll.dll+0x1800526b0)

Thread T30 created by T28 here:
    #0 0x7ffe25ad0897 in __asan_wrap_CreateThread D:\a\_work\1\s\src\vctools\asan\llvm\compiler-rt\lib\asan\asan_win.cpp:163
    #1 0x7ffe58df387e in beginthreadex+0x14e (C:\WINDOWS\SYSTEM32\ucrtbased.dll+0x1800b387e)
    #2 0x7ffe9017ecc8 in tbb::spin_rw_mutex_v3::internal_release_writer+0x1cb52 (k:\BlenderGit\2022_asan_debug_ninja\bin\blender.shared\tbb_debug.dll+0x18001ecc8)
    #3 0x7ffe9017e73e in tbb::spin_rw_mutex_v3::internal_release_writer+0x1c5c8 (k:\BlenderGit\2022_asan_debug_ninja\bin\blender.shared\tbb_debug.dll+0x18001e73e)
    #4 0x7ffe9017eafa in tbb::spin_rw_mutex_v3::internal_release_writer+0x1c984 (k:\BlenderGit\2022_asan_debug_ninja\bin\blender.shared\tbb_debug.dll+0x18001eafa)
    #5 0x7ffe58df300f in register_onexit_function+0x12f (C:\WINDOWS\SYSTEM32\ucrtbased.dll+0x1800b300f)
    #6 0x7ffe25acebde in __asan::AsanThread::ThreadStart D:\a\_work\1\s\src\vctools\asan\llvm\compiler-rt\lib\asan\asan_thread.cpp:299
    #7 0x7ffeaa3e7343 in BaseThreadInitThunk+0x13 (C:\WINDOWS\System32\KERNEL32.DLL+0x180017343)
    #8 0x7ffeac2026b0 in RtlUserThreadStart+0x20 (C:\WINDOWS\SYSTEM32\ntdll.dll+0x1800526b0)

Thread T28 created by T0 here:
    #0 0x7ffe25ad0897 in __asan_wrap_CreateThread D:\a\_work\1\s\src\vctools\asan\llvm\compiler-rt\lib\asan\asan_win.cpp:163
    #1 0x7ffe58df387e in beginthreadex+0x14e (C:\WINDOWS\SYSTEM32\ucrtbased.dll+0x1800b387e)
    #2 0x7ffe9017ecc8 in tbb::spin_rw_mutex_v3::internal_release_writer+0x1cb52 (k:\BlenderGit\2022_asan_debug_ninja\bin\blender.shared\tbb_debug.dll+0x18001ecc8)
    #3 0x7ffe9017734a in tbb::spin_rw_mutex_v3::internal_release_writer+0x151d4 (k:\BlenderGit\2022_asan_debug_ninja\bin\blender.shared\tbb_debug.dll+0x18001734a)
    #4 0x7ff6844ee82d in tbb::interface5::internal::task_base::spawn K:\BlenderGit\blender\lib\windows_x64\tbb\include\tbb\task.h:1125
    #5 0x7ff685ff6f40 in tbb::task_group::run<Task> K:\BlenderGit\blender\lib\windows_x64\tbb\include\tbb\task_group.h:208
    #6 0x7ff685ff5d5a in tbb_task_pool_run K:\BlenderGit\blender\source\blender\blenlib\intern\task_pool.cc:210
    #7 0x7ff685ff6009 in tbb_task_pool_work_and_wait K:\BlenderGit\blender\source\blender\blenlib\intern\task_pool.cc:228
    #8 0x7ff685ff55d4 in BLI_task_pool_work_and_wait K:\BlenderGit\blender\source\blender\blenlib\intern\task_pool.cc:472
    #9 0x7ff6863b82eb in blender::deg::`anonymous namespace'::evaluate_graph_threaded_stage K:\BlenderGit\blender\source\blender\depsgraph\intern\eval\deg_eval.cc:323
    #10 0x7ff6863b5b60 in blender::deg::deg_evaluate_on_refresh K:\BlenderGit\blender\source\blender\depsgraph\intern\eval\deg_eval.cc:428
    #11 0x7ff6862f9dbc in deg_flush_updates_and_refresh K:\BlenderGit\blender\source\blender\depsgraph\intern\depsgraph_eval.cc:47
    #12 0x7ff6862f9c3c in DEG_evaluate_on_refresh K:\BlenderGit\blender\source\blender\depsgraph\intern\depsgraph_eval.cc:80
    #13 0x7ff68459f4cb in scene_graph_update_tagged K:\BlenderGit\blender\source\blender\blenkernel\intern\scene.cc:2532
    #14 0x7ff68458a4cb in BKE_scene_graph_update_tagged K:\BlenderGit\blender\source\blender\blenkernel\intern\scene.cc:2581
    #15 0x7ff68652129b in wm_event_do_depsgraph K:\BlenderGit\blender\source\blender\windowmanager\intern\wm_event_system.cc:478
    #16 0x7ff6864ac566 in wm_file_read_post K:\BlenderGit\blender\source\blender\windowmanager\intern\wm_files.cc:779
    #17 0x7ff6864a520b in wm_homefile_read_post K:\BlenderGit\blender\source\blender\windowmanager\intern\wm_files.cc:1528
    #18 0x7ff68649a363 in WM_init K:\BlenderGit\blender\source\blender\windowmanager\intern\wm_init_exit.cc:356
    #19 0x7ff68370cada in main K:\BlenderGit\blender\source\creator\creator.cc:525
    #20 0x7ff691bcb8a8 in invoke_main D:\a\_work\1\s\src\vctools\crt\vcstartup\src\startup\exe_common.inl:78
    #21 0x7ff691bcb7fd in __scrt_common_main_seh D:\a\_work\1\s\src\vctools\crt\vcstartup\src\startup\exe_common.inl:288
    #22 0x7ff691bcb6bd in __scrt_common_main D:\a\_work\1\s\src\vctools\crt\vcstartup\src\startup\exe_common.inl:330
    #23 0x7ff691bcb91d in mainCRTStartup D:\a\_work\1\s\src\vctools\crt\vcstartup\src\startup\exe_main.cpp:16
    #24 0x7ffeaa3e7343 in BaseThreadInitThunk+0x13 (C:\WINDOWS\System32\KERNEL32.DLL+0x180017343)
    #25 0x7ffeac2026b0 in RtlUserThreadStart+0x20 (C:\WINDOWS\SYSTEM32\ntdll.dll+0x1800526b0)

SUMMARY: AddressSanitizer: heap-use-after-free k:\Microsoft Visual Studio\2022\Community\VC\Tools\MSVC\14.39.33519\include\memory:1359 in std::_Ptr_base<blender::SharedCache<blender::Array<int,4,blender::GuardedAllocator> >::CacheData>::_Incref
Shadow bytes around the buggy address:
  0x03ab5fc34690: 00 00 00 00 00 00 00 00 00 00 00 00 fa fa fa fa
  0x03ab5fc346a0: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa
  0x03ab5fc346b0: fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd
  0x03ab5fc346c0: fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd
  0x03ab5fc346d0: fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd
=>0x03ab5fc346e0: fd[fd]fd fd fd fd fd fd fd fd fd fd fd fd fd fd
  0x03ab5fc346f0: fd fd fd fd fd fd fd fa fa fa fa fa fa fa fa fa
  0x03ab5fc34700: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa
  0x03ab5fc34710: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
  0x03ab5fc34720: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
  0x03ab5fc34730: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
Shadow byte legend (one shadow byte represents 8 application bytes):
  Addressable:           00
  Partially addressable: 01 02 03 04 05 06 07
  Heap left redzone:       fa
  Freed heap region:       fd
  Stack left redzone:      f1
  Stack mid redzone:       f2
  Stack right redzone:     f3
  Stack after return:      f5
  Stack use after scope:   f8
  Global redzone:          f9
  Global init order:       f6
  Poisoned by user:        f7
  Container overflow:      fc
  Array cookie:            ac
  Intra object redzone:    bb
  ASan internal:           fe
  Left alloca redzone:     ca
  Right alloca redzone:    cb
==26996==ABORTING
asan nabs this one pretty easily. ``` Read blend: "k:\BlenderGit\2022_lite_msvc\bin\Debug\Dingtotest.blend" ================================================================= ==26996==ERROR: AddressSanitizer: heap-use-after-free on address 0x11a2ffda3708 at pc 0x7ff6847c771f bp 0x002820ff57f0 sp 0x002820ff57f8 READ of size 8 at 0x11a2ffda3708 thread T33 #0 0x7ff6847c771e in std::_Ptr_base<blender::SharedCache<blender::Array<int,4,blender::GuardedAllocator> >::CacheData>::_Incref k:\Microsoft Visual Studio\2022\Community\VC\Tools\MSVC\14.39.33519\include\memory:1359 #1 0x7ff6847a6e12 in std::_Ptr_base<blender::SharedCache<blender::Array<int,4,blender::GuardedAllocator> >::CacheData>::_Copy_construct_from<blender::SharedCache<blender::Array<int,4,blender::GuardedAllocator> >::CacheData> k:\Microsoft Visual Studio\2022\Community\VC\Tools\MSVC\14.39.33519\include\memory:1318 #2 0x7ff6847be762 in std::shared_ptr<blender::SharedCache<blender::Array<int,4,blender::GuardedAllocator> >::CacheData>::shared_ptr<blender::SharedCache<blender::Array<int,4,blender::GuardedAllocator> >::CacheData> k:\Microsoft Visual Studio\2022\Community\VC\Tools\MSVC\14.39.33519\include\memory:1595 #3 0x7ff6847c118d in std::shared_ptr<blender::SharedCache<blender::Array<int,4,blender::GuardedAllocator> >::CacheData>::operator= k:\Microsoft Visual Studio\2022\Community\VC\Tools\MSVC\14.39.33519\include\memory:1654 #4 0x7ff6847c0c0f in blender::SharedCache<blender::Array<int,4,blender::GuardedAllocator> >::operator=+0x1f (k:\BlenderGit\2022_asan_debug_ninja\bin\blender.exe+0x1411c0c0f) #5 0x7ff68479d103 in mesh_copy_data K:\BlenderGit\blender\source\blender\blenkernel\intern\mesh.cc:152 #6 0x7ff68456ddd8 in BKE_id_copy_in_lib K:\BlenderGit\blender\source\blender\blenkernel\intern\lib_id.cc:668 #7 0x7ff68456d934 in BKE_id_copy_ex K:\BlenderGit\blender\source\blender\blenkernel\intern\lib_id.cc:715 #8 0x7ff68479139c in BKE_mesh_copy_for_eval K:\BlenderGit\blender\source\blender\blenkernel\intern\mesh.cc:863 #9 0x7ff6859337ea in mesh_calc_modifiers K:\BlenderGit\blender\source\blender\blenkernel\intern\DerivedMesh.cc:659 #10 0x7ff6859380e6 in mesh_build_data K:\BlenderGit\blender\source\blender\blenkernel\intern\DerivedMesh.cc:1298 #11 0x7ff68592ae52 in makeDerivedMesh K:\BlenderGit\blender\source\blender\blenkernel\intern\DerivedMesh.cc:1476 #12 0x7ff6856f26f4 in BKE_object_handle_data_update K:\BlenderGit\blender\source\blender\blenkernel\intern\object_update.cc:160 #13 0x7ff6856f098d in BKE_object_eval_uber_data K:\BlenderGit\blender\source\blender\blenkernel\intern\object_update.cc:315 #14 0x7ff68642a917 in `blender::deg::DepsgraphNodeBuilder::build_object_data_geometry'::`2'::<lambda_1>::operator() K:\BlenderGit\blender\source\blender\depsgraph\intern\builder\deg_builder_nodes.cc:1681 #15 0x7ff68643d281 in std::invoke<`blender::deg::DepsgraphNodeBuilder::build_object_data_geometry'::`2'::<lambda_1> &,Depsgraph *> k:\Microsoft Visual Studio\2022\Community\VC\Tools\MSVC\14.39.33519\include\type_traits:1739 #16 0x7ff68642ef0f in std::_Func_impl_no_alloc<`blender::deg::DepsgraphNodeBuilder::build_object_data_geometry'::`2'::<lambda_1>,void,Depsgraph *>::_Do_call k:\Microsoft Visual Studio\2022\Community\VC\Tools\MSVC\14.39.33519\include\functional:905 #17 0x7ff6863b9570 in std::_Func_class<void,Depsgraph *>::operator() k:\Microsoft Visual Studio\2022\Community\VC\Tools\MSVC\14.39.33519\include\functional:951 #18 0x7ff6863b689a in blender::deg::`anonymous namespace'::evaluate_node K:\BlenderGit\blender\source\blender\depsgraph\intern\eval\deg_eval.cc:101 #19 0x7ff6863b60ea in blender::deg::`anonymous namespace'::deg_task_run_func K:\BlenderGit\blender\source\blender\depsgraph\intern\eval\deg_eval.cc:118 #20 0x7ff685ff59b0 in Task::operator() K:\BlenderGit\blender\source\blender\blenlib\intern\task_pool.cc:166 #21 0x7ff685ff8545 in tbb::internal::function_task<Task>::execute K:\BlenderGit\blender\lib\windows_x64\tbb\include\tbb\task.h:1059 #22 0x7ffe90188090 in tbb::spin_rw_mutex_v3::internal_release_writer+0x25f1a (k:\BlenderGit\2022_asan_debug_ninja\bin\blender.shared\tbb_debug.dll+0x180028090) #23 0x7ffe90186252 in tbb::spin_rw_mutex_v3::internal_release_writer+0x240dc (k:\BlenderGit\2022_asan_debug_ninja\bin\blender.shared\tbb_debug.dll+0x180026252) #24 0x7ffe9016df85 in tbb::spin_rw_mutex_v3::internal_release_writer+0xbe0f (k:\BlenderGit\2022_asan_debug_ninja\bin\blender.shared\tbb_debug.dll+0x18000df85) #25 0x7ffe90178a0f in tbb::spin_rw_mutex_v3::internal_release_writer+0x16899 (k:\BlenderGit\2022_asan_debug_ninja\bin\blender.shared\tbb_debug.dll+0x180018a0f) #26 0x7ffe9017e779 in tbb::spin_rw_mutex_v3::internal_release_writer+0x1c603 (k:\BlenderGit\2022_asan_debug_ninja\bin\blender.shared\tbb_debug.dll+0x18001e779) #27 0x7ffe9017eafa in tbb::spin_rw_mutex_v3::internal_release_writer+0x1c984 (k:\BlenderGit\2022_asan_debug_ninja\bin\blender.shared\tbb_debug.dll+0x18001eafa) #28 0x7ffe58df300f in register_onexit_function+0x12f (C:\WINDOWS\SYSTEM32\ucrtbased.dll+0x1800b300f) #29 0x7ffe25acebde in __asan::AsanThread::ThreadStart D:\a\_work\1\s\src\vctools\asan\llvm\compiler-rt\lib\asan\asan_thread.cpp:299 #30 0x7ffeaa3e7343 in BaseThreadInitThunk+0x13 (C:\WINDOWS\System32\KERNEL32.DLL+0x180017343) #31 0x7ffeac2026b0 in RtlUserThreadStart+0x20 (C:\WINDOWS\SYSTEM32\ntdll.dll+0x1800526b0) 0x11a2ffda3708 is located 392 bytes inside of 568-byte region [0x11a2ffda3580,0x11a2ffda37b8) freed by thread T30 here: #0 0x7ff691bca6f3 in operator delete D:\a\_work\1\s\src\vctools\asan\llvm\compiler-rt\lib\asan\asan_win_delete_scalar_size_thunk.cpp:41 #1 0x7ff6847c5f70 in blender::bke::MeshRuntime::`scalar deleting destructor'+0x30 (k:\BlenderGit\2022_asan_debug_ninja\bin\blender.exe+0x1411c5f70) #2 0x7ff68479dd3f in mesh_free_data K:\BlenderGit\blender\source\blender\blenkernel\intern\mesh.cc:228 #3 0x7ff68464557c in BKE_libblock_free_datablock K:\BlenderGit\blender\source\blender\blenkernel\intern\lib_id_delete.cc:76 #4 0x7ff686346b3b in blender::deg::deg_free_eval_copy_datablock K:\BlenderGit\blender\source\blender\depsgraph\intern\eval\deg_eval_copy_on_write.cc:1018 #5 0x7ff68634688a in blender::deg::deg_update_eval_copy_datablock K:\BlenderGit\blender\source\blender\depsgraph\intern\eval\deg_eval_copy_on_write.cc:897 #6 0x7ff686346d99 in blender::deg::deg_create_eval_copy K:\BlenderGit\blender\source\blender\depsgraph\intern\eval\deg_eval_copy_on_write.cc:1033 #7 0x7ff686426dd1 in `blender::deg::DepsgraphNodeBuilder::add_id_node'::`11'::<lambda_1>::operator() K:\BlenderGit\blender\source\blender\depsgraph\intern\builder\deg_builder_nodes.cc:182 #8 0x7ff68643daf1 in std::invoke<`blender::deg::DepsgraphNodeBuilder::add_id_node'::`11'::<lambda_1> &,Depsgraph *> k:\Microsoft Visual Studio\2022\Community\VC\Tools\MSVC\14.39.33519\include\type_traits:1739 #9 0x7ff68642cb1f in std::_Func_impl_no_alloc<`blender::deg::DepsgraphNodeBuilder::add_id_node'::`11'::<lambda_1>,void,Depsgraph *>::_Do_call k:\Microsoft Visual Studio\2022\Community\VC\Tools\MSVC\14.39.33519\include\functional:905 #10 0x7ff6863b9570 in std::_Func_class<void,Depsgraph *>::operator() k:\Microsoft Visual Studio\2022\Community\VC\Tools\MSVC\14.39.33519\include\functional:951 #11 0x7ff6863b689a in blender::deg::`anonymous namespace'::evaluate_node K:\BlenderGit\blender\source\blender\depsgraph\intern\eval\deg_eval.cc:101 #12 0x7ff6863b60ea in blender::deg::`anonymous namespace'::deg_task_run_func K:\BlenderGit\blender\source\blender\depsgraph\intern\eval\deg_eval.cc:118 #13 0x7ff685ff59b0 in Task::operator() K:\BlenderGit\blender\source\blender\blenlib\intern\task_pool.cc:166 #14 0x7ff685ff8545 in tbb::internal::function_task<Task>::execute K:\BlenderGit\blender\lib\windows_x64\tbb\include\tbb\task.h:1059 #15 0x7ffe90188090 in tbb::spin_rw_mutex_v3::internal_release_writer+0x25f1a (k:\BlenderGit\2022_asan_debug_ninja\bin\blender.shared\tbb_debug.dll+0x180028090) #16 0x7ffe90186252 in tbb::spin_rw_mutex_v3::internal_release_writer+0x240dc (k:\BlenderGit\2022_asan_debug_ninja\bin\blender.shared\tbb_debug.dll+0x180026252) #17 0x7ffe9016df85 in tbb::spin_rw_mutex_v3::internal_release_writer+0xbe0f (k:\BlenderGit\2022_asan_debug_ninja\bin\blender.shared\tbb_debug.dll+0x18000df85) #18 0x7ffe90178a0f in tbb::spin_rw_mutex_v3::internal_release_writer+0x16899 (k:\BlenderGit\2022_asan_debug_ninja\bin\blender.shared\tbb_debug.dll+0x180018a0f) #19 0x7ffe9017e779 in tbb::spin_rw_mutex_v3::internal_release_writer+0x1c603 (k:\BlenderGit\2022_asan_debug_ninja\bin\blender.shared\tbb_debug.dll+0x18001e779) #20 0x7ffe9017eafa in tbb::spin_rw_mutex_v3::internal_release_writer+0x1c984 (k:\BlenderGit\2022_asan_debug_ninja\bin\blender.shared\tbb_debug.dll+0x18001eafa) #21 0x7ffe58df300f in register_onexit_function+0x12f (C:\WINDOWS\SYSTEM32\ucrtbased.dll+0x1800b300f) #22 0x7ffe25acebde in __asan::AsanThread::ThreadStart D:\a\_work\1\s\src\vctools\asan\llvm\compiler-rt\lib\asan\asan_thread.cpp:299 #23 0x7ffeaa3e7343 in BaseThreadInitThunk+0x13 (C:\WINDOWS\System32\KERNEL32.DLL+0x180017343) #24 0x7ffeac2026b0 in RtlUserThreadStart+0x20 (C:\WINDOWS\SYSTEM32\ntdll.dll+0x1800526b0) previously allocated by thread T28 here: #0 0x7ff691bca665 in operator new D:\a\_work\1\s\src\vctools\asan\llvm\compiler-rt\lib\asan\asan_win_new_scalar_thunk.cpp:40 #1 0x7ff68479c640 in mesh_copy_data K:\BlenderGit\blender\source\blender\blenkernel\intern\mesh.cc:113 #2 0x7ff68456ddd8 in BKE_id_copy_in_lib K:\BlenderGit\blender\source\blender\blenkernel\intern\lib_id.cc:668 #3 0x7ff68456d934 in BKE_id_copy_ex K:\BlenderGit\blender\source\blender\blenkernel\intern\lib_id.cc:715 #4 0x7ff68634963c in blender::deg::`anonymous namespace'::id_copy_inplace_no_main K:\BlenderGit\blender\source\blender\depsgraph\intern\eval\deg_eval_copy_on_write.cc:287 #5 0x7ff68634cad5 in blender::deg::`anonymous namespace'::deg_expand_eval_copy_datablock K:\BlenderGit\blender\source\blender\depsgraph\intern\eval\deg_eval_copy_on_write.cc:822 #6 0x7ff68634689f in blender::deg::deg_update_eval_copy_datablock K:\BlenderGit\blender\source\blender\depsgraph\intern\eval\deg_eval_copy_on_write.cc:898 #7 0x7ff686346d99 in blender::deg::deg_create_eval_copy K:\BlenderGit\blender\source\blender\depsgraph\intern\eval\deg_eval_copy_on_write.cc:1033 #8 0x7ff686426dd1 in `blender::deg::DepsgraphNodeBuilder::add_id_node'::`11'::<lambda_1>::operator() K:\BlenderGit\blender\source\blender\depsgraph\intern\builder\deg_builder_nodes.cc:182 #9 0x7ff68643daf1 in std::invoke<`blender::deg::DepsgraphNodeBuilder::add_id_node'::`11'::<lambda_1> &,Depsgraph *> k:\Microsoft Visual Studio\2022\Community\VC\Tools\MSVC\14.39.33519\include\type_traits:1739 #10 0x7ff68642cb1f in std::_Func_impl_no_alloc<`blender::deg::DepsgraphNodeBuilder::add_id_node'::`11'::<lambda_1>,void,Depsgraph *>::_Do_call k:\Microsoft Visual Studio\2022\Community\VC\Tools\MSVC\14.39.33519\include\functional:905 #11 0x7ff6863b9570 in std::_Func_class<void,Depsgraph *>::operator() k:\Microsoft Visual Studio\2022\Community\VC\Tools\MSVC\14.39.33519\include\functional:951 #12 0x7ff6863b689a in blender::deg::`anonymous namespace'::evaluate_node K:\BlenderGit\blender\source\blender\depsgraph\intern\eval\deg_eval.cc:101 #13 0x7ff6863b60ea in blender::deg::`anonymous namespace'::deg_task_run_func K:\BlenderGit\blender\source\blender\depsgraph\intern\eval\deg_eval.cc:118 #14 0x7ff685ff59b0 in Task::operator() K:\BlenderGit\blender\source\blender\blenlib\intern\task_pool.cc:166 #15 0x7ff685ff8545 in tbb::internal::function_task<Task>::execute K:\BlenderGit\blender\lib\windows_x64\tbb\include\tbb\task.h:1059 #16 0x7ffe90188090 in tbb::spin_rw_mutex_v3::internal_release_writer+0x25f1a (k:\BlenderGit\2022_asan_debug_ninja\bin\blender.shared\tbb_debug.dll+0x180028090) #17 0x7ffe90186252 in tbb::spin_rw_mutex_v3::internal_release_writer+0x240dc (k:\BlenderGit\2022_asan_debug_ninja\bin\blender.shared\tbb_debug.dll+0x180026252) #18 0x7ffe9016df85 in tbb::spin_rw_mutex_v3::internal_release_writer+0xbe0f (k:\BlenderGit\2022_asan_debug_ninja\bin\blender.shared\tbb_debug.dll+0x18000df85) #19 0x7ffe90178a0f in tbb::spin_rw_mutex_v3::internal_release_writer+0x16899 (k:\BlenderGit\2022_asan_debug_ninja\bin\blender.shared\tbb_debug.dll+0x180018a0f) #20 0x7ffe9017e779 in tbb::spin_rw_mutex_v3::internal_release_writer+0x1c603 (k:\BlenderGit\2022_asan_debug_ninja\bin\blender.shared\tbb_debug.dll+0x18001e779) #21 0x7ffe9017eafa in tbb::spin_rw_mutex_v3::internal_release_writer+0x1c984 (k:\BlenderGit\2022_asan_debug_ninja\bin\blender.shared\tbb_debug.dll+0x18001eafa) #22 0x7ffe58df300f in register_onexit_function+0x12f (C:\WINDOWS\SYSTEM32\ucrtbased.dll+0x1800b300f) #23 0x7ffe25acebde in __asan::AsanThread::ThreadStart D:\a\_work\1\s\src\vctools\asan\llvm\compiler-rt\lib\asan\asan_thread.cpp:299 #24 0x7ffeaa3e7343 in BaseThreadInitThunk+0x13 (C:\WINDOWS\System32\KERNEL32.DLL+0x180017343) #25 0x7ffeac2026b0 in RtlUserThreadStart+0x20 (C:\WINDOWS\SYSTEM32\ntdll.dll+0x1800526b0) Thread T33 created by T27 here: #0 0x7ffe25ad0897 in __asan_wrap_CreateThread D:\a\_work\1\s\src\vctools\asan\llvm\compiler-rt\lib\asan\asan_win.cpp:163 #1 0x7ffe58df387e in beginthreadex+0x14e (C:\WINDOWS\SYSTEM32\ucrtbased.dll+0x1800b387e) #2 0x7ffe9017ecc8 in tbb::spin_rw_mutex_v3::internal_release_writer+0x1cb52 (k:\BlenderGit\2022_asan_debug_ninja\bin\blender.shared\tbb_debug.dll+0x18001ecc8) #3 0x7ffe9017e886 in tbb::spin_rw_mutex_v3::internal_release_writer+0x1c710 (k:\BlenderGit\2022_asan_debug_ninja\bin\blender.shared\tbb_debug.dll+0x18001e886) #4 0x7ffe9017eafa in tbb::spin_rw_mutex_v3::internal_release_writer+0x1c984 (k:\BlenderGit\2022_asan_debug_ninja\bin\blender.shared\tbb_debug.dll+0x18001eafa) #5 0x7ffe58df300f in register_onexit_function+0x12f (C:\WINDOWS\SYSTEM32\ucrtbased.dll+0x1800b300f) #6 0x7ffe25acebde in __asan::AsanThread::ThreadStart D:\a\_work\1\s\src\vctools\asan\llvm\compiler-rt\lib\asan\asan_thread.cpp:299 #7 0x7ffeaa3e7343 in BaseThreadInitThunk+0x13 (C:\WINDOWS\System32\KERNEL32.DLL+0x180017343) #8 0x7ffeac2026b0 in RtlUserThreadStart+0x20 (C:\WINDOWS\SYSTEM32\ntdll.dll+0x1800526b0) Thread T27 created by T0 here: #0 0x7ffe25ad0897 in __asan_wrap_CreateThread D:\a\_work\1\s\src\vctools\asan\llvm\compiler-rt\lib\asan\asan_win.cpp:163 #1 0x7ffe58df387e in beginthreadex+0x14e (C:\WINDOWS\SYSTEM32\ucrtbased.dll+0x1800b387e) #2 0x7ffe9017ecc8 in tbb::spin_rw_mutex_v3::internal_release_writer+0x1cb52 (k:\BlenderGit\2022_asan_debug_ninja\bin\blender.shared\tbb_debug.dll+0x18001ecc8) #3 0x7ffe9017734a in tbb::spin_rw_mutex_v3::internal_release_writer+0x151d4 (k:\BlenderGit\2022_asan_debug_ninja\bin\blender.shared\tbb_debug.dll+0x18001734a) #4 0x7ff6844ee82d in tbb::interface5::internal::task_base::spawn K:\BlenderGit\blender\lib\windows_x64\tbb\include\tbb\task.h:1125 #5 0x7ff685ff6f40 in tbb::task_group::run<Task> K:\BlenderGit\blender\lib\windows_x64\tbb\include\tbb\task_group.h:208 #6 0x7ff685ff5d5a in tbb_task_pool_run K:\BlenderGit\blender\source\blender\blenlib\intern\task_pool.cc:210 #7 0x7ff685ff6009 in tbb_task_pool_work_and_wait K:\BlenderGit\blender\source\blender\blenlib\intern\task_pool.cc:228 #8 0x7ff685ff55d4 in BLI_task_pool_work_and_wait K:\BlenderGit\blender\source\blender\blenlib\intern\task_pool.cc:472 #9 0x7ff6863b82eb in blender::deg::`anonymous namespace'::evaluate_graph_threaded_stage K:\BlenderGit\blender\source\blender\depsgraph\intern\eval\deg_eval.cc:323 #10 0x7ff6863b5b60 in blender::deg::deg_evaluate_on_refresh K:\BlenderGit\blender\source\blender\depsgraph\intern\eval\deg_eval.cc:428 #11 0x7ff6862f9dbc in deg_flush_updates_and_refresh K:\BlenderGit\blender\source\blender\depsgraph\intern\depsgraph_eval.cc:47 #12 0x7ff6862f9c3c in DEG_evaluate_on_refresh K:\BlenderGit\blender\source\blender\depsgraph\intern\depsgraph_eval.cc:80 #13 0x7ff68459f4cb in scene_graph_update_tagged K:\BlenderGit\blender\source\blender\blenkernel\intern\scene.cc:2532 #14 0x7ff68458a4cb in BKE_scene_graph_update_tagged K:\BlenderGit\blender\source\blender\blenkernel\intern\scene.cc:2581 #15 0x7ff68652129b in wm_event_do_depsgraph K:\BlenderGit\blender\source\blender\windowmanager\intern\wm_event_system.cc:478 #16 0x7ff6864ac566 in wm_file_read_post K:\BlenderGit\blender\source\blender\windowmanager\intern\wm_files.cc:779 #17 0x7ff6864a520b in wm_homefile_read_post K:\BlenderGit\blender\source\blender\windowmanager\intern\wm_files.cc:1528 #18 0x7ff68649a363 in WM_init K:\BlenderGit\blender\source\blender\windowmanager\intern\wm_init_exit.cc:356 #19 0x7ff68370cada in main K:\BlenderGit\blender\source\creator\creator.cc:525 #20 0x7ff691bcb8a8 in invoke_main D:\a\_work\1\s\src\vctools\crt\vcstartup\src\startup\exe_common.inl:78 #21 0x7ff691bcb7fd in __scrt_common_main_seh D:\a\_work\1\s\src\vctools\crt\vcstartup\src\startup\exe_common.inl:288 #22 0x7ff691bcb6bd in __scrt_common_main D:\a\_work\1\s\src\vctools\crt\vcstartup\src\startup\exe_common.inl:330 #23 0x7ff691bcb91d in mainCRTStartup D:\a\_work\1\s\src\vctools\crt\vcstartup\src\startup\exe_main.cpp:16 #24 0x7ffeaa3e7343 in BaseThreadInitThunk+0x13 (C:\WINDOWS\System32\KERNEL32.DLL+0x180017343) #25 0x7ffeac2026b0 in RtlUserThreadStart+0x20 (C:\WINDOWS\SYSTEM32\ntdll.dll+0x1800526b0) Thread T30 created by T28 here: #0 0x7ffe25ad0897 in __asan_wrap_CreateThread D:\a\_work\1\s\src\vctools\asan\llvm\compiler-rt\lib\asan\asan_win.cpp:163 #1 0x7ffe58df387e in beginthreadex+0x14e (C:\WINDOWS\SYSTEM32\ucrtbased.dll+0x1800b387e) #2 0x7ffe9017ecc8 in tbb::spin_rw_mutex_v3::internal_release_writer+0x1cb52 (k:\BlenderGit\2022_asan_debug_ninja\bin\blender.shared\tbb_debug.dll+0x18001ecc8) #3 0x7ffe9017e73e in tbb::spin_rw_mutex_v3::internal_release_writer+0x1c5c8 (k:\BlenderGit\2022_asan_debug_ninja\bin\blender.shared\tbb_debug.dll+0x18001e73e) #4 0x7ffe9017eafa in tbb::spin_rw_mutex_v3::internal_release_writer+0x1c984 (k:\BlenderGit\2022_asan_debug_ninja\bin\blender.shared\tbb_debug.dll+0x18001eafa) #5 0x7ffe58df300f in register_onexit_function+0x12f (C:\WINDOWS\SYSTEM32\ucrtbased.dll+0x1800b300f) #6 0x7ffe25acebde in __asan::AsanThread::ThreadStart D:\a\_work\1\s\src\vctools\asan\llvm\compiler-rt\lib\asan\asan_thread.cpp:299 #7 0x7ffeaa3e7343 in BaseThreadInitThunk+0x13 (C:\WINDOWS\System32\KERNEL32.DLL+0x180017343) #8 0x7ffeac2026b0 in RtlUserThreadStart+0x20 (C:\WINDOWS\SYSTEM32\ntdll.dll+0x1800526b0) Thread T28 created by T0 here: #0 0x7ffe25ad0897 in __asan_wrap_CreateThread D:\a\_work\1\s\src\vctools\asan\llvm\compiler-rt\lib\asan\asan_win.cpp:163 #1 0x7ffe58df387e in beginthreadex+0x14e (C:\WINDOWS\SYSTEM32\ucrtbased.dll+0x1800b387e) #2 0x7ffe9017ecc8 in tbb::spin_rw_mutex_v3::internal_release_writer+0x1cb52 (k:\BlenderGit\2022_asan_debug_ninja\bin\blender.shared\tbb_debug.dll+0x18001ecc8) #3 0x7ffe9017734a in tbb::spin_rw_mutex_v3::internal_release_writer+0x151d4 (k:\BlenderGit\2022_asan_debug_ninja\bin\blender.shared\tbb_debug.dll+0x18001734a) #4 0x7ff6844ee82d in tbb::interface5::internal::task_base::spawn K:\BlenderGit\blender\lib\windows_x64\tbb\include\tbb\task.h:1125 #5 0x7ff685ff6f40 in tbb::task_group::run<Task> K:\BlenderGit\blender\lib\windows_x64\tbb\include\tbb\task_group.h:208 #6 0x7ff685ff5d5a in tbb_task_pool_run K:\BlenderGit\blender\source\blender\blenlib\intern\task_pool.cc:210 #7 0x7ff685ff6009 in tbb_task_pool_work_and_wait K:\BlenderGit\blender\source\blender\blenlib\intern\task_pool.cc:228 #8 0x7ff685ff55d4 in BLI_task_pool_work_and_wait K:\BlenderGit\blender\source\blender\blenlib\intern\task_pool.cc:472 #9 0x7ff6863b82eb in blender::deg::`anonymous namespace'::evaluate_graph_threaded_stage K:\BlenderGit\blender\source\blender\depsgraph\intern\eval\deg_eval.cc:323 #10 0x7ff6863b5b60 in blender::deg::deg_evaluate_on_refresh K:\BlenderGit\blender\source\blender\depsgraph\intern\eval\deg_eval.cc:428 #11 0x7ff6862f9dbc in deg_flush_updates_and_refresh K:\BlenderGit\blender\source\blender\depsgraph\intern\depsgraph_eval.cc:47 #12 0x7ff6862f9c3c in DEG_evaluate_on_refresh K:\BlenderGit\blender\source\blender\depsgraph\intern\depsgraph_eval.cc:80 #13 0x7ff68459f4cb in scene_graph_update_tagged K:\BlenderGit\blender\source\blender\blenkernel\intern\scene.cc:2532 #14 0x7ff68458a4cb in BKE_scene_graph_update_tagged K:\BlenderGit\blender\source\blender\blenkernel\intern\scene.cc:2581 #15 0x7ff68652129b in wm_event_do_depsgraph K:\BlenderGit\blender\source\blender\windowmanager\intern\wm_event_system.cc:478 #16 0x7ff6864ac566 in wm_file_read_post K:\BlenderGit\blender\source\blender\windowmanager\intern\wm_files.cc:779 #17 0x7ff6864a520b in wm_homefile_read_post K:\BlenderGit\blender\source\blender\windowmanager\intern\wm_files.cc:1528 #18 0x7ff68649a363 in WM_init K:\BlenderGit\blender\source\blender\windowmanager\intern\wm_init_exit.cc:356 #19 0x7ff68370cada in main K:\BlenderGit\blender\source\creator\creator.cc:525 #20 0x7ff691bcb8a8 in invoke_main D:\a\_work\1\s\src\vctools\crt\vcstartup\src\startup\exe_common.inl:78 #21 0x7ff691bcb7fd in __scrt_common_main_seh D:\a\_work\1\s\src\vctools\crt\vcstartup\src\startup\exe_common.inl:288 #22 0x7ff691bcb6bd in __scrt_common_main D:\a\_work\1\s\src\vctools\crt\vcstartup\src\startup\exe_common.inl:330 #23 0x7ff691bcb91d in mainCRTStartup D:\a\_work\1\s\src\vctools\crt\vcstartup\src\startup\exe_main.cpp:16 #24 0x7ffeaa3e7343 in BaseThreadInitThunk+0x13 (C:\WINDOWS\System32\KERNEL32.DLL+0x180017343) #25 0x7ffeac2026b0 in RtlUserThreadStart+0x20 (C:\WINDOWS\SYSTEM32\ntdll.dll+0x1800526b0) SUMMARY: AddressSanitizer: heap-use-after-free k:\Microsoft Visual Studio\2022\Community\VC\Tools\MSVC\14.39.33519\include\memory:1359 in std::_Ptr_base<blender::SharedCache<blender::Array<int,4,blender::GuardedAllocator> >::CacheData>::_Incref Shadow bytes around the buggy address: 0x03ab5fc34690: 00 00 00 00 00 00 00 00 00 00 00 00 fa fa fa fa 0x03ab5fc346a0: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa 0x03ab5fc346b0: fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd 0x03ab5fc346c0: fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd 0x03ab5fc346d0: fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd =>0x03ab5fc346e0: fd[fd]fd fd fd fd fd fd fd fd fd fd fd fd fd fd 0x03ab5fc346f0: fd fd fd fd fd fd fd fa fa fa fa fa fa fa fa fa 0x03ab5fc34700: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa 0x03ab5fc34710: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0x03ab5fc34720: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0x03ab5fc34730: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 Shadow byte legend (one shadow byte represents 8 application bytes): Addressable: 00 Partially addressable: 01 02 03 04 05 06 07 Heap left redzone: fa Freed heap region: fd Stack left redzone: f1 Stack mid redzone: f2 Stack right redzone: f3 Stack after return: f5 Stack use after scope: f8 Global redzone: f9 Global init order: f6 Poisoned by user: f7 Container overflow: fc Array cookie: ac Intra object redzone: bb ASan internal: fe Left alloca redzone: ca Right alloca redzone: cb ==26996==ABORTING ```
Member

I wasn't able to reproduce it yet, but my ASAN setup is also broken right now for unknown reasons. Can someone try reproducing it with -t 1 and -t 2?

I wasn't able to reproduce it yet, but my ASAN setup is also broken right now for unknown reasons. Can someone try reproducing it with `-t 1` and `-t 2`?
Contributor

I was able to reproduce it using -t 1
but it seems weird because it is looking like a race condition (that I don't think should happen with 1 thread)
I am using valgrind to reproduce (I am assuming that its helps to reproduce because its slow things down and make a race condition more likely to happen) but if for some reason its problematic to use valgrind please let me know.
from the valgrind output it looks like
preprocess_geometry_node_tree_for_evaluation in node_runtime.cc is called multiple times
and the geometry_nodes_lazy_function_graph_info that was created in node_runtime.cc line 24
is rested by node_runtime.cc line 23
while being used by another thread

again seems like it should be impossible while using -t 1 but...

another option is that it is just one thread but someplace keeps the geometry_nodes_lazy_function_graph_info by pointer and then call
preprocess_geometry_node_tree_for_evaluation again before using the saved pointer

I was able to reproduce it using -t 1 but it seems weird because it is looking like a race condition (that I don't think should happen with 1 thread) I am using valgrind to reproduce (I am assuming that its helps to reproduce because its slow things down and make a race condition more likely to happen) but if for some reason its problematic to use valgrind please let me know. from the valgrind output it looks like preprocess_geometry_node_tree_for_evaluation in node_runtime.cc is called multiple times and the geometry_nodes_lazy_function_graph_info that was created in node_runtime.cc line 24 is rested by node_runtime.cc line 23 while being used by another thread again seems like it should be impossible while using -t 1 but... another option is that it is just one thread but someplace keeps the geometry_nodes_lazy_function_graph_info by pointer and then call preprocess_geometry_node_tree_for_evaluation again before using the saved pointer
Member

Just noticed that it may actually still use more than one thread here even when passing -t 1, because the job system uses threads independently from tbb (also see WM_jobs_start).

Might still be useful to get another asan report with fewer threads.

You could also try making it so that start_bake_job is called with BakeRequestsMode::Sync.

Just noticed that it may actually still use more than one thread here even when passing `-t 1`, because the job system uses threads independently from tbb (also see `WM_jobs_start`). Might still be useful to get another asan report with fewer threads. You could also try making it so that `start_bake_job` is called with `BakeRequestsMode::Sync`.
Member

Can someone try reproducing it with -t 1 and -t 2?

given the last asan dump was kinda noisy, -t1 asan attached below., my build is a few days old though (28th)

> Can someone try reproducing it with -t 1 and -t 2? given the last asan dump was kinda noisy, -t1 asan attached below., my build is a few days old though (28th)
Contributor

where can I read about ASAN? I tried googling it but did not find anything relevant.
after changing the code to always use BakeRequestsMode::Sync I wasn't able to reproudce the crash.
if no one will solve this I will try to look into it a bit more later.

where can I read about ASAN? I tried googling it but did not find anything relevant. after changing the code to always use BakeRequestsMode::Sync I wasn't able to reproudce the crash. if no one will solve this I will try to look into it a bit more later.
Member

ASAN means "Address Sanitizer". We have some docs about it here and here.

ASAN means "Address Sanitizer". We have some docs about it [here](https://developer.blender.org/docs/handbook/tooling/asan/) and [here](https://developer.blender.org/docs/handbook/testing/setup/#asan-builds).
Member

mesh_free_data freeing but leaving the now dangling pointer in mesh->runtime seems to be somewhat inviting this class of bugs.

`mesh_free_data` freeing but leaving the now dangling pointer in `mesh->runtime` seems to be somewhat inviting this class of bugs.
Member

fixing that, moves the problem to a new spot

fixing that, moves the problem to a new spot
20 KiB
Contributor

The problem seems to be that the WM_set_locked_interface(job->wm, true); happens inside the thread and then the main thread may check the lock while the thread is in the middle of changing it. I think that the check happen for the animation but didn't found where.
I have a fix, to which branch should I open a pull request?.

The problem seems to be that the WM_set_locked_interface(job->wm, true); happens inside the thread and then the main thread may check the lock while the thread is in the middle of changing it. I think that the check happen for the animation but didn't found where. I have a fix, to which branch should I open a pull request?.
Author
Owner

Fixes should be against the main branch. :)

Fixes should be against the `main` branch. :)
Blender Bot added
Status
Resolved
and removed
Status
Confirmed
labels 2024-04-04 18:42:58 +02:00
Sign in to join this conversation.
No Label
Interest
Alembic
Interest
Animation & Rigging
Interest
Asset System
Interest
Audio
Interest
Automated Testing
Interest
Blender Asset Bundle
Interest
BlendFile
Interest
Collada
Interest
Compatibility
Interest
Compositing
Interest
Core
Interest
Cycles
Interest
Dependency Graph
Interest
Development Management
Interest
EEVEE
Interest
Freestyle
Interest
Geometry Nodes
Interest
Grease Pencil
Interest
ID Management
Interest
Images & Movies
Interest
Import Export
Interest
Line Art
Interest
Masking
Interest
Metal
Interest
Modeling
Interest
Modifiers
Interest
Motion Tracking
Interest
Nodes & Physics
Interest
OpenGL
Interest
Overlay
Interest
Overrides
Interest
Performance
Interest
Physics
Interest
Pipeline, Assets & IO
Interest
Platforms, Builds & Tests
Interest
Python API
Interest
Render & Cycles
Interest
Render Pipeline
Interest
Sculpt, Paint & Texture
Interest
Text Editor
Interest
Translations
Interest
Triaging
Interest
Undo
Interest
USD
Interest
User Interface
Interest
UV Editing
Interest
VFX & Video
Interest
Video Sequencer
Interest
Viewport & EEVEE
Interest
Virtual Reality
Interest
Vulkan
Interest
Wayland
Interest
Workbench
Interest: X11
Legacy
Asset Browser Project
Legacy
Blender 2.8 Project
Legacy
Milestone 1: Basic, Local Asset Browser
Legacy
OpenGL Error
Meta
Good First Issue
Meta
Papercut
Meta
Retrospective
Meta
Security
Module
Animation & Rigging
Module
Core
Module
Development Management
Module
Grease Pencil
Module
Modeling
Module
Nodes & Physics
Module
Pipeline, Assets & IO
Module
Platforms, Builds & Tests
Module
Python API
Module
Render & Cycles
Module
Sculpt, Paint & Texture
Module
Triaging
Module
User Interface
Module
VFX & Video
Module
Viewport & EEVEE
Platform
FreeBSD
Platform
Linux
Platform
macOS
Platform
Windows
Severity
High
Severity
Low
Severity
Normal
Severity
Unbreak Now!
Status
Archived
Status
Confirmed
Status
Duplicate
Status
Needs Info from Developers
Status
Needs Information from User
Status
Needs Triage
Status
Resolved
Type
Bug
Type
Design
Type
Known Issue
Type
Patch
Type
Report
Type
To Do
No Milestone
No project
No Assignees
6 Participants
Notifications
Due Date
The due date is invalid or out of range. Please use the format 'yyyy-mm-dd'.

No due date set.

Dependencies

No dependencies set.

Reference: blender/blender#119958
No description provided.