Use-after-free when expanding hierarchy in Outliner after deleting NLA track #84586

Closed
opened 2021-01-11 09:31:34 +01:00 by Robert Guetzkow · 7 comments

System Information
Operating system: Linux-5.8.0-36-generic-x86_64-with-debian-bullseye-sid 64 Bits
Graphics card: SVGA3D; build: RELEASE; LLVM; VMware, Inc. 3.3 (Core Profile) Mesa 20.0.8

Blender Version
Broken: version:

  • 2.92.0 Alpha, branch: master, commit date: 2021-01-08 10:20, hash: 03f1d8acab
  • 2.91.0
    Worked: 2.83.x

Short description of error
When an NLA track is deleted and the NLA tracks entry in the Outliner is expanded to show the hierarchy below, ASAN detects a use-after-free.

Exact steps for others to reproduce the error

  • Open the attached file.
  • Delete NlaTrack in the Nonlinear Animation editor.

Expand the Scene Collection > Collection > Cube > Animation > NLA tracks entry.

#84586.blend

Alternatively:

  • Create a keyframe animation.
  • Open the Nonlinear Animation editor.
  • Use Push Down Action.
  • Delete the track.

In the Outliner find the NLA tracks entry and try to expand the hierarchy below it by clicking on the triangle icon.

## 3185==ERROR: AddressSanitizer: heap-use-after-free on address 0x60b0005ced50 at pc 0x00001704cf5f bp 0x7fffffffa460 sp 0x7fffffffa450
READ of size 1 at 0x60b0005ced50 thread T0
    - 0 0x1704cf5e in BLF_draw /home/dev/01-data/01-git/blender-git/blender/source/blender/blenfont/intern/blf.c:544
    - 1 0x9353246 in UI_fontstyle_draw_simple /home/dev/01-data/01-git/blender-git/blender/source/blender/editors/interface/interface_style.c:311
    - 2 0x982ce06 in outliner_draw_tree_element /home/dev/01-data/01-git/blender-git/blender/source/blender/editors/space_outliner/outliner_draw.c:3114
    - 3 0x982dc0f in outliner_draw_tree_element /home/dev/01-data/01-git/blender-git/blender/source/blender/editors/space_outliner/outliner_draw.c:3162
    - 4 0x982dc0f in outliner_draw_tree_element /home/dev/01-data/01-git/blender-git/blender/source/blender/editors/space_outliner/outliner_draw.c:3162
    - 5 0x982dc0f in outliner_draw_tree_element /home/dev/01-data/01-git/blender-git/blender/source/blender/editors/space_outliner/outliner_draw.c:3162
    - 6 0x982dc0f in outliner_draw_tree_element /home/dev/01-data/01-git/blender-git/blender/source/blender/editors/space_outliner/outliner_draw.c:3162
    - 7 0x982dc0f in outliner_draw_tree_element /home/dev/01-data/01-git/blender-git/blender/source/blender/editors/space_outliner/outliner_draw.c:3162
    - 8 0x982dc0f in outliner_draw_tree_element /home/dev/01-data/01-git/blender-git/blender/source/blender/editors/space_outliner/outliner_draw.c:3162
    - 9 0x9833197 in outliner_draw_tree /home/dev/01-data/01-git/blender-git/blender/source/blender/editors/space_outliner/outliner_draw.c:3508
    - 10 0x9834a1b in draw_outliner /home/dev/01-data/01-git/blender-git/blender/source/blender/editors/space_outliner/outliner_draw.c:3637
    - 11 0x98843db in outliner_main_region_draw /home/dev/01-data/01-git/blender-git/blender/source/blender/editors/space_outliner/space_outliner.c:92
    - 12 0x7909e1c in ED_region_do_draw /home/dev/01-data/01-git/blender-git/blender/source/blender/editors/screen/area.c:546
    - 13 0x4fd2335 in wm_draw_window_offscreen /home/dev/01-data/01-git/blender-git/blender/source/blender/windowmanager/intern/wm_draw.c:731
    - 14 0x4fd3557 in wm_draw_window /home/dev/01-data/01-git/blender-git/blender/source/blender/windowmanager/intern/wm_draw.c:872
    - 15 0x4fd49c7 in wm_draw_update /home/dev/01-data/01-git/blender-git/blender/source/blender/windowmanager/intern/wm_draw.c:1073
    - 16 0x4fc4fa7 in WM_main /home/dev/01-data/01-git/blender-git/blender/source/blender/windowmanager/intern/wm.c:641
    - 17 0x3523a3a in main /home/dev/01-data/01-git/blender-git/blender/source/creator/creator.c:522
    - 18 0x7ffff6e490b2 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x270b2)
    - 19 0x3522bed in _start (/home/dev/01-data/01-git/blender-git/build_linux_debug_full/bin/blender+0x3522bed)

0x60b0005ced50 is located 48 bytes inside of 112-byte region [0x60b0005ced20,0x60b0005ced90)
freed by thread T0 here:
    - 0 0x7ffff76907cf in __interceptor_free (/lib/x86_64-linux-gnu/libasan.so.5+0x10d7cf)
    - 1 0x18fba180 in MEM_lockfree_freeN /home/dev/01-data/01-git/blender-git/blender/intern/guardedalloc/intern/mallocn_lockfree_impl.c:129
    - 2 0x18c3d585 in BLI_freelinkN /home/dev/01-data/01-git/blender-git/blender/source/blender/blenlib/intern/listbase.c:290
    - 3 0x392af3c in BKE_nlatrack_free /home/dev/01-data/01-git/blender-git/blender/source/blender/blenkernel/intern/nla.c:131
    - 4 0x973eeaf in nlaedit_delete_tracks_exec /home/dev/01-data/01-git/blender-git/blender/source/blender/editors/space_nla/nla_channels.c:814
    - 5 0x4fe1cf2 in wm_operator_invoke /home/dev/01-data/01-git/blender-git/blender/source/blender/windowmanager/intern/wm_event_system.c:1312
    - 6 0x4fe9aec in wm_handler_operator_call /home/dev/01-data/01-git/blender-git/blender/source/blender/windowmanager/intern/wm_event_system.c:2141
    - 7 0x4fed63b in wm_handlers_do_keymap_with_keymap_handler /home/dev/01-data/01-git/blender-git/blender/source/blender/windowmanager/intern/wm_event_system.c:2466
    - 8 0x4ff0dee in wm_handlers_do_intern /home/dev/01-data/01-git/blender-git/blender/source/blender/windowmanager/intern/wm_event_system.c:2762
    - 9 0x4ff207c in wm_handlers_do /home/dev/01-data/01-git/blender-git/blender/source/blender/windowmanager/intern/wm_event_system.c:2886
    - 10 0x4ff83f3 in wm_event_do_handlers /home/dev/01-data/01-git/blender-git/blender/source/blender/windowmanager/intern/wm_event_system.c:3382
    - 11 0x4fc4f8f in WM_main /home/dev/01-data/01-git/blender-git/blender/source/blender/windowmanager/intern/wm.c:635
    - 12 0x3523a3a in main /home/dev/01-data/01-git/blender-git/blender/source/creator/creator.c:522
    - 13 0x7ffff6e490b2 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x270b2)

previously allocated by thread T0 here:
    - 0 0x7ffff7690bc8 in malloc (/lib/x86_64-linux-gnu/libasan.so.5+0x10dbc8)
    - 1 0x18fbabe0 in MEM_lockfree_mallocN /home/dev/01-data/01-git/blender-git/blender/intern/guardedalloc/intern/mallocn_lockfree_impl.c:276
    - 2 0x18fba2ea in MEM_lockfree_dupallocN /home/dev/01-data/01-git/blender-git/blender/intern/guardedalloc/intern/mallocn_lockfree_impl.c:145
    - 3 0x392b8ab in BKE_nlatrack_copy /home/dev/01-data/01-git/blender-git/blender/source/blender/blenkernel/intern/nla.c:237
    - 4 0x6e52b9b in rna_NLA_tracks_override_apply /home/dev/01-data/01-git/blender-git/blender/source/blender/makesrna/intern/rna_animation.c:780
    - 5 0x6dfd3a4 in rna_property_override_operation_apply /home/dev/01-data/01-git/blender-git/blender/source/blender/makesrna/intern/rna_access_compare_override.c:616
    - 6 0x6e01497 in rna_property_override_apply_ex /home/dev/01-data/01-git/blender-git/blender/source/blender/makesrna/intern/rna_access_compare_override.c:1098
    - 7 0x6e01d70 in RNA_struct_override_apply /home/dev/01-data/01-git/blender-git/blender/source/blender/makesrna/intern/rna_access_compare_override.c:1155
    - 8 0x3789d1d in BKE_lib_override_library_update /home/dev/01-data/01-git/blender-git/blender/source/blender/blenkernel/intern/lib_override.c:1818
    - 9 0x378ae17 in BKE_lib_override_library_main_update /home/dev/01-data/01-git/blender-git/blender/source/blender/blenkernel/intern/lib_override.c:1885
    - 10 0x5140288 in blo_read_file_internal /home/dev/01-data/01-git/blender-git/blender/source/blender/blenloader/intern/readfile.c:4133
    - 11 0x51139b0 in BLO_read_from_file /home/dev/01-data/01-git/blender-git/blender/source/blender/blenloader/intern/readblenentry.c:368
    - 12 0x9dfd740 in BKE_blendfile_read_ex /home/dev/01-data/01-git/blender-git/blender/source/blender/blenkernel/intern/blendfile.c:446
    - 13 0x9dfd8ea in BKE_blendfile_read /home/dev/01-data/01-git/blender-git/blender/source/blender/blenkernel/intern/blendfile.c:468
    - 14 0x5012456 in WM_file_read /home/dev/01-data/01-git/blender-git/blender/source/blender/windowmanager/intern/wm_files.c:717
    - 15 0x501d5a6 in wm_file_read_opwrap /home/dev/01-data/01-git/blender-git/blender/source/blender/windowmanager/intern/wm_files.c:2185
    - 16 0x501e82a in wm_open_mainfile__open /home/dev/01-data/01-git/blender-git/blender/source/blender/windowmanager/intern/wm_files.c:2325
    - 17 0x501d911 in operator_state_dispatch /home/dev/01-data/01-git/blender-git/blender/source/blender/windowmanager/intern/wm_files.c:2221
    - 18 0x501ea9f in wm_open_mainfile_dispatch /home/dev/01-data/01-git/blender-git/blender/source/blender/windowmanager/intern/wm_files.c:2349
    - 19 0x501de16 in wm_open_mainfile__discard_changes /home/dev/01-data/01-git/blender-git/blender/source/blender/windowmanager/intern/wm_files.c:2266
    - 20 0x501d911 in operator_state_dispatch /home/dev/01-data/01-git/blender-git/blender/source/blender/windowmanager/intern/wm_files.c:2221
    - 21 0x501ea9f in wm_open_mainfile_dispatch /home/dev/01-data/01-git/blender-git/blender/source/blender/windowmanager/intern/wm_files.c:2349
    - 22 0x501eacc in wm_open_mainfile_invoke /home/dev/01-data/01-git/blender-git/blender/source/blender/windowmanager/intern/wm_files.c:2354
    - 23 0x4fe1725 in wm_operator_invoke /home/dev/01-data/01-git/blender-git/blender/source/blender/windowmanager/intern/wm_event_system.c:1300
    - 24 0x4fe37c3 in wm_operator_call_internal /home/dev/01-data/01-git/blender-git/blender/source/blender/windowmanager/intern/wm_event_system.c:1541
    - 25 0x4fe38bc in WM_operator_name_call_ptr /home/dev/01-data/01-git/blender-git/blender/source/blender/windowmanager/intern/wm_event_system.c:1555
    - 26 0x91ce62a in ui_apply_but_funcs_after /home/dev/01-data/01-git/blender-git/blender/source/blender/editors/interface/interface_handlers.c:939
    - 27 0x9259475 in ui_popup_handler /home/dev/01-data/01-git/blender-git/blender/source/blender/editors/interface/interface_handlers.c:10937
    - 28 0x4fdaec6 in wm_handler_ui_call /home/dev/01-data/01-git/blender-git/blender/source/blender/windowmanager/intern/wm_event_system.c:643
    - 29 0x4ff103a in wm_handlers_do_intern /home/dev/01-data/01-git/blender-git/blender/source/blender/windowmanager/intern/wm_event_system.c:2778

SUMMARY: AddressSanitizer: heap-use-after-free /home/dev/01-data/01-git/blender-git/blender/source/blender/blenfont/intern/blf.c:544 in BLF_draw
Shadow bytes around the buggy address:
  0x0c16800b1d50: 00 00 00 00 00 00 00 00 00 00 fa fa fa fa fa fa
  0x0c16800b1d60: fa fa 00 00 00 00 00 00 00 00 00 00 00 00 00 00
  0x0c16800b1d70: fa fa fa fa fa fa fa fa 00 00 00 00 00 00 00 00
  0x0c16800b1d80: 00 00 00 00 00 00 fa fa fa fa fa fa fa fa 00 00
  0x0c16800b1d90: 00 00 00 00 00 00 00 00 00 00 00 00 fa fa fa fa
# >0x0c16800b1da0: fa fa fa fa fd fd fd fd fd fd[fd]fd fd fd fd fd
  0x0c16800b1db0: fd fd fa fa fa fa fa fa fa fa 00 00 00 00 00 00
  0x0c16800b1dc0: 00 00 00 00 00 00 00 00 fa fa fa fa fa fa fa fa
  0x0c16800b1dd0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 fa fa
  0x0c16800b1de0: fa fa fa fa fa fa 00 00 00 00 00 00 00 00 00 00
  0x0c16800b1df0: 00 00 00 fa fa fa fa fa fa fa fa fa 00 00 00 00
Shadow byte legend (one shadow byte represents 8 application bytes):

Addressable: 00
Partially addressable: 01 02 03 04 05 06 07
Heap left redzone: fa
Freed heap region: fd
Stack left redzone: f1
Stack mid redzone: f2
Stack right redzone: f3
Stack after return: f5
Stack use after scope: f8
Global redzone: f9
Global init order: f6
Poisoned by user: f7
Container overflow: fc
Array cookie: ac
Intra object redzone: bb
ASan internal: fe
Left alloca redzone: ca
Right alloca redzone: cb
Shadow gap: cc

**System Information** Operating system: Linux-5.8.0-36-generic-x86_64-with-debian-bullseye-sid 64 Bits Graphics card: SVGA3D; build: RELEASE; LLVM; VMware, Inc. 3.3 (Core Profile) Mesa 20.0.8 **Blender Version** Broken: version: - 2.92.0 Alpha, branch: master, commit date: 2021-01-08 10:20, hash: `03f1d8acab` - 2.91.0 Worked: 2.83.x **Short description of error** When an NLA track is deleted and the *NLA tracks* entry in the Outliner is expanded to show the hierarchy below, ASAN detects a use-after-free. **Exact steps for others to reproduce the error** - Open the attached file. - Delete *NlaTrack* in the *Nonlinear Animation* editor. # Expand the *Scene Collection > Collection > Cube > Animation > NLA tracks* entry. [#84586.blend](https://archive.blender.org/developer/F9559547/T84586.blend) Alternatively: - Create a keyframe animation. - Open the *Nonlinear Animation* editor. - Use *Push Down Action*. - Delete the track. # In the *Outliner* find the *NLA tracks* entry and try to expand the hierarchy below it by clicking on the triangle icon. ```lines ## 3185==ERROR: AddressSanitizer: heap-use-after-free on address 0x60b0005ced50 at pc 0x00001704cf5f bp 0x7fffffffa460 sp 0x7fffffffa450 READ of size 1 at 0x60b0005ced50 thread T0 - 0 0x1704cf5e in BLF_draw /home/dev/01-data/01-git/blender-git/blender/source/blender/blenfont/intern/blf.c:544 - 1 0x9353246 in UI_fontstyle_draw_simple /home/dev/01-data/01-git/blender-git/blender/source/blender/editors/interface/interface_style.c:311 - 2 0x982ce06 in outliner_draw_tree_element /home/dev/01-data/01-git/blender-git/blender/source/blender/editors/space_outliner/outliner_draw.c:3114 - 3 0x982dc0f in outliner_draw_tree_element /home/dev/01-data/01-git/blender-git/blender/source/blender/editors/space_outliner/outliner_draw.c:3162 - 4 0x982dc0f in outliner_draw_tree_element /home/dev/01-data/01-git/blender-git/blender/source/blender/editors/space_outliner/outliner_draw.c:3162 - 5 0x982dc0f in outliner_draw_tree_element /home/dev/01-data/01-git/blender-git/blender/source/blender/editors/space_outliner/outliner_draw.c:3162 - 6 0x982dc0f in outliner_draw_tree_element /home/dev/01-data/01-git/blender-git/blender/source/blender/editors/space_outliner/outliner_draw.c:3162 - 7 0x982dc0f in outliner_draw_tree_element /home/dev/01-data/01-git/blender-git/blender/source/blender/editors/space_outliner/outliner_draw.c:3162 - 8 0x982dc0f in outliner_draw_tree_element /home/dev/01-data/01-git/blender-git/blender/source/blender/editors/space_outliner/outliner_draw.c:3162 - 9 0x9833197 in outliner_draw_tree /home/dev/01-data/01-git/blender-git/blender/source/blender/editors/space_outliner/outliner_draw.c:3508 - 10 0x9834a1b in draw_outliner /home/dev/01-data/01-git/blender-git/blender/source/blender/editors/space_outliner/outliner_draw.c:3637 - 11 0x98843db in outliner_main_region_draw /home/dev/01-data/01-git/blender-git/blender/source/blender/editors/space_outliner/space_outliner.c:92 - 12 0x7909e1c in ED_region_do_draw /home/dev/01-data/01-git/blender-git/blender/source/blender/editors/screen/area.c:546 - 13 0x4fd2335 in wm_draw_window_offscreen /home/dev/01-data/01-git/blender-git/blender/source/blender/windowmanager/intern/wm_draw.c:731 - 14 0x4fd3557 in wm_draw_window /home/dev/01-data/01-git/blender-git/blender/source/blender/windowmanager/intern/wm_draw.c:872 - 15 0x4fd49c7 in wm_draw_update /home/dev/01-data/01-git/blender-git/blender/source/blender/windowmanager/intern/wm_draw.c:1073 - 16 0x4fc4fa7 in WM_main /home/dev/01-data/01-git/blender-git/blender/source/blender/windowmanager/intern/wm.c:641 - 17 0x3523a3a in main /home/dev/01-data/01-git/blender-git/blender/source/creator/creator.c:522 - 18 0x7ffff6e490b2 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x270b2) - 19 0x3522bed in _start (/home/dev/01-data/01-git/blender-git/build_linux_debug_full/bin/blender+0x3522bed) 0x60b0005ced50 is located 48 bytes inside of 112-byte region [0x60b0005ced20,0x60b0005ced90) freed by thread T0 here: - 0 0x7ffff76907cf in __interceptor_free (/lib/x86_64-linux-gnu/libasan.so.5+0x10d7cf) - 1 0x18fba180 in MEM_lockfree_freeN /home/dev/01-data/01-git/blender-git/blender/intern/guardedalloc/intern/mallocn_lockfree_impl.c:129 - 2 0x18c3d585 in BLI_freelinkN /home/dev/01-data/01-git/blender-git/blender/source/blender/blenlib/intern/listbase.c:290 - 3 0x392af3c in BKE_nlatrack_free /home/dev/01-data/01-git/blender-git/blender/source/blender/blenkernel/intern/nla.c:131 - 4 0x973eeaf in nlaedit_delete_tracks_exec /home/dev/01-data/01-git/blender-git/blender/source/blender/editors/space_nla/nla_channels.c:814 - 5 0x4fe1cf2 in wm_operator_invoke /home/dev/01-data/01-git/blender-git/blender/source/blender/windowmanager/intern/wm_event_system.c:1312 - 6 0x4fe9aec in wm_handler_operator_call /home/dev/01-data/01-git/blender-git/blender/source/blender/windowmanager/intern/wm_event_system.c:2141 - 7 0x4fed63b in wm_handlers_do_keymap_with_keymap_handler /home/dev/01-data/01-git/blender-git/blender/source/blender/windowmanager/intern/wm_event_system.c:2466 - 8 0x4ff0dee in wm_handlers_do_intern /home/dev/01-data/01-git/blender-git/blender/source/blender/windowmanager/intern/wm_event_system.c:2762 - 9 0x4ff207c in wm_handlers_do /home/dev/01-data/01-git/blender-git/blender/source/blender/windowmanager/intern/wm_event_system.c:2886 - 10 0x4ff83f3 in wm_event_do_handlers /home/dev/01-data/01-git/blender-git/blender/source/blender/windowmanager/intern/wm_event_system.c:3382 - 11 0x4fc4f8f in WM_main /home/dev/01-data/01-git/blender-git/blender/source/blender/windowmanager/intern/wm.c:635 - 12 0x3523a3a in main /home/dev/01-data/01-git/blender-git/blender/source/creator/creator.c:522 - 13 0x7ffff6e490b2 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x270b2) previously allocated by thread T0 here: - 0 0x7ffff7690bc8 in malloc (/lib/x86_64-linux-gnu/libasan.so.5+0x10dbc8) - 1 0x18fbabe0 in MEM_lockfree_mallocN /home/dev/01-data/01-git/blender-git/blender/intern/guardedalloc/intern/mallocn_lockfree_impl.c:276 - 2 0x18fba2ea in MEM_lockfree_dupallocN /home/dev/01-data/01-git/blender-git/blender/intern/guardedalloc/intern/mallocn_lockfree_impl.c:145 - 3 0x392b8ab in BKE_nlatrack_copy /home/dev/01-data/01-git/blender-git/blender/source/blender/blenkernel/intern/nla.c:237 - 4 0x6e52b9b in rna_NLA_tracks_override_apply /home/dev/01-data/01-git/blender-git/blender/source/blender/makesrna/intern/rna_animation.c:780 - 5 0x6dfd3a4 in rna_property_override_operation_apply /home/dev/01-data/01-git/blender-git/blender/source/blender/makesrna/intern/rna_access_compare_override.c:616 - 6 0x6e01497 in rna_property_override_apply_ex /home/dev/01-data/01-git/blender-git/blender/source/blender/makesrna/intern/rna_access_compare_override.c:1098 - 7 0x6e01d70 in RNA_struct_override_apply /home/dev/01-data/01-git/blender-git/blender/source/blender/makesrna/intern/rna_access_compare_override.c:1155 - 8 0x3789d1d in BKE_lib_override_library_update /home/dev/01-data/01-git/blender-git/blender/source/blender/blenkernel/intern/lib_override.c:1818 - 9 0x378ae17 in BKE_lib_override_library_main_update /home/dev/01-data/01-git/blender-git/blender/source/blender/blenkernel/intern/lib_override.c:1885 - 10 0x5140288 in blo_read_file_internal /home/dev/01-data/01-git/blender-git/blender/source/blender/blenloader/intern/readfile.c:4133 - 11 0x51139b0 in BLO_read_from_file /home/dev/01-data/01-git/blender-git/blender/source/blender/blenloader/intern/readblenentry.c:368 - 12 0x9dfd740 in BKE_blendfile_read_ex /home/dev/01-data/01-git/blender-git/blender/source/blender/blenkernel/intern/blendfile.c:446 - 13 0x9dfd8ea in BKE_blendfile_read /home/dev/01-data/01-git/blender-git/blender/source/blender/blenkernel/intern/blendfile.c:468 - 14 0x5012456 in WM_file_read /home/dev/01-data/01-git/blender-git/blender/source/blender/windowmanager/intern/wm_files.c:717 - 15 0x501d5a6 in wm_file_read_opwrap /home/dev/01-data/01-git/blender-git/blender/source/blender/windowmanager/intern/wm_files.c:2185 - 16 0x501e82a in wm_open_mainfile__open /home/dev/01-data/01-git/blender-git/blender/source/blender/windowmanager/intern/wm_files.c:2325 - 17 0x501d911 in operator_state_dispatch /home/dev/01-data/01-git/blender-git/blender/source/blender/windowmanager/intern/wm_files.c:2221 - 18 0x501ea9f in wm_open_mainfile_dispatch /home/dev/01-data/01-git/blender-git/blender/source/blender/windowmanager/intern/wm_files.c:2349 - 19 0x501de16 in wm_open_mainfile__discard_changes /home/dev/01-data/01-git/blender-git/blender/source/blender/windowmanager/intern/wm_files.c:2266 - 20 0x501d911 in operator_state_dispatch /home/dev/01-data/01-git/blender-git/blender/source/blender/windowmanager/intern/wm_files.c:2221 - 21 0x501ea9f in wm_open_mainfile_dispatch /home/dev/01-data/01-git/blender-git/blender/source/blender/windowmanager/intern/wm_files.c:2349 - 22 0x501eacc in wm_open_mainfile_invoke /home/dev/01-data/01-git/blender-git/blender/source/blender/windowmanager/intern/wm_files.c:2354 - 23 0x4fe1725 in wm_operator_invoke /home/dev/01-data/01-git/blender-git/blender/source/blender/windowmanager/intern/wm_event_system.c:1300 - 24 0x4fe37c3 in wm_operator_call_internal /home/dev/01-data/01-git/blender-git/blender/source/blender/windowmanager/intern/wm_event_system.c:1541 - 25 0x4fe38bc in WM_operator_name_call_ptr /home/dev/01-data/01-git/blender-git/blender/source/blender/windowmanager/intern/wm_event_system.c:1555 - 26 0x91ce62a in ui_apply_but_funcs_after /home/dev/01-data/01-git/blender-git/blender/source/blender/editors/interface/interface_handlers.c:939 - 27 0x9259475 in ui_popup_handler /home/dev/01-data/01-git/blender-git/blender/source/blender/editors/interface/interface_handlers.c:10937 - 28 0x4fdaec6 in wm_handler_ui_call /home/dev/01-data/01-git/blender-git/blender/source/blender/windowmanager/intern/wm_event_system.c:643 - 29 0x4ff103a in wm_handlers_do_intern /home/dev/01-data/01-git/blender-git/blender/source/blender/windowmanager/intern/wm_event_system.c:2778 SUMMARY: AddressSanitizer: heap-use-after-free /home/dev/01-data/01-git/blender-git/blender/source/blender/blenfont/intern/blf.c:544 in BLF_draw Shadow bytes around the buggy address: 0x0c16800b1d50: 00 00 00 00 00 00 00 00 00 00 fa fa fa fa fa fa 0x0c16800b1d60: fa fa 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0x0c16800b1d70: fa fa fa fa fa fa fa fa 00 00 00 00 00 00 00 00 0x0c16800b1d80: 00 00 00 00 00 00 fa fa fa fa fa fa fa fa 00 00 0x0c16800b1d90: 00 00 00 00 00 00 00 00 00 00 00 00 fa fa fa fa # >0x0c16800b1da0: fa fa fa fa fd fd fd fd fd fd[fd]fd fd fd fd fd 0x0c16800b1db0: fd fd fa fa fa fa fa fa fa fa 00 00 00 00 00 00 0x0c16800b1dc0: 00 00 00 00 00 00 00 00 fa fa fa fa fa fa fa fa 0x0c16800b1dd0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 fa fa 0x0c16800b1de0: fa fa fa fa fa fa 00 00 00 00 00 00 00 00 00 00 0x0c16800b1df0: 00 00 00 fa fa fa fa fa fa fa fa fa 00 00 00 00 Shadow byte legend (one shadow byte represents 8 application bytes): ``` Addressable: 00 Partially addressable: 01 02 03 04 05 06 07 Heap left redzone: fa Freed heap region: fd Stack left redzone: f1 Stack mid redzone: f2 Stack right redzone: f3 Stack after return: f5 Stack use after scope: f8 Global redzone: f9 Global init order: f6 Poisoned by user: f7 Container overflow: fc Array cookie: ac Intra object redzone: bb ASan internal: fe Left alloca redzone: ca Right alloca redzone: cb Shadow gap: cc ``` ```
Author
Member

Added subscriber: @rjg

Added subscriber: @rjg
Author
Member

Changed status from 'Needs Triage' to: 'Confirmed'

Changed status from 'Needs Triage' to: 'Confirmed'
Author
Member

Unlike 2.83.x it seems that 2.91 and later keeps a reference around to the NLA that has already been removed. In 2.83 the entry disappears in the Outliner once you click on it.

Unlike 2.83.x it seems that 2.91 and later keeps a reference around to the NLA that has already been removed. In 2.83 the entry disappears in the Outliner once you click on it.
Member

Added subscriber: @lichtwerk

Added subscriber: @lichtwerk
Philipp Oeser self-assigned this 2021-01-11 11:55:57 +01:00
Member

Will check on this

Will check on this

This issue was referenced by b4530deec4

This issue was referenced by b4530deec478e1982156a2a76bd4bdadaf651fb3
Member

Changed status from 'Confirmed' to: 'Resolved'

Changed status from 'Confirmed' to: 'Resolved'
Thomas Dinges added this to the 2.91 milestone 2023-02-08 16:20:07 +01:00
Sign in to join this conversation.
No Label
Interest
Alembic
Interest
Animation & Rigging
Interest
Asset Browser
Interest
Asset Browser Project Overview
Interest
Audio
Interest
Automated Testing
Interest
Blender Asset Bundle
Interest
BlendFile
Interest
Collada
Interest
Compatibility
Interest
Compositing
Interest
Core
Interest
Cycles
Interest
Dependency Graph
Interest
Development Management
Interest
EEVEE
Interest
EEVEE & Viewport
Interest
Freestyle
Interest
Geometry Nodes
Interest
Grease Pencil
Interest
ID Management
Interest
Images & Movies
Interest
Import Export
Interest
Line Art
Interest
Masking
Interest
Metal
Interest
Modeling
Interest
Modifiers
Interest
Motion Tracking
Interest
Nodes & Physics
Interest
OpenGL
Interest
Overlay
Interest
Overrides
Interest
Performance
Interest
Physics
Interest
Pipeline, Assets & IO
Interest
Platforms, Builds & Tests
Interest
Python API
Interest
Render & Cycles
Interest
Render Pipeline
Interest
Sculpt, Paint & Texture
Interest
Text Editor
Interest
Translations
Interest
Triaging
Interest
Undo
Interest
USD
Interest
User Interface
Interest
UV Editing
Interest
VFX & Video
Interest
Video Sequencer
Interest
Virtual Reality
Interest
Vulkan
Interest
Wayland
Interest
Workbench
Interest: X11
Legacy
Blender 2.8 Project
Legacy
Milestone 1: Basic, Local Asset Browser
Legacy
OpenGL Error
Meta
Good First Issue
Meta
Papercut
Meta
Retrospective
Meta
Security
Module
Animation & Rigging
Module
Core
Module
Development Management
Module
EEVEE & Viewport
Module
Grease Pencil
Module
Modeling
Module
Nodes & Physics
Module
Pipeline, Assets & IO
Module
Platforms, Builds & Tests
Module
Python API
Module
Render & Cycles
Module
Sculpt, Paint & Texture
Module
Triaging
Module
User Interface
Module
VFX & Video
Platform
FreeBSD
Platform
Linux
Platform
macOS
Platform
Windows
Priority
High
Priority
Low
Priority
Normal
Priority
Unbreak Now!
Status
Archived
Status
Confirmed
Status
Duplicate
Status
Needs Info from Developers
Status
Needs Information from User
Status
Needs Triage
Status
Resolved
Type
Bug
Type
Design
Type
Known Issue
Type
Patch
Type
Report
Type
To Do
No Milestone
No project
No Assignees
3 Participants
Notifications
Due Date
The due date is invalid or out of range. Please use the format 'yyyy-mm-dd'.

No due date set.

Dependencies

No dependencies set.

Reference: blender/blender#84586
No description provided.