Jemalloc SEGV for 1MB chunk

Bernd Walter ticso at cicely7.cicely.de
Thu Jan 29 04:28:24 PST 2009


On Wed, Jan 28, 2009 at 05:31:43PM +0530, Channa wrote:
> Hi,
> Thanks for your reply.
> You mean to say i should modify the test as below:
> 
> #include <stdio.h>
> #include <stdlib.h>
> #include <string.h>
> 
> 
> int main()
> {
> int i;
> char *buf;
> size_t size = 1048576 ;
> 
>         buf = malloc(size);
>   for (i = 0; i <= 1048575; i++)
>     buf[i] = 'a';
> buf[size]='\0';
> printf("The length of buff is : %d\n",strlen(buf));
> free(buf);
> return 0;
> }
> 
> I NULL terminated the string
> buf[size] = '\0'  <== The last character is NULL
> 
> But still i get a SEGV at strlen.
> 
> Could you please tell me if my changes above are correct?

buf[size - 1]='\0';

It should panic with this line instead of strlen, because you tried
writing one byte behind allocation.
Originally your code wasn't terminating the string at all so strlen
was the first one to access behind allocation.

-- 
B.Walter <bernd at bwct.de> http://www.bwct.de
Modbus/TCP Ethernet I/O Baugruppen, ARM basierte FreeBSD Rechner uvm.


More information about the freebsd-current mailing list