Project

General

Profile

Actions

Bug #8385

closed

RBD / QEMU Crash: Invalid fastbin entry (free)

Added by Mike Dawson almost 10 years ago. Updated almost 8 years ago.

Status:
Closed
Priority:
High
Assignee:
Target version:
-
% Done:

0%

Source:
Community (user)
Tags:
Backport:
Regression:
Severity:
2 - major
Reviewed:
Affected Versions:
ceph-qa-suite:
Pull request ID:
Crash signature (v1):
Crash signature (v2):

Description

After the fix for Issue #6480, RBD and Qemu have been much more stable on our workload. With 0.67.8 we just saw another similar crash. Josh mentioned at the time he thought he fixed most, but not all of the potential issues. It seems that there is at least one verified bug remaining.

  • Error in `qemu-system-x86_64': invalid fastbin entry (free): 0x00007f6670027f90 *** ======= Backtrace: =========
    /lib/x86_64-linux-gnu/libc.so.6(+0x80a46)[0x7f696fc5aa46]
    /usr/lib/librbd.so.1(_ZNSt10_List_baseIN4ceph6buffer3ptrESaIS2_EE8_M_clearEv+0x27)[0x7f6975c5c6b7]
    /usr/lib/librados.so.2(_ZN4Pipe6writerEv+0xb1f)[0x7f69750b1fdf]
    /usr/lib/librados.so.2(_ZN4Pipe6Writer5entryEv+0xd)[0x7f69750bcccd]
    /lib/x86_64-linux-gnu/libpthread.so.0(+0x7f8e)[0x7f696ffaaf8e]
    /lib/x86_64-linux-gnu/libc.so.6(clone+0x6d)[0x7f696fcd4a0d] ======= Memory map: ========

Unfortunately, I do not have a coredump this time. I'll set up our hosts to produce coredumps in the future.


Files

bt-vm-threaded-crash.txt (128 KB) bt-vm-threaded-crash.txt Andrey Korolyov, 08/12/2014 03:27 AM
Actions #1

Updated by Andrey Korolyov over 9 years ago

Any interest in a lookalike bug from Cuttlefish?

/lib/x86_64-linux-gnu/libc.so.6(+0x7e566)[0x7f7cd15ad566]
/usr/lib/librados.so.2(_ZN16PrioritizedQueueIN13DispatchQueue9QueueItemEmE7dequeueEv+0x21b)[0x7f7cd4b1ebdb]
/usr/lib/librados.so.2(_ZN13DispatchQueue5entryEv+0x1c7)[0x7f7cd4b1bea7]
/usr/lib/librados.so.2(_ZN13DispatchQueue14DispatchThread5entryEv+0xd)[0x7f7cd4b845ad]
/lib/x86_64-linux-gnu/libpthread.so.0(+0x7e9a)[0x7f7cd18f3e9a]
/lib/x86_64-linux-gnu/libc.so.6(clone+0x6d)[0x7f7cd16213dd]

Coredump is ten gig large and may be shared upon request along with our packages/source. Text backtrace is attached.

Actions #2

Updated by Sage Weil over 9 years ago

  • Status changed from New to Need More Info
Actions #3

Updated by Josh Durgin about 9 years ago

Are you guys still seeing this?

Actions #4

Updated by Mike Dawson about 9 years ago

Yes, we still see these crashes occasionally. We're running 0.67.9. Have not tested newer releases.

Actions #5

Updated by Josh Durgin about 8 years ago

Actions #6

Updated by Jason Dillaman almost 8 years ago

  • Status changed from Need More Info to Closed

Closing ticket as there have been no similar issues noted against Hammer or later releases.

Actions

Also available in: Atom PDF