You are not logged in.

#1 2019-01-13 21:53:19

FirefighterBlu3
Member
Registered: 2015-02-27
Posts: 10

[Solved] Blender startup crash, dlopen() libgobject-2.0 version bounds

Currently:
kernel 4.20.0-arch1-1-ARCH
nvidia 415.25-5
blender 17:2.79.b.git4.2c0c1f49-2
xorg-server 1.20.3-1

Same versions on my laptop. Works on my laptop, but not on my desktop - segfault on startup.

#backtrace

#0  0x0000555556114610 in sig_handle_crash (signum=11)
    at /usr/src/debug/blender-2.79.b.git4.2c0c1f49/source/creator/creator_signals.c:119
#1  0x00007ffff213ae00 in <signal handler called> () at /usr/lib/libc.so.6
#2  0x00007ffff7fe0005 in elf_machine_rela
    (skip_ifunc=0, reloc_addr_arg=0x7fffe3468ab0, version=0x30, sym=0x7fffe3415a08, reloc=0x7fffe341da78, map=0x7fffdb4e5100)
    at ../sysdeps/x86_64/dl-machine.h:308
#3  0x00007ffff7fe0005 in elf_dynamic_do_Rela
    (skip_ifunc=0, lazy=<optimized out>, nrelative=<optimized out>, relsize=<optimized out>, reladdr=<optimized out>, map=0x7fffdb4e5100) at do-re
#4  0x00007ffff7fe0005 in _dl_relocate_object
    (scope=<optimized out>, reloc_mode=reloc_mode@entry=1, consider_profiling=<optimized out>, consider_profiling@entry=0)
    at dl-reloc.c:258
#5  0x00007ffff7fe7406 in dl_open_worker (a=a@entry=0x7fffffffba30) at dl-open.c:366
#6  0x00007ffff223af27 in __GI__dl_catch_exception (exception=<optimized out>, operate=<optimized out>, args=<optimized out>)
    at dl-error-skeleton.c:196
#7  0x00007ffff7fe6dff in _dl_open
    (file=0x7fffc5dc228a "libc.so.6", mode=-2147483647, caller_dlopen=0x7fffc5d6ae15, nsid=<optimized out>, argc=2, argv=0x7fffffffde88, env=0x7ff
#8  0x00007ffff22c815a in dlopen_doit (a=a@entry=0x7fffffffbc50) at dlopen.c:66
#9  0x00007ffff223af27 in __GI__dl_catch_exception
    (exception=exception@entry=0x7fffffffbbf0, operate=<optimized out>, args=<optimized out>) at dl-error-skeleton.c:196
#10 0x00007ffff223afc3 in __GI__dl_catch_error
    (objname=0x7fffe3009010, errstring=0x7fffe3009018, mallocedp=0x7fffe3009008, operate=<optimized out>, args=<optimized out>)
    at dl-error-skeleton.c:215
#11 0x00007ffff22c88bf in _dlerror_run (operate=operate@entry=0x7ffff22c8100 <dlopen_doit>, args=args@entry=0x7fffffffbc50)
    at dlerror.c:163
#12 0x00007ffff22c81fa in __dlopen (file=<optimized out>, mode=<optimized out>) at dlopen.c:87
#13 0x00007fffc5d6ae15 in  () at /usr/lib/libGLX_nvidia.so.0
#14 0x00007fffc5d0ef10 in  () at /usr/lib/libGLX_nvidia.so.0
#15 0x00007ffff7fe350a in call_init
    (l=0x7fffdb4e3300, argc=argc@entry=2, argv=argv@entry=0x7fffffffde88, env=env@entry=0x7fffffffdea0) at dl-init.c:58
#16 0x00007ffff7fe364a in call_init (env=0x7fffffffdea0, argv=0x7fffffffde88, argc=2, l=<optimized out>) at dl-init.c:30
#17 0x00007ffff7fe364a in _dl_init (main_map=main_map@entry=0x7fffdb4e3300, argc=2, argv=0x7fffffffde88, env=0x7fffffffdea0)
    at dl-init.c:119
#18 0x00007ffff7fe7533 in dl_open_worker (a=a@entry=0x7fffffffbf80) at dl-open.c:506
#19 0x00007ffff223af27 in __GI__dl_catch_exception (exception=<optimized out>, operate=<optimized out>, args=<optimized out>)
    at dl-error-skeleton.c:196
#20 0x00007ffff7fe6dff in _dl_open
    (file=0x7fffe23ed900 "libGLX_nvidia.so.0", mode=-2147483647, caller_dlopen=0x7fffe5856635 <__glXLookupVendorByName+3586>, nsid=<optimized out>
#21 0x00007ffff22c815a in dlopen_doit (a=a@entry=0x7fffffffc1a0) at dlopen.c:66
#22 0x00007ffff223af27 in __GI__dl_catch_exception
    (exception=exception@entry=0x7fffffffc140, operate=<optimized out>, args=<optimized out>) at dl-error-skeleton.c:196
#23 0x00007ffff223afc3 in __GI__dl_catch_error
    (objname=0x7fffe3009010, errstring=0x7fffe3009018, mallocedp=0x7fffe3009008, operate=<optimized out>, args=<optimized out>)
    at dl-error-skeleton.c:215
#24 0x00007ffff22c88bf in _dlerror_run (operate=operate@entry=0x7ffff22c8100 <dlopen_doit>, args=args@entry=0x7fffffffc1a0)
    at dlerror.c:163
#25 0x00007ffff22c81fa in __dlopen (file=<optimized out>, mode=<optimized out>) at dlopen.c:87
#26 0x00007fffe5856635 in __glXLookupVendorByName (vendorName=0x7fffe30081a8 "nvidia") at libglxmapping.c:430

# strace snippet

[pid  7641] openat(AT_FDCWD, "/usr/lib/libGLX_nvidia.so.0", O_RDONLY|O_CLOEXEC) = 9
[pid  7641] read(9, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0p\377\4\0\0\0\0\0@\0\0\0\0\0\0\0\220r\23\0\0\0\0\0\0\0\0\0@\08\0\4\0@\0\26\0\25
[pid  7641] fstat(9, {st_mode=S_IFREG|0755, st_size=1275920, ...}) = 0
[pid  7641] mmap(NULL, 3403272, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 9, 0) = 0x7ff1eb0c0000
[pid  7641] mprotect(0x7ff1eb1d3000, 2093056, PROT_NONE) = 0
[pid  7641] mmap(0x7ff1eb3d2000, 155648, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 9, 0x112000) = 0x7ff1eb3d2000
[pid  7641] mmap(0x7ff1eb3f8000, 28168, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x7ff1eb3f8000
[pid  7641] close(9)                    = 0
[pid  7641] openat(AT_FDCWD, "/usr/lib/libnvidia-tls.so.415.25", O_RDONLY|O_CLOEXEC) = 9
[pid  7641] read(9, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\240\t\0\0\0\0\0\0@\0\0\0\0\0\0\0P3\0\0\0\0\0\0\0\0\0\0@\08\0\6\0@\0\25\0\24\0\
[pid  7641] lseek(9, 11136, SEEK_SET)   = 11136
[pid  7641] read(9, "\4\0\0\0\20\0\0\0\1\0\0\0GNU\0\0\0\0\0\2\0\0\0\3\0\0\0c\0\0\0", 32) = 32
[pid  7641] fstat(9, {st_mode=S_IFREG|0755, st_size=14480, ...}) = 0
[pid  7641] lseek(9, 11136, SEEK_SET)   = 11136
[pid  7641] read(9, "\4\0\0\0\20\0\0\0\1\0\0\0GNU\0\0\0\0\0\2\0\0\0\3\0\0\0c\0\0\0", 32) = 32
[pid  7641] mmap(NULL, 2110752, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 9, 0) = 0x7ff1eaebc000
[pid  7641] mprotect(0x7ff1eaebf000, 2097152, PROT_NONE) = 0
[pid  7641] mmap(0x7ff1eb0bf000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 9, 0x3000) = 0x7ff1eb0bf000
[pid  7641] close(9)                    = 0
[pid  7641] openat(AT_FDCWD, "/usr/lib/libnvidia-glcore.so.415.25", O_RDONLY|O_CLOEXEC) = 9
[pid  7641] read(9, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\220\30'\0\0\0\0\0@\0\0\0\0\0\0\0\310V\241\1\0\0\0\0\0\0\0\0@\08\0\5\0@\0\32\0\
[pid  7641] fstat(9, {st_mode=S_IFREG|0755, st_size=27352392, ...}) = 0
[pid  7641] mmap(NULL, 29539776, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 9, 0) = 0x7ff1e9290000
[pid  7641] mprotect(0x7ff1ea983000, 2097152, PROT_NONE) = 0
[pid  7641] mmap(0x7ff1eab83000, 3289088, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 9, 0x16f3000) = 0x7ff1eab83000
[pid  7641] mmap(0x7ff1eaea6000, 89536, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x7ff1eaea6000
[pid  7641] close(9)                    = 0
[pid  7641] --- SIGSEGV {si_signo=SIGSEGV, si_code=SEGV_MAPERR, si_addr=0x38} ---

I'm suspecting hidden corruption from somewhere as libgobject is not an uncommon library.

Carefully stepping through things with GDB, the bad version=0x30 value is set in glibc/elf/do-rel.h lines 121 to 136 by map->l_versions being 0x0 and line 136 resolving to 0x30.

    121           const ElfW(Half) *const version =
    122             (const void *) D_PTR (map, l_info[VERSYMIDX (DT_VERSYM)]);
    123 
    124           for (; r < end; ++r)
    125             {
    126 #if defined ELF_MACHINE_IRELATIVE && !defined RTLD_BOOTSTRAP
    127               if (ELFW(R_TYPE) (r->r_info) == ELF_MACHINE_IRELATIVE)
    128                 {
    129                   if (r2 == NULL)
    130                     r2 = r;
    131                   end2 = r;
    132                   continue;
    133                 }
    134 #endif
    135 
    136               ElfW(Half) ndx = version[ELFW(R_SYM) (r->r_info)] & 0x7fff;
    137               elf_machine_rel (map, r, &symtab[ELFW(R_SYM) (r->r_info)],
    138                                &map->l_versions[ndx],
    139                                (void *) (l_addr + r->r_offset), skip_ifunc);
    140             }

Anyone else having a similar issue with blender and have any info?

Last edited by FirefighterBlu3 (2019-01-18 20:31:05)

Offline

#2 2019-01-14 01:40:22

FirefighterBlu3
Member
Registered: 2015-02-27
Posts: 10

Re: [Solved] Blender startup crash, dlopen() libgobject-2.0 version bounds

(obsolete content)

Last edited by FirefighterBlu3 (2019-01-16 18:41:05)

Offline

#3 2019-01-14 16:12:54

FirefighterBlu3
Member
Registered: 2015-02-27
Posts: 10

Re: [Solved] Blender startup crash, dlopen() libgobject-2.0 version bounds

(obsolete content)

Last edited by FirefighterBlu3 (2019-01-16 18:41:44)

Offline

#4 2019-01-14 16:21:53

ewaller
Administrator
From: Pasadena, CA
Registered: 2009-07-13
Posts: 20,701

Re: [Solved] Blender startup crash, dlopen() libgobject-2.0 version bounds

Please edit your posts to use BBCode code tags around your program output.

https://bbs.archlinux.org/help.php#bbcode


Nothing is too wonderful to be true, if it be consistent with the laws of nature -- Michael Faraday
The shortest way to ruin a country is to give power to demagogues.— Dionysius of Halicarnassus
---
How to Ask Questions the Smart Way

Offline

#5 2019-01-14 16:24:34

V1del
Forum Moderator
Registered: 2012-10-16
Posts: 25,376

Re: [Solved] Blender startup crash, dlopen() libgobject-2.0 version bounds

Please wrap output in [ code ] tags and don't bump your thread each time a new thought occurs to you, you can use the edit functionality to append new information.

What's your general GL setup? Outputs of

pacman -Qs libgl
glxinfo | grep OpenGL #Needs mesa-demos

Offline

#6 2019-01-16 18:26:28

FirefighterBlu3
Member
Registered: 2015-02-27
Posts: 10

Re: [Solved] Blender startup crash, dlopen() libgobject-2.0 version bounds

I'll edit my above posts and remove the GL data as it's not relevant now.

Deep diving into the internals of things, it turns out not to be a GL thing at all but an index error on libgobject version maps. I'll paste some info I've shared with glibc maintainers.

Short story; rebooted, blender crashes on launch, segfault in RESOLVE_MAP() macro.

The library associated with this segfault is libgobject-2.0.so.0.5800.2, standard package update from some time back.

In elf_dynamic_do_Rel(), version and ndx are calculated incorrectly between do-rel.h:121 and 136. 'ndx' is 2, map->l_versions is 0x0 and therefore address obtained from "&map->l_versions[ndx]" is yielding 0x30 which will eventually generate a segmentation fault in the RESOLVE_MAP macro when (version)->hash is attempted.

Thread 1 "blender" received signal SIGSEGV, Segmentation fault.
0x00007ffff7fe0005 in elf_machine_rela (skip_ifunc=0, reloc_addr_arg=0x7fffe3468ab0, version=0x30, sym=0x7fffe3415a08,
   reloc=0x7fffe341da78, map=0x7fffdb4e5100) at ../sysdeps/x86_64/dl-machine.h:308
308           struct link_map *sym_map = RESOLVE_MAP (&sym, version, r_type);

(gdb) p map->l_versions
$251 = (struct r_found_version *) 0x0
(gdb) p ndx
$252 = 2
(gdb) p &map->l_versions[2]
$253 = (struct r_found_version *) 0x30

Dynamic section at offset 0x537f8 contains 26 entries: 
 Tag        Type                         Name/Value 
0x0000000000000001 (NEEDED)             Shared library: [libpthread.so.0] 
0x0000000000000001 (NEEDED)             Shared library: [libc.so.6] 
0x0000000000000001 (NEEDED)             Shared library: [libglib-2.0.so.0] 
0x0000000000000001 (NEEDED)             Shared library: [libffi.so.6] 
0x000000000000000e (SONAME)             Library soname: [libgobject-2.0.so.0] 
0x000000000000000c (INIT)               0xb000 
0x000000000000000d (FINI)               0x3d5b8 
0x0000000000000019 (INIT_ARRAY)         0x54308 
0x000000000000001b (INIT_ARRAYSZ)       16 (bytes) 
0x000000000000001a (FINI_ARRAY)         0x54318 
0x000000000000001c (FINI_ARRAYSZ)       8 (bytes) 
0x000000006ffffef5 (GNU_HASH)           0x260 
0x0000000000000005 (STRTAB)             0x5278 
0x0000000000000006 (SYMTAB)             0x17e0 
0x000000000000000a (STRSZ)              13428 (bytes) 
0x000000000000000b (SYMENT)             24 (bytes) 
0x0000000000000007 (RELA)               0x8c20 
0x0000000000000008 (RELASZ)             7608 (bytes) 
0x0000000000000009 (RELAENT)            24 (bytes) 
0x0000000000000018 (BIND_NOW)            
0x000000006ffffffb (FLAGS_1)            Flags: NOW NODELETE 
0x000000006ffffffe (VERNEED)            0x8bd0 
0x000000006fffffff (VERNEEDNUM)         1 
0x000000006ffffff0 (VERSYM)             0x86ec 
0x000000006ffffff9 (RELACOUNT)          131 
0x0000000000000000 (NULL)               0x0

Florian suggested it was related to https://sourceware.org/bugzilla/show_bug.cgi?id=20839 and suggested LD_DEBUG however I've spent hours studying the debug output and seen nothing abnormal or functionally different from my laptop. I've been comparing installed versions of linked libraries and haven't found anything different yet, including consistency checks.

Offline

#7 2019-01-16 21:25:52

seth
Member
From: Won't reply 2 private help req
Registered: 2012-09-03
Posts: 77,796

Re: [Solved] Blender startup crash, dlopen() libgobject-2.0 version bounds

Have you tried the lts kernel or the nvidia-390xx series?

Online

#8 2019-01-17 18:38:38

maxrd2
Member
Registered: 2014-09-16
Posts: 16

Re: [Solved] Blender startup crash, dlopen() libgobject-2.0 version bounds

I have same (?) crash here after updating system few days ago.
Kernel 4.20.1-arch1-1-ARCH
nVidia 750ti 415.25-1

crashes on both:
blender 17:2.79.b.git4.2c0c1f49-2
blender-2.8-git 2.8.r84080.2d98dce7ee2-1 from AUR

tried with linux-lts-4.19.15-1 and it also crashes

Last edited by maxrd2 (2019-01-17 18:57:38)

Offline

#9 2019-01-17 18:40:26

seth
Member
From: Won't reply 2 private help req
Registered: 2012-09-03
Posts: 77,796

Re: [Solved] Blender startup crash, dlopen() libgobject-2.0 version bounds

seth wrote:

Have you tried the lts kernel or the nvidia-390xx series?

Online

#10 2019-01-17 19:20:35

maxrd2
Member
Registered: 2014-09-16
Posts: 16

Re: [Solved] Blender startup crash, dlopen() libgobject-2.0 version bounds

Tried now and updated the sys again, and it still crashes. So it crashes on:
linux 4.20.1-arch1-1-ARCH - nvidia 415.25-1 - blender 17:2.79.b.git4.2c0c1f49-2
linux 4.20.1-arch1-1-ARCH - nvidia 415.25-1 - blender-2.8-git 2.8.r84080.2d98dce7ee2-1
linux-lts-4.19.15-1 - nvidia 415.25-1 - blender 17:2.79.b.git4.2c0c1f49-2
linux 4.20.3-arch1-1-ARCH - nvidia-390xx 390.87-28 - blender 17:2.79.b.git4.2c0c1f49-3

Offline

#11 2019-01-17 21:13:11

FirefighterBlu3
Member
Registered: 2015-02-27
Posts: 10

Re: [Solved] Blender startup crash, dlopen() libgobject-2.0 version bounds

Solved for me, aur/libunity-7.1.4-6 made blender crash. -7 was released. Compiled and installed and blender works fine. In my case it was as Florian suggested; the LD_DEBUG output showed that the libunity library was getting mapped in then destroyed. There's a subtle bug (referenced above) where link maps aren't properly cleaned up in this rare situation.

Offline

#12 2019-01-17 21:17:25

FirefighterBlu3
Member
Registered: 2015-02-27
Posts: 10

Re: [Solved] Blender startup crash, dlopen() libgobject-2.0 version bounds

@maxrd2 run blender like this: LD_DEBUG=all LD_DEBUG_OUTPUT=/tmp/blender.ldout blender. Once it's done crashing, grep for 'destroying' in the /tmp/blender.ldout.* files. Try updating/rebuilding any of these that come back.

This was mine:

┌[✓ david@Scott ~ 
└─> grep destroying /tmp/blender.ldout3.1*
/tmp/blender.ldout3.1691:      1691:    file=/usr/lib/libunity.so.9 [0];  destroying link map
/tmp/blender.ldout3.1691:      1691:    file=/usr/lib/libunity/libunity-protocol-private.so.0 [0];  destroying link map
/tmp/blender.ldout3.1691:      1691:    file=/usr/lib/libdee-1.0.so.4 [0];  destroying link map
/tmp/blender.ldout3.1691:      1691:    file=/usr/lib/libdbusmenu-glib.so.4 [0];  destroying link map
/tmp/blender.ldout3.1691:      1691:    file=/usr/lib/libnuma.so.1 [0];  destroying link map

And the problem library was libunity.

Offline

#13 2019-01-18 12:24:10

maxrd2
Member
Registered: 2014-09-16
Posts: 16

Re: [Solved] Blender startup crash, dlopen() libgobject-2.0 version bounds

Removed libunity which also removed dee, which were installed for i don't know which reason, nothing was depending on them...
and problem solved... thank you!

/tmp/blender.ldout.25603:     25603:    file=/usr/lib/libunity.so.9 [0];  destroying link map
/tmp/blender.ldout.25603:     25603:    file=/usr/lib/libunity/libunity-protocol-private.so.0 [0];  destroying link map
/tmp/blender.ldout.25603:     25603:    file=/usr/lib/libdee-1.0.so.4 [0];  destroying link map
/tmp/blender.ldout.25603:     25603:    file=/usr/lib/libdbusmenu-glib.so.4 [0];  destroying link map
/tmp/blender.ldout.25603:     25603:    file=/usr/lib/libunity.so [0];  destroying link map
/tmp/blender.ldout.25603:     25603:    file=/usr/lib/libunity/libunity-protocol-private.so.0 [0];  destroying link map
/tmp/blender.ldout.25603:     25603:    file=/usr/lib/libdee-1.0.so.4 [0];  destroying link map
/tmp/blender.ldout.25603:     25603:    file=/usr/lib/libdbusmenu-glib.so.4 [0];  destroying link map

Offline

#14 2019-01-18 13:18:28

V1del
Forum Moderator
Registered: 2012-10-16
Posts: 25,376

Re: [Solved] Blender startup crash, dlopen() libgobject-2.0 version bounds

FirefighterBl3 if this is [SOLVED] for you, can you please mark it as such in your title so that future posters might know that they could stumble over a solution here.

https://wiki.archlinux.org/index.php/Co … ow_to_post

Offline

#15 2019-01-18 20:30:08

FirefighterBlu3
Member
Registered: 2015-02-27
Posts: 10

Re: [Solved] Blender startup crash, dlopen() libgobject-2.0 version bounds

V1del yep. I was waiting to see if this fixed it for maxrd2 as well

Offline

Board footer

Powered by FluxBB