* RE: Add HID over GATT functional tests
2026-09-23 19:31 [PATCH BlueZ v1 1/7] client/gatt: Fix setting descriptor value from scripts Luiz Augusto von Dentz
@ 2026-09-23 22:30 ` bluez.test.bot
0 siblings, 0 replies; 14+ messages in thread
From: bluez.test.bot @ 2026-09-23 22:30 UTC (permalink / raw)
To: linux-bluetooth, luiz.dentz
[-- Attachment #1: Type: text/plain, Size: 101260 bytes --]
This is automated email and please do not reply to this email!
Dear submitter,
Thank you for submitting the patches to the linux bluetooth mailing list.
This is a CI test results with your patch series:
PW Link:https://patchwork.kernel.org/series/1172525/
---Test result---
Test Summary:
CheckPatch PASS 1.65 seconds
GitLint PASS 1.25 seconds
BuildEll PASS 13.11 seconds
BluezMake PASS 203.42 seconds
MakeCheck PASS 12.97 seconds
MakeDistcheck PASS 93.61 seconds
CheckValgrind PASS 145.14 seconds
CheckSmatch PASS 164.87 seconds
bluezmakeextell PASS 58.89 seconds
TestFunctional FAIL 779.20 seconds
IncrementalBuild PASS 224.46 seconds
ScanBuild PASS 575.20 seconds
Details
##############################
Test: TestFunctional - FAIL
Desc: Run test-functional
Output:
FAIL functional.test_hog::test_hog[no-sci-hosts15-vm2]: failed on teardown with "pytest_bluezenv.plugin.CoredumpWarning: Core dump: test-bluezenv-hosts15.0-bluetoothd-1790201609-113.core
/usr/bin/gdb: warning: Couldn't determine a path for the index cache directory.
[New LWP 113]
[Thread debugging using libthread_db enabled]
Using host libthread_db library "/usr/lib/x86_64-linux-gnu/libthread_db.so.1".
Core was generated by `/home/runner/work/bluez/bluez/src/src/src/bluetoothd --nodetach -f /run/bluetoo'.
Program terminated with signal SIGABRT, Aborted.
#0 __pthread_kill_implementation (threadid=<optimized out>, signo=6, no_tid=0) at ./nptl/pthread_kill.c:44
warning: 44 ./nptl/pthread_kill.c: No such file or directory
Thread 1 (Thread 0x7fdb1a71d900 (LWP 113)):
#0 __pthread_kill_implementation (threadid=<optimized out>, signo=6, no_tid=0) at ./nptl/pthread_kill.c:44
tid = <optimized out>
ret = 0
pd = <optimized out>
old_mask = {__val = {0}}
ret = <optimized out>
#1 __pthread_kill_internal (threadid=<optimized out>, signo=6) at ./nptl/pthread_kill.c:89
No locals.
#2 __GI___pthread_kill (threadid=<optimized out>, signo=signo@entry=6) at ./nptl/pthread_kill.c:100
No locals.
#3 0x00007fdb1ae78b7e in __GI_raise (sig=sig@entry=6) at ../sysdeps/posix/raise.c:26
ret = <optimized out>
#4 0x00007fdb1ae5b8ec in __GI_abort () at ./stdlib/abort.c:77
act = {__sigaction_handler = {sa_handler = 0x0, sa_sigaction = 0x0}, sa_mask = {__val = {0 <repeats 16 times>}}, sa_flags = 0, sa_restorer = 0x0}
#5 0x00007fdb1ba83a0f in __sanitizer::Abort () at ../../../../src/libsanitizer/sanitizer_common/sanitizer_posix_libcdep.cpp:165
No locals.
#6 0x00007fdb1bba9c2d in __sanitizer::Die () at ../../../../src/libsanitizer/sanitizer_common/sanitizer_termination.cpp:58
No locals.
#7 0x00007fdb1bb7e93c in __asan::ScopedInErrorReport::~ScopedInErrorReport (this=0x7ffec9e5cd36) at ../../../../src/libsanitizer/asan/asan_report.cpp:221
buffer_copy = {buffer_ = {<__sanitizer::InternalMmapVectorNoCtor<char, false>> = {data_ = 0x7fdb1a301000 '=' <repeats 65 times>, "\n==113==ERROR: AddressSanitizer: heap-use-after-free on address 0x7c1b19c009e4 at pc 0x5642107432e3 bp 0x7ffec9e5d9b0 sp 0x7ffec9e5d9a0"..., capacity_bytes_ = 4096, size_ = 3936}, <No data fields>}}
buffer_copy = <optimized out>
l = <optimized out>
#8 0x00007fdb1bb7de02 in __asan::ReportGenericError (pc=94841743880931, bp=140732285704624, sp=sp@entry=140732285704608, addr=136455837977060, is_write=is_write@entry=true, access_size=4, fatal=true, exp=<optimized out>) at ../../../../src/libsanitizer/asan/asan_report.cpp:536
in_report = {error_report_lock_ = {<No data fields>}, static current_error_ = {kind = __asan::kErrorKindGeneric, {Base = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\360e\311\376\177\000\0002\000\000\000\000\000\000\000 %\242\030\333{\000\0001\000\000\000\000\000\000\000X\326\345\311\376\177\000\000 %\242\030\333{\000\000\300\315\345\311\376\177\000\000\037{\250\033\333\177\000\000\001\000\000\000\000\000\000\000 %\242\030\333{\000\000\020\326\345\311\376\177\000\000\322\025\267\033\333\177\000\000\000\000\000\000\000\000\000\000\305\234\270\033\036\000\000\000\360\315\345\311\376\177\000\000\003\000\000\000\000\000\000\000\020\026\267\033\333\177\000\000\217\233\354\032\333\177\000\000\v\n\241\020BV\000\000\320\330\345\311"...}, tid = 0}, DeadlySignal = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\360e\311\376\177\000\0002\000\000\000\000\000\000\000 %\242\030\333{\000\0001\000\000\000\000\000\000\000X\326\345\311\376\177\000\000 %\242\030\333{\000\000\300\315\345\311\376\177\000\000\037{\250\033\333\177\000\000\001\000\000\000\000\000\000\000 %\242\030\333{\000\000\020\326\345\311\376\177\000\000\322\025\267\033\333\177\000\000\000\000\000\000\000\000\000\000\305\234\270\033\036\000\000\000\360\315\345\311\376\177\000\000\003\000\000\000\000\000\000\000\020\026\267\033\333\177\000\000\217\233\354\032\333\177\000\000\v\n\241\020BV\000\000\320\330\345\311"...}, tid = 0}, signal = {siginfo = 0x7fdb00000002, context = 0x7c1b19c009e4, addr = 0, pc = 0, sp = 10260676871990, bp = 136455837977060, is_memory_access = 20, write_flag = __sanitizer::SignalContext::Unknown, is_true_faulting_addr = 208}}, DoubleFree = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\360e\311\376\177\000\0002\000\000\000\000\000\000\000 %\242\030\333{\000\0001\000\000\000\000\000\000\000X\326\345\311\376\177\000\000 %\242\030\333{\000\000\300\315\345\311\376\177\000\000\037{\250\033\333\177\000\000\001\000\000\000\000\000\000\000 %\242\030\333{\000\000\020\326\345\311\376\177\000\000\322\025\267\033\333\177\000\000\000\000\000\000\000\000\000\000\305\234\270\033\036\000\000\000\360\315\345\311\376\177\000\000\003\000\000\000\000\000\000\000\020\026\267\033\333\177\000\000\217\233\354\032\333\177\000\000\v\n\241\020BV\000\000\320\330\345\311"...}, tid = 0}, second_free_stack = 0x7fdb00000002, addr_description = {addr = 136455837977060, alloc_tid = 0, free_tid = 0, alloc_stack_id = 1846, free_stack_id = 2389, chunk_access = {bad_addr = 136455837977060, offset = 20, chunk_begin = 136455837977040, chunk_size = 40, user_requested_alignment = 8, access_type = 2, alloc_type = 1}}}, NewDeleteTypeMismatch = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\360e\311\376\177\000\0002\000\000\000\000\000\000\000 %\242\030\333{\000\0001\000\000\000\000\000\000\000X\326\345\311\376\177\000\000 %\242\030\333{\000\000\300\315\345\311\376\177\000\000\037{\250\033\333\177\000\000\001\000\000\000\000\000\000\000 %\242\030\333{\000\000\020\326\345\311\376\177\000\000\322\025\267\033\333\177\000\000\000\000\000\000\000\000\000\000\305\234\270\033\036\000\000\000\360\315\345\311\376\177\000\000\003\000\000\000\000\000\000\000\020\026\267\033\333\177\000\000\217\233\354\032\333\177\000\000\v\n\241\020BV\000\000\320\330\345\311"...}, tid = 0}, free_stack = 0x7fdb00000002, addr_description = {addr = 136455837977060, alloc_tid = 0, free_tid = 0, alloc_stack_id = 1846, free_stack_id = 2389, chunk_access = {bad_addr = 136455837977060, offset = 20, chunk_begin = 136455837977040, chunk_size = 40, user_requested_alignment = 8, access_type = 2, alloc_type = 1}}, delete_size = 14546846794988041728, delete_alignment = 136318399050544}, FreeNotMalloced = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\360e\311\376\177\000\0002\000\000\000\000\000\000\000 %\242\030\333{\000\0001\000\000\000\000\000\000\000X\326\345\311\376\177\000\000 %\242\030\333{\000\000\300\315\345\311\376\177\000\000\037{\250\033\333\177\000\000\001\000\000\000\000\000\000\000 %\242\030\333{\000\000\020\326\345\311\376\177\000\000\322\025\267\033\333\177\000\000\000\000\000\000\000\000\000\000\305\234\270\033\036\000\000\000\360\315\345\311\376\177\000\000\003\000\000\000\000\000\000\000\020\026\267\033\333\177\000\000\217\233\354\032\333\177\000\000\v\n\241\020BV\000\000\320\330\345\311"...}, tid = 0}, free_stack = 0x7fdb00000002, addr_description = {data = {kind = 432015844, {shadow = {addr = 0, kind = __asan::kShadowKindLow, shadow_byte = 0 '\000'}, heap = {addr = 0, alloc_tid = 0, free_tid = 10260676871990, alloc_stack_id = 432015844, free_stack_id = 31771, chunk_access = {bad_addr = 20, offset = 136455837977040, chunk_begin = 40, chunk_size = 62887350919176, user_requested_alignment = 1536, access_type = 3, alloc_type = 2}}, stack = {addr = 0, tid = 0, offset = 10260676871990, frame_pc = 136455837977060, access_size = 20, frame_descr = 0x7c1b19c009d0 "U\t"}, global = {addr = 0, static kMaxGlobals = 4, globals = {{beg = 0, size = 10260676871990, size_with_redzone = 136455837977060, name = 0x14 <error: Cannot access memory at address 0x14>, module_name = 0x7c1b19c009d0 "U\t", has_dynamic_init = 40, gcc_location = 0x39321a366008, odr_indicator = 14546846794988041728}, {beg = 136318399050544, size = 140579027621506, size_with_redzone = 140732285703143, name = 0xf <error: Cannot access memory at address 0xf>, module_name = 0x7ffec9e5d3e7 "", has_dynamic_init = 206158430224, gcc_location = 0x7ffec9e5d9c0, odr_indicator = 140732285704400}, {beg = 140579027828192, size = 140579026652003, size_with_redzone = 140579014324432, name = 0xc9e0c816694ab600 <error: Cannot access memory at address 0xc9e0c816694ab600>, module_name = 0x7c0b00000000 "", has_dynamic_init = 140732285703168, gcc_location = 0x71, odr_indicator = 136180941333664}, {beg = 140732285703168, size = 49, size_with_redzone = 140732285702928, name = 0x7fdb1ae9643c <__GI___dprintf+156> "H\213\225H\377\377\377dH+\024%(", module_name = 0x3000000020 <error: Cannot access memory at address 0x3000000020>, has_dynamic_init = 140732285702944, gcc_location = 0x7ffec9e5d260, odr_indicator = 14546846794988041728}}, reg_sites = {3387283456, 32766, 0, 0}, access_size = 140732285703188, size = 227 '\343'}, wild = {addr = 0, access_size = 0}}}}}, AllocTypeMismatch = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\360e\311\376\177\000\0002\000\000\000\000\000\000\000 %\242\030\333{\000\0001\000\000\000\000\000\000\000X\326\345\311\376\177\000\000 %\242\030\333{\000\000\300\315\345\311\376\177\000\000\037{\250\033\333\177\000\000\001\000\000\000\000\000\000\000 %\242\030\333{\000\000\020\326\345\311\376\177\000\000\322\025\267\033\333\177\000\000\000\000\000\000\000\000\000\000\305\234\270\033\036\000\000\000\360\315\345\311\376\177\000\000\003\000\000\000\000\000\000\000\020\026\267\033\333\177\000\000\217\233\354\032\333\177\000\000\v\n\241\020BV\000\000\320\330\345\311"...}, tid = 0}, dealloc_stack = 0x7fdb00000002, alloc_type = 432015844, dealloc_type = 31771, addr_description = {data = {kind = __asan::kAddressKindWild, {shadow = {addr = 0, kind = (__asan::kShadowKindHigh | unknown: 0x34), shadow_byte = 7 '\a'}, heap = {addr = 0, alloc_tid = 10260676871990, free_tid = 136455837977060, alloc_stack_id = 20, free_stack_id = 0, chunk_access = {bad_addr = 136455837977040, offset = 40, chunk_begin = 62887350919176, chunk_size = 14546846794988041728, user_requested_alignment = 816, access_type = 3, alloc_type = 1}}, stack = {addr = 0, tid = 10260676871990, offset = 136455837977060, frame_pc = 20, access_size = 136455837977040, frame_descr = 0x28 <error: Cannot access memory at address 0x28>}, global = {addr = 0, static kMaxGlobals = 4, globals = {{beg = 10260676871990, size = 136455837977060, size_with_redzone = 20, name = 0x7c1b19c009d0 "U\t", module_name = 0x28 <error: Cannot access memory at address 0x28>, has_dynamic_init = 62887350919176, gcc_location = 0xc9e0c816694ab600, odr_indicator = 136318399050544}, {beg = 140579027621506, size = 140732285703143, size_with_redzone = 15, name = 0x7ffec9e5d3e7 "", module_name = 0x3000000010 <error: Cannot access memory at address 0x3000000010>, has_dynamic_init = 140732285704640, gcc_location = 0x7ffec9e5d8d0, odr_indicator = 140579027828192}, {beg = 140579026652003, size = 140579014324432, size_with_redzone = 14546846794988041728, name = 0x7c0b00000000 "", module_name = 0x7ffec9e5d400 "f\235\270\033\333\177", has_dynamic_init = 113, gcc_location = 0x7bdb18a224a0, odr_indicator = 140732285703168}, {beg = 49, size = 140732285702928, size_with_redzone = 140579026068540, name = 0x3000000020 <error: Cannot access memory at address 0x3000000020>, module_name = 0x7ffec9e5d320 "\037{\250\033\333\177", has_dynamic_init = 140732285702752, gcc_location = 0xc9e0c816694ab600, odr_indicator = 140732285704192}}, reg_sites = {0, 0, 3387282452, 32766}, access_size = 94841743880931, size = 176 '\260'}, wild = {addr = 0, access_size = 10260676871990}}}}}, MallocUsableSizeNotOwned = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\360e\311\376\177\000\0002\000\000\000\000\000\000\000 %\242\030\333{\000\0001\000\000\000\000\000\000\000X\326\345\311\376\177\000\000 %\242\030\333{\000\000\300\315\345\311\376\177\000\000\037{\250\033\333\177\000\000\001\000\000\000\000\000\000\000 %\242\030\333{\000\000\020\326\345\311\376\177\000\000\322\025\267\033\333\177\000\000\000\000\000\000\000\000\000\000\305\234\270\033\036\000\000\000\360\315\345\311\376\177\000\000\003\000\000\000\000\000\000\000\020\026\267\033\333\177\000\000\217\233\354\032\333\177\000\000\v\n\241\020BV\000\000\320\330\345\311"...}, tid = 0}, stack = 0x7fdb00000002, addr_description = {data = {kind = 432015844, {shadow = {addr = 0, kind = __asan::kShadowKindLow, shadow_byte = 0 '\000'}, heap = {addr = 0, alloc_tid = 0, free_tid = 10260676871990, alloc_stack_id = 432015844, free_stack_id = 31771, chunk_access = {bad_addr = 20, offset = 136455837977040, chunk_begin = 40, chunk_size = 62887350919176, user_requested_alignment = 1536, access_type = 3, alloc_type = 2}}, stack = {addr = 0, tid = 0, offset = 10260676871990, frame_pc = 136455837977060, access_size = 20, frame_descr = 0x7c1b19c009d0 "U\t"}, global = {addr = 0, static kMaxGlobals = 4, globals = {{beg = 0, size = 10260676871990, size_with_redzone = 136455837977060, name = 0x14 <error: Cannot access memory at address 0x14>, module_name = 0x7c1b19c009d0 "U\t", has_dynamic_init = 40, gcc_location = 0x39321a366008, odr_indicator = 14546846794988041728}, {beg = 136318399050544, size = 140579027621506, size_with_redzone = 140732285703143, name = 0xf <error: Cannot access memory at address 0xf>, module_name = 0x7ffec9e5d3e7 "", has_dynamic_init = 206158430224, gcc_location = 0x7ffec9e5d9c0, odr_indicator = 140732285704400}, {beg = 140579027828192, size = 140579026652003, size_with_redzone = 140579014324432, name = 0xc9e0c816694ab600 <error: Cannot access memory at address 0xc9e0c816694ab600>, module_name = 0x7c0b00000000 "", has_dynamic_init = 140732285703168, gcc_location = 0x71, odr_indicator = 136180941333664}, {beg = 140732285703168, size = 49, size_with_redzone = 140732285702928, name = 0x7fdb1ae9643c <__GI___dprintf+156> "H\213\225H\377\377\377dH+\024%(", module_name = 0x3000000020 <error: Cannot access memory at address 0x3000000020>, has_dynamic_init = 140732285702944, gcc_location = 0x7ffec9e5d260, odr_indicator = 14546846794988041728}}, reg_sites = {3387283456, 32766, 0, 0}, access_size = 140732285703188, size = 227 '\343'}, wild = {addr = 0, access_size = 0}}}}}, SanitizerGetAllocatedSizeNotOwned = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\360e\311\376\177\000\0002\000\000\000\000\000\000\000 %\242\030\333{\000\0001\000\000\000\000\000\000\000X\326\345\311\376\177\000\000 %\242\030\333{\000\000\300\315\345\311\376\177\000\000\037{\250\033\333\177\000\000\001\000\000\000\000\000\000\000 %\242\030\333{\000\000\020\326\345\311\376\177\000\000\322\025\267\033\333\177\000\000\000\000\000\000\000\000\000\000\305\234\270\033\036\000\000\000\360\315\345\311\376\177\000\000\003\000\000\000\000\000\000\000\020\026\267\033\333\177\000\000\217\233\354\032\333\177\000\000\v\n\241\020BV\000\000\320\330\345\311"...}, tid = 0}, stack = 0x7fdb00000002, addr_description = {data = {kind = 432015844, {shadow = {addr = 0, kind = __asan::kShadowKindLow, shadow_byte = 0 '\000'}, heap = {addr = 0, alloc_tid = 0, free_tid = 10260676871990, alloc_stack_id = 432015844, free_stack_id = 31771, chunk_access = {bad_addr = 20, offset = 136455837977040, chunk_begin = 40, chunk_size = 62887350919176, user_requested_alignment = 1536, access_type = 3, alloc_type = 2}}, stack = {addr = 0, tid = 0, offset = 10260676871990, frame_pc = 136455837977060, access_size = 20, frame_descr = 0x7c1b19c009d0 "U\t"}, global = {addr = 0, static kMaxGlobals = 4, globals = {{beg = 0, size = 10260676871990, size_with_redzone = 136455837977060, name = 0x14 <error: Cannot access memory at address 0x14>, module_name = 0x7c1b19c009d0 "U\t", has_dynamic_init = 40, gcc_location = 0x39321a366008, odr_indicator = 14546846794988041728}, {beg = 136318399050544, size = 140579027621506, size_with_redzone = 140732285703143, name = 0xf <error: Cannot access memory at address 0xf>, module_name = 0x7ffec9e5d3e7 "", has_dynamic_init = 206158430224, gcc_location = 0x7ffec9e5d9c0, odr_indicator = 140732285704400}, {beg = 140579027828192, size = 140579026652003, size_with_redzone = 140579014324432, name = 0xc9e0c816694ab600 <error: Cannot access memory at address 0xc9e0c816694ab600>, module_name = 0x7c0b00000000 "", has_dynamic_init = 140732285703168, gcc_location = 0x71, odr_indicator = 136180941333664}, {beg = 140732285703168, size = 49, size_with_redzone = 140732285702928, name = 0x7fdb1ae9643c <__GI___dprintf+156> "H\213\225H\377\377\377dH+\024%(", module_name = 0x3000000020 <error: Cannot access memory at address 0x3000000020>, has_dynamic_init = 140732285702944, gcc_location = 0x7ffec9e5d260, odr_indicator = 14546846794988041728}}, reg_sites = {3387283456, 32766, 0, 0}, access_size = 140732285703188, size = 227 '\343'}, wild = {addr = 0, access_size = 0}}}}}, CallocOverflow = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\360e\311\376\177\000\0002\000\000\000\000\000\000\000 %\242\030\333{\000\0001\000\000\000\000\000\000\000X\326\345\311\376\177\000\000 %\242\030\333{\000\000\300\315\345\311\376\177\000\000\037{\250\033\333\177\000\000\001\000\000\000\000\000\000\000 %\242\030\333{\000\000\020\326\345\311\376\177\000\000\322\025\267\033\333\177\000\000\000\000\000\000\000\000\000\000\305\234\270\033\036\000\000\000\360\315\345\311\376\177\000\000\003\000\000\000\000\000\000\000\020\026\267\033\333\177\000\000\217\233\354\032\333\177\000\000\v\n\241\020BV\000\000\320\330\345\311"...}, tid = 0}, stack = 0x7fdb00000002, count = 136455837977060, size = 0}, ReallocArrayOverflow = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\360e\311\376\177\000\0002\000\000\000\000\000\000\000 %\242\030\333{\000\0001\000\000\000\000\000\000\000X\326\345\311\376\177\000\000 %\242\030\333{\000\000\300\315\345\311\376\177\000\000\037{\250\033\333\177\000\000\001\000\000\000\000\000\000\000 %\242\030\333{\000\000\020\326\345\311\376\177\000\000\322\025\267\033\333\177\000\000\000\000\000\000\000\000\000\000\305\234\270\033\036\000\000\000\360\315\345\311\376\177\000\000\003\000\000\000\000\000\000\000\020\026\267\033\333\177\000\000\217\233\354\032\333\177\000\000\v\n\241\020BV\000\000\320\330\345\311"...}, tid = 0}, stack = 0x7fdb00000002, count = 136455837977060, size = 0}, PvallocOverflow = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\360e\311\376\177\000\0002\000\000\000\000\000\000\000 %\242\030\333{\000\0001\000\000\000\000\000\000\000X\326\345\311\376\177\000\000 %\242\030\333{\000\000\300\315\345\311\376\177\000\000\037{\250\033\333\177\000\000\001\000\000\000\000\000\000\000 %\242\030\333{\000\000\020\326\345\311\376\177\000\000\322\025\267\033\333\177\000\000\000\000\000\000\000\000\000\000\305\234\270\033\036\000\000\000\360\315\345\311\376\177\000\000\003\000\000\000\000\000\000\000\020\026\267\033\333\177\000\000\217\233\354\032\333\177\000\000\v\n\241\020BV\000\000\320\330\345\311"...}, tid = 0}, stack = 0x7fdb00000002, size = 136455837977060}, InvalidAllocationAlignment = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\360e\311\376\177\000\0002\000\000\000\000\000\000\000 %\242\030\333{\000\0001\000\000\000\000\000\000\000X\326\345\311\376\177\000\000 %\242\030\333{\000\000\300\315\345\311\376\177\000\000\037{\250\033\333\177\000\000\001\000\000\000\000\000\000\000 %\242\030\333{\000\000\020\326\345\311\376\177\000\000\322\025\267\033\333\177\000\000\000\000\000\000\000\000\000\000\305\234\270\033\036\000\000\000\360\315\345\311\376\177\000\000\003\000\000\000\000\000\000\000\020\026\267\033\333\177\000\000\217\233\354\032\333\177\000\000\v\n\241\020BV\000\000\320\330\345\311"...}, tid = 0}, stack = 0x7fdb00000002, alignment = 136455837977060}, InvalidAlignedAllocAlignment = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\360e\311\376\177\000\0002\000\000\000\000\000\000\000 %\242\030\333{\000\0001\000\000\000\000\000\000\000X\326\345\311\376\177\000\000 %\242\030\333{\000\000\300\315\345\311\376\177\000\000\037{\250\033\333\177\000\000\001\000\000\000\000\000\000\000 %\242\030\333{\000\000\020\326\345\311\376\177\000\000\322\025\267\033\333\177\000\000\000\000\000\000\000\000\000\000\305\234\270\033\036\000\000\000\360\315\345\311\376\177\000\000\003\000\000\000\000\000\000\000\020\026\267\033\333\177\000\000\217\233\354\032\333\177\000\000\v\n\241\020BV\000\000\320\330\345\311"...}, tid = 0}, stack = 0x7fdb00000002, size = 136455837977060, alignment = 0}, InvalidPosixMemalignAlignment = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\360e\311\376\177\000\0002\000\000\000\000\000\000\000 %\242\030\333{\000\0001\000\000\000\000\000\000\000X\326\345\311\376\177\000\000 %\242\030\333{\000\000\300\315\345\311\376\177\000\000\037{\250\033\333\177\000\000\001\000\000\000\000\000\000\000 %\242\030\333{\000\000\020\326\345\311\376\177\000\000\322\025\267\033\333\177\000\000\000\000\000\000\000\000\000\000\305\234\270\033\036\000\000\000\360\315\345\311\376\177\000\000\003\000\000\000\000\000\000\000\020\026\267\033\333\177\000\000\217\233\354\032\333\177\000\000\v\n\241\020BV\000\000\320\330\345\311"...}, tid = 0}, stack = 0x7fdb00000002, alignment = 136455837977060}, AllocationSizeTooBig = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\360e\311\376\177\000\0002\000\000\000\000\000\000\000 %\242\030\333{\000\0001\000\000\000\000\000\000\000X\326\345\311\376\177\000\000 %\242\030\333{\000\000\300\315\345\311\376\177\000\000\037{\250\033\333\177\000\000\001\000\000\000\000\000\000\000 %\242\030\333{\000\000\020\326\345\311\376\177\000\000\322\025\267\033\333\177\000\000\000\000\000\000\000\000\000\000\305\234\270\033\036\000\000\000\360\315\345\311\376\177\000\000\003\000\000\000\000\000\000\000\020\026\267\033\333\177\000\000\217\233\354\032\333\177\000\000\v\n\241\020BV\000\000\320\330\345\311"...}, tid = 0}, stack = 0x7fdb00000002, user_size = 136455837977060, total_size = 0, max_size = 0}, RssLimitExceeded = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\360e\311\376\177\000\0002\000\000\000\000\000\000\000 %\242\030\333{\000\0001\000\000\000\000\000\000\000X\326\345\311\376\177\000\000 %\242\030\333{\000\000\300\315\345\311\376\177\000\000\037{\250\033\333\177\000\000\001\000\000\000\000\000\000\000 %\242\030\333{\000\000\020\326\345\311\376\177\000\000\322\025\267\033\333\177\000\000\000\000\000\000\000\000\000\000\305\234\270\033\036\000\000\000\360\315\345\311\376\177\000\000\003\000\000\000\000\000\000\000\020\026\267\033\333\177\000\000\217\233\354\032\333\177\000\000\v\n\241\020BV\000\000\320\330\345\311"...}, tid = 0}, stack = 0x7fdb00000002}, OutOfMemory = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\360e\311\376\177\000\0002\000\000\000\000\000\000\000 %\242\030\333{\000\0001\000\000\000\000\000\000\000X\326\345\311\376\177\000\000 %\242\030\333{\000\000\300\315\345\311\376\177\000\000\037{\250\033\333\177\000\000\001\000\000\000\000\000\000\000 %\242\030\333{\000\000\020\326\345\311\376\177\000\000\322\025\267\033\333\177\000\000\000\000\000\000\000\000\000\000\305\234\270\033\036\000\000\000\360\315\345\311\376\177\000\000\003\000\000\000\000\000\000\000\020\026\267\033\333\177\000\000\217\233\354\032\333\177\000\000\v\n\241\020BV\000\000\320\330\345\311"...}, tid = 0}, stack = 0x7fdb00000002, requested_size = 136455837977060}, StringFunctionMemoryRangesOverlap = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\360e\311\376\177\000\0002\000\000\000\000\000\000\000 %\242\030\333{\000\0001\000\000\000\000\000\000\000X\326\345\311\376\177\000\000 %\242\030\333{\000\000\300\315\345\311\376\177\000\000\037{\250\033\333\177\000\000\001\000\000\000\000\000\000\000 %\242\030\333{\000\000\020\326\345\311\376\177\000\000\322\025\267\033\333\177\000\000\000\000\000\000\000\000\000\000\305\234\270\033\036\000\000\000\360\315\345\311\376\177\000\000\003\000\000\000\000\000\000\000\020\026\267\033\333\177\000\000\217\233\354\032\333\177\000\000\v\n\241\020BV\000\000\320\330\345\311"...}, tid = 0}, stack = 0x7fdb00000002, length1 = 136455837977060, length2 = 0, addr1_description = {data = {kind = __asan::kAddressKindWild, {shadow = {addr = 10260676871990, kind = (unknown: 0xe4), shadow_byte = 9 '\t'}, heap = {addr = 10260676871990, alloc_tid = 136455837977060, free_tid = 20, alloc_stack_id = 432015824, free_stack_id = 31771, chunk_access = {bad_addr = 40, offset = 62887350919176, chunk_begin = 14546846794988041728, chunk_size = 136318399050544, user_requested_alignment = 1666, access_type = 1, alloc_type = 0}}, stack = {addr = 10260676871990, tid = 136455837977060, offset = 20, frame_pc = 136455837977040, access_size = 40, frame_descr = 0x39321a366008 <error: Cannot access memory at address 0x39321a366008>}, global = {addr = 10260676871990, static kMaxGlobals = 4, globals = {{beg = 136455837977060, size = 20, size_with_redzone = 136455837977040, name = 0x28 <error: Cannot access memory at address 0x28>, module_name = 0x39321a366008 <error: Cannot access memory at address 0x39321a366008>, has_dynamic_init = 14546846794988041728, gcc_location = 0x7bfb19c07330, odr_indicator = 140579027621506}, {beg = 140732285703143, size = 15, size_with_redzone = 140732285703143, name = 0x3000000010 <error: Cannot access memory at address 0x3000000010>, module_name = 0x7ffec9e5d9c0 "\320\t\300\031\033|", has_dynamic_init = 140732285704400, gcc_location = 0x7fdb1b043de0 <_nl_C_locobj>, odr_indicator = 140579026652003}, {beg = 140579014324432, size = 14546846794988041728, size_with_redzone = 136386686484480, name = 0x7ffec9e5d400 "f\235\270\033\333\177", module_name = 0x71 <error: Cannot access memory at address 0x71>, has_dynamic_init = 136180941333664, gcc_location = 0x7ffec9e5d400, odr_indicator = 49}, {beg = 140732285702928, size = 140579026068540, size_with_redzone = 206158430240, name = 0x7ffec9e5d320 "\037{\250\033\333\177", module_name = 0x7ffec9e5d260 "", has_dynamic_init = 14546846794988041728, gcc_location = 0x7ffec9e5d800, odr_indicator = 0}}, reg_sites = {3387282452, 32766, 276050659, 22082}, access_size = 140732285704624, size = 160 '\240'}, wild = {addr = 10260676871990, access_size = 136455837977060}}}}, addr2_description = {data = {kind = __asan::kAddressKindGlobal, {shadow = {addr = 140579039975319, kind = __asan::kShadowKindGap, shadow_byte = 253 '\375'}, heap = {addr = 140579039975319, alloc_tid = 56293228674305, free_tid = 17022617666704, alloc_stack_id = 65535, free_stack_id = 0, chunk_access = {bad_addr = 94841748015232, offset = 140732285704272, chunk_begin = 136387118408592, chunk_size = 94841744650166, user_requested_alignment = 1792, access_type = 1, alloc_type = 3}}, stack = {addr = 140579039975319, tid = 56293228674305, offset = 17022617666704, frame_pc = 65535, access_size = 94841748015232, frame_descr = 0x7ffec9e5d850 ""}, global = {addr = 140579039975319, static kMaxGlobals = 4, globals = {{beg = 56293228674305, size = 17022617666704, size_with_redzone = 65535, name = 0x564210b34880 "%s:%s() ", module_name = 0x7ffec9e5d850 "", has_dynamic_init = 136387118408592, gcc_location = 0x5642107fefb6 <btd_debug+358>, odr_indicator = 136180940068608}, {beg = 94841748133408, size = 30064836607, size_with_redzone = 94841748128032, name = 0x7bdb18a223a0 "0", module_name = 0x7bdb188eb4a0 "PO\276\031K|", has_dynamic_init = 140732285704352, gcc_location = 0x7fdb1bbaff7d <__sanitizer::DTLS_on_tls_get_addr(void*, void*, unsigned long, unsigned long)+125>, odr_indicator = 96}, {beg = 14546846794988041728, size = 140732285704400, size_with_redzone = 14546846794988041728, name = 0xf7b63144450 <error: Cannot access memory at address 0xf7b63144450>, module_name = 0x7fdb1bc19f78 "\001", has_dynamic_init = 65535, gcc_location = 0xc9e0c816694ab600, odr_indicator = 140579018234040}, {beg = 136180940059808, size = 94841748015168, size_with_redzone = 94841748024160, name = 0x7c1b19c009d0 "U\t", module_name = 0x9ed48 <error: Cannot access memory at address 0x9ed48>, has_dynamic_init = 140732285704496, gcc_location = 0x7bdb18a22380, odr_indicator = 17022617666672}}, reg_sites = {65535, 0, 280297760, 22082}, access_size = 140732285704512, size = 160 '\240'}, wild = {addr = 140579039975319, access_size = 56293228674305}}}}, function = 0x5642107fefb6 <btd_debug+358> "I9\336uMH\307\205"}, StringFunctionSizeOverflow = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\360e\311\376\177\000\0002\000\000\000\000\000\000\000 %\242\030\333{\000\0001\000\000\000\000\000\000\000X\326\345\311\376\177\000\000 %\242\030\333{\000\000\300\315\345\311\376\177\000\000\037{\250\033\333\177\000\000\001\000\000\000\000\000\000\000 %\242\030\333{\000\000\020\326\345\311\376\177\000\000\322\025\267\033\333\177\000\000\000\000\000\000\000\000\000\000\305\234\270\033\036\000\000\000\360\315\345\311\376\177\000\000\003\000\000\000\000\000\000\000\020\026\267\033\333\177\000\000\217\233\354\032\333\177\000\000\v\n\241\020BV\000\000\320\330\345\311"...}, tid = 0}, stack = 0x7fdb00000002, addr_description = {data = {kind = 432015844, {shadow = {addr = 0, kind = __asan::kShadowKindLow, shadow_byte = 0 '\000'}, heap = {addr = 0, alloc_tid = 0, free_tid = 10260676871990, alloc_stack_id = 432015844, free_stack_id = 31771, chunk_access = {bad_addr = 20, offset = 136455837977040, chunk_begin = 40, chunk_size = 62887350919176, user_requested_alignment = 1536, access_type = 3, alloc_type = 2}}, stack = {addr = 0, tid = 0, offset = 10260676871990, frame_pc = 136455837977060, access_size = 20, frame_descr = 0x7c1b19c009d0 "U\t"}, global = {addr = 0, static kMaxGlobals = 4, globals = {{beg = 0, size = 10260676871990, size_with_redzone = 136455837977060, name = 0x14 <error: Cannot access memory at address 0x14>, module_name = 0x7c1b19c009d0 "U\t", has_dynamic_init = 40, gcc_location = 0x39321a366008, odr_indicator = 14546846794988041728}, {beg = 136318399050544, size = 140579027621506, size_with_redzone = 140732285703143, name = 0xf <error: Cannot access memory at address 0xf>, module_name = 0x7ffec9e5d3e7 "", has_dynamic_init = 206158430224, gcc_location = 0x7ffec9e5d9c0, odr_indicator = 140732285704400}, {beg = 140579027828192, size = 140579026652003, size_with_redzone = 140579014324432, name = 0xc9e0c816694ab600 <error: Cannot access memory at address 0xc9e0c816694ab600>, module_name = 0x7c0b00000000 "", has_dynamic_init = 140732285703168, gcc_location = 0x71, odr_indicator = 136180941333664}, {beg = 140732285703168, size = 49, size_with_redzone = 140732285702928, name = 0x7fdb1ae9643c <__GI___dprintf+156> "H\213\225H\377\377\377dH+\024%(", module_name = 0x3000000020 <error: Cannot access memory at address 0x3000000020>, has_dynamic_init = 140732285702944, gcc_location = 0x7ffec9e5d260, odr_indicator = 14546846794988041728}}, reg_sites = {3387283456, 32766, 0, 0}, access_size = 140732285703188, size = 227 '\343'}, wild = {addr = 0, access_size = 0}}}}, size = 140732285704624}, BadParamsToAnnotateContiguousContainer = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\360e\311\376\177\000\0002\000\000\000\000\000\000\000 %\242\030\333{\000\0001\000\000\000\000\000\000\000X\326\345\311\376\177\000\000 %\242\030\333{\000\000\300\315\345\311\376\177\000\000\037{\250\033\333\177\000\000\001\000\000\000\000\000\000\000 %\242\030\333{\000\000\020\326\345\311\376\177\000\000\322\025\267\033\333\177\000\000\000\000\000\000\000\000\000\000\305\234\270\033\036\000\000\000\360\315\345\311\376\177\000\000\003\000\000\000\000\000\000\000\020\026\267\033\333\177\000\000\217\233\354\032\333\177\000\000\v\n\241\020BV\000\000\320\330\345\311"...}, tid = 0}, stack = 0x7fdb00000002, beg = 136455837977060, end = 0, old_mid = 0, new_mid = 10260676871990}, BadParamsToAnnotateDoubleEndedContiguousContainer = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\360e\311\376\177\000\0002\000\000\000\000\000\000\000 %\242\030\333{\000\0001\000\000\000\000\000\000\000X\326\345\311\376\177\000\000 %\242\030\333{\000\000\300\315\345\311\376\177\000\000\037{\250\033\333\177\000\000\001\000\000\000\000\000\000\000 %\242\030\333{\000\000\020\326\345\311\376\177\000\000\322\025\267\033\333\177\000\000\000\000\000\000\000\000\000\000\305\234\270\033\036\000\000\000\360\315\345\311\376\177\000\000\003\000\000\000\000\000\000\000\020\026\267\033\333\177\000\000\217\233\354\032\333\177\000\000\v\n\241\020BV\000\000\320\330\345\311"...}, tid = 0}, stack = 0x7fdb00000002, storage_beg = 136455837977060, storage_end = 0, old_container_beg = 0, old_container_end = 10260676871990, new_container_beg = 136455837977060, new_container_end = 20}, BadParamsToCopyContiguousContainerAnnotations = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\360e\311\376\177\000\0002\000\000\000\000\000\000\000 %\242\030\333{\000\0001\000\000\000\000\000\000\000X\326\345\311\376\177\000\000 %\242\030\333{\000\000\300\315\345\311\376\177\000\000\037{\250\033\333\177\000\000\001\000\000\000\000\000\000\000 %\242\030\333{\000\000\020\326\345\311\376\177\000\000\322\025\267\033\333\177\000\000\000\000\000\000\000\000\000\000\305\234\270\033\036\000\000\000\360\315\345\311\376\177\000\000\003\000\000\000\000\000\000\000\020\026\267\033\333\177\000\000\217\233\354\032\333\177\000\000\v\n\241\020BV\000\000\320\330\345\311"...}, tid = 0}, stack = 0x7fdb00000002, old_storage_beg = 136455837977060, old_storage_end = 0, new_storage_beg = 0, new_storage_end = 10260676871990}, ODRViolation = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\360e\311\376\177\000\0002\000\000\000\000\000\000\000 %\242\030\333{\000\0001\000\000\000\000\000\000\000X\326\345\311\376\177\000\000 %\242\030\333{\000\000\300\315\345\311\376\177\000\000\037{\250\033\333\177\000\000\001\000\000\000\000\000\000\000 %\242\030\333{\000\000\020\326\345\311\376\177\000\000\322\025\267\033\333\177\000\000\000\000\000\000\000\000\000\000\305\234\270\033\036\000\000\000\360\315\345\311\376\177\000\000\003\000\000\000\000\000\000\000\020\026\267\033\333\177\000\000\217\233\354\032\333\177\000\000\v\n\241\020BV\000\000\320\330\345\311"...}, tid = 0}, global1 = {beg = 140578574565378, size = 136455837977060, size_with_redzone = 0, name = 0x0, module_name = 0x95500000736 <error: Cannot access memory at address 0x95500000736>, has_dynamic_init = 136455837977060, gcc_location = 0x14, odr_indicator = 136455837977040}, global2 = {beg = 40, size = 62887350919176, size_with_redzone = 14546846794988041728, name = 0x7bfb19c07330 "R\004", module_name = 0x7fdb1b011682 "T ", has_dynamic_init = 140732285703143, gcc_location = 0xf, odr_indicator = 140732285703143}, stack_id1 = 16, stack_id2 = 48}, InvalidPointerPair = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\360e\311\376\177\000\0002\000\000\000\000\000\000\000 %\242\030\333{\000\0001\000\000\000\000\000\000\000X\326\345\311\376\177\000\000 %\242\030\333{\000\000\300\315\345\311\376\177\000\000\037{\250\033\333\177\000\000\001\000\000\000\000\000\000\000 %\242\030\333{\000\000\020\326\345\311\376\177\000\000\322\025\267\033\333\177\000\000\000\000\000\000\000\000\000\000\305\234\270\033\036\000\000\000\360\315\345\311\376\177\000\000\003\000\000\000\000\000\000\000\020\026\267\033\333\177\000\000\217\233\354\032\333\177\000\000\v\n\241\020BV\000\000\320\330\345\311"...}, tid = 0}, pc = 140578574565378, bp = 136455837977060, sp = 0, addr1_description = {data = {kind = __asan::kAddressKindWild, {shadow = {addr = 10260676871990, kind = (unknown: 0xe4), shadow_byte = 9 '\t'}, heap = {addr = 10260676871990, alloc_tid = 136455837977060, free_tid = 20, alloc_stack_id = 432015824, free_stack_id = 31771, chunk_access = {bad_addr = 40, offset = 62887350919176, chunk_begin = 14546846794988041728, chunk_size = 136318399050544, user_requested_alignment = 1666, access_type = 1, alloc_type = 0}}, stack = {addr = 10260676871990, tid = 136455837977060, offset = 20, frame_pc = 136455837977040, access_size = 40, frame_descr = 0x39321a366008 <error: Cannot access memory at address 0x39321a366008>}, global = {addr = 10260676871990, static kMaxGlobals = 4, globals = {{beg = 136455837977060, size = 20, size_with_redzone = 136455837977040, name = 0x28 <error: Cannot access memory at address 0x28>, module_name = 0x39321a366008 <error: Cannot access memory at address 0x39321a366008>, has_dynamic_init = 14546846794988041728, gcc_location = 0x7bfb19c07330, odr_indicator = 140579027621506}, {beg = 140732285703143, size = 15, size_with_redzone = 140732285703143, name = 0x3000000010 <error: Cannot access memory at address 0x3000000010>, module_name = 0x7ffec9e5d9c0 "\320\t\300\031\033|", has_dynamic_init = 140732285704400, gcc_location = 0x7fdb1b043de0 <_nl_C_locobj>, odr_indicator = 140579026652003}, {beg = 140579014324432, size = 14546846794988041728, size_with_redzone = 136386686484480, name = 0x7ffec9e5d400 "f\235\270\033\333\177", module_name = 0x71 <error: Cannot access memory at address 0x71>, has_dynamic_init = 136180941333664, gcc_location = 0x7ffec9e5d400, odr_indicator = 49}, {beg = 140732285702928, size = 140579026068540, size_with_redzone = 206158430240, name = 0x7ffec9e5d320 "\037{\250\033\333\177", module_name = 0x7ffec9e5d260 "", has_dynamic_init = 14546846794988041728, gcc_location = 0x7ffec9e5d800, odr_indicator = 0}}, reg_sites = {3387282452, 32766, 276050659, 22082}, access_size = 140732285704624, size = 160 '\240'}, wild = {addr = 10260676871990, access_size = 136455837977060}}}}, addr2_description = {data = {kind = __asan::kAddressKindGlobal, {shadow = {addr = 140579039975319, kind = __asan::kShadowKindGap, shadow_byte = 253 '\375'}, heap = {addr = 140579039975319, alloc_tid = 56293228674305, free_tid = 17022617666704, alloc_stack_id = 65535, free_stack_id = 0, chunk_access = {bad_addr = 94841748015232, offset = 140732285704272, chunk_begin = 136387118408592, chunk_size = 94841744650166, user_requested_alignment = 1792, access_type = 1, alloc_type = 3}}, stack = {addr = 140579039975319, tid = 56293228674305, offset = 17022617666704, frame_pc = 65535, access_size = 94841748015232, frame_descr = 0x7ffec9e5d850 ""}, global = {addr = 140579039975319, static kMaxGlobals = 4, globals = {{beg = 56293228674305, size = 17022617666704, size_with_redzone = 65535, name = 0x564210b34880 "%s:%s() ", module_name = 0x7ffec9e5d850 "", has_dynamic_init = 136387118408592, gcc_location = 0x5642107fefb6 <btd_debug+358>, odr_indicator = 136180940068608}, {beg = 94841748133408, size = 30064836607, size_with_redzone = 94841748128032, name = 0x7bdb18a223a0 "0", module_name = 0x7bdb188eb4a0 "PO\276\031K|", has_dynamic_init = 140732285704352, gcc_location = 0x7fdb1bbaff7d <__sanitizer::DTLS_on_tls_get_addr(void*, void*, unsigned long, unsigned long)+125>, odr_indicator = 96}, {beg = 14546846794988041728, size = 140732285704400, size_with_redzone = 14546846794988041728, name = 0xf7b63144450 <error: Cannot access memory at address 0xf7b63144450>, module_name = 0x7fdb1bc19f78 "\001", has_dynamic_init = 65535, gcc_location = 0xc9e0c816694ab600, odr_indicator = 140579018234040}, {beg = 136180940059808, size = 94841748015168, size_with_redzone = 94841748024160, name = 0x7c1b19c009d0 "U\t", module_name = 0x9ed48 <error: Cannot access memory at address 0x9ed48>, has_dynamic_init = 140732285704496, gcc_location = 0x7bdb18a22380, odr_indicator = 17022617666672}}, reg_sites = {65535, 0, 280297760, 22082}, access_size = 140732285704512, size = 160 '\240'}, wild = {addr = 140579039975319, access_size = 56293228674305}}}}}, Generic = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\360e\311\376\177\000\0002\000\000\000\000\000\000\000 %\242\030\333{\000\0001\000\000\000\000\000\000\000X\326\345\311\376\177\000\000 %\242\030\333{\000\000\300\315\345\311\376\177\000\000\037{\250\033\333\177\000\000\001\000\000\000\000\000\000\000 %\242\030\333{\000\000\020\326\345\311\376\177\000\000\322\025\267\033\333\177\000\000\000\000\000\000\000\000\000\000\305\234\270\033\036\000\000\000\360\315\345\311\376\177\000\000\003\000\000\000\000\000\000\000\020\026\267\033\333\177\000\000\217\233\354\032\333\177\000\000\v\n\241\020BV\000\000\320\330\345\311"...}, tid = 0}, addr_description = {data = {kind = __asan::kAddressKindHeap, {shadow = {addr = 136455837977060, kind = __asan::kShadowKindLow, shadow_byte = 0 '\000'}, heap = {addr = 136455837977060, alloc_tid = 0, free_tid = 0, alloc_stack_id = 1846, free_stack_id = 2389, chunk_access = {bad_addr = 136455837977060, offset = 20, chunk_begin = 136455837977040, chunk_size = 40, user_requested_alignment = 8, access_type = 2, alloc_type = 1}}, stack = {addr = 136455837977060, tid = 0, offset = 0, frame_pc = 10260676871990, access_size = 136455837977060, frame_descr = 0x14 <error: Cannot access memory at address 0x14>}, global = {addr = 136455837977060, static kMaxGlobals = 4, globals = {{beg = 0, size = 0, size_with_redzone = 10260676871990, name = 0x7c1b19c009e4 "", module_name = 0x14 <error: Cannot access memory at address 0x14>, has_dynamic_init = 136455837977040, gcc_location = 0x28, odr_indicator = 62887350919176}, {beg = 14546846794988041728, size = 136318399050544, size_with_redzone = 140579027621506, name = 0x7ffec9e5d3e7 "", module_name = 0xf <error: Cannot access memory at address 0xf>, has_dynamic_init = 140732285703143, gcc_location = 0x3000000010, odr_indicator = 140732285704640}, {beg = 140732285704400, size = 140579027828192, size_with_redzone = 140579026652003, name = 0x7fdb1a3630d0 "", module_name = 0xc9e0c816694ab600 <error: Cannot access memory at address 0xc9e0c816694ab600>, has_dynamic_init = 136386686484480, gcc_location = 0x7ffec9e5d400, odr_indicator = 113}, {beg = 136180941333664, size = 140732285703168, size_with_redzone = 49, name = 0x7ffec9e5d310 " %\242\030\333{", module_name = 0x7fdb1ae9643c <__GI___dprintf+156> "H\213\225H\377\377\377dH+\024%(", has_dynamic_init = 206158430240, gcc_location = 0x7ffec9e5d320, odr_indicator = 140732285702752}}, reg_sites = {1766503936, 3386951702, 3387283456, 32766}, access_size = 0, size = 20 '\024'}, wild = {addr = 136455837977060, access_size = 0}}}}, pc = 94841743880931, bp = 140732285704624, sp = 140732285704608, access_size = 4, bug_descr = 0x7fdb1bbd9797 "heap-use-after-free", is_write = true, shadow_val = 253 '\375'}}}, halt_on_error_ = true}
error = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\360e\311\376\177\000\0002\000\000\000\000\000\000\000 %\242\030\333{\000\0001\000\000\000\000\000\000\000X\326\345\311\376\177\000\000 %\242\030\333{\000\000\300\315\345\311\376\177\000\000\037{\250\033\333\177\000\000\001\000\000\000\000\000\000\000 %\242\030\333{\000\000\020\326\345\311\376\177\000\000\322\025\267\033\333\177\000\000\000\000\000\000\000\000\000\000\305\234\270\033\036\000\000\000\360\315\345\311\376\177\000\000\003\000\000\000\000\000\000\000\020\026\267\033\333\177\000\000\217\233\354\032\333\177\000\000\v\n\241\020BV\000\000\320\330\345\311"...}, tid = 0}, addr_description = {data = {kind = __asan::kAddressKindHeap, {shadow = {addr = 136455837977060, kind = __asan::kShadowKindLow, shadow_byte = 0 '\000'}, heap = {addr = 136455837977060, alloc_tid = 0, free_tid = 0, alloc_stack_id = 1846, free_stack_id = 2389, chunk_access = {bad_addr = 136455837977060, offset = 20, chunk_begin = 136455837977040, chunk_size = 40, user_requested_alignment = 8, access_type = 2, alloc_type = 1}}, stack = {addr = 136455837977060, tid = 0, offset = 0, frame_pc = 10260676871990, access_size = 136455837977060, frame_descr = 0x14 <error: Cannot access memory at address 0x14>}, global = {addr = 136455837977060, static kMaxGlobals = 4, globals = {{beg = 0, size = 0, size_with_redzone = 10260676871990, name = 0x7c1b19c009e4 "", module_name = 0x14 <error: Cannot access memory at address 0x14>, has_dynamic_init = 136455837977040, gcc_location = 0x28, odr_indicator = 62887350919176}, {beg = 14546846794988041728, size = 136318399050544, size_with_redzone = 140579027621506, name = 0x7ffec9e5d3e7 "", module_name = 0xf <error: Cannot access memory at address 0xf>, has_dynamic_init = 140732285703143, gcc_location = 0x3000000010, odr_indicator = 140732285704640}, {beg = 140732285704400, size = 140579027828192, size_with_redzone = 140579026652003, name = 0x7fdb1a3630d0 "", module_name = 0xc9e0c816694ab600 <error: Cannot access memory at address 0xc9e0c816694ab600>, has_dynamic_init = 136386686484480, gcc_location = 0x7ffec9e5d400, odr_indicator = 113}, {beg = 136180941333664, size = 140732285703168, size_with_redzone = 49, name = 0x7ffec9e5d310 " %\242\030\333{", module_name = 0x7fdb1ae9643c <__GI___dprintf+156> "H\213\225H\377\377\377dH+\024%(", has_dynamic_init = 206158430240, gcc_location = 0x7ffec9e5d320, odr_indicator = 140732285702752}}, reg_sites = {1766503936, 3386951702, 3387283456, 32766}, access_size = 0, size = 20 '\024'}, wild = {addr = 136455837977060, access_size = 0}}}}, pc = 94841743880931, bp = 140732285704624, sp = 140732285704608, access_size = 4, bug_descr = 0x7fdb1bbd9797 "heap-use-after-free", is_write = true, shadow_val = 253 '\375'}
#9 0x00007fdb1bb7df8d in __asan::ReportGenericError (pc=<optimized out>, bp=bp@entry=140732285704624, sp=sp@entry=140732285704608, addr=<optimized out>, is_write=is_write@entry=true, access_size=access_size@entry=4, exp=<optimized out>, fatal=true) at ../../../../src/libsanitizer/asan/asan_report.cpp:536
in_report = <optimized out>
error = <optimized out>
enable_fp = <optimized out>
#10 0x00007fdb1bb7f85c in __asan::__asan_report_store4 (addr=<optimized out>) at ../../../../src/libsanitizer/asan/asan_rtl.cpp:135
bp = 140732285704624
pc = <optimized out>
local_stack = 136318399050576
sp = 140732285704608
#11 0x00005642107432e3 in report_notify_destroy (user_data=<optimized out>) at profiles/input/hog-lib.c:359
report = <optimized out>
__func__ = "report_notify_destroy"
#12 0x00005642107e5f52 in attrib_callbacks_destroy (data=0x7c3b19bf1540) at attrib/gattrib.c:126
cb = 0x7c3b19bf1540
#13 0x00005642109d4d6b in notify_data_unref (data=<optimized out>) at src/shared/gatt-client.c:256
notify_data = <optimized out>
#14 notify_data_unref (data=<optimized out>) at src/shared/gatt-client.c:248
notify_data = <optimized out>
#15 0x000056421097f382 in queue_remove_all (queue=queue@entry=0x7c0b19bea390, function=function@entry=0x0, user_data=user_data@entry=0x0, destroy=0x5642109d4e70 <notify_data_cleanup>) at src/shared/queue.c:341
tmp = 0x7bfb19c07350
entry = 0x0
count = <optimized out>
#16 0x000056421097f679 in queue_destroy (queue=0x7c0b19bea390, destroy=<optimized out>) at src/shared/queue.c:60
No locals.
#17 0x00005642109db8ba in bt_gatt_client_free (client=0x7ceb19be1440) at src/shared/gatt-client.c:2293
No locals.
#18 0x00005642109dd56c in bt_gatt_client_unref (client=<optimized out>) at src/shared/gatt-client.c:2605
No locals.
#19 0x00005642107e74ed in g_attrib_unref (attrib=0x7c4b19be5500) at attrib/gattrib.c:154
__func__ = "g_attrib_unref"
#20 0x00005642108ead7e in attio_cleanup (device=<optimized out>) at src/device.c:874
attrib = <optimized out>
#21 0x00005642108eb2c7 in device_free (user_data=0x7d4b19be0080) at src/device.c:918
device = 0x7d4b19be0080
__func__ = "device_free"
#22 0x0000564210968eda in remove_interface (data=0x7c4b19be4f50, name=name@entry=0x564210b75ae0 "org.bluez.Device1") at gdbus/object.c:742
iface = 0x7c3b19be5ae0
#23 0x000056421096ba9c in g_dbus_unregister_interface (connection=<optimized out>, path=<optimized out>, name=<optimized out>) at gdbus/object.c:1499
data = <optimized out>
#24 0x00005642108a6598 in adapter_remove (adapter=adapter@entry=0x7d0b19be0200) at src/adapter.c:7321
device = 0x7d4b19be0080
db = <optimized out>
ranging_manager = <optimized out>
__func__ = "adapter_remove"
#25 0x00005642108a70d8 in adapter_cleanup () at src/adapter.c:11274
adapter = 0x7d0b19be0200
#26 0x0000564210658330 in main (argc=<optimized out>, argv=<optimized out>) at src/main.c:1723
context = <optimized out>
err = <optimized out>
sdp_mtu = 0
sdp_flags = <optimized out>
gdbus_flags = <optimized out>
__func__ = "main""
FAIL functional.test_hog::test_hog[sci-hosts15-vm2]: failed on teardown with "pytest_bluezenv.plugin.CoredumpWarning: Core dump: test-bluezenv-hosts15.0-bluetoothd-1790201622-129.core
/usr/bin/gdb: warning: Couldn't determine a path for the index cache directory.
[New LWP 129]
[Thread debugging using libthread_db enabled]
Using host libthread_db library "/usr/lib/x86_64-linux-gnu/libthread_db.so.1".
Core was generated by `/home/runner/work/bluez/bluez/src/src/src/bluetoothd --nodetach -f /run/bluetoo'.
Program terminated with signal SIGABRT, Aborted.
#0 __pthread_kill_implementation (threadid=<optimized out>, signo=6, no_tid=0) at ./nptl/pthread_kill.c:44
warning: 44 ./nptl/pthread_kill.c: No such file or directory
Thread 1 (Thread 0x7f2242104900 (LWP 129)):
#0 __pthread_kill_implementation (threadid=<optimized out>, signo=6, no_tid=0) at ./nptl/pthread_kill.c:44
tid = <optimized out>
ret = 0
pd = <optimized out>
old_mask = {__val = {0}}
ret = <optimized out>
#1 __pthread_kill_internal (threadid=<optimized out>, signo=6) at ./nptl/pthread_kill.c:89
No locals.
#2 __GI___pthread_kill (threadid=<optimized out>, signo=signo@entry=6) at ./nptl/pthread_kill.c:100
No locals.
#3 0x00007f224285fb7e in __GI_raise (sig=sig@entry=6) at ../sysdeps/posix/raise.c:26
ret = <optimized out>
#4 0x00007f22428428ec in __GI_abort () at ./stdlib/abort.c:77
act = {__sigaction_handler = {sa_handler = 0x0, sa_sigaction = 0x0}, sa_mask = {__val = {0 <repeats 16 times>}}, sa_flags = 0, sa_restorer = 0x0}
#5 0x00007f224346aa0f in __sanitizer::Abort () at ../../../../src/libsanitizer/sanitizer_common/sanitizer_posix_libcdep.cpp:165
No locals.
#6 0x00007f2243590c2d in __sanitizer::Die () at ../../../../src/libsanitizer/sanitizer_common/sanitizer_termination.cpp:58
No locals.
#7 0x00007f224356593c in __asan::ScopedInErrorReport::~ScopedInErrorReport (this=0x7fffc7608166) at ../../../../src/libsanitizer/asan/asan_report.cpp:221
buffer_copy = {buffer_ = {<__sanitizer::InternalMmapVectorNoCtor<char, false>> = {data_ = 0x7f2241918000 '=' <repeats 65 times>, "\n==129==ERROR: AddressSanitizer: heap-use-after-free on address 0x7b6241600964 at pc 0x5556495e52e3 bp 0x7fffc7608de0 sp 0x7fffc7608dd0"..., capacity_bytes_ = 4096, size_ = 3936}, <No data fields>}}
buffer_copy = <optimized out>
l = <optimized out>
#8 0x00007f2243564e02 in __asan::ReportGenericError (pc=93829086466787, bp=140736538381792, sp=sp@entry=140736538381776, addr=135661933824356, is_write=is_write@entry=true, access_size=4, fatal=true, exp=<optimized out>) at ../../../../src/libsanitizer/asan/asan_report.cpp:536
in_report = {error_report_lock_ = {<No data fields>}, static current_error_ = {kind = __asan::kErrorKindGeneric, {Base = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\260\340\306\377\177\000\0002\000\000\000\000\000\000\000 \202B@\"{\000\0001\000\000\000\000\000\000\000\210\212`\307\377\177\000\000 \202B@\"{\000\000\360\201`\307\377\177\000\000\037\353FC\"\177\000\000\001\000\000\000\000\000\000\000 \202B@\"{\000\000@\212`\307\377\177\000\000\322\205UC\"\177\000\000\000\000\000\000\000\000\000\000\305\fWC\036\000\000\000 \202`\307\377\177\000\000\003\000\000\000\000\000\000\000\020\206UC\"\177\000\000\217\v\213B\"\177\000\000\v*\213IVU\000\000\000\215`\307"...}, tid = 0}, DeadlySignal = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\260\340\306\377\177\000\0002\000\000\000\000\000\000\000 \202B@\"{\000\0001\000\000\000\000\000\000\000\210\212`\307\377\177\000\000 \202B@\"{\000\000\360\201`\307\377\177\000\000\037\353FC\"\177\000\000\001\000\000\000\000\000\000\000 \202B@\"{\000\000@\212`\307\377\177\000\000\322\205UC\"\177\000\000\000\000\000\000\000\000\000\000\305\fWC\036\000\000\000 \202`\307\377\177\000\000\003\000\000\000\000\000\000\000\020\206UC\"\177\000\000\217\v\213B\"\177\000\000\v*\213IVU\000\000\000\215`\307"...}, tid = 0}, signal = {siginfo = 0x7f2200000002, context = 0x7b6241600964, addr = 0, pc = 0, sp = 10458245367602, bp = 135661933824356, is_memory_access = 20, write_flag = __sanitizer::SignalContext::Unknown, is_true_faulting_addr = 80}}, DoubleFree = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\260\340\306\377\177\000\0002\000\000\000\000\000\000\000 \202B@\"{\000\0001\000\000\000\000\000\000\000\210\212`\307\377\177\000\000 \202B@\"{\000\000\360\201`\307\377\177\000\000\037\353FC\"\177\000\000\001\000\000\000\000\000\000\000 \202B@\"{\000\000@\212`\307\377\177\000\000\322\205UC\"\177\000\000\000\000\000\000\000\000\000\000\305\fWC\036\000\000\000 \202`\307\377\177\000\000\003\000\000\000\000\000\000\000\020\206UC\"\177\000\000\217\v\213B\"\177\000\000\v*\213IVU\000\000\000\215`\307"...}, tid = 0}, second_free_stack = 0x7f2200000002, addr_description = {addr = 135661933824356, alloc_tid = 0, free_tid = 0, alloc_stack_id = 1842, free_stack_id = 2435, chunk_access = {bad_addr = 135661933824356, offset = 20, chunk_begin = 135661933824336, chunk_size = 40, user_requested_alignment = 8, access_type = 2, alloc_type = 1}}}, NewDeleteTypeMismatch = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\260\340\306\377\177\000\0002\000\000\000\000\000\000\000 \202B@\"{\000\0001\000\000\000\000\000\000\000\210\212`\307\377\177\000\000 \202B@\"{\000\000\360\201`\307\377\177\000\000\037\353FC\"\177\000\000\001\000\000\000\000\000\000\000 \202B@\"{\000\000@\212`\307\377\177\000\000\322\205UC\"\177\000\000\000\000\000\000\000\000\000\000\305\fWC\036\000\000\000 \202`\307\377\177\000\000\003\000\000\000\000\000\000\000\020\206UC\"\177\000\000\217\v\213B\"\177\000\000\v*\213IVU\000\000\000\215`\307"...}, tid = 0}, free_stack = 0x7f2200000002, addr_description = {addr = 135661933824356, alloc_tid = 0, free_tid = 0, alloc_stack_id = 1842, free_stack_id = 2435, chunk_access = {bad_addr = 135661933824356, offset = 20, chunk_begin = 135661933824336, chunk_size = 40, user_requested_alignment = 8, access_type = 2, alloc_type = 1}}, delete_size = 4585564030955459840, delete_alignment = 135524494906928}, FreeNotMalloced = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\260\340\306\377\177\000\0002\000\000\000\000\000\000\000 \202B@\"{\000\0001\000\000\000\000\000\000\000\210\212`\307\377\177\000\000 \202B@\"{\000\000\360\201`\307\377\177\000\000\037\353FC\"\177\000\000\001\000\000\000\000\000\000\000 \202B@\"{\000\000@\212`\307\377\177\000\000\322\205UC\"\177\000\000\000\000\000\000\000\000\000\000\305\fWC\036\000\000\000 \202`\307\377\177\000\000\003\000\000\000\000\000\000\000\020\206UC\"\177\000\000\217\v\213B\"\177\000\000\v*\213IVU\000\000\000\215`\307"...}, tid = 0}, free_stack = 0x7f2200000002, addr_description = {data = {kind = 1096812900, {shadow = {addr = 0, kind = __asan::kShadowKindLow, shadow_byte = 0 '\000'}, heap = {addr = 0, alloc_tid = 0, free_tid = 10458245367602, alloc_stack_id = 1096812900, free_stack_id = 31586, chunk_access = {bad_addr = 20, offset = 135661933824336, chunk_begin = 40, chunk_size = 55200024125448, user_requested_alignment = 1280, access_type = 1, alloc_type = 2}}, stack = {addr = 0, tid = 0, offset = 10458245367602, frame_pc = 135661933824356, access_size = 20, frame_descr = 0x7b6241600950 "\203\t"}, global = {addr = 0, static kMaxGlobals = 4, globals = {{beg = 0, size = 10458245367602, size_with_redzone = 135661933824356, name = 0x14 <error: Cannot access memory at address 0x14>, module_name = 0x7b6241600950 "\203\t", has_dynamic_init = 40, gcc_location = 0x323441d46008, odr_indicator = 4585564030955459840}, {beg = 135524494906928, size = 139785123366530, size_with_redzone = 140736538380311, name = 0xf <error: Cannot access memory at address 0xf>, module_name = 0x7fffc7608817 "", has_dynamic_init = 206158430224, gcc_location = 0x7fffc7608df0, odr_indicator = 140736538381568}, {beg = 139785123573216, size = 139785122397027, size_with_redzone = 139785110069456, name = 0x3fa33230d7e89500 <error: Cannot access memory at address 0x3fa33230d7e89500>, module_name = 0x7b5200000000 "", has_dynamic_init = 140736538380336, gcc_location = 0x81, odr_indicator = 135387037204896}, {beg = 140736538380336, size = 49, size_with_redzone = 140736538380096, name = 0x7f224287d43c <__GI___dprintf+156> "H\213\225H\377\377\377dH+\024%(", module_name = 0x3000000020 <error: Cannot access memory at address 0x3000000020>, has_dynamic_init = 140736538380112, gcc_location = 0x7fffc7608690, odr_indicator = 4585564030955459840}}, reg_sites = {3344993328, 32767, 0, 0}, access_size = 140736538380356, size = 227 '\343'}, wild = {addr = 0, access_size = 0}}}}}, AllocTypeMismatch = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\260\340\306\377\177\000\0002\000\000\000\000\000\000\000 \202B@\"{\000\0001\000\000\000\000\000\000\000\210\212`\307\377\177\000\000 \202B@\"{\000\000\360\201`\307\377\177\000\000\037\353FC\"\177\000\000\001\000\000\000\000\000\000\000 \202B@\"{\000\000@\212`\307\377\177\000\000\322\205UC\"\177\000\000\000\000\000\000\000\000\000\000\305\fWC\036\000\000\000 \202`\307\377\177\000\000\003\000\000\000\000\000\000\000\020\206UC\"\177\000\000\217\v\213B\"\177\000\000\v*\213IVU\000\000\000\215`\307"...}, tid = 0}, dealloc_stack = 0x7f2200000002, alloc_type = 1096812900, dealloc_type = 31586, addr_description = {data = {kind = __asan::kAddressKindWild, {shadow = {addr = 0, kind = (__asan::kShadowKindHigh | unknown: 0x30), shadow_byte = 7 '\a'}, heap = {addr = 0, alloc_tid = 10458245367602, free_tid = 135661933824356, alloc_stack_id = 20, free_stack_id = 0, chunk_access = {bad_addr = 135661933824336, offset = 40, chunk_begin = 55200024125448, chunk_size = 4585564030955459840, user_requested_alignment = 1584, access_type = 1, alloc_type = 2}}, stack = {addr = 0, tid = 10458245367602, offset = 135661933824356, frame_pc = 20, access_size = 135661933824336, frame_descr = 0x28 <error: Cannot access memory at address 0x28>}, global = {addr = 0, static kMaxGlobals = 4, globals = {{beg = 10458245367602, size = 135661933824356, size_with_redzone = 20, name = 0x7b6241600950 "\203\t", module_name = 0x28 <error: Cannot access memory at address 0x28>, has_dynamic_init = 55200024125448, gcc_location = 0x3fa33230d7e89500, odr_indicator = 135524494906928}, {beg = 139785123366530, size = 140736538380311, size_with_redzone = 15, name = 0x7fffc7608817 "", module_name = 0x3000000010 <error: Cannot access memory at address 0x3000000010>, has_dynamic_init = 140736538381808, gcc_location = 0x7fffc7608d00, odr_indicator = 139785123573216}, {beg = 139785122397027, size = 139785110069456, size_with_redzone = 4585564030955459840, name = 0x7b5200000000 "", module_name = 0x7fffc7608830 "f\rWC\"\177", has_dynamic_init = 129, gcc_location = 0x7b22404281a0, odr_indicator = 140736538380336}, {beg = 49, size = 140736538380096, size_with_redzone = 139785121813564, name = 0x3000000020 <error: Cannot access memory at address 0x3000000020>, module_name = 0x7fffc7608750 "\037\353FC\"\177", has_dynamic_init = 140736538379920, gcc_location = 0x3fa33230d7e89500, odr_indicator = 140736538381360}}, reg_sites = {0, 0, 3344992324, 32767}, access_size = 93829086466787, size = 224 '\340'}, wild = {addr = 0, access_size = 10458245367602}}}}}, MallocUsableSizeNotOwned = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\260\340\306\377\177\000\0002\000\000\000\000\000\000\000 \202B@\"{\000\0001\000\000\000\000\000\000\000\210\212`\307\377\177\000\000 \202B@\"{\000\000\360\201`\307\377\177\000\000\037\353FC\"\177\000\000\001\000\000\000\000\000\000\000 \202B@\"{\000\000@\212`\307\377\177\000\000\322\205UC\"\177\000\000\000\000\000\000\000\000\000\000\305\fWC\036\000\000\000 \202`\307\377\177\000\000\003\000\000\000\000\000\000\000\020\206UC\"\177\000\000\217\v\213B\"\177\000\000\v*\213IVU\000\000\000\215`\307"...}, tid = 0}, stack = 0x7f2200000002, addr_description = {data = {kind = 1096812900, {shadow = {addr = 0, kind = __asan::kShadowKindLow, shadow_byte = 0 '\000'}, heap = {addr = 0, alloc_tid = 0, free_tid = 10458245367602, alloc_stack_id = 1096812900, free_stack_id = 31586, chunk_access = {bad_addr = 20, offset = 135661933824336, chunk_begin = 40, chunk_size = 55200024125448, user_requested_alignment = 1280, access_type = 1, alloc_type = 2}}, stack = {addr = 0, tid = 0, offset = 10458245367602, frame_pc = 135661933824356, access_size = 20, frame_descr = 0x7b6241600950 "\203\t"}, global = {addr = 0, static kMaxGlobals = 4, globals = {{beg = 0, size = 10458245367602, size_with_redzone = 135661933824356, name = 0x14 <error: Cannot access memory at address 0x14>, module_name = 0x7b6241600950 "\203\t", has_dynamic_init = 40, gcc_location = 0x323441d46008, odr_indicator = 4585564030955459840}, {beg = 135524494906928, size = 139785123366530, size_with_redzone = 140736538380311, name = 0xf <error: Cannot access memory at address 0xf>, module_name = 0x7fffc7608817 "", has_dynamic_init = 206158430224, gcc_location = 0x7fffc7608df0, odr_indicator = 140736538381568}, {beg = 139785123573216, size = 139785122397027, size_with_redzone = 139785110069456, name = 0x3fa33230d7e89500 <error: Cannot access memory at address 0x3fa33230d7e89500>, module_name = 0x7b5200000000 "", has_dynamic_init = 140736538380336, gcc_location = 0x81, odr_indicator = 135387037204896}, {beg = 140736538380336, size = 49, size_with_redzone = 140736538380096, name = 0x7f224287d43c <__GI___dprintf+156> "H\213\225H\377\377\377dH+\024%(", module_name = 0x3000000020 <error: Cannot access memory at address 0x3000000020>, has_dynamic_init = 140736538380112, gcc_location = 0x7fffc7608690, odr_indicator = 4585564030955459840}}, reg_sites = {3344993328, 32767, 0, 0}, access_size = 140736538380356, size = 227 '\343'}, wild = {addr = 0, access_size = 0}}}}}, SanitizerGetAllocatedSizeNotOwned = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\260\340\306\377\177\000\0002\000\000\000\000\000\000\000 \202B@\"{\000\0001\000\000\000\000\000\000\000\210\212`\307\377\177\000\000 \202B@\"{\000\000\360\201`\307\377\177\000\000\037\353FC\"\177\000\000\001\000\000\000\000\000\000\000 \202B@\"{\000\000@\212`\307\377\177\000\000\322\205UC\"\177\000\000\000\000\000\000\000\000\000\000\305\fWC\036\000\000\000 \202`\307\377\177\000\000\003\000\000\000\000\000\000\000\020\206UC\"\177\000\000\217\v\213B\"\177\000\000\v*\213IVU\000\000\000\215`\307"...}, tid = 0}, stack = 0x7f2200000002, addr_description = {data = {kind = 1096812900, {shadow = {addr = 0, kind = __asan::kShadowKindLow, shadow_byte = 0 '\000'}, heap = {addr = 0, alloc_tid = 0, free_tid = 10458245367602, alloc_stack_id = 1096812900, free_stack_id = 31586, chunk_access = {bad_addr = 20, offset = 135661933824336, chunk_begin = 40, chunk_size = 55200024125448, user_requested_alignment = 1280, access_type = 1, alloc_type = 2}}, stack = {addr = 0, tid = 0, offset = 10458245367602, frame_pc = 135661933824356, access_size = 20, frame_descr = 0x7b6241600950 "\203\t"}, global = {addr = 0, static kMaxGlobals = 4, globals = {{beg = 0, size = 10458245367602, size_with_redzone = 135661933824356, name = 0x14 <error: Cannot access memory at address 0x14>, module_name = 0x7b6241600950 "\203\t", has_dynamic_init = 40, gcc_location = 0x323441d46008, odr_indicator = 4585564030955459840}, {beg = 135524494906928, size = 139785123366530, size_with_redzone = 140736538380311, name = 0xf <error: Cannot access memory at address 0xf>, module_name = 0x7fffc7608817 "", has_dynamic_init = 206158430224, gcc_location = 0x7fffc7608df0, odr_indicator = 140736538381568}, {beg = 139785123573216, size = 139785122397027, size_with_redzone = 139785110069456, name = 0x3fa33230d7e89500 <error: Cannot access memory at address 0x3fa33230d7e89500>, module_name = 0x7b5200000000 "", has_dynamic_init = 140736538380336, gcc_location = 0x81, odr_indicator = 135387037204896}, {beg = 140736538380336, size = 49, size_with_redzone = 140736538380096, name = 0x7f224287d43c <__GI___dprintf+156> "H\213\225H\377\377\377dH+\024%(", module_name = 0x3000000020 <error: Cannot access memory at address 0x3000000020>, has_dynamic_init = 140736538380112, gcc_location = 0x7fffc7608690, odr_indicator = 4585564030955459840}}, reg_sites = {3344993328, 32767, 0, 0}, access_size = 140736538380356, size = 227 '\343'}, wild = {addr = 0, access_size = 0}}}}}, CallocOverflow = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\260\340\306\377\177\000\0002\000\000\000\000\000\000\000 \202B@\"{\000\0001\000\000\000\000\000\000\000\210\212`\307\377\177\000\000 \202B@\"{\000\000\360\201`\307\377\177\000\000\037\353FC\"\177\000\000\001\000\000\000\000\000\000\000 \202B@\"{\000\000@\212`\307\377\177\000\000\322\205UC\"\177\000\000\000\000\000\000\000\000\000\000\305\fWC\036\000\000\000 \202`\307\377\177\000\000\003\000\000\000\000\000\000\000\020\206UC\"\177\000\000\217\v\213B\"\177\000\000\v*\213IVU\000\000\000\215`\307"...}, tid = 0}, stack = 0x7f2200000002, count = 135661933824356, size = 0}, ReallocArrayOverflow = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\260\340\306\377\177\000\0002\000\000\000\000\000\000\000 \202B@\"{\000\0001\000\000\000\000\000\000\000\210\212`\307\377\177\000\000 \202B@\"{\000\000\360\201`\307\377\177\000\000\037\353FC\"\177\000\000\001\000\000\000\000\000\000\000 \202B@\"{\000\000@\212`\307\377\177\000\000\322\205UC\"\177\000\000\000\000\000\000\000\000\000\000\305\fWC\036\000\000\000 \202`\307\377\177\000\000\003\000\000\000\000\000\000\000\020\206UC\"\177\000\000\217\v\213B\"\177\000\000\v*\213IVU\000\000\000\215`\307"...}, tid = 0}, stack = 0x7f2200000002, count = 135661933824356, size = 0}, PvallocOverflow = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\260\340\306\377\177\000\0002\000\000\000\000\000\000\000 \202B@\"{\000\0001\000\000\000\000\000\000\000\210\212`\307\377\177\000\000 \202B@\"{\000\000\360\201`\307\377\177\000\000\037\353FC\"\177\000\000\001\000\000\000\000\000\000\000 \202B@\"{\000\000@\212`\307\377\177\000\000\322\205UC\"\177\000\000\000\000\000\000\000\000\000\000\305\fWC\036\000\000\000 \202`\307\377\177\000\000\003\000\000\000\000\000\000\000\020\206UC\"\177\000\000\217\v\213B\"\177\000\000\v*\213IVU\000\000\000\215`\307"...}, tid = 0}, stack = 0x7f2200000002, size = 135661933824356}, InvalidAllocationAlignment = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\260\340\306\377\177\000\0002\000\000\000\000\000\000\000 \202B@\"{\000\0001\000\000\000\000\000\000\000\210\212`\307\377\177\000\000 \202B@\"{\000\000\360\201`\307\377\177\000\000\037\353FC\"\177\000\000\001\000\000\000\000\000\000\000 \202B@\"{\000\000@\212`\307\377\177\000\000\322\205UC\"\177\000\000\000\000\000\000\000\000\000\000\305\fWC\036\000\000\000 \202`\307\377\177\000\000\003\000\000\000\000\000\000\000\020\206UC\"\177\000\000\217\v\213B\"\177\000\000\v*\213IVU\000\000\000\215`\307"...}, tid = 0}, stack = 0x7f2200000002, alignment = 135661933824356}, InvalidAlignedAllocAlignment = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\260\340\306\377\177\000\0002\000\000\000\000\000\000\000 \202B@\"{\000\0001\000\000\000\000\000\000\000\210\212`\307\377\177\000\000 \202B@\"{\000\000\360\201`\307\377\177\000\000\037\353FC\"\177\000\000\001\000\000\000\000\000\000\000 \202B@\"{\000\000@\212`\307\377\177\000\000\322\205UC\"\177\000\000\000\000\000\000\000\000\000\000\305\fWC\036\000\000\000 \202`\307\377\177\000\000\003\000\000\000\000\000\000\000\020\206UC\"\177\000\000\217\v\213B\"\177\000\000\v*\213IVU\000\000\000\215`\307"...}, tid = 0}, stack = 0x7f2200000002, size = 135661933824356, alignment = 0}, InvalidPosixMemalignAlignment = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\260\340\306\377\177\000\0002\000\000\000\000\000\000\000 \202B@\"{\000\0001\000\000\000\000\000\000\000\210\212`\307\377\177\000\000 \202B@\"{\000\000\360\201`\307\377\177\000\000\037\353FC\"\177\000\000\001\000\000\000\000\000\000\000 \202B@\"{\000\000@\212`\307\377\177\000\000\322\205UC\"\177\000\000\000\000\000\000\000\000\000\000\305\fWC\036\000\000\000 \202`\307\377\177\000\000\003\000\000\000\000\000\000\000\020\206UC\"\177\000\000\217\v\213B\"\177\000\000\v*\213IVU\000\000\000\215`\307"...}, tid = 0}, stack = 0x7f2200000002, alignment = 135661933824356}, AllocationSizeTooBig = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\260\340\306\377\177\000\0002\000\000\000\000\000\000\000 \202B@\"{\000\0001\000\000\000\000\000\000\000\210\212`\307\377\177\000\000 \202B@\"{\000\000\360\201`\307\377\177\000\000\037\353FC\"\177\000\000\001\000\000\000\000\000\000\000 \202B@\"{\000\000@\212`\307\377\177\000\000\322\205UC\"\177\000\000\000\000\000\000\000\000\000\000\305\fWC\036\000\000\000 \202`\307\377\177\000\000\003\000\000\000\000\000\000\000\020\206UC\"\177\000\000\217\v\213B\"\177\000\000\v*\213IVU\000\000\000\215`\307"...}, tid = 0}, stack = 0x7f2200000002, user_size = 135661933824356, total_size = 0, max_size = 0}, RssLimitExceeded = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\260\340\306\377\177\000\0002\000\000\000\000\000\000\000 \202B@\"{\000\0001\000\000\000\000\000\000\000\210\212`\307\377\177\000\000 \202B@\"{\000\000\360\201`\307\377\177\000\000\037\353FC\"\177\000\000\001\000\000\000\000\000\000\000 \202B@\"{\000\000@\212`\307\377\177\000\000\322\205UC\"\177\000\000\000\000\000\000\000\000\000\000\305\fWC\036\000\000\000 \202`\307\377\177\000\000\003\000\000\000\000\000\000\000\020\206UC\"\177\000\000\217\v\213B\"\177\000\000\v*\213IVU\000\000\000\215`\307"...}, tid = 0}, stack = 0x7f2200000002}, OutOfMemory = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\260\340\306\377\177\000\0002\000\000\000\000\000\000\000 \202B@\"{\000\0001\000\000\000\000\000\000\000\210\212`\307\377\177\000\000 \202B@\"{\000\000\360\201`\307\377\177\000\000\037\353FC\"\177\000\000\001\000\000\000\000\000\000\000 \202B@\"{\000\000@\212`\307\377\177\000\000\322\205UC\"\177\000\000\000\000\000\000\000\000\000\000\305\fWC\036\000\000\000 \202`\307\377\177\000\000\003\000\000\000\000\000\000\000\020\206UC\"\177\000\000\217\v\213B\"\177\000\000\v*\213IVU\000\000\000\215`\307"...}, tid = 0}, stack = 0x7f2200000002, requested_size = 135661933824356}, StringFunctionMemoryRangesOverlap = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\260\340\306\377\177\000\0002\000\000\000\000\000\000\000 \202B@\"{\000\0001\000\000\000\000\000\000\000\210\212`\307\377\177\000\000 \202B@\"{\000\000\360\201`\307\377\177\000\000\037\353FC\"\177\000\000\001\000\000\000\000\000\000\000 \202B@\"{\000\000@\212`\307\377\177\000\000\322\205UC\"\177\000\000\000\000\000\000\000\000\000\000\305\fWC\036\000\000\000 \202`\307\377\177\000\000\003\000\000\000\000\000\000\000\020\206UC\"\177\000\000\217\v\213B\"\177\000\000\v*\213IVU\000\000\000\215`\307"...}, tid = 0}, stack = 0x7f2200000002, length1 = 135661933824356, length2 = 0, addr1_description = {data = {kind = __asan::kAddressKindWild, {shadow = {addr = 10458245367602, kind = (unknown: 0x64), shadow_byte = 9 '\t'}, heap = {addr = 10458245367602, alloc_tid = 135661933824356, free_tid = 20, alloc_stack_id = 1096812880, free_stack_id = 31586, chunk_access = {bad_addr = 40, offset = 55200024125448, chunk_begin = 4585564030955459840, chunk_size = 135524494906928, user_requested_alignment = 1666, access_type = 0, alloc_type = 2}}, stack = {addr = 10458245367602, tid = 135661933824356, offset = 20, frame_pc = 135661933824336, access_size = 40, frame_descr = 0x323441d46008 <error: Cannot access memory at address 0x323441d46008>}, global = {addr = 10458245367602, static kMaxGlobals = 4, globals = {{beg = 135661933824356, size = 20, size_with_redzone = 135661933824336, name = 0x28 <error: Cannot access memory at address 0x28>, module_name = 0x323441d46008 <error: Cannot access memory at address 0x323441d46008>, has_dynamic_init = 4585564030955459840, gcc_location = 0x7b4241609630, odr_indicator = 139785123366530}, {beg = 140736538380311, size = 15, size_with_redzone = 140736538380311, name = 0x3000000010 <error: Cannot access memory at address 0x3000000010>, module_name = 0x7fffc7608df0 "P\t`Ab{", has_dynamic_init = 140736538381568, gcc_location = 0x7f2242a2ade0 <_nl_C_locobj>, odr_indicator = 139785122397027}, {beg = 139785110069456, size = 4585564030955459840, size_with_redzone = 135592117534720, name = 0x7fffc7608830 "f\rWC\"\177", module_name = 0x81 <error: Cannot access memory at address 0x81>, has_dynamic_init = 135387037204896, gcc_location = 0x7fffc7608830, odr_indicator = 49}, {beg = 140736538380096, size = 139785121813564, size_with_redzone = 206158430240, name = 0x7fffc7608750 "\037\353FC\"\177", module_name = 0x7fffc7608690 "0\214`\307\377\177", has_dynamic_init = 4585564030955459840, gcc_location = 0x7fffc7608c30, odr_indicator = 0}}, reg_sites = {3344992324, 32767, 1230918371, 21846}, access_size = 140736538381792, size = 208 '\320'}, wild = {addr = 10458245367602, access_size = 135661933824356}}}}, addr2_description = {data = {kind = __asan::kAddressKindGlobal, {shadow = {addr = 139785135720343, kind = __asan::kShadowKindGap, shadow_byte = 253 '\375'}, heap = {addr = 139785135720343, alloc_tid = 56293186403585, free_tid = 16923379650608, alloc_stack_id = 65535, free_stack_id = 0, chunk_access = {bad_addr = 93829090601088, offset = 140736538381440, chunk_begin = 135593214252992, chunk_size = 93829087236022, user_requested_alignment = 1600, access_type = 3, alloc_type = 3}}, stack = {addr = 139785135720343, tid = 56293186403585, offset = 16923379650608, frame_pc = 65535, access_size = 93829090601088, frame_descr = 0x7fffc7608c80 "@\366.@\"{"}, global = {addr = 139785135720343, static kMaxGlobals = 4, globals = {{beg = 56293186403585, size = 16923379650608, size_with_redzone = 65535, name = 0x5556499d6880 "%s:%s() ", module_name = 0x7fffc7608c80 "@\366.@\"{", has_dynamic_init = 135593214252992, gcc_location = 0x5556496a0fb6 <btd_debug+358>, odr_indicator = 135387035924032}, {beg = 93829090719264, size = 30064836607, size_with_redzone = 93829090713888, name = 0x7b22404280a0 "0", module_name = 0x7b22402ecd60 "pN^A\222{", has_dynamic_init = 140736538381520, gcc_location = 0x7f2243596f7d <__sanitizer::DTLS_on_tls_get_addr(void*, void*, unsigned long, unsigned long)+125>, odr_indicator = 96}, {beg = 4585564030955459840, size = 140736538381568, size_with_redzone = 4585564030955459840, name = 0xf6448084ff0 <error: Cannot access memory at address 0xf6448084ff0>, module_name = 0x7f2243600f78 "\001", has_dynamic_init = 65535, gcc_location = 0x3fa33230d7e89500, odr_indicator = 139785113979064}, {beg = 135387035913568, size = 93829090601024, size_with_redzone = 93829090610016, name = 0x7b6241600950 "\203\t", module_name = 0xa9964 <error: Cannot access memory at address 0xa9964>, has_dynamic_init = 140736538381664, gcc_location = 0x7b2240428080, odr_indicator = 16923379650576}}, reg_sites = {65535, 0, 1235165472, 21846}, access_size = 140736538381680, size = 96 '`'}, wild = {addr = 139785135720343, access_size = 56293186403585}}}}, function = 0x5556496a0fb6 <btd_debug+358> "I9\336uMH\307\205"}, StringFunctionSizeOverflow = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\260\340\306\377\177\000\0002\000\000\000\000\000\000\000 \202B@\"{\000\0001\000\000\000\000\000\000\000\210\212`\307\377\177\000\000 \202B@\"{\000\000\360\201`\307\377\177\000\000\037\353FC\"\177\000\000\001\000\000\000\000\000\000\000 \202B@\"{\000\000@\212`\307\377\177\000\000\322\205UC\"\177\000\000\000\000\000\000\000\000\000\000\305\fWC\036\000\000\000 \202`\307\377\177\000\000\003\000\000\000\000\000\000\000\020\206UC\"\177\000\000\217\v\213B\"\177\000\000\v*\213IVU\000\000\000\215`\307"...}, tid = 0}, stack = 0x7f2200000002, addr_description = {data = {kind = 1096812900, {shadow = {addr = 0, kind = __asan::kShadowKindLow, shadow_byte = 0 '\000'}, heap = {addr = 0, alloc_tid = 0, free_tid = 10458245367602, alloc_stack_id = 1096812900, free_stack_id = 31586, chunk_access = {bad_addr = 20, offset = 135661933824336, chunk_begin = 40, chunk_size = 55200024125448, user_requested_alignment = 1280, access_type = 1, alloc_type = 2}}, stack = {addr = 0, tid = 0, offset = 10458245367602, frame_pc = 135661933824356, access_size = 20, frame_descr = 0x7b6241600950 "\203\t"}, global = {addr = 0, static kMaxGlobals = 4, globals = {{beg = 0, size = 10458245367602, size_with_redzone = 135661933824356, name = 0x14 <error: Cannot access memory at address 0x14>, module_name = 0x7b6241600950 "\203\t", has_dynamic_init = 40, gcc_location = 0x323441d46008, odr_indicator = 4585564030955459840}, {beg = 135524494906928, size = 139785123366530, size_with_redzone = 140736538380311, name = 0xf <error: Cannot access memory at address 0xf>, module_name = 0x7fffc7608817 "", has_dynamic_init = 206158430224, gcc_location = 0x7fffc7608df0, odr_indicator = 140736538381568}, {beg = 139785123573216, size = 139785122397027, size_with_redzone = 139785110069456, name = 0x3fa33230d7e89500 <error: Cannot access memory at address 0x3fa33230d7e89500>, module_name = 0x7b5200000000 "", has_dynamic_init = 140736538380336, gcc_location = 0x81, odr_indicator = 135387037204896}, {beg = 140736538380336, size = 49, size_with_redzone = 140736538380096, name = 0x7f224287d43c <__GI___dprintf+156> "H\213\225H\377\377\377dH+\024%(", module_name = 0x3000000020 <error: Cannot access memory at address 0x3000000020>, has_dynamic_init = 140736538380112, gcc_location = 0x7fffc7608690, odr_indicator = 4585564030955459840}}, reg_sites = {3344993328, 32767, 0, 0}, access_size = 140736538380356, size = 227 '\343'}, wild = {addr = 0, access_size = 0}}}}, size = 140736538381792}, BadParamsToAnnotateContiguousContainer = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\260\340\306\377\177\000\0002\000\000\000\000\000\000\000 \202B@\"{\000\0001\000\000\000\000\000\000\000\210\212`\307\377\177\000\000 \202B@\"{\000\000\360\201`\307\377\177\000\000\037\353FC\"\177\000\000\001\000\000\000\000\000\000\000 \202B@\"{\000\000@\212`\307\377\177\000\000\322\205UC\"\177\000\000\000\000\000\000\000\000\000\000\305\fWC\036\000\000\000 \202`\307\377\177\000\000\003\000\000\000\000\000\000\000\020\206UC\"\177\000\000\217\v\213B\"\177\000\000\v*\213IVU\000\000\000\215`\307"...}, tid = 0}, stack = 0x7f2200000002, beg = 135661933824356, end = 0, old_mid = 0, new_mid = 10458245367602}, BadParamsToAnnotateDoubleEndedContiguousContainer = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\260\340\306\377\177\000\0002\000\000\000\000\000\000\000 \202B@\"{\000\0001\000\000\000\000\000\000\000\210\212`\307\377\177\000\000 \202B@\"{\000\000\360\201`\307\377\177\000\000\037\353FC\"\177\000\000\001\000\000\000\000\000\000\000 \202B@\"{\000\000@\212`\307\377\177\000\000\322\205UC\"\177\000\000\000\000\000\000\000\000\000\000\305\fWC\036\000\000\000 \202`\307\377\177\000\000\003\000\000\000\000\000\000\000\020\206UC\"\177\000\000\217\v\213B\"\177\000\000\v*\213IVU\000\000\000\215`\307"...}, tid = 0}, stack = 0x7f2200000002, storage_beg = 135661933824356, storage_end = 0, old_container_beg = 0, old_container_end = 10458245367602, new_container_beg = 135661933824356, new_container_end = 20}, BadParamsToCopyContiguousContainerAnnotations = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\260\340\306\377\177\000\0002\000\000\000\000\000\000\000 \202B@\"{\000\0001\000\000\000\000\000\000\000\210\212`\307\377\177\000\000 \202B@\"{\000\000\360\201`\307\377\177\000\000\037\353FC\"\177\000\000\001\000\000\000\000\000\000\000 \202B@\"{\000\000@\212`\307\377\177\000\000\322\205UC\"\177\000\000\000\000\000\000\000\000\000\000\305\fWC\036\000\000\000 \202`\307\377\177\000\000\003\000\000\000\000\000\000\000\020\206UC\"\177\000\000\217\v\213B\"\177\000\000\v*\213IVU\000\000\000\215`\307"...}, tid = 0}, stack = 0x7f2200000002, old_storage_beg = 135661933824356, old_storage_end = 0, new_storage_beg = 0, new_storage_end = 10458245367602}, ODRViolation = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\260\340\306\377\177\000\0002\000\000\000\000\000\000\000 \202B@\"{\000\0001\000\000\000\000\000\000\000\210\212`\307\377\177\000\000 \202B@\"{\000\000\360\201`\307\377\177\000\000\037\353FC\"\177\000\000\001\000\000\000\000\000\000\000 \202B@\"{\000\000@\212`\307\377\177\000\000\322\205UC\"\177\000\000\000\000\000\000\000\000\000\000\305\fWC\036\000\000\000 \202`\307\377\177\000\000\003\000\000\000\000\000\000\000\020\206UC\"\177\000\000\217\v\213B\"\177\000\000\v*\213IVU\000\000\000\215`\307"...}, tid = 0}, global1 = {beg = 139784005615618, size = 135661933824356, size_with_redzone = 0, name = 0x0, module_name = 0x98300000732 <error: Cannot access memory at address 0x98300000732>, has_dynamic_init = 135661933824356, gcc_location = 0x14, odr_indicator = 135661933824336}, global2 = {beg = 40, size = 55200024125448, size_with_redzone = 4585564030955459840, name = 0x7b4241609630 "K\004", module_name = 0x7f22429f8682 "T ", has_dynamic_init = 140736538380311, gcc_location = 0xf, odr_indicator = 140736538380311}, stack_id1 = 16, stack_id2 = 48}, InvalidPointerPair = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\260\340\306\377\177\000\0002\000\000\000\000\000\000\000 \202B@\"{\000\0001\000\000\000\000\000\000\000\210\212`\307\377\177\000\000 \202B@\"{\000\000\360\201`\307\377\177\000\000\037\353FC\"\177\000\000\001\000\000\000\000\000\000\000 \202B@\"{\000\000@\212`\307\377\177\000\000\322\205UC\"\177\000\000\000\000\000\000\000\000\000\000\305\fWC\036\000\000\000 \202`\307\377\177\000\000\003\000\000\000\000\000\000\000\020\206UC\"\177\000\000\217\v\213B\"\177\000\000\v*\213IVU\000\000\000\215`\307"...}, tid = 0}, pc = 139784005615618, bp = 135661933824356, sp = 0, addr1_description = {data = {kind = __asan::kAddressKindWild, {shadow = {addr = 10458245367602, kind = (unknown: 0x64), shadow_byte = 9 '\t'}, heap = {addr = 10458245367602, alloc_tid = 135661933824356, free_tid = 20, alloc_stack_id = 1096812880, free_stack_id = 31586, chunk_access = {bad_addr = 40, offset = 55200024125448, chunk_begin = 4585564030955459840, chunk_size = 135524494906928, user_requested_alignment = 1666, access_type = 0, alloc_type = 2}}, stack = {addr = 10458245367602, tid = 135661933824356, offset = 20, frame_pc = 135661933824336, access_size = 40, frame_descr = 0x323441d46008 <error: Cannot access memory at address 0x323441d46008>}, global = {addr = 10458245367602, static kMaxGlobals = 4, globals = {{beg = 135661933824356, size = 20, size_with_redzone = 135661933824336, name = 0x28 <error: Cannot access memory at address 0x28>, module_name = 0x323441d46008 <error: Cannot access memory at address 0x323441d46008>, has_dynamic_init = 4585564030955459840, gcc_location = 0x7b4241609630, odr_indicator = 139785123366530}, {beg = 140736538380311, size = 15, size_with_redzone = 140736538380311, name = 0x3000000010 <error: Cannot access memory at address 0x3000000010>, module_name = 0x7fffc7608df0 "P\t`Ab{", has_dynamic_init = 140736538381568, gcc_location = 0x7f2242a2ade0 <_nl_C_locobj>, odr_indicator = 139785122397027}, {beg = 139785110069456, size = 4585564030955459840, size_with_redzone = 135592117534720, name = 0x7fffc7608830 "f\rWC\"\177", module_name = 0x81 <error: Cannot access memory at address 0x81>, has_dynamic_init = 135387037204896, gcc_location = 0x7fffc7608830, odr_indicator = 49}, {beg = 140736538380096, size = 139785121813564, size_with_redzone = 206158430240, name = 0x7fffc7608750 "\037\353FC\"\177", module_name = 0x7fffc7608690 "0\214`\307\377\177", has_dynamic_init = 4585564030955459840, gcc_location = 0x7fffc7608c30, odr_indicator = 0}}, reg_sites = {3344992324, 32767, 1230918371, 21846}, access_size = 140736538381792, size = 208 '\320'}, wild = {addr = 10458245367602, access_size = 135661933824356}}}}, addr2_description = {data = {kind = __asan::kAddressKindGlobal, {shadow = {addr = 139785135720343, kind = __asan::kShadowKindGap, shadow_byte = 253 '\375'}, heap = {addr = 139785135720343, alloc_tid = 56293186403585, free_tid = 16923379650608, alloc_stack_id = 65535, free_stack_id = 0, chunk_access = {bad_addr = 93829090601088, offset = 140736538381440, chunk_begin = 135593214252992, chunk_size = 93829087236022, user_requested_alignment = 1600, access_type = 3, alloc_type = 3}}, stack = {addr = 139785135720343, tid = 56293186403585, offset = 16923379650608, frame_pc = 65535, access_size = 93829090601088, frame_descr = 0x7fffc7608c80 "@\366.@\"{"}, global = {addr = 139785135720343, static kMaxGlobals = 4, globals = {{beg = 56293186403585, size = 16923379650608, size_with_redzone = 65535, name = 0x5556499d6880 "%s:%s() ", module_name = 0x7fffc7608c80 "@\366.@\"{", has_dynamic_init = 135593214252992, gcc_location = 0x5556496a0fb6 <btd_debug+358>, odr_indicator = 135387035924032}, {beg = 93829090719264, size = 30064836607, size_with_redzone = 93829090713888, name = 0x7b22404280a0 "0", module_name = 0x7b22402ecd60 "pN^A\222{", has_dynamic_init = 140736538381520, gcc_location = 0x7f2243596f7d <__sanitizer::DTLS_on_tls_get_addr(void*, void*, unsigned long, unsigned long)+125>, odr_indicator = 96}, {beg = 4585564030955459840, size = 140736538381568, size_with_redzone = 4585564030955459840, name = 0xf6448084ff0 <error: Cannot access memory at address 0xf6448084ff0>, module_name = 0x7f2243600f78 "\001", has_dynamic_init = 65535, gcc_location = 0x3fa33230d7e89500, odr_indicator = 139785113979064}, {beg = 135387035913568, size = 93829090601024, size_with_redzone = 93829090610016, name = 0x7b6241600950 "\203\t", module_name = 0xa9964 <error: Cannot access memory at address 0xa9964>, has_dynamic_init = 140736538381664, gcc_location = 0x7b2240428080, odr_indicator = 16923379650576}}, reg_sites = {65535, 0, 1235165472, 21846}, access_size = 140736538381680, size = 96 '`'}, wild = {addr = 139785135720343, access_size = 56293186403585}}}}}, Generic = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\260\340\306\377\177\000\0002\000\000\000\000\000\000\000 \202B@\"{\000\0001\000\000\000\000\000\000\000\210\212`\307\377\177\000\000 \202B@\"{\000\000\360\201`\307\377\177\000\000\037\353FC\"\177\000\000\001\000\000\000\000\000\000\000 \202B@\"{\000\000@\212`\307\377\177\000\000\322\205UC\"\177\000\000\000\000\000\000\000\000\000\000\305\fWC\036\000\000\000 \202`\307\377\177\000\000\003\000\000\000\000\000\000\000\020\206UC\"\177\000\000\217\v\213B\"\177\000\000\v*\213IVU\000\000\000\215`\307"...}, tid = 0}, addr_description = {data = {kind = __asan::kAddressKindHeap, {shadow = {addr = 135661933824356, kind = __asan::kShadowKindLow, shadow_byte = 0 '\000'}, heap = {addr = 135661933824356, alloc_tid = 0, free_tid = 0, alloc_stack_id = 1842, free_stack_id = 2435, chunk_access = {bad_addr = 135661933824356, offset = 20, chunk_begin = 135661933824336, chunk_size = 40, user_requested_alignment = 8, access_type = 2, alloc_type = 1}}, stack = {addr = 135661933824356, tid = 0, offset = 0, frame_pc = 10458245367602, access_size = 135661933824356, frame_descr = 0x14 <error: Cannot access memory at address 0x14>}, global = {addr = 135661933824356, static kMaxGlobals = 4, globals = {{beg = 0, size = 0, size_with_redzone = 10458245367602, name = 0x7b6241600964 "", module_name = 0x14 <error: Cannot access memory at address 0x14>, has_dynamic_init = 135661933824336, gcc_location = 0x28, odr_indicator = 55200024125448}, {beg = 4585564030955459840, size = 135524494906928, size_with_redzone = 139785123366530, name = 0x7fffc7608817 "", module_name = 0xf <error: Cannot access memory at address 0xf>, has_dynamic_init = 140736538380311, gcc_location = 0x3000000010, odr_indicator = 140736538381808}, {beg = 140736538381568, size = 139785123573216, size_with_redzone = 139785122397027, name = 0x7f2241d4a0d0 "", module_name = 0x3fa33230d7e89500 <error: Cannot access memory at address 0x3fa33230d7e89500>, has_dynamic_init = 135592117534720, gcc_location = 0x7fffc7608830, odr_indicator = 129}, {beg = 135387037204896, size = 140736538380336, size_with_redzone = 49, name = 0x7fffc7608740 " \202B@\"{", module_name = 0x7f224287d43c <__GI___dprintf+156> "H\213\225H\377\377\377dH+\024%(", has_dynamic_init = 206158430240, gcc_location = 0x7fffc7608750, odr_indicator = 140736538379920}}, reg_sites = {3622343936, 1067659824, 3344993328, 32767}, access_size = 0, size = 68 'D'}, wild = {addr = 135661933824356, access_size = 0}}}}, pc = 93829086466787, bp = 140736538381792, sp = 140736538381776, access_size = 4, bug_descr = 0x7f22435c0797 "heap-use-after-free", is_write = true, shadow_val = 253 '\375'}}}, halt_on_error_ = true}
error = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\260\340\306\377\177\000\0002\000\000\000\000\000\000\000 \202B@\"{\000\0001\000\000\000\000\000\000\000\210\212`\307\377\177\000\000 \202B@\"{\000\000\360\201`\307\377\177\000\000\037\353FC\"\177\000\000\001\000\000\000\000\000\000\000 \202B@\"{\000\000@\212`\307\377\177\000\000\322\205UC\"\177\000\000\000\000\000\000\000\000\000\000\305\fWC\036\000\000\000 \202`\307\377\177\000\000\003\000\000\000\000\000\000\000\020\206UC\"\177\000\000\217\v\213B\"\177\000\000\v*\213IVU\000\000\000\215`\307"...}, tid = 0}, addr_description = {data = {kind = __asan::kAddressKindHeap, {shadow = {addr = 135661933824356, kind = __asan::kShadowKindLow, shadow_byte = 0 '\000'}, heap = {addr = 135661933824356, alloc_tid = 0, free_tid = 0, alloc_stack_id = 1842, free_stack_id = 2435, chunk_access = {bad_addr = 135661933824356, offset = 20, chunk_begin = 135661933824336, chunk_size = 40, user_requested_alignment = 8, access_type = 2, alloc_type = 1}}, stack = {addr = 135661933824356, tid = 0, offset = 0, frame_pc = 10458245367602, access_size = 135661933824356, frame_descr = 0x14 <error: Cannot access memory at address 0x14>}, global = {addr = 135661933824356, static kMaxGlobals = 4, globals = {{beg = 0, size = 0, size_with_redzone = 10458245367602, name = 0x7b6241600964 "", module_name = 0x14 <error: Cannot access memory at address 0x14>, has_dynamic_init = 135661933824336, gcc_location = 0x28, odr_indicator = 55200024125448}, {beg = 4585564030955459840, size = 135524494906928, size_with_redzone = 139785123366530, name = 0x7fffc7608817 "", module_name = 0xf <error: Cannot access memory at address 0xf>, has_dynamic_init = 140736538380311, gcc_location = 0x3000000010, odr_indicator = 140736538381808}, {beg = 140736538381568, size = 139785123573216, size_with_redzone = 139785122397027, name = 0x7f2241d4a0d0 "", module_name = 0x3fa33230d7e89500 <error: Cannot access memory at address 0x3fa33230d7e89500>, has_dynamic_init = 135592117534720, gcc_location = 0x7fffc7608830, odr_indicator = 129}, {beg = 135387037204896, size = 140736538380336, size_with_redzone = 49, name = 0x7fffc7608740 " \202B@\"{", module_name = 0x7f224287d43c <__GI___dprintf+156> "H\213\225H\377\377\377dH+\024%(", has_dynamic_init = 206158430240, gcc_location = 0x7fffc7608750, odr_indicator = 140736538379920}}, reg_sites = {3622343936, 1067659824, 3344993328, 32767}, access_size = 0, size = 68 'D'}, wild = {addr = 135661933824356, access_size = 0}}}}, pc = 93829086466787, bp = 140736538381792, sp = 140736538381776, access_size = 4, bug_descr = 0x7f22435c0797 "heap-use-after-free", is_write = true, shadow_val = 253 '\375'}
#9 0x00007f2243564f8d in __asan::ReportGenericError (pc=<optimized out>, bp=bp@entry=140736538381792, sp=sp@entry=140736538381776, addr=<optimized out>, is_write=is_write@entry=true, access_size=access_size@entry=4, exp=<optimized out>, fatal=true) at ../../../../src/libsanitizer/asan/asan_report.cpp:536
in_report = <optimized out>
error = <optimized out>
enable_fp = <optimized out>
#10 0x00007f224356685c in __asan::__asan_report_store4 (addr=<optimized out>) at ../../../../src/libsanitizer/asan/asan_rtl.cpp:135
bp = 140736538381792
pc = <optimized out>
local_stack = 135524494906960
sp = 140736538381776
#11 0x00005556495e52e3 in report_notify_destroy (user_data=<optimized out>) at profiles/input/hog-lib.c:359
report = <optimized out>
__func__ = "report_notify_destroy"
#12 0x0000555649687f52 in attrib_callbacks_destroy (data=0x7b82415f2680) at attrib/gattrib.c:126
cb = 0x7b82415f2680
#13 0x0000555649876d6b in notify_data_unref (data=<optimized out>) at src/shared/gatt-client.c:256
notify_data = <optimized out>
#14 notify_data_unref (data=<optimized out>) at src/shared/gatt-client.c:248
notify_data = <optimized out>
#15 0x0000555649821382 in queue_remove_all (queue=queue@entry=0x7b52415e97c0, function=function@entry=0x0, user_data=user_data@entry=0x0, destroy=0x555649876e70 <notify_data_cleanup>) at src/shared/queue.c:341
tmp = 0x7b4241609650
entry = 0x0
count = <optimized out>
#16 0x0000555649821679 in queue_destroy (queue=0x7b52415e97c0, destroy=<optimized out>) at src/shared/queue.c:60
No locals.
#17 0x000055564987d8ba in bt_gatt_client_free (client=0x7c32415e1080) at src/shared/gatt-client.c:2293
No locals.
#18 0x000055564987f56c in bt_gatt_client_unref (client=<optimized out>) at src/shared/gatt-client.c:2605
No locals.
#19 0x00005556496894ed in g_attrib_unref (attrib=0x7b92415e50a0) at attrib/gattrib.c:154
__func__ = "g_attrib_unref"
#20 0x000055564978cd7e in attio_cleanup (device=<optimized out>) at src/device.c:874
attrib = <optimized out>
#21 0x000055564978d2c7 in device_free (user_data=0x7c92415e0080) at src/device.c:918
device = 0x7c92415e0080
__func__ = "device_free"
#22 0x000055564980aeda in remove_interface (data=0x7b92415e4e70, name=name@entry=0x555649a17ae0 "org.bluez.Device1") at gdbus/object.c:742
iface = 0x7b82415e5ae0
#23 0x000055564980da9c in g_dbus_unregister_interface (connection=<optimized out>, path=<optimized out>, name=<optimized out>) at gdbus/object.c:1499
data = <optimized out>
#24 0x0000555649748598 in adapter_remove (adapter=adapter@entry=0x7c52415e0200) at src/adapter.c:7321
device = 0x7c92415e0080
db = <optimized out>
ranging_manager = <optimized out>
__func__ = "adapter_remove"
#25 0x00005556497490d8 in adapter_cleanup () at src/adapter.c:11274
adapter = 0x7c52415e0200
#26 0x00005556494fa330 in main (argc=<optimized out>, argv=<optimized out>) at src/main.c:1723
context = <optimized out>
err = <optimized out>
sdp_mtu = 0
sdp_flags = <optimized out>
gdbus_flags = <optimized out>
__func__ = "main""
https://github.com/bluez/bluez/pull/2574
---
Regards,
Linux Bluetooth
^ permalink raw reply [flat|nested] 14+ messages in thread
* RE: Add HID over GATT functional tests
2026-09-24 13:55 [PATCH BlueZ v2 1/8] attrib: Fix unregistering notifications registered with bt_gatt_client Luiz Augusto von Dentz
@ 2026-09-24 15:25 ` bluez.test.bot
0 siblings, 0 replies; 14+ messages in thread
From: bluez.test.bot @ 2026-09-24 15:25 UTC (permalink / raw)
To: linux-bluetooth, luiz.dentz
[-- Attachment #1: Type: text/plain, Size: 103704 bytes --]
This is automated email and please do not reply to this email!
Dear submitter,
Thank you for submitting the patches to the linux bluetooth mailing list.
This is a CI test results with your patch series:
PW Link:https://patchwork.kernel.org/series/1173166/
---Test result---
Test Summary:
CheckPatch PASS 3.04 seconds
GitLint FAIL 2.13 seconds
BuildEll PASS 17.71 seconds
BluezMake PASS 321.52 seconds
MakeCheck PASS 14.38 seconds
MakeDistcheck PASS 132.25 seconds
CheckValgrind PASS 238.68 seconds
CheckSmatch PASS 250.48 seconds
bluezmakeextell PASS 90.64 seconds
TestFunctional FAIL 1040.06 seconds
IncrementalBuild PASS 373.42 seconds
ScanBuild PASS 1065.31 seconds
Details
##############################
Test: GitLint - FAIL
Desc: Run gitlint
Output:
[BlueZ,v2,1/8] attrib: Fix unregistering notifications registered with bt_gatt_client
1: T1 Title exceeds max length (85>80): "[BlueZ,v2,1/8] attrib: Fix unregistering notifications registered with bt_gatt_client"
##############################
Test: TestFunctional - FAIL
Desc: Run test-functional
Output:
FAIL functional.test_hog::test_hog[no-sci-hosts15-vm2]: failed on teardown with "pytest_bluezenv.plugin.CoredumpWarning: Core dump: test-bluezenv-hosts15.0-bluetoothd-1790261889-112.core
/usr/bin/gdb: warning: Couldn't determine a path for the index cache directory.
[New LWP 112]
[Thread debugging using libthread_db enabled]
Using host libthread_db library "/usr/lib/x86_64-linux-gnu/libthread_db.so.1".
Core was generated by `/home/runner/work/bluez/bluez/src/src/src/bluetoothd --nodetach -f /run/bluetoo'.
Program terminated with signal SIGABRT, Aborted.
#0 __pthread_kill_implementation (threadid=<optimized out>, signo=6, no_tid=0) at ./nptl/pthread_kill.c:44
warning: 44 ./nptl/pthread_kill.c: No such file or directory
Thread 1 (Thread 0x7f556fb87900 (LWP 112)):
#0 __pthread_kill_implementation (threadid=<optimized out>, signo=6, no_tid=0) at ./nptl/pthread_kill.c:44
tid = <optimized out>
ret = 0
pd = <optimized out>
old_mask = {__val = {0}}
ret = <optimized out>
#1 __pthread_kill_internal (threadid=<optimized out>, signo=6) at ./nptl/pthread_kill.c:89
No locals.
#2 __GI___pthread_kill (threadid=<optimized out>, signo=signo@entry=6) at ./nptl/pthread_kill.c:100
No locals.
#3 0x00007f55702e2b7e in __GI_raise (sig=sig@entry=6) at ../sysdeps/posix/raise.c:26
ret = <optimized out>
#4 0x00007f55702c58ec in __GI_abort () at ./stdlib/abort.c:77
act = {__sigaction_handler = {sa_handler = 0x0, sa_sigaction = 0x0}, sa_mask = {__val = {0 <repeats 16 times>}}, sa_flags = 0, sa_restorer = 0x0}
#5 0x00007f5570eeda0f in __sanitizer::Abort () at ../../../../src/libsanitizer/sanitizer_common/sanitizer_posix_libcdep.cpp:165
No locals.
#6 0x00007f5571013c2d in __sanitizer::Die () at ../../../../src/libsanitizer/sanitizer_common/sanitizer_termination.cpp:58
No locals.
#7 0x00007f5570fe893c in __asan::ScopedInErrorReport::~ScopedInErrorReport (this=0x7fff9fc589b6) at ../../../../src/libsanitizer/asan/asan_report.cpp:221
buffer_copy = {buffer_ = {<__sanitizer::InternalMmapVectorNoCtor<char, false>> = {data_ = 0x7b5569cd9000 '=' <repeats 65 times>, "\n==112==ERROR: AddressSanitizer: heap-use-after-free on address 0x7b956f000aa4 at pc 0x5620c8bcf2e3 bp 0x7fff9fc59630 sp 0x7fff9fc59620"..., capacity_bytes_ = 8192, size_ = 4298}, <No data fields>}}
buffer_copy = <optimized out>
l = <optimized out>
#8 0x00007f5570fe7e02 in __asan::ReportGenericError (pc=94698806768355, bp=140735873914416, sp=sp@entry=140735873914400, addr=135881742617252, is_write=is_write@entry=true, access_size=4, fatal=true, exp=<optimized out>) at ../../../../src/libsanitizer/asan/asan_report.cpp:536
in_report = {error_report_lock_ = {<No data fields>}, static current_error_ = {kind = __asan::kErrorKindGeneric, {Base = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\260E\237\377\177\000\0002\000\000\000\000\000\000\000\240'\342mU{\000\0001\000\000\000\000\000\000\000\330\222\305\237\377\177\000\000\240'\342mU{\000\000@\212\305\237\377\177\000\000\037\033\357pU\177\000\000\001\000\000\000\000\000\000\000\240'\342mU{\000\000\220\222\305\237\377\177\000\000\322\265\375pU\177\000\000\240\212\305\237\377\177\000\0008w\357p\036\000\000\000p\212\305\237\377\177\000\000\003\000\000\000\000\000\000\000\020\266\375pU\177\000\000\217;3pU\177\000\000\273\321\351\310 V\000\000P\225\305\237"...}, tid = 0}, DeadlySignal = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\260E\237\377\177\000\0002\000\000\000\000\000\000\000\240'\342mU{\000\0001\000\000\000\000\000\000\000\330\222\305\237\377\177\000\000\240'\342mU{\000\000@\212\305\237\377\177\000\000\037\033\357pU\177\000\000\001\000\000\000\000\000\000\000\240'\342mU{\000\000\220\222\305\237\377\177\000\000\322\265\375pU\177\000\000\240\212\305\237\377\177\000\0008w\357p\036\000\000\000p\212\305\237\377\177\000\000\003\000\000\000\000\000\000\000\020\266\375pU\177\000\000\217;3pU\177\000\000\273\321\351\310 V\000\000P\225\305\237"...}, tid = 0}, signal = {siginfo = 0x7f5500000002, context = 0x7b956f000aa4, addr = 0, pc = 0, sp = 10342281250613, bp = 135881742617252, is_memory_access = 20, write_flag = __sanitizer::SignalContext::Unknown, is_true_faulting_addr = 144}}, DoubleFree = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\260E\237\377\177\000\0002\000\000\000\000\000\000\000\240'\342mU{\000\0001\000\000\000\000\000\000\000\330\222\305\237\377\177\000\000\240'\342mU{\000\000@\212\305\237\377\177\000\000\037\033\357pU\177\000\000\001\000\000\000\000\000\000\000\240'\342mU{\000\000\220\222\305\237\377\177\000\000\322\265\375pU\177\000\000\240\212\305\237\377\177\000\0008w\357p\036\000\000\000p\212\305\237\377\177\000\000\003\000\000\000\000\000\000\000\020\266\375pU\177\000\000\217;3pU\177\000\000\273\321\351\310 V\000\000P\225\305\237"...}, tid = 0}, second_free_stack = 0x7f5500000002, addr_description = {addr = 135881742617252, alloc_tid = 0, free_tid = 0, alloc_stack_id = 1845, free_stack_id = 2408, chunk_access = {bad_addr = 135881742617252, offset = 20, chunk_begin = 135881742617232, chunk_size = 40, user_requested_alignment = 8, access_type = 2, alloc_type = 1}}}, NewDeleteTypeMismatch = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\260E\237\377\177\000\0002\000\000\000\000\000\000\000\240'\342mU{\000\0001\000\000\000\000\000\000\000\330\222\305\237\377\177\000\000\240'\342mU{\000\000@\212\305\237\377\177\000\000\037\033\357pU\177\000\000\001\000\000\000\000\000\000\000\240'\342mU{\000\000\220\222\305\237\377\177\000\000\322\265\375pU\177\000\000\240\212\305\237\377\177\000\0008w\357p\036\000\000\000p\212\305\237\377\177\000\000\003\000\000\000\000\000\000\000\020\266\375pU\177\000\000\217;3pU\177\000\000\273\321\351\310 V\000\000P\225\305\237"...}, tid = 0}, free_stack = 0x7f5500000002, addr_description = {addr = 135881742617252, alloc_tid = 0, free_tid = 0, alloc_stack_id = 1845, free_stack_id = 2408, chunk_access = {bad_addr = 135881742617252, offset = 20, chunk_begin = 135881742617232, chunk_size = 40, user_requested_alignment = 8, access_type = 2, alloc_type = 1}}, delete_size = 5000786010338791936, delete_alignment = 16}, FreeNotMalloced = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\260E\237\377\177\000\0002\000\000\000\000\000\000\000\240'\342mU{\000\0001\000\000\000\000\000\000\000\330\222\305\237\377\177\000\000\240'\342mU{\000\000@\212\305\237\377\177\000\000\037\033\357pU\177\000\000\001\000\000\000\000\000\000\000\240'\342mU{\000\000\220\222\305\237\377\177\000\000\322\265\375pU\177\000\000\240\212\305\237\377\177\000\0008w\357p\036\000\000\000p\212\305\237\377\177\000\000\003\000\000\000\000\000\000\000\020\266\375pU\177\000\000\217;3pU\177\000\000\273\321\351\310 V\000\000P\225\305\237"...}, tid = 0}, free_stack = 0x7f5500000002, addr_description = {data = {kind = 1862273700, {shadow = {addr = 0, kind = __asan::kShadowKindLow, shadow_byte = 0 '\000'}, heap = {addr = 0, alloc_tid = 0, free_tid = 10342281250613, alloc_stack_id = 1862273700, free_stack_id = 31637, chunk_access = {bad_addr = 20, offset = 135881742617232, chunk_begin = 40, chunk_size = 61802964934664, user_requested_alignment = 512, access_type = 1, alloc_type = 2}}, stack = {addr = 0, tid = 0, offset = 10342281250613, frame_pc = 135881742617252, access_size = 20, frame_descr = 0x7b956f000a90 "h\t"}, global = {addr = 0, static kMaxGlobals = 4, globals = {{beg = 0, size = 10342281250613, size_with_redzone = 135881742617252, name = 0x14 <error: Cannot access memory at address 0x14>, module_name = 0x7b956f000a90 "h\t", has_dynamic_init = 40, gcc_location = 0x38359fc56008, odr_indicator = 5000786010338791936}, {beg = 16, size = 140004932695682, size_with_redzone = 140735873912935, name = 0xf <error: Cannot access memory at address 0xf>, module_name = 0x7fff9fc59067 "", has_dynamic_init = 206158430224, gcc_location = 0x7fff9fc59640, odr_indicator = 140735873914192}, {beg = 140004932902368, size = 140004931726179, size_with_redzone = 136087900959056, name = 0x45665c618ffc9200 <error: Cannot access memory at address 0x45665c618ffc9200>, module_name = 0x7fff00000000 <error: Cannot access memory at address 0x7fff00000000>, has_dynamic_init = 140735873912960, gcc_location = 0x70, odr_indicator = 135606845974304}, {beg = 140735873912960, size = 49, size_with_redzone = 140735873912720, name = 0x7f557030043c <__GI___dprintf+156> "H\213\225H\377\377\377dH+\024%(", module_name = 0x3000000020 <error: Cannot access memory at address 0x3000000020>, has_dynamic_init = 140735873912736, gcc_location = 0x7fff9fc58ee0, odr_indicator = 5000786010338791936}}, reg_sites = {2680525952, 32767, 0, 0}, access_size = 140735873912980, size = 227 '\343'}, wild = {addr = 0, access_size = 0}}}}}, AllocTypeMismatch = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\260E\237\377\177\000\0002\000\000\000\000\000\000\000\240'\342mU{\000\0001\000\000\000\000\000\000\000\330\222\305\237\377\177\000\000\240'\342mU{\000\000@\212\305\237\377\177\000\000\037\033\357pU\177\000\000\001\000\000\000\000\000\000\000\240'\342mU{\000\000\220\222\305\237\377\177\000\000\322\265\375pU\177\000\000\240\212\305\237\377\177\000\0008w\357p\036\000\000\000p\212\305\237\377\177\000\000\003\000\000\000\000\000\000\000\020\266\375pU\177\000\000\217;3pU\177\000\000\273\321\351\310 V\000\000P\225\305\237"...}, tid = 0}, dealloc_stack = 0x7f5500000002, alloc_type = 1862273700, dealloc_type = 31637, addr_description = {data = {kind = __asan::kAddressKindWild, {shadow = {addr = 0, kind = (__asan::kShadowKindGap | unknown: 0x34), shadow_byte = 7 '\a'}, heap = {addr = 0, alloc_tid = 10342281250613, free_tid = 135881742617252, alloc_stack_id = 20, free_stack_id = 0, chunk_access = {bad_addr = 135881742617232, offset = 40, chunk_begin = 61802964934664, chunk_size = 5000786010338791936, user_requested_alignment = 16, access_type = 0, alloc_type = 0}}, stack = {addr = 0, tid = 10342281250613, offset = 135881742617252, frame_pc = 20, access_size = 135881742617232, frame_descr = 0x28 <error: Cannot access memory at address 0x28>}, global = {addr = 0, static kMaxGlobals = 4, globals = {{beg = 10342281250613, size = 135881742617252, size_with_redzone = 20, name = 0x7b956f000a90 "h\t", module_name = 0x28 <error: Cannot access memory at address 0x28>, has_dynamic_init = 61802964934664, gcc_location = 0x45665c618ffc9200, odr_indicator = 16}, {beg = 140004932695682, size = 140735873912935, size_with_redzone = 15, name = 0x7fff9fc59067 "", module_name = 0x3000000010 <error: Cannot access memory at address 0x3000000010>, has_dynamic_init = 140735873914432, gcc_location = 0x7fff9fc59550, odr_indicator = 140004932902368}, {beg = 140004931726179, size = 136087900959056, size_with_redzone = 5000786010338791936, name = 0x7fff00000000 <error: Cannot access memory at address 0x7fff00000000>, module_name = 0x7fff9fc59080 "f=\377pU\177", has_dynamic_init = 112, gcc_location = 0x7b556de22720, odr_indicator = 140735873912960}, {beg = 49, size = 140735873912720, size_with_redzone = 140004931142716, name = 0x3000000020 <error: Cannot access memory at address 0x3000000020>, module_name = 0x7fff9fc58fa0 "\037\033\357pU\177", has_dynamic_init = 140735873912544, gcc_location = 0x45665c618ffc9200, odr_indicator = 140735873913984}}, reg_sites = {0, 0, 2680524948, 32767}, access_size = 94698806768355, size = 48 '0'}, wild = {addr = 0, access_size = 10342281250613}}}}}, MallocUsableSizeNotOwned = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\260E\237\377\177\000\0002\000\000\000\000\000\000\000\240'\342mU{\000\0001\000\000\000\000\000\000\000\330\222\305\237\377\177\000\000\240'\342mU{\000\000@\212\305\237\377\177\000\000\037\033\357pU\177\000\000\001\000\000\000\000\000\000\000\240'\342mU{\000\000\220\222\305\237\377\177\000\000\322\265\375pU\177\000\000\240\212\305\237\377\177\000\0008w\357p\036\000\000\000p\212\305\237\377\177\000\000\003\000\000\000\000\000\000\000\020\266\375pU\177\000\000\217;3pU\177\000\000\273\321\351\310 V\000\000P\225\305\237"...}, tid = 0}, stack = 0x7f5500000002, addr_description = {data = {kind = 1862273700, {shadow = {addr = 0, kind = __asan::kShadowKindLow, shadow_byte = 0 '\000'}, heap = {addr = 0, alloc_tid = 0, free_tid = 10342281250613, alloc_stack_id = 1862273700, free_stack_id = 31637, chunk_access = {bad_addr = 20, offset = 135881742617232, chunk_begin = 40, chunk_size = 61802964934664, user_requested_alignment = 512, access_type = 1, alloc_type = 2}}, stack = {addr = 0, tid = 0, offset = 10342281250613, frame_pc = 135881742617252, access_size = 20, frame_descr = 0x7b956f000a90 "h\t"}, global = {addr = 0, static kMaxGlobals = 4, globals = {{beg = 0, size = 10342281250613, size_with_redzone = 135881742617252, name = 0x14 <error: Cannot access memory at address 0x14>, module_name = 0x7b956f000a90 "h\t", has_dynamic_init = 40, gcc_location = 0x38359fc56008, odr_indicator = 5000786010338791936}, {beg = 16, size = 140004932695682, size_with_redzone = 140735873912935, name = 0xf <error: Cannot access memory at address 0xf>, module_name = 0x7fff9fc59067 "", has_dynamic_init = 206158430224, gcc_location = 0x7fff9fc59640, odr_indicator = 140735873914192}, {beg = 140004932902368, size = 140004931726179, size_with_redzone = 136087900959056, name = 0x45665c618ffc9200 <error: Cannot access memory at address 0x45665c618ffc9200>, module_name = 0x7fff00000000 <error: Cannot access memory at address 0x7fff00000000>, has_dynamic_init = 140735873912960, gcc_location = 0x70, odr_indicator = 135606845974304}, {beg = 140735873912960, size = 49, size_with_redzone = 140735873912720, name = 0x7f557030043c <__GI___dprintf+156> "H\213\225H\377\377\377dH+\024%(", module_name = 0x3000000020 <error: Cannot access memory at address 0x3000000020>, has_dynamic_init = 140735873912736, gcc_location = 0x7fff9fc58ee0, odr_indicator = 5000786010338791936}}, reg_sites = {2680525952, 32767, 0, 0}, access_size = 140735873912980, size = 227 '\343'}, wild = {addr = 0, access_size = 0}}}}}, SanitizerGetAllocatedSizeNotOwned = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\260E\237\377\177\000\0002\000\000\000\000\000\000\000\240'\342mU{\000\0001\000\000\000\000\000\000\000\330\222\305\237\377\177\000\000\240'\342mU{\000\000@\212\305\237\377\177\000\000\037\033\357pU\177\000\000\001\000\000\000\000\000\000\000\240'\342mU{\000\000\220\222\305\237\377\177\000\000\322\265\375pU\177\000\000\240\212\305\237\377\177\000\0008w\357p\036\000\000\000p\212\305\237\377\177\000\000\003\000\000\000\000\000\000\000\020\266\375pU\177\000\000\217;3pU\177\000\000\273\321\351\310 V\000\000P\225\305\237"...}, tid = 0}, stack = 0x7f5500000002, addr_description = {data = {kind = 1862273700, {shadow = {addr = 0, kind = __asan::kShadowKindLow, shadow_byte = 0 '\000'}, heap = {addr = 0, alloc_tid = 0, free_tid = 10342281250613, alloc_stack_id = 1862273700, free_stack_id = 31637, chunk_access = {bad_addr = 20, offset = 135881742617232, chunk_begin = 40, chunk_size = 61802964934664, user_requested_alignment = 512, access_type = 1, alloc_type = 2}}, stack = {addr = 0, tid = 0, offset = 10342281250613, frame_pc = 135881742617252, access_size = 20, frame_descr = 0x7b956f000a90 "h\t"}, global = {addr = 0, static kMaxGlobals = 4, globals = {{beg = 0, size = 10342281250613, size_with_redzone = 135881742617252, name = 0x14 <error: Cannot access memory at address 0x14>, module_name = 0x7b956f000a90 "h\t", has_dynamic_init = 40, gcc_location = 0x38359fc56008, odr_indicator = 5000786010338791936}, {beg = 16, size = 140004932695682, size_with_redzone = 140735873912935, name = 0xf <error: Cannot access memory at address 0xf>, module_name = 0x7fff9fc59067 "", has_dynamic_init = 206158430224, gcc_location = 0x7fff9fc59640, odr_indicator = 140735873914192}, {beg = 140004932902368, size = 140004931726179, size_with_redzone = 136087900959056, name = 0x45665c618ffc9200 <error: Cannot access memory at address 0x45665c618ffc9200>, module_name = 0x7fff00000000 <error: Cannot access memory at address 0x7fff00000000>, has_dynamic_init = 140735873912960, gcc_location = 0x70, odr_indicator = 135606845974304}, {beg = 140735873912960, size = 49, size_with_redzone = 140735873912720, name = 0x7f557030043c <__GI___dprintf+156> "H\213\225H\377\377\377dH+\024%(", module_name = 0x3000000020 <error: Cannot access memory at address 0x3000000020>, has_dynamic_init = 140735873912736, gcc_location = 0x7fff9fc58ee0, odr_indicator = 5000786010338791936}}, reg_sites = {2680525952, 32767, 0, 0}, access_size = 140735873912980, size = 227 '\343'}, wild = {addr = 0, access_size = 0}}}}}, CallocOverflow = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\260E\237\377\177\000\0002\000\000\000\000\000\000\000\240'\342mU{\000\0001\000\000\000\000\000\000\000\330\222\305\237\377\177\000\000\240'\342mU{\000\000@\212\305\237\377\177\000\000\037\033\357pU\177\000\000\001\000\000\000\000\000\000\000\240'\342mU{\000\000\220\222\305\237\377\177\000\000\322\265\375pU\177\000\000\240\212\305\237\377\177\000\0008w\357p\036\000\000\000p\212\305\237\377\177\000\000\003\000\000\000\000\000\000\000\020\266\375pU\177\000\000\217;3pU\177\000\000\273\321\351\310 V\000\000P\225\305\237"...}, tid = 0}, stack = 0x7f5500000002, count = 135881742617252, size = 0}, ReallocArrayOverflow = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\260E\237\377\177\000\0002\000\000\000\000\000\000\000\240'\342mU{\000\0001\000\000\000\000\000\000\000\330\222\305\237\377\177\000\000\240'\342mU{\000\000@\212\305\237\377\177\000\000\037\033\357pU\177\000\000\001\000\000\000\000\000\000\000\240'\342mU{\000\000\220\222\305\237\377\177\000\000\322\265\375pU\177\000\000\240\212\305\237\377\177\000\0008w\357p\036\000\000\000p\212\305\237\377\177\000\000\003\000\000\000\000\000\000\000\020\266\375pU\177\000\000\217;3pU\177\000\000\273\321\351\310 V\000\000P\225\305\237"...}, tid = 0}, stack = 0x7f5500000002, count = 135881742617252, size = 0}, PvallocOverflow = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\260E\237\377\177\000\0002\000\000\000\000\000\000\000\240'\342mU{\000\0001\000\000\000\000\000\000\000\330\222\305\237\377\177\000\000\240'\342mU{\000\000@\212\305\237\377\177\000\000\037\033\357pU\177\000\000\001\000\000\000\000\000\000\000\240'\342mU{\000\000\220\222\305\237\377\177\000\000\322\265\375pU\177\000\000\240\212\305\237\377\177\000\0008w\357p\036\000\000\000p\212\305\237\377\177\000\000\003\000\000\000\000\000\000\000\020\266\375pU\177\000\000\217;3pU\177\000\000\273\321\351\310 V\000\000P\225\305\237"...}, tid = 0}, stack = 0x7f5500000002, size = 135881742617252}, InvalidAllocationAlignment = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\260E\237\377\177\000\0002\000\000\000\000\000\000\000\240'\342mU{\000\0001\000\000\000\000\000\000\000\330\222\305\237\377\177\000\000\240'\342mU{\000\000@\212\305\237\377\177\000\000\037\033\357pU\177\000\000\001\000\000\000\000\000\000\000\240'\342mU{\000\000\220\222\305\237\377\177\000\000\322\265\375pU\177\000\000\240\212\305\237\377\177\000\0008w\357p\036\000\000\000p\212\305\237\377\177\000\000\003\000\000\000\000\000\000\000\020\266\375pU\177\000\000\217;3pU\177\000\000\273\321\351\310 V\000\000P\225\305\237"...}, tid = 0}, stack = 0x7f5500000002, alignment = 135881742617252}, InvalidAlignedAllocAlignment = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\260E\237\377\177\000\0002\000\000\000\000\000\000\000\240'\342mU{\000\0001\000\000\000\000\000\000\000\330\222\305\237\377\177\000\000\240'\342mU{\000\000@\212\305\237\377\177\000\000\037\033\357pU\177\000\000\001\000\000\000\000\000\000\000\240'\342mU{\000\000\220\222\305\237\377\177\000\000\322\265\375pU\177\000\000\240\212\305\237\377\177\000\0008w\357p\036\000\000\000p\212\305\237\377\177\000\000\003\000\000\000\000\000\000\000\020\266\375pU\177\000\000\217;3pU\177\000\000\273\321\351\310 V\000\000P\225\305\237"...}, tid = 0}, stack = 0x7f5500000002, size = 135881742617252, alignment = 0}, InvalidPosixMemalignAlignment = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\260E\237\377\177\000\0002\000\000\000\000\000\000\000\240'\342mU{\000\0001\000\000\000\000\000\000\000\330\222\305\237\377\177\000\000\240'\342mU{\000\000@\212\305\237\377\177\000\000\037\033\357pU\177\000\000\001\000\000\000\000\000\000\000\240'\342mU{\000\000\220\222\305\237\377\177\000\000\322\265\375pU\177\000\000\240\212\305\237\377\177\000\0008w\357p\036\000\000\000p\212\305\237\377\177\000\000\003\000\000\000\000\000\000\000\020\266\375pU\177\000\000\217;3pU\177\000\000\273\321\351\310 V\000\000P\225\305\237"...}, tid = 0}, stack = 0x7f5500000002, alignment = 135881742617252}, AllocationSizeTooBig = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\260E\237\377\177\000\0002\000\000\000\000\000\000\000\240'\342mU{\000\0001\000\000\000\000\000\000\000\330\222\305\237\377\177\000\000\240'\342mU{\000\000@\212\305\237\377\177\000\000\037\033\357pU\177\000\000\001\000\000\000\000\000\000\000\240'\342mU{\000\000\220\222\305\237\377\177\000\000\322\265\375pU\177\000\000\240\212\305\237\377\177\000\0008w\357p\036\000\000\000p\212\305\237\377\177\000\000\003\000\000\000\000\000\000\000\020\266\375pU\177\000\000\217;3pU\177\000\000\273\321\351\310 V\000\000P\225\305\237"...}, tid = 0}, stack = 0x7f5500000002, user_size = 135881742617252, total_size = 0, max_size = 0}, RssLimitExceeded = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\260E\237\377\177\000\0002\000\000\000\000\000\000\000\240'\342mU{\000\0001\000\000\000\000\000\000\000\330\222\305\237\377\177\000\000\240'\342mU{\000\000@\212\305\237\377\177\000\000\037\033\357pU\177\000\000\001\000\000\000\000\000\000\000\240'\342mU{\000\000\220\222\305\237\377\177\000\000\322\265\375pU\177\000\000\240\212\305\237\377\177\000\0008w\357p\036\000\000\000p\212\305\237\377\177\000\000\003\000\000\000\000\000\000\000\020\266\375pU\177\000\000\217;3pU\177\000\000\273\321\351\310 V\000\000P\225\305\237"...}, tid = 0}, stack = 0x7f5500000002}, OutOfMemory = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\260E\237\377\177\000\0002\000\000\000\000\000\000\000\240'\342mU{\000\0001\000\000\000\000\000\000\000\330\222\305\237\377\177\000\000\240'\342mU{\000\000@\212\305\237\377\177\000\000\037\033\357pU\177\000\000\001\000\000\000\000\000\000\000\240'\342mU{\000\000\220\222\305\237\377\177\000\000\322\265\375pU\177\000\000\240\212\305\237\377\177\000\0008w\357p\036\000\000\000p\212\305\237\377\177\000\000\003\000\000\000\000\000\000\000\020\266\375pU\177\000\000\217;3pU\177\000\000\273\321\351\310 V\000\000P\225\305\237"...}, tid = 0}, stack = 0x7f5500000002, requested_size = 135881742617252}, StringFunctionMemoryRangesOverlap = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\260E\237\377\177\000\0002\000\000\000\000\000\000\000\240'\342mU{\000\0001\000\000\000\000\000\000\000\330\222\305\237\377\177\000\000\240'\342mU{\000\000@\212\305\237\377\177\000\000\037\033\357pU\177\000\000\001\000\000\000\000\000\000\000\240'\342mU{\000\000\220\222\305\237\377\177\000\000\322\265\375pU\177\000\000\240\212\305\237\377\177\000\0008w\357p\036\000\000\000p\212\305\237\377\177\000\000\003\000\000\000\000\000\000\000\020\266\375pU\177\000\000\217;3pU\177\000\000\273\321\351\310 V\000\000P\225\305\237"...}, tid = 0}, stack = 0x7f5500000002, length1 = 135881742617252, length2 = 0, addr1_description = {data = {kind = __asan::kAddressKindWild, {shadow = {addr = 10342281250613, kind = (unknown: 0xa4), shadow_byte = 10 '\n'}, heap = {addr = 10342281250613, alloc_tid = 135881742617252, free_tid = 20, alloc_stack_id = 1862273680, free_stack_id = 31637, chunk_access = {bad_addr = 40, offset = 61802964934664, chunk_begin = 5000786010338791936, chunk_size = 16, user_requested_alignment = 1666, access_type = 3, alloc_type = 2}}, stack = {addr = 10342281250613, tid = 135881742617252, offset = 20, frame_pc = 135881742617232, access_size = 40, frame_descr = 0x38359fc56008 <error: Cannot access memory at address 0x38359fc56008>}, global = {addr = 10342281250613, static kMaxGlobals = 4, globals = {{beg = 135881742617252, size = 20, size_with_redzone = 135881742617232, name = 0x28 <error: Cannot access memory at address 0x28>, module_name = 0x38359fc56008 <error: Cannot access memory at address 0x38359fc56008>, has_dynamic_init = 5000786010338791936, gcc_location = 0x10, odr_indicator = 140004932695682}, {beg = 140735873912935, size = 15, size_with_redzone = 140735873912935, name = 0x3000000010 <error: Cannot access memory at address 0x3000000010>, module_name = 0x7fff9fc59640 "\220\n", has_dynamic_init = 140735873914192, gcc_location = 0x7f55704adde0 <_nl_C_locobj>, odr_indicator = 140004931726179}, {beg = 136087900959056, size = 5000786010338791936, size_with_redzone = 140733193388032, name = 0x7fff9fc59080 "f=\377pU\177", module_name = 0x70 <error: Cannot access memory at address 0x70>, has_dynamic_init = 135606845974304, gcc_location = 0x7fff9fc59080, odr_indicator = 49}, {beg = 140735873912720, size = 140004931142716, size_with_redzone = 206158430240, name = 0x7fff9fc58fa0 "\037\033\357pU\177", module_name = 0x7fff9fc58ee0 "\200\224\305\237\377\177", has_dynamic_init = 5000786010338791936, gcc_location = 0x7fff9fc59480, odr_indicator = 0}}, reg_sites = {2680524948, 32767, 3367826147, 22048}, access_size = 140735873914416, size = 32 ' '}, wild = {addr = 10342281250613, access_size = 135881742617252}}}}, addr2_description = {data = {kind = __asan::kAddressKindGlobal, {shadow = {addr = 140004945049495, kind = __asan::kShadowKindGap, shadow_byte = 253 '\375'}, heap = {addr = 140004945049495, alloc_tid = 57392033561857, free_tid = 16950855746784, alloc_stack_id = 65535, free_stack_id = 0, chunk_access = {bad_addr = 94698810902656, offset = 140735873914064, chunk_begin = 136156620396832, chunk_size = 94698807539558, user_requested_alignment = 1296, access_type = 1, alloc_type = 2}}, stack = {addr = 140004945049495, tid = 57392033561857, offset = 16950855746784, frame_pc = 65535, access_size = 94698810902656, frame_descr = 0x7fff9fc594d0 "\020\225\305\237\377\177"}, global = {addr = 140004945049495, static kMaxGlobals = 4, globals = {{beg = 57392033561857, size = 16950855746784, size_with_redzone = 65535, name = 0x5620c8fc0880 "%s:%s() ", module_name = 0x7fff9fc594d0 "\020\225\305\237\377\177", has_dynamic_init = 136156620396832, gcc_location = 0x5620c8c8b766 <btd_debug+358>, odr_indicator = 140735873914128}, {beg = 140004944431426, size = 19860395280, size_with_redzone = 87, name = 0x7f557104598c "sendmsg", module_name = 0x45665c618ffc9200 <error: Cannot access memory at address 0x45665c618ffc9200>, has_dynamic_init = 1, gcc_location = 0x7b556e057340, odr_indicator = 16950856035904}, {beg = 94698809707719, size = 135605002436695, size_with_redzone = 140735873914224, name = 0xf6aadc0ae40 <error: Cannot access memory at address 0xf6aadc0ae40>, module_name = 0x7b556e057250 "", has_dynamic_init = 140735873914496, gcc_location = 0x45665c618ffc9200, odr_indicator = 16950855890002}, {beg = 3847307972724495752, size = 94698810902592, size_with_redzone = 94698810911584, name = 0x7b956f000a90 "h\t", module_name = 0xa148d <error: Cannot access memory at address 0xa148d>, has_dynamic_init = 135606845974048, gcc_location = 0x45665c618ffc9200, odr_indicator = 67}}, reg_sites = {2680526312, 32767, 2680526560, 32767}, access_size = 140004931353514, size = 116 't'}, wild = {addr = 140004945049495, access_size = 57392033561857}}}}, function = 0x7fff9fc595e8 "0\254\344\310 V"}, StringFunctionSizeOverflow = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\260E\237\377\177\000\0002\000\000\000\000\000\000\000\240'\342mU{\000\0001\000\000\000\000\000\000\000\330\222\305\237\377\177\000\000\240'\342mU{\000\000@\212\305\237\377\177\000\000\037\033\357pU\177\000\000\001\000\000\000\000\000\000\000\240'\342mU{\000\000\220\222\305\237\377\177\000\000\322\265\375pU\177\000\000\240\212\305\237\377\177\000\0008w\357p\036\000\000\000p\212\305\237\377\177\000\000\003\000\000\000\000\000\000\000\020\266\375pU\177\000\000\217;3pU\177\000\000\273\321\351\310 V\000\000P\225\305\237"...}, tid = 0}, stack = 0x7f5500000002, addr_description = {data = {kind = 1862273700, {shadow = {addr = 0, kind = __asan::kShadowKindLow, shadow_byte = 0 '\000'}, heap = {addr = 0, alloc_tid = 0, free_tid = 10342281250613, alloc_stack_id = 1862273700, free_stack_id = 31637, chunk_access = {bad_addr = 20, offset = 135881742617232, chunk_begin = 40, chunk_size = 61802964934664, user_requested_alignment = 512, access_type = 1, alloc_type = 2}}, stack = {addr = 0, tid = 0, offset = 10342281250613, frame_pc = 135881742617252, access_size = 20, frame_descr = 0x7b956f000a90 "h\t"}, global = {addr = 0, static kMaxGlobals = 4, globals = {{beg = 0, size = 10342281250613, size_with_redzone = 135881742617252, name = 0x14 <error: Cannot access memory at address 0x14>, module_name = 0x7b956f000a90 "h\t", has_dynamic_init = 40, gcc_location = 0x38359fc56008, odr_indicator = 5000786010338791936}, {beg = 16, size = 140004932695682, size_with_redzone = 140735873912935, name = 0xf <error: Cannot access memory at address 0xf>, module_name = 0x7fff9fc59067 "", has_dynamic_init = 206158430224, gcc_location = 0x7fff9fc59640, odr_indicator = 140735873914192}, {beg = 140004932902368, size = 140004931726179, size_with_redzone = 136087900959056, name = 0x45665c618ffc9200 <error: Cannot access memory at address 0x45665c618ffc9200>, module_name = 0x7fff00000000 <error: Cannot access memory at address 0x7fff00000000>, has_dynamic_init = 140735873912960, gcc_location = 0x70, odr_indicator = 135606845974304}, {beg = 140735873912960, size = 49, size_with_redzone = 140735873912720, name = 0x7f557030043c <__GI___dprintf+156> "H\213\225H\377\377\377dH+\024%(", module_name = 0x3000000020 <error: Cannot access memory at address 0x3000000020>, has_dynamic_init = 140735873912736, gcc_location = 0x7fff9fc58ee0, odr_indicator = 5000786010338791936}}, reg_sites = {2680525952, 32767, 0, 0}, access_size = 140735873912980, size = 227 '\343'}, wild = {addr = 0, access_size = 0}}}}, size = 140735873914416}, BadParamsToAnnotateContiguousContainer = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\260E\237\377\177\000\0002\000\000\000\000\000\000\000\240'\342mU{\000\0001\000\000\000\000\000\000\000\330\222\305\237\377\177\000\000\240'\342mU{\000\000@\212\305\237\377\177\000\000\037\033\357pU\177\000\000\001\000\000\000\000\000\000\000\240'\342mU{\000\000\220\222\305\237\377\177\000\000\322\265\375pU\177\000\000\240\212\305\237\377\177\000\0008w\357p\036\000\000\000p\212\305\237\377\177\000\000\003\000\000\000\000\000\000\000\020\266\375pU\177\000\000\217;3pU\177\000\000\273\321\351\310 V\000\000P\225\305\237"...}, tid = 0}, stack = 0x7f5500000002, beg = 135881742617252, end = 0, old_mid = 0, new_mid = 10342281250613}, BadParamsToAnnotateDoubleEndedContiguousContainer = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\260E\237\377\177\000\0002\000\000\000\000\000\000\000\240'\342mU{\000\0001\000\000\000\000\000\000\000\330\222\305\237\377\177\000\000\240'\342mU{\000\000@\212\305\237\377\177\000\000\037\033\357pU\177\000\000\001\000\000\000\000\000\000\000\240'\342mU{\000\000\220\222\305\237\377\177\000\000\322\265\375pU\177\000\000\240\212\305\237\377\177\000\0008w\357p\036\000\000\000p\212\305\237\377\177\000\000\003\000\000\000\000\000\000\000\020\266\375pU\177\000\000\217;3pU\177\000\000\273\321\351\310 V\000\000P\225\305\237"...}, tid = 0}, stack = 0x7f5500000002, storage_beg = 135881742617252, storage_end = 0, old_container_beg = 0, old_container_end = 10342281250613, new_container_beg = 135881742617252, new_container_end = 20}, BadParamsToCopyContiguousContainerAnnotations = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\260E\237\377\177\000\0002\000\000\000\000\000\000\000\240'\342mU{\000\0001\000\000\000\000\000\000\000\330\222\305\237\377\177\000\000\240'\342mU{\000\000@\212\305\237\377\177\000\000\037\033\357pU\177\000\000\001\000\000\000\000\000\000\000\240'\342mU{\000\000\220\222\305\237\377\177\000\000\322\265\375pU\177\000\000\240\212\305\237\377\177\000\0008w\357p\036\000\000\000p\212\305\237\377\177\000\000\003\000\000\000\000\000\000\000\020\266\375pU\177\000\000\217;3pU\177\000\000\273\321\351\310 V\000\000P\225\305\237"...}, tid = 0}, stack = 0x7f5500000002, old_storage_beg = 135881742617252, old_storage_end = 0, new_storage_beg = 0, new_storage_end = 10342281250613}, ODRViolation = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\260E\237\377\177\000\0002\000\000\000\000\000\000\000\240'\342mU{\000\0001\000\000\000\000\000\000\000\330\222\305\237\377\177\000\000\240'\342mU{\000\000@\212\305\237\377\177\000\000\037\033\357pU\177\000\000\001\000\000\000\000\000\000\000\240'\342mU{\000\000\220\222\305\237\377\177\000\000\322\265\375pU\177\000\000\240\212\305\237\377\177\000\0008w\357p\036\000\000\000p\212\305\237\377\177\000\000\003\000\000\000\000\000\000\000\020\266\375pU\177\000\000\217;3pU\177\000\000\273\321\351\310 V\000\000P\225\305\237"...}, tid = 0}, global1 = {beg = 140003048947714, size = 135881742617252, size_with_redzone = 0, name = 0x0, module_name = 0x96800000735 <error: Cannot access memory at address 0x96800000735>, has_dynamic_init = 135881742617252, gcc_location = 0x14, odr_indicator = 135881742617232}, global2 = {beg = 40, size = 61802964934664, size_with_redzone = 5000786010338791936, name = 0x10 <error: Cannot access memory at address 0x10>, module_name = 0x7f557047b682 "T ", has_dynamic_init = 140735873912935, gcc_location = 0xf, odr_indicator = 140735873912935}, stack_id1 = 16, stack_id2 = 48}, InvalidPointerPair = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\260E\237\377\177\000\0002\000\000\000\000\000\000\000\240'\342mU{\000\0001\000\000\000\000\000\000\000\330\222\305\237\377\177\000\000\240'\342mU{\000\000@\212\305\237\377\177\000\000\037\033\357pU\177\000\000\001\000\000\000\000\000\000\000\240'\342mU{\000\000\220\222\305\237\377\177\000\000\322\265\375pU\177\000\000\240\212\305\237\377\177\000\0008w\357p\036\000\000\000p\212\305\237\377\177\000\000\003\000\000\000\000\000\000\000\020\266\375pU\177\000\000\217;3pU\177\000\000\273\321\351\310 V\000\000P\225\305\237"...}, tid = 0}, pc = 140003048947714, bp = 135881742617252, sp = 0, addr1_description = {data = {kind = __asan::kAddressKindWild, {shadow = {addr = 10342281250613, kind = (unknown: 0xa4), shadow_byte = 10 '\n'}, heap = {addr = 10342281250613, alloc_tid = 135881742617252, free_tid = 20, alloc_stack_id = 1862273680, free_stack_id = 31637, chunk_access = {bad_addr = 40, offset = 61802964934664, chunk_begin = 5000786010338791936, chunk_size = 16, user_requested_alignment = 1666, access_type = 3, alloc_type = 2}}, stack = {addr = 10342281250613, tid = 135881742617252, offset = 20, frame_pc = 135881742617232, access_size = 40, frame_descr = 0x38359fc56008 <error: Cannot access memory at address 0x38359fc56008>}, global = {addr = 10342281250613, static kMaxGlobals = 4, globals = {{beg = 135881742617252, size = 20, size_with_redzone = 135881742617232, name = 0x28 <error: Cannot access memory at address 0x28>, module_name = 0x38359fc56008 <error: Cannot access memory at address 0x38359fc56008>, has_dynamic_init = 5000786010338791936, gcc_location = 0x10, odr_indicator = 140004932695682}, {beg = 140735873912935, size = 15, size_with_redzone = 140735873912935, name = 0x3000000010 <error: Cannot access memory at address 0x3000000010>, module_name = 0x7fff9fc59640 "\220\n", has_dynamic_init = 140735873914192, gcc_location = 0x7f55704adde0 <_nl_C_locobj>, odr_indicator = 140004931726179}, {beg = 136087900959056, size = 5000786010338791936, size_with_redzone = 140733193388032, name = 0x7fff9fc59080 "f=\377pU\177", module_name = 0x70 <error: Cannot access memory at address 0x70>, has_dynamic_init = 135606845974304, gcc_location = 0x7fff9fc59080, odr_indicator = 49}, {beg = 140735873912720, size = 140004931142716, size_with_redzone = 206158430240, name = 0x7fff9fc58fa0 "\037\033\357pU\177", module_name = 0x7fff9fc58ee0 "\200\224\305\237\377\177", has_dynamic_init = 5000786010338791936, gcc_location = 0x7fff9fc59480, odr_indicator = 0}}, reg_sites = {2680524948, 32767, 3367826147, 22048}, access_size = 140735873914416, size = 32 ' '}, wild = {addr = 10342281250613, access_size = 135881742617252}}}}, addr2_description = {data = {kind = __asan::kAddressKindGlobal, {shadow = {addr = 140004945049495, kind = __asan::kShadowKindGap, shadow_byte = 253 '\375'}, heap = {addr = 140004945049495, alloc_tid = 57392033561857, free_tid = 16950855746784, alloc_stack_id = 65535, free_stack_id = 0, chunk_access = {bad_addr = 94698810902656, offset = 140735873914064, chunk_begin = 136156620396832, chunk_size = 94698807539558, user_requested_alignment = 1296, access_type = 1, alloc_type = 2}}, stack = {addr = 140004945049495, tid = 57392033561857, offset = 16950855746784, frame_pc = 65535, access_size = 94698810902656, frame_descr = 0x7fff9fc594d0 "\020\225\305\237\377\177"}, global = {addr = 140004945049495, static kMaxGlobals = 4, globals = {{beg = 57392033561857, size = 16950855746784, size_with_redzone = 65535, name = 0x5620c8fc0880 "%s:%s() ", module_name = 0x7fff9fc594d0 "\020\225\305\237\377\177", has_dynamic_init = 136156620396832, gcc_location = 0x5620c8c8b766 <btd_debug+358>, odr_indicator = 140735873914128}, {beg = 140004944431426, size = 19860395280, size_with_redzone = 87, name = 0x7f557104598c "sendmsg", module_name = 0x45665c618ffc9200 <error: Cannot access memory at address 0x45665c618ffc9200>, has_dynamic_init = 1, gcc_location = 0x7b556e057340, odr_indicator = 16950856035904}, {beg = 94698809707719, size = 135605002436695, size_with_redzone = 140735873914224, name = 0xf6aadc0ae40 <error: Cannot access memory at address 0xf6aadc0ae40>, module_name = 0x7b556e057250 "", has_dynamic_init = 140735873914496, gcc_location = 0x45665c618ffc9200, odr_indicator = 16950855890002}, {beg = 3847307972724495752, size = 94698810902592, size_with_redzone = 94698810911584, name = 0x7b956f000a90 "h\t", module_name = 0xa148d <error: Cannot access memory at address 0xa148d>, has_dynamic_init = 135606845974048, gcc_location = 0x45665c618ffc9200, odr_indicator = 67}}, reg_sites = {2680526312, 32767, 2680526560, 32767}, access_size = 140004931353514, size = 116 't'}, wild = {addr = 140004945049495, access_size = 57392033561857}}}}}, Generic = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\260E\237\377\177\000\0002\000\000\000\000\000\000\000\240'\342mU{\000\0001\000\000\000\000\000\000\000\330\222\305\237\377\177\000\000\240'\342mU{\000\000@\212\305\237\377\177\000\000\037\033\357pU\177\000\000\001\000\000\000\000\000\000\000\240'\342mU{\000\000\220\222\305\237\377\177\000\000\322\265\375pU\177\000\000\240\212\305\237\377\177\000\0008w\357p\036\000\000\000p\212\305\237\377\177\000\000\003\000\000\000\000\000\000\000\020\266\375pU\177\000\000\217;3pU\177\000\000\273\321\351\310 V\000\000P\225\305\237"...}, tid = 0}, addr_description = {data = {kind = __asan::kAddressKindHeap, {shadow = {addr = 135881742617252, kind = __asan::kShadowKindLow, shadow_byte = 0 '\000'}, heap = {addr = 135881742617252, alloc_tid = 0, free_tid = 0, alloc_stack_id = 1845, free_stack_id = 2408, chunk_access = {bad_addr = 135881742617252, offset = 20, chunk_begin = 135881742617232, chunk_size = 40, user_requested_alignment = 8, access_type = 2, alloc_type = 1}}, stack = {addr = 135881742617252, tid = 0, offset = 0, frame_pc = 10342281250613, access_size = 135881742617252, frame_descr = 0x14 <error: Cannot access memory at address 0x14>}, global = {addr = 135881742617252, static kMaxGlobals = 4, globals = {{beg = 0, size = 0, size_with_redzone = 10342281250613, name = 0x7b956f000aa4 "", module_name = 0x14 <error: Cannot access memory at address 0x14>, has_dynamic_init = 135881742617232, gcc_location = 0x28, odr_indicator = 61802964934664}, {beg = 5000786010338791936, size = 16, size_with_redzone = 140004932695682, name = 0x7fff9fc59067 "", module_name = 0xf <error: Cannot access memory at address 0xf>, has_dynamic_init = 140735873912935, gcc_location = 0x3000000010, odr_indicator = 140735873914432}, {beg = 140735873914192, size = 140004932902368, size_with_redzone = 140004931726179, name = 0x7bc56efeb150 "_", module_name = 0x45665c618ffc9200 <error: Cannot access memory at address 0x45665c618ffc9200>, has_dynamic_init = 140733193388032, gcc_location = 0x7fff9fc59080, odr_indicator = 112}, {beg = 135606845974304, size = 140735873912960, size_with_redzone = 49, name = 0x7fff9fc58f90 "\240'\342mU{", module_name = 0x7f557030043c <__GI___dprintf+156> "H\213\225H\377\377\377dH+\024%(", has_dynamic_init = 206158430240, gcc_location = 0x7fff9fc58fa0, odr_indicator = 140735873912544}}, reg_sites = {2415694336, 1164336225, 2680525952, 32767}, access_size = 0, size = 148 '\224'}, wild = {addr = 135881742617252, access_size = 0}}}}, pc = 94698806768355, bp = 140735873914416, sp = 140735873914400, access_size = 4, bug_descr = 0x7f5571043797 "heap-use-after-free", is_write = true, shadow_val = 253 '\375'}}}, halt_on_error_ = true}
error = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\260E\237\377\177\000\0002\000\000\000\000\000\000\000\240'\342mU{\000\0001\000\000\000\000\000\000\000\330\222\305\237\377\177\000\000\240'\342mU{\000\000@\212\305\237\377\177\000\000\037\033\357pU\177\000\000\001\000\000\000\000\000\000\000\240'\342mU{\000\000\220\222\305\237\377\177\000\000\322\265\375pU\177\000\000\240\212\305\237\377\177\000\0008w\357p\036\000\000\000p\212\305\237\377\177\000\000\003\000\000\000\000\000\000\000\020\266\375pU\177\000\000\217;3pU\177\000\000\273\321\351\310 V\000\000P\225\305\237"...}, tid = 0}, addr_description = {data = {kind = __asan::kAddressKindHeap, {shadow = {addr = 135881742617252, kind = __asan::kShadowKindLow, shadow_byte = 0 '\000'}, heap = {addr = 135881742617252, alloc_tid = 0, free_tid = 0, alloc_stack_id = 1845, free_stack_id = 2408, chunk_access = {bad_addr = 135881742617252, offset = 20, chunk_begin = 135881742617232, chunk_size = 40, user_requested_alignment = 8, access_type = 2, alloc_type = 1}}, stack = {addr = 135881742617252, tid = 0, offset = 0, frame_pc = 10342281250613, access_size = 135881742617252, frame_descr = 0x14 <error: Cannot access memory at address 0x14>}, global = {addr = 135881742617252, static kMaxGlobals = 4, globals = {{beg = 0, size = 0, size_with_redzone = 10342281250613, name = 0x7b956f000aa4 "", module_name = 0x14 <error: Cannot access memory at address 0x14>, has_dynamic_init = 135881742617232, gcc_location = 0x28, odr_indicator = 61802964934664}, {beg = 5000786010338791936, size = 16, size_with_redzone = 140004932695682, name = 0x7fff9fc59067 "", module_name = 0xf <error: Cannot access memory at address 0xf>, has_dynamic_init = 140735873912935, gcc_location = 0x3000000010, odr_indicator = 140735873914432}, {beg = 140735873914192, size = 140004932902368, size_with_redzone = 140004931726179, name = 0x7bc56efeb150 "_", module_name = 0x45665c618ffc9200 <error: Cannot access memory at address 0x45665c618ffc9200>, has_dynamic_init = 140733193388032, gcc_location = 0x7fff9fc59080, odr_indicator = 112}, {beg = 135606845974304, size = 140735873912960, size_with_redzone = 49, name = 0x7fff9fc58f90 "\240'\342mU{", module_name = 0x7f557030043c <__GI___dprintf+156> "H\213\225H\377\377\377dH+\024%(", has_dynamic_init = 206158430240, gcc_location = 0x7fff9fc58fa0, odr_indicator = 140735873912544}}, reg_sites = {2415694336, 1164336225, 2680525952, 32767}, access_size = 0, size = 148 '\224'}, wild = {addr = 135881742617252, access_size = 0}}}}, pc = 94698806768355, bp = 140735873914416, sp = 140735873914400, access_size = 4, bug_descr = 0x7f5571043797 "heap-use-after-free", is_write = true, shadow_val = 253 '\375'}
#9 0x00007f5570fe7f8d in __asan::ReportGenericError (pc=<optimized out>, bp=bp@entry=140735873914416, sp=sp@entry=140735873914400, addr=<optimized out>, is_write=is_write@entry=true, access_size=access_size@entry=4, exp=<optimized out>, fatal=true) at ../../../../src/libsanitizer/asan/asan_report.cpp:536
in_report = <optimized out>
error = <optimized out>
enable_fp = <optimized out>
#10 0x00007f5570fe985c in __asan::__asan_report_store4 (addr=<optimized out>) at ../../../../src/libsanitizer/asan/asan_rtl.cpp:135
bp = 140735873914416
pc = <optimized out>
local_stack = 94698809371696
sp = 140735873914400
#11 0x00005620c8bcf2e3 in report_notify_destroy (user_data=<optimized out>) at profiles/input/hog-lib.c:359
report = <optimized out>
__func__ = "report_notify_destroy"
#12 0x00005620c8c72052 in attrib_callbacks_destroy (data=0x7bb56eff1c60) at attrib/gattrib.c:130
cb = 0x7bb56eff1c60
#13 0x00005620c8e6151b in notify_data_unref (data=<optimized out>) at src/shared/gatt-client.c:256
notify_data = <optimized out>
#14 notify_data_unref (data=<optimized out>) at src/shared/gatt-client.c:248
notify_data = <optimized out>
#15 0x00005620c8e5c3e0 in destroy_write_op (data=0x7b856f000bc0) at src/shared/gatt-client.c:3189
op = 0x7b856f000bc0
#16 0x00005620c8e6c153 in request_unref (data=0x7b956f006510) at src/shared/gatt-client.c:201
req = 0x7b956f006510
client = 0x7c656efe1940
#17 0x00005620c8e4b1a4 in destroy_att_send_op (data=0x7bb56eff2c20) at src/shared/att.c:215
op = 0x7bb56eff2c20
#18 0x00005620c8e54fe0 in bt_att_cancel (att=<optimized out>, id=<optimized out>) at src/shared/att.c:1925
entry = 0x0
op = <optimized out>
#19 0x00005620c8e60cc3 in cancel_request (req=<optimized out>) at src/shared/gatt-client.c:2783
No locals.
#20 0x00005620c8e0bb32 in queue_remove_all (queue=0x7b856efeadb0, function=function@entry=0x0, user_data=user_data@entry=0x0, destroy=destroy@entry=0x5620c8e61230 <cancel_pending>) at src/shared/queue.c:341
tmp = 0x7b756f00a3f0
entry = 0x0
count = <optimized out>
#21 0x00005620c8e67d3f in bt_gatt_client_cancel_all (client=client@entry=0x7c656efe1940) at src/shared/gatt-client.c:2811
No locals.
#22 0x00005620c8e67fdd in bt_gatt_client_free (client=0x7c656efe1940) at src/shared/gatt-client.c:2290
No locals.
#23 0x00005620c8e69d1c in bt_gatt_client_unref (client=<optimized out>) at src/shared/gatt-client.c:2605
No locals.
#24 0x00005620c8c735ed in g_attrib_unref (attrib=0x7bd56efe18a0) at attrib/gattrib.c:158
__func__ = "g_attrib_unref"
#25 0x00005620c8d7752e in attio_cleanup (device=<optimized out>) at src/device.c:874
attrib = <optimized out>
#26 0x00005620c8d77a77 in device_free (user_data=0x7cc56efe0080) at src/device.c:918
device = 0x7cc56efe0080
__func__ = "device_free"
#27 0x00005620c8df568a in remove_interface (data=0x7bc56efe4e70, name=name@entry=0x5620c9001ae0 "org.bluez.Device1") at gdbus/object.c:742
iface = 0x7bb56efe5ae0
#28 0x00005620c8df824c in g_dbus_unregister_interface (connection=<optimized out>, path=<optimized out>, name=<optimized out>) at gdbus/object.c:1499
data = <optimized out>
#29 0x00005620c8d32d48 in adapter_remove (adapter=adapter@entry=0x7c856efe0200) at src/adapter.c:7321
device = 0x7cc56efe0080
db = <optimized out>
ranging_manager = <optimized out>
__func__ = "adapter_remove"
#30 0x00005620c8d33888 in adapter_cleanup () at src/adapter.c:11274
adapter = 0x7c856efe0200
#31 0x00005620c8ae4330 in main (argc=<optimized out>, argv=<optimized out>) at src/main.c:1723
context = <optimized out>
err = <optimized out>
sdp_mtu = 0
sdp_flags = <optimized out>
gdbus_flags = <optimized out>
__func__ = "main""
FAIL functional.test_hog::test_hog[sci-hosts15-vm2]: failed on teardown with "pytest_bluezenv.plugin.CoredumpWarning: Core dump: test-bluezenv-hosts15.0-bluetoothd-1790261899-128.core
/usr/bin/gdb: warning: Couldn't determine a path for the index cache directory.
[New LWP 128]
[Thread debugging using libthread_db enabled]
Using host libthread_db library "/usr/lib/x86_64-linux-gnu/libthread_db.so.1".
Core was generated by `/home/runner/work/bluez/bluez/src/src/src/bluetoothd --nodetach -f /run/bluetoo'.
Program terminated with signal SIGABRT, Aborted.
#0 __pthread_kill_implementation (threadid=<optimized out>, signo=6, no_tid=0) at ./nptl/pthread_kill.c:44
warning: 44 ./nptl/pthread_kill.c: No such file or directory
Thread 1 (Thread 0x7f27f96d3900 (LWP 128)):
#0 __pthread_kill_implementation (threadid=<optimized out>, signo=6, no_tid=0) at ./nptl/pthread_kill.c:44
tid = <optimized out>
ret = 0
pd = <optimized out>
old_mask = {__val = {0}}
ret = <optimized out>
#1 __pthread_kill_internal (threadid=<optimized out>, signo=6) at ./nptl/pthread_kill.c:89
No locals.
#2 __GI___pthread_kill (threadid=<optimized out>, signo=signo@entry=6) at ./nptl/pthread_kill.c:100
No locals.
#3 0x00007f27f9e2eb7e in __GI_raise (sig=sig@entry=6) at ../sysdeps/posix/raise.c:26
ret = <optimized out>
#4 0x00007f27f9e118ec in __GI_abort () at ./stdlib/abort.c:77
act = {__sigaction_handler = {sa_handler = 0x0, sa_sigaction = 0x0}, sa_mask = {__val = {0 <repeats 16 times>}}, sa_flags = 0, sa_restorer = 0x0}
#5 0x00007f27faa39a0f in __sanitizer::Abort () at ../../../../src/libsanitizer/sanitizer_common/sanitizer_posix_libcdep.cpp:165
No locals.
#6 0x00007f27fab5fc2d in __sanitizer::Die () at ../../../../src/libsanitizer/sanitizer_common/sanitizer_termination.cpp:58
No locals.
#7 0x00007f27fab3493c in __asan::ScopedInErrorReport::~ScopedInErrorReport (this=0x7ffe82debf76) at ../../../../src/libsanitizer/asan/asan_report.cpp:221
buffer_copy = {buffer_ = {<__sanitizer::InternalMmapVectorNoCtor<char, false>> = {data_ = 0x7b27f3825000 '=' <repeats 65 times>, "\n==128==ERROR: AddressSanitizer: heap-use-after-free on address 0x7b67f8c006e4 at pc 0x558db2bfd2e3 bp 0x7ffe82decbf0 sp 0x7ffe82decbe0"..., capacity_bytes_ = 8192, size_ = 4298}, <No data fields>}}
buffer_copy = <optimized out>
l = <optimized out>
#8 0x00007f27fab33e02 in __asan::ReportGenericError (pc=94067077665507, bp=140731094060016, sp=sp@entry=140731094060000, addr=135686485182180, is_write=is_write@entry=true, access_size=4, fatal=true, exp=<optimized out>) at ../../../../src/libsanitizer/asan/asan_report.cpp:536
in_report = {error_report_lock_ = {<No data fields>}, static current_error_ = {kind = __asan::kErrorKindGeneric, {Base = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\360^\202\376\177\000\0002\000\000\000\000\000\000\000\240\202\242\367'{\000\0001\000\000\000\000\000\000\000\230\310\336\202\376\177\000\000\240\202\242\367'{\000\000\000\300\336\202\376\177\000\000\037\333\243\372'\177\000\000\001\000\000\000\000\000\000\000\240\202\242\367'{\000\000P\310\336\202\376\177\000\000\322u\262\372'\177\000\000`\300\336\202\376\177\000\00087\244\372\036\000\000\0000\300\336\202\376\177\000\000\003\000\000\000\000\000\000\000\020v\262\372'\177\000\000\217\373\347\371'\177\000\000\273\261\354\262\215U\000\000\020\313\336\202"...}, tid = 0}, DeadlySignal = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\360^\202\376\177\000\0002\000\000\000\000\000\000\000\240\202\242\367'{\000\0001\000\000\000\000\000\000\000\230\310\336\202\376\177\000\000\240\202\242\367'{\000\000\000\300\336\202\376\177\000\000\037\333\243\372'\177\000\000\001\000\000\000\000\000\000\000\240\202\242\367'{\000\000P\310\336\202\376\177\000\000\322u\262\372'\177\000\000`\300\336\202\376\177\000\00087\244\372\036\000\000\0000\300\336\202\376\177\000\000\003\000\000\000\000\000\000\000\020v\262\372'\177\000\000\217\373\347\371'\177\000\000\273\261\354\262\215U\000\000\020\313\336\202"...}, tid = 0}, signal = {siginfo = 0x7f2700000002, context = 0x7b67f8c006e4, addr = 0, pc = 0, sp = 10441065498421, bp = 135686485182180, is_memory_access = 20, write_flag = __sanitizer::SignalContext::Unknown, is_true_faulting_addr = 208}}, DoubleFree = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\360^\202\376\177\000\0002\000\000\000\000\000\000\000\240\202\242\367'{\000\0001\000\000\000\000\000\000\000\230\310\336\202\376\177\000\000\240\202\242\367'{\000\000\000\300\336\202\376\177\000\000\037\333\243\372'\177\000\000\001\000\000\000\000\000\000\000\240\202\242\367'{\000\000P\310\336\202\376\177\000\000\322u\262\372'\177\000\000`\300\336\202\376\177\000\00087\244\372\036\000\000\0000\300\336\202\376\177\000\000\003\000\000\000\000\000\000\000\020v\262\372'\177\000\000\217\373\347\371'\177\000\000\273\261\354\262\215U\000\000\020\313\336\202"...}, tid = 0}, second_free_stack = 0x7f2700000002, addr_description = {addr = 135686485182180, alloc_tid = 0, free_tid = 0, alloc_stack_id = 1845, free_stack_id = 2431, chunk_access = {bad_addr = 135686485182180, offset = 20, chunk_begin = 135686485182160, chunk_size = 40, user_requested_alignment = 8, access_type = 2, alloc_type = 1}}}, NewDeleteTypeMismatch = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\360^\202\376\177\000\0002\000\000\000\000\000\000\000\240\202\242\367'{\000\0001\000\000\000\000\000\000\000\230\310\336\202\376\177\000\000\240\202\242\367'{\000\000\000\300\336\202\376\177\000\000\037\333\243\372'\177\000\000\001\000\000\000\000\000\000\000\240\202\242\367'{\000\000P\310\336\202\376\177\000\000\322u\262\372'\177\000\000`\300\336\202\376\177\000\00087\244\372\036\000\000\0000\300\336\202\376\177\000\000\003\000\000\000\000\000\000\000\020v\262\372'\177\000\000\217\373\347\371'\177\000\000\273\261\354\262\215U\000\000\020\313\336\202"...}, tid = 0}, free_stack = 0x7f2700000002, addr_description = {addr = 135686485182180, alloc_tid = 0, free_tid = 0, alloc_stack_id = 1845, free_stack_id = 2431, chunk_access = {bad_addr = 135686485182180, offset = 20, chunk_begin = 135686485182160, chunk_size = 40, user_requested_alignment = 8, access_type = 2, alloc_type = 1}}, delete_size = 11908522307766607616, delete_alignment = 16}, FreeNotMalloced = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\360^\202\376\177\000\0002\000\000\000\000\000\000\000\240\202\242\367'{\000\0001\000\000\000\000\000\000\000\230\310\336\202\376\177\000\000\240\202\242\367'{\000\000\000\300\336\202\376\177\000\000\037\333\243\372'\177\000\000\001\000\000\000\000\000\000\000\240\202\242\367'{\000\000P\310\336\202\376\177\000\000\322u\262\372'\177\000\000`\300\336\202\376\177\000\00087\244\372\036\000\000\0000\300\336\202\376\177\000\000\003\000\000\000\000\000\000\000\020v\262\372'\177\000\000\217\373\347\371'\177\000\000\273\261\354\262\215U\000\000\020\313\336\202"...}, tid = 0}, free_stack = 0x7f2700000002, addr_description = {data = {kind = 4173334244, {shadow = {addr = 0, kind = __asan::kShadowKindLow, shadow_byte = 0 '\000'}, heap = {addr = 0, alloc_tid = 0, free_tid = 10441065498421, alloc_stack_id = 4173334244, free_stack_id = 31591, chunk_access = {bad_addr = 20, offset = 135686485182160, chunk_begin = 40, chunk_size = 62884811792392, user_requested_alignment = 3840, access_type = 1, alloc_type = 1}}, stack = {addr = 0, tid = 0, offset = 10441065498421, frame_pc = 135686485182180, access_size = 20, frame_descr = 0x7b67f8c006d0 "\177\t"}, global = {addr = 0, static kMaxGlobals = 4, globals = {{beg = 0, size = 10441065498421, size_with_redzone = 135686485182180, name = 0x14 <error: Cannot access memory at address 0x14>, module_name = 0x7b67f8c006d0 "\177\t", has_dynamic_init = 40, gcc_location = 0x393182de6008, odr_indicator = 11908522307766607616}, {beg = 16, size = 139809674524290, size_with_redzone = 140731094058535, name = 0xf <error: Cannot access memory at address 0xf>, module_name = 0x7ffe82dec627 "", has_dynamic_init = 206158430224, gcc_location = 0x7ffe82decc00, odr_indicator = 140731094059792}, {beg = 139809674730976, size = 139809673554787, size_with_redzone = 135892643527184, name = 0xa54391f1e23e5f00 <error: Cannot access memory at address 0xa54391f1e23e5f00>, module_name = 0x7ffe00000000 <error: Cannot access memory at address 0x7ffe00000000>, has_dynamic_init = 140731094058560, gcc_location = 0x80, odr_indicator = 135411588563488}, {beg = 140731094058560, size = 49, size_with_redzone = 140731094058320, name = 0x7f27f9e4c43c <__GI___dprintf+156> "H\213\225H\377\377\377dH+\024%(", module_name = 0x3000000020 <error: Cannot access memory at address 0x3000000020>, has_dynamic_init = 140731094058336, gcc_location = 0x7ffe82dec4a0, odr_indicator = 11908522307766607616}}, reg_sites = {2195638848, 32766, 0, 0}, access_size = 140731094058580, size = 227 '\343'}, wild = {addr = 0, access_size = 0}}}}}, AllocTypeMismatch = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\360^\202\376\177\000\0002\000\000\000\000\000\000\000\240\202\242\367'{\000\0001\000\000\000\000\000\000\000\230\310\336\202\376\177\000\000\240\202\242\367'{\000\000\000\300\336\202\376\177\000\000\037\333\243\372'\177\000\000\001\000\000\000\000\000\000\000\240\202\242\367'{\000\000P\310\336\202\376\177\000\000\322u\262\372'\177\000\000`\300\336\202\376\177\000\00087\244\372\036\000\000\0000\300\336\202\376\177\000\000\003\000\000\000\000\000\000\000\020v\262\372'\177\000\000\217\373\347\371'\177\000\000\273\261\354\262\215U\000\000\020\313\336\202"...}, tid = 0}, dealloc_stack = 0x7f2700000002, alloc_type = 4173334244, dealloc_type = 31591, addr_description = {data = {kind = __asan::kAddressKindWild, {shadow = {addr = 0, kind = (__asan::kShadowKindGap | unknown: 0x34), shadow_byte = 7 '\a'}, heap = {addr = 0, alloc_tid = 10441065498421, free_tid = 135686485182180, alloc_stack_id = 20, free_stack_id = 0, chunk_access = {bad_addr = 135686485182160, offset = 40, chunk_begin = 62884811792392, chunk_size = 11908522307766607616, user_requested_alignment = 16, access_type = 0, alloc_type = 0}}, stack = {addr = 0, tid = 10441065498421, offset = 135686485182180, frame_pc = 20, access_size = 135686485182160, frame_descr = 0x28 <error: Cannot access memory at address 0x28>}, global = {addr = 0, static kMaxGlobals = 4, globals = {{beg = 10441065498421, size = 135686485182180, size_with_redzone = 20, name = 0x7b67f8c006d0 "\177\t", module_name = 0x28 <error: Cannot access memory at address 0x28>, has_dynamic_init = 62884811792392, gcc_location = 0xa54391f1e23e5f00, odr_indicator = 16}, {beg = 139809674524290, size = 140731094058535, size_with_redzone = 15, name = 0x7ffe82dec627 "", module_name = 0x3000000010 <error: Cannot access memory at address 0x3000000010>, has_dynamic_init = 140731094060032, gcc_location = 0x7ffe82decb10, odr_indicator = 139809674730976}, {beg = 139809673554787, size = 135892643527184, size_with_redzone = 11908522307766607616, name = 0x7ffe00000000 <error: Cannot access memory at address 0x7ffe00000000>, module_name = 0x7ffe82dec640 "f\375\263\372'\177", has_dynamic_init = 128, gcc_location = 0x7b27f7a28220, odr_indicator = 140731094058560}, {beg = 49, size = 140731094058320, size_with_redzone = 139809672971324, name = 0x3000000020 <error: Cannot access memory at address 0x3000000020>, module_name = 0x7ffe82dec560 "\037\333\243\372'\177", has_dynamic_init = 140731094058144, gcc_location = 0xa54391f1e23e5f00, odr_indicator = 140731094059584}}, reg_sites = {0, 0, 2195637844, 32766}, access_size = 94067077665507, size = 240 '\360'}, wild = {addr = 0, access_size = 10441065498421}}}}}, MallocUsableSizeNotOwned = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\360^\202\376\177\000\0002\000\000\000\000\000\000\000\240\202\242\367'{\000\0001\000\000\000\000\000\000\000\230\310\336\202\376\177\000\000\240\202\242\367'{\000\000\000\300\336\202\376\177\000\000\037\333\243\372'\177\000\000\001\000\000\000\000\000\000\000\240\202\242\367'{\000\000P\310\336\202\376\177\000\000\322u\262\372'\177\000\000`\300\336\202\376\177\000\00087\244\372\036\000\000\0000\300\336\202\376\177\000\000\003\000\000\000\000\000\000\000\020v\262\372'\177\000\000\217\373\347\371'\177\000\000\273\261\354\262\215U\000\000\020\313\336\202"...}, tid = 0}, stack = 0x7f2700000002, addr_description = {data = {kind = 4173334244, {shadow = {addr = 0, kind = __asan::kShadowKindLow, shadow_byte = 0 '\000'}, heap = {addr = 0, alloc_tid = 0, free_tid = 10441065498421, alloc_stack_id = 4173334244, free_stack_id = 31591, chunk_access = {bad_addr = 20, offset = 135686485182160, chunk_begin = 40, chunk_size = 62884811792392, user_requested_alignment = 3840, access_type = 1, alloc_type = 1}}, stack = {addr = 0, tid = 0, offset = 10441065498421, frame_pc = 135686485182180, access_size = 20, frame_descr = 0x7b67f8c006d0 "\177\t"}, global = {addr = 0, static kMaxGlobals = 4, globals = {{beg = 0, size = 10441065498421, size_with_redzone = 135686485182180, name = 0x14 <error: Cannot access memory at address 0x14>, module_name = 0x7b67f8c006d0 "\177\t", has_dynamic_init = 40, gcc_location = 0x393182de6008, odr_indicator = 11908522307766607616}, {beg = 16, size = 139809674524290, size_with_redzone = 140731094058535, name = 0xf <error: Cannot access memory at address 0xf>, module_name = 0x7ffe82dec627 "", has_dynamic_init = 206158430224, gcc_location = 0x7ffe82decc00, odr_indicator = 140731094059792}, {beg = 139809674730976, size = 139809673554787, size_with_redzone = 135892643527184, name = 0xa54391f1e23e5f00 <error: Cannot access memory at address 0xa54391f1e23e5f00>, module_name = 0x7ffe00000000 <error: Cannot access memory at address 0x7ffe00000000>, has_dynamic_init = 140731094058560, gcc_location = 0x80, odr_indicator = 135411588563488}, {beg = 140731094058560, size = 49, size_with_redzone = 140731094058320, name = 0x7f27f9e4c43c <__GI___dprintf+156> "H\213\225H\377\377\377dH+\024%(", module_name = 0x3000000020 <error: Cannot access memory at address 0x3000000020>, has_dynamic_init = 140731094058336, gcc_location = 0x7ffe82dec4a0, odr_indicator = 11908522307766607616}}, reg_sites = {2195638848, 32766, 0, 0}, access_size = 140731094058580, size = 227 '\343'}, wild = {addr = 0, access_size = 0}}}}}, SanitizerGetAllocatedSizeNotOwned = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\360^\202\376\177\000\0002\000\000\000\000\000\000\000\240\202\242\367'{\000\0001\000\000\000\000\000\000\000\230\310\336\202\376\177\000\000\240\202\242\367'{\000\000\000\300\336\202\376\177\000\000\037\333\243\372'\177\000\000\001\000\000\000\000\000\000\000\240\202\242\367'{\000\000P\310\336\202\376\177\000\000\322u\262\372'\177\000\000`\300\336\202\376\177\000\00087\244\372\036\000\000\0000\300\336\202\376\177\000\000\003\000\000\000\000\000\000\000\020v\262\372'\177\000\000\217\373\347\371'\177\000\000\273\261\354\262\215U\000\000\020\313\336\202"...}, tid = 0}, stack = 0x7f2700000002, addr_description = {data = {kind = 4173334244, {shadow = {addr = 0, kind = __asan::kShadowKindLow, shadow_byte = 0 '\000'}, heap = {addr = 0, alloc_tid = 0, free_tid = 10441065498421, alloc_stack_id = 4173334244, free_stack_id = 31591, chunk_access = {bad_addr = 20, offset = 135686485182160, chunk_begin = 40, chunk_size = 62884811792392, user_requested_alignment = 3840, access_type = 1, alloc_type = 1}}, stack = {addr = 0, tid = 0, offset = 10441065498421, frame_pc = 135686485182180, access_size = 20, frame_descr = 0x7b67f8c006d0 "\177\t"}, global = {addr = 0, static kMaxGlobals = 4, globals = {{beg = 0, size = 10441065498421, size_with_redzone = 135686485182180, name = 0x14 <error: Cannot access memory at address 0x14>, module_name = 0x7b67f8c006d0 "\177\t", has_dynamic_init = 40, gcc_location = 0x393182de6008, odr_indicator = 11908522307766607616}, {beg = 16, size = 139809674524290, size_with_redzone = 140731094058535, name = 0xf <error: Cannot access memory at address 0xf>, module_name = 0x7ffe82dec627 "", has_dynamic_init = 206158430224, gcc_location = 0x7ffe82decc00, odr_indicator = 140731094059792}, {beg = 139809674730976, size = 139809673554787, size_with_redzone = 135892643527184, name = 0xa54391f1e23e5f00 <error: Cannot access memory at address 0xa54391f1e23e5f00>, module_name = 0x7ffe00000000 <error: Cannot access memory at address 0x7ffe00000000>, has_dynamic_init = 140731094058560, gcc_location = 0x80, odr_indicator = 135411588563488}, {beg = 140731094058560, size = 49, size_with_redzone = 140731094058320, name = 0x7f27f9e4c43c <__GI___dprintf+156> "H\213\225H\377\377\377dH+\024%(", module_name = 0x3000000020 <error: Cannot access memory at address 0x3000000020>, has_dynamic_init = 140731094058336, gcc_location = 0x7ffe82dec4a0, odr_indicator = 11908522307766607616}}, reg_sites = {2195638848, 32766, 0, 0}, access_size = 140731094058580, size = 227 '\343'}, wild = {addr = 0, access_size = 0}}}}}, CallocOverflow = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\360^\202\376\177\000\0002\000\000\000\000\000\000\000\240\202\242\367'{\000\0001\000\000\000\000\000\000\000\230\310\336\202\376\177\000\000\240\202\242\367'{\000\000\000\300\336\202\376\177\000\000\037\333\243\372'\177\000\000\001\000\000\000\000\000\000\000\240\202\242\367'{\000\000P\310\336\202\376\177\000\000\322u\262\372'\177\000\000`\300\336\202\376\177\000\00087\244\372\036\000\000\0000\300\336\202\376\177\000\000\003\000\000\000\000\000\000\000\020v\262\372'\177\000\000\217\373\347\371'\177\000\000\273\261\354\262\215U\000\000\020\313\336\202"...}, tid = 0}, stack = 0x7f2700000002, count = 135686485182180, size = 0}, ReallocArrayOverflow = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\360^\202\376\177\000\0002\000\000\000\000\000\000\000\240\202\242\367'{\000\0001\000\000\000\000\000\000\000\230\310\336\202\376\177\000\000\240\202\242\367'{\000\000\000\300\336\202\376\177\000\000\037\333\243\372'\177\000\000\001\000\000\000\000\000\000\000\240\202\242\367'{\000\000P\310\336\202\376\177\000\000\322u\262\372'\177\000\000`\300\336\202\376\177\000\00087\244\372\036\000\000\0000\300\336\202\376\177\000\000\003\000\000\000\000\000\000\000\020v\262\372'\177\000\000\217\373\347\371'\177\000\000\273\261\354\262\215U\000\000\020\313\336\202"...}, tid = 0}, stack = 0x7f2700000002, count = 135686485182180, size = 0}, PvallocOverflow = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\360^\202\376\177\000\0002\000\000\000\000\000\000\000\240\202\242\367'{\000\0001\000\000\000\000\000\000\000\230\310\336\202\376\177\000\000\240\202\242\367'{\000\000\000\300\336\202\376\177\000\000\037\333\243\372'\177\000\000\001\000\000\000\000\000\000\000\240\202\242\367'{\000\000P\310\336\202\376\177\000\000\322u\262\372'\177\000\000`\300\336\202\376\177\000\00087\244\372\036\000\000\0000\300\336\202\376\177\000\000\003\000\000\000\000\000\000\000\020v\262\372'\177\000\000\217\373\347\371'\177\000\000\273\261\354\262\215U\000\000\020\313\336\202"...}, tid = 0}, stack = 0x7f2700000002, size = 135686485182180}, InvalidAllocationAlignment = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\360^\202\376\177\000\0002\000\000\000\000\000\000\000\240\202\242\367'{\000\0001\000\000\000\000\000\000\000\230\310\336\202\376\177\000\000\240\202\242\367'{\000\000\000\300\336\202\376\177\000\000\037\333\243\372'\177\000\000\001\000\000\000\000\000\000\000\240\202\242\367'{\000\000P\310\336\202\376\177\000\000\322u\262\372'\177\000\000`\300\336\202\376\177\000\00087\244\372\036\000\000\0000\300\336\202\376\177\000\000\003\000\000\000\000\000\000\000\020v\262\372'\177\000\000\217\373\347\371'\177\000\000\273\261\354\262\215U\000\000\020\313\336\202"...}, tid = 0}, stack = 0x7f2700000002, alignment = 135686485182180}, InvalidAlignedAllocAlignment = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\360^\202\376\177\000\0002\000\000\000\000\000\000\000\240\202\242\367'{\000\0001\000\000\000\000\000\000\000\230\310\336\202\376\177\000\000\240\202\242\367'{\000\000\000\300\336\202\376\177\000\000\037\333\243\372'\177\000\000\001\000\000\000\000\000\000\000\240\202\242\367'{\000\000P\310\336\202\376\177\000\000\322u\262\372'\177\000\000`\300\336\202\376\177\000\00087\244\372\036\000\000\0000\300\336\202\376\177\000\000\003\000\000\000\000\000\000\000\020v\262\372'\177\000\000\217\373\347\371'\177\000\000\273\261\354\262\215U\000\000\020\313\336\202"...}, tid = 0}, stack = 0x7f2700000002, size = 135686485182180, alignment = 0}, InvalidPosixMemalignAlignment = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\360^\202\376\177\000\0002\000\000\000\000\000\000\000\240\202\242\367'{\000\0001\000\000\000\000\000\000\000\230\310\336\202\376\177\000\000\240\202\242\367'{\000\000\000\300\336\202\376\177\000\000\037\333\243\372'\177\000\000\001\000\000\000\000\000\000\000\240\202\242\367'{\000\000P\310\336\202\376\177\000\000\322u\262\372'\177\000\000`\300\336\202\376\177\000\00087\244\372\036\000\000\0000\300\336\202\376\177\000\000\003\000\000\000\000\000\000\000\020v\262\372'\177\000\000\217\373\347\371'\177\000\000\273\261\354\262\215U\000\000\020\313\336\202"...}, tid = 0}, stack = 0x7f2700000002, alignment = 135686485182180}, AllocationSizeTooBig = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\360^\202\376\177\000\0002\000\000\000\000\000\000\000\240\202\242\367'{\000\0001\000\000\000\000\000\000\000\230\310\336\202\376\177\000\000\240\202\242\367'{\000\000\000\300\336\202\376\177\000\000\037\333\243\372'\177\000\000\001\000\000\000\000\000\000\000\240\202\242\367'{\000\000P\310\336\202\376\177\000\000\322u\262\372'\177\000\000`\300\336\202\376\177\000\00087\244\372\036\000\000\0000\300\336\202\376\177\000\000\003\000\000\000\000\000\000\000\020v\262\372'\177\000\000\217\373\347\371'\177\000\000\273\261\354\262\215U\000\000\020\313\336\202"...}, tid = 0}, stack = 0x7f2700000002, user_size = 135686485182180, total_size = 0, max_size = 0}, RssLimitExceeded = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\360^\202\376\177\000\0002\000\000\000\000\000\000\000\240\202\242\367'{\000\0001\000\000\000\000\000\000\000\230\310\336\202\376\177\000\000\240\202\242\367'{\000\000\000\300\336\202\376\177\000\000\037\333\243\372'\177\000\000\001\000\000\000\000\000\000\000\240\202\242\367'{\000\000P\310\336\202\376\177\000\000\322u\262\372'\177\000\000`\300\336\202\376\177\000\00087\244\372\036\000\000\0000\300\336\202\376\177\000\000\003\000\000\000\000\000\000\000\020v\262\372'\177\000\000\217\373\347\371'\177\000\000\273\261\354\262\215U\000\000\020\313\336\202"...}, tid = 0}, stack = 0x7f2700000002}, OutOfMemory = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\360^\202\376\177\000\0002\000\000\000\000\000\000\000\240\202\242\367'{\000\0001\000\000\000\000\000\000\000\230\310\336\202\376\177\000\000\240\202\242\367'{\000\000\000\300\336\202\376\177\000\000\037\333\243\372'\177\000\000\001\000\000\000\000\000\000\000\240\202\242\367'{\000\000P\310\336\202\376\177\000\000\322u\262\372'\177\000\000`\300\336\202\376\177\000\00087\244\372\036\000\000\0000\300\336\202\376\177\000\000\003\000\000\000\000\000\000\000\020v\262\372'\177\000\000\217\373\347\371'\177\000\000\273\261\354\262\215U\000\000\020\313\336\202"...}, tid = 0}, stack = 0x7f2700000002, requested_size = 135686485182180}, StringFunctionMemoryRangesOverlap = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\360^\202\376\177\000\0002\000\000\000\000\000\000\000\240\202\242\367'{\000\0001\000\000\000\000\000\000\000\230\310\336\202\376\177\000\000\240\202\242\367'{\000\000\000\300\336\202\376\177\000\000\037\333\243\372'\177\000\000\001\000\000\000\000\000\000\000\240\202\242\367'{\000\000P\310\336\202\376\177\000\000\322u\262\372'\177\000\000`\300\336\202\376\177\000\00087\244\372\036\000\000\0000\300\336\202\376\177\000\000\003\000\000\000\000\000\000\000\020v\262\372'\177\000\000\217\373\347\371'\177\000\000\273\261\354\262\215U\000\000\020\313\336\202"...}, tid = 0}, stack = 0x7f2700000002, length1 = 135686485182180, length2 = 0, addr1_description = {data = {kind = __asan::kAddressKindWild, {shadow = {addr = 10441065498421, kind = (unknown: 0xe4), shadow_byte = 6 '\006'}, heap = {addr = 10441065498421, alloc_tid = 135686485182180, free_tid = 20, alloc_stack_id = 4173334224, free_stack_id = 31591, chunk_access = {bad_addr = 40, offset = 62884811792392, chunk_begin = 11908522307766607616, chunk_size = 16, user_requested_alignment = 1666, access_type = 3, alloc_type = 1}}, stack = {addr = 10441065498421, tid = 135686485182180, offset = 20, frame_pc = 135686485182160, access_size = 40, frame_descr = 0x393182de6008 <error: Cannot access memory at address 0x393182de6008>}, global = {addr = 10441065498421, static kMaxGlobals = 4, globals = {{beg = 135686485182180, size = 20, size_with_redzone = 135686485182160, name = 0x28 <error: Cannot access memory at address 0x28>, module_name = 0x393182de6008 <error: Cannot access memory at address 0x393182de6008>, has_dynamic_init = 11908522307766607616, gcc_location = 0x10, odr_indicator = 139809674524290}, {beg = 140731094058535, size = 15, size_with_redzone = 140731094058535, name = 0x3000000010 <error: Cannot access memory at address 0x3000000010>, module_name = 0x7ffe82decc00 "\320\006\300\370g{", has_dynamic_init = 140731094059792, gcc_location = 0x7f27f9ff9de0 <_nl_C_locobj>, odr_indicator = 139809673554787}, {beg = 135892643527184, size = 11908522307766607616, size_with_redzone = 140728898420736, name = 0x7ffe82dec640 "f\375\263\372'\177", module_name = 0x80 <error: Cannot access memory at address 0x80>, has_dynamic_init = 135411588563488, gcc_location = 0x7ffe82dec640, odr_indicator = 49}, {beg = 140731094058320, size = 139809672971324, size_with_redzone = 206158430240, name = 0x7ffe82dec560 "\037\333\243\372'\177", module_name = 0x7ffe82dec4a0 "@\312\336\202\376\177", has_dynamic_init = 11908522307766607616, gcc_location = 0x7ffe82deca40, odr_indicator = 0}}, reg_sites = {2195637844, 32766, 2998915811, 21901}, access_size = 140731094060016, size = 224 '\340'}, wild = {addr = 10441065498421, access_size = 135686485182180}}}}, addr2_description = {data = {kind = __asan::kAddressKindGlobal, {shadow = {addr = 139809686878103, kind = __asan::kShadowKindGap, shadow_byte = 253 '\375'}, heap = {addr = 139809686878103, alloc_tid = 57391548660993, free_tid = 16926448570432, alloc_stack_id = 65535, free_stack_id = 0, chunk_access = {bad_addr = 94067081799808, offset = 140731094059664, chunk_begin = 135961362961568, chunk_size = 94067078436710, user_requested_alignment = 2768, access_type = 0, alloc_type = 3}}, stack = {addr = 139809686878103, tid = 57391548660993, offset = 16926448570432, frame_pc = 65535, access_size = 94067081799808, frame_descr = 0x7ffe82deca90 "\320\312\336\202\376\177"}, global = {addr = 139809686878103, static kMaxGlobals = 4, globals = {{beg = 57391548660993, size = 16926448570432, size_with_redzone = 65535, name = 0x558db2fee880 "%s:%s() ", module_name = 0x7ffe82deca90 "\320\312\336\202\376\177", has_dynamic_init = 135961362961568, gcc_location = 0x558db2cb9766 <btd_debug+358>, odr_indicator = 140731094059728}, {beg = 139809686260034, size = 19375508176, size_with_redzone = 87, name = 0x7f27fab9198c "sendmsg", module_name = 0xa54391f1e23e5f00 <error: Cannot access memory at address 0xa54391f1e23e5f00>, has_dynamic_init = 1, gcc_location = 0x7b27f7c60940, odr_indicator = 16926448861440}, {beg = 94067080604871, size = 135407433941079, size_with_redzone = 140731094059824, name = 0xf64fef8c100 <error: Cannot access memory at address 0xf64fef8c100>, module_name = 0x7b27f7c60850 "", has_dynamic_init = 140731094060096, gcc_location = 0xa54391f1e23e5f00, odr_indicator = 16926448715730}, {beg = 3990578735385332552, size = 94067081799744, size_with_redzone = 94067081808736, name = 0x7b67f8c006d0 "\177\t", module_name = 0xa96fb <error: Cannot access memory at address 0xa96fb>, has_dynamic_init = 135411588563232, gcc_location = 0xa54391f1e23e5f00, odr_indicator = 67}}, reg_sites = {2195639208, 32766, 2195639456, 32766}, access_size = 139809673182122, size = 116 't'}, wild = {addr = 139809686878103, access_size = 57391548660993}}}}, function = 0x7ffe82decba8 "0\214\347\262\215U"}, StringFunctionSizeOverflow = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\360^\202\376\177\000\0002\000\000\000\000\000\000\000\240\202\242\367'{\000\0001\000\000\000\000\000\000\000\230\310\336\202\376\177\000\000\240\202\242\367'{\000\000\000\300\336\202\376\177\000\000\037\333\243\372'\177\000\000\001\000\000\000\000\000\000\000\240\202\242\367'{\000\000P\310\336\202\376\177\000\000\322u\262\372'\177\000\000`\300\336\202\376\177\000\00087\244\372\036\000\000\0000\300\336\202\376\177\000\000\003\000\000\000\000\000\000\000\020v\262\372'\177\000\000\217\373\347\371'\177\000\000\273\261\354\262\215U\000\000\020\313\336\202"...}, tid = 0}, stack = 0x7f2700000002, addr_description = {data = {kind = 4173334244, {shadow = {addr = 0, kind = __asan::kShadowKindLow, shadow_byte = 0 '\000'}, heap = {addr = 0, alloc_tid = 0, free_tid = 10441065498421, alloc_stack_id = 4173334244, free_stack_id = 31591, chunk_access = {bad_addr = 20, offset = 135686485182160, chunk_begin = 40, chunk_size = 62884811792392, user_requested_alignment = 3840, access_type = 1, alloc_type = 1}}, stack = {addr = 0, tid = 0, offset = 10441065498421, frame_pc = 135686485182180, access_size = 20, frame_descr = 0x7b67f8c006d0 "\177\t"}, global = {addr = 0, static kMaxGlobals = 4, globals = {{beg = 0, size = 10441065498421, size_with_redzone = 135686485182180, name = 0x14 <error: Cannot access memory at address 0x14>, module_name = 0x7b67f8c006d0 "\177\t", has_dynamic_init = 40, gcc_location = 0x393182de6008, odr_indicator = 11908522307766607616}, {beg = 16, size = 139809674524290, size_with_redzone = 140731094058535, name = 0xf <error: Cannot access memory at address 0xf>, module_name = 0x7ffe82dec627 "", has_dynamic_init = 206158430224, gcc_location = 0x7ffe82decc00, odr_indicator = 140731094059792}, {beg = 139809674730976, size = 139809673554787, size_with_redzone = 135892643527184, name = 0xa54391f1e23e5f00 <error: Cannot access memory at address 0xa54391f1e23e5f00>, module_name = 0x7ffe00000000 <error: Cannot access memory at address 0x7ffe00000000>, has_dynamic_init = 140731094058560, gcc_location = 0x80, odr_indicator = 135411588563488}, {beg = 140731094058560, size = 49, size_with_redzone = 140731094058320, name = 0x7f27f9e4c43c <__GI___dprintf+156> "H\213\225H\377\377\377dH+\024%(", module_name = 0x3000000020 <error: Cannot access memory at address 0x3000000020>, has_dynamic_init = 140731094058336, gcc_location = 0x7ffe82dec4a0, odr_indicator = 11908522307766607616}}, reg_sites = {2195638848, 32766, 0, 0}, access_size = 140731094058580, size = 227 '\343'}, wild = {addr = 0, access_size = 0}}}}, size = 140731094060016}, BadParamsToAnnotateContiguousContainer = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\360^\202\376\177\000\0002\000\000\000\000\000\000\000\240\202\242\367'{\000\0001\000\000\000\000\000\000\000\230\310\336\202\376\177\000\000\240\202\242\367'{\000\000\000\300\336\202\376\177\000\000\037\333\243\372'\177\000\000\001\000\000\000\000\000\000\000\240\202\242\367'{\000\000P\310\336\202\376\177\000\000\322u\262\372'\177\000\000`\300\336\202\376\177\000\00087\244\372\036\000\000\0000\300\336\202\376\177\000\000\003\000\000\000\000\000\000\000\020v\262\372'\177\000\000\217\373\347\371'\177\000\000\273\261\354\262\215U\000\000\020\313\336\202"...}, tid = 0}, stack = 0x7f2700000002, beg = 135686485182180, end = 0, old_mid = 0, new_mid = 10441065498421}, BadParamsToAnnotateDoubleEndedContiguousContainer = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\360^\202\376\177\000\0002\000\000\000\000\000\000\000\240\202\242\367'{\000\0001\000\000\000\000\000\000\000\230\310\336\202\376\177\000\000\240\202\242\367'{\000\000\000\300\336\202\376\177\000\000\037\333\243\372'\177\000\000\001\000\000\000\000\000\000\000\240\202\242\367'{\000\000P\310\336\202\376\177\000\000\322u\262\372'\177\000\000`\300\336\202\376\177\000\00087\244\372\036\000\000\0000\300\336\202\376\177\000\000\003\000\000\000\000\000\000\000\020v\262\372'\177\000\000\217\373\347\371'\177\000\000\273\261\354\262\215U\000\000\020\313\336\202"...}, tid = 0}, stack = 0x7f2700000002, storage_beg = 135686485182180, storage_end = 0, old_container_beg = 0, old_container_end = 10441065498421, new_container_beg = 135686485182180, new_container_end = 20}, BadParamsToCopyContiguousContainerAnnotations = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\360^\202\376\177\000\0002\000\000\000\000\000\000\000\240\202\242\367'{\000\0001\000\000\000\000\000\000\000\230\310\336\202\376\177\000\000\240\202\242\367'{\000\000\000\300\336\202\376\177\000\000\037\333\243\372'\177\000\000\001\000\000\000\000\000\000\000\240\202\242\367'{\000\000P\310\336\202\376\177\000\000\322u\262\372'\177\000\000`\300\336\202\376\177\000\00087\244\372\036\000\000\0000\300\336\202\376\177\000\000\003\000\000\000\000\000\000\000\020v\262\372'\177\000\000\217\373\347\371'\177\000\000\273\261\354\262\215U\000\000\020\313\336\202"...}, tid = 0}, stack = 0x7f2700000002, old_storage_beg = 135686485182180, old_storage_end = 0, new_storage_beg = 0, new_storage_end = 10441065498421}, ODRViolation = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\360^\202\376\177\000\0002\000\000\000\000\000\000\000\240\202\242\367'{\000\0001\000\000\000\000\000\000\000\230\310\336\202\376\177\000\000\240\202\242\367'{\000\000\000\300\336\202\376\177\000\000\037\333\243\372'\177\000\000\001\000\000\000\000\000\000\000\240\202\242\367'{\000\000P\310\336\202\376\177\000\000\322u\262\372'\177\000\000`\300\336\202\376\177\000\00087\244\372\036\000\000\0000\300\336\202\376\177\000\000\003\000\000\000\000\000\000\000\020v\262\372'\177\000\000\217\373\347\371'\177\000\000\273\261\354\262\215U\000\000\020\313\336\202"...}, tid = 0}, global1 = {beg = 139805480452098, size = 135686485182180, size_with_redzone = 0, name = 0x0, module_name = 0x97f00000735 <error: Cannot access memory at address 0x97f00000735>, has_dynamic_init = 135686485182180, gcc_location = 0x14, odr_indicator = 135686485182160}, global2 = {beg = 40, size = 62884811792392, size_with_redzone = 11908522307766607616, name = 0x10 <error: Cannot access memory at address 0x10>, module_name = 0x7f27f9fc7682 "T ", has_dynamic_init = 140731094058535, gcc_location = 0xf, odr_indicator = 140731094058535}, stack_id1 = 16, stack_id2 = 48}, InvalidPointerPair = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\360^\202\376\177\000\0002\000\000\000\000\000\000\000\240\202\242\367'{\000\0001\000\000\000\000\000\000\000\230\310\336\202\376\177\000\000\240\202\242\367'{\000\000\000\300\336\202\376\177\000\000\037\333\243\372'\177\000\000\001\000\000\000\000\000\000\000\240\202\242\367'{\000\000P\310\336\202\376\177\000\000\322u\262\372'\177\000\000`\300\336\202\376\177\000\00087\244\372\036\000\000\0000\300\336\202\376\177\000\000\003\000\000\000\000\000\000\000\020v\262\372'\177\000\000\217\373\347\371'\177\000\000\273\261\354\262\215U\000\000\020\313\336\202"...}, tid = 0}, pc = 139805480452098, bp = 135686485182180, sp = 0, addr1_description = {data = {kind = __asan::kAddressKindWild, {shadow = {addr = 10441065498421, kind = (unknown: 0xe4), shadow_byte = 6 '\006'}, heap = {addr = 10441065498421, alloc_tid = 135686485182180, free_tid = 20, alloc_stack_id = 4173334224, free_stack_id = 31591, chunk_access = {bad_addr = 40, offset = 62884811792392, chunk_begin = 11908522307766607616, chunk_size = 16, user_requested_alignment = 1666, access_type = 3, alloc_type = 1}}, stack = {addr = 10441065498421, tid = 135686485182180, offset = 20, frame_pc = 135686485182160, access_size = 40, frame_descr = 0x393182de6008 <error: Cannot access memory at address 0x393182de6008>}, global = {addr = 10441065498421, static kMaxGlobals = 4, globals = {{beg = 135686485182180, size = 20, size_with_redzone = 135686485182160, name = 0x28 <error: Cannot access memory at address 0x28>, module_name = 0x393182de6008 <error: Cannot access memory at address 0x393182de6008>, has_dynamic_init = 11908522307766607616, gcc_location = 0x10, odr_indicator = 139809674524290}, {beg = 140731094058535, size = 15, size_with_redzone = 140731094058535, name = 0x3000000010 <error: Cannot access memory at address 0x3000000010>, module_name = 0x7ffe82decc00 "\320\006\300\370g{", has_dynamic_init = 140731094059792, gcc_location = 0x7f27f9ff9de0 <_nl_C_locobj>, odr_indicator = 139809673554787}, {beg = 135892643527184, size = 11908522307766607616, size_with_redzone = 140728898420736, name = 0x7ffe82dec640 "f\375\263\372'\177", module_name = 0x80 <error: Cannot access memory at address 0x80>, has_dynamic_init = 135411588563488, gcc_location = 0x7ffe82dec640, odr_indicator = 49}, {beg = 140731094058320, size = 139809672971324, size_with_redzone = 206158430240, name = 0x7ffe82dec560 "\037\333\243\372'\177", module_name = 0x7ffe82dec4a0 "@\312\336\202\376\177", has_dynamic_init = 11908522307766607616, gcc_location = 0x7ffe82deca40, odr_indicator = 0}}, reg_sites = {2195637844, 32766, 2998915811, 21901}, access_size = 140731094060016, size = 224 '\340'}, wild = {addr = 10441065498421, access_size = 135686485182180}}}}, addr2_description = {data = {kind = __asan::kAddressKindGlobal, {shadow = {addr = 139809686878103, kind = __asan::kShadowKindGap, shadow_byte = 253 '\375'}, heap = {addr = 139809686878103, alloc_tid = 57391548660993, free_tid = 16926448570432, alloc_stack_id = 65535, free_stack_id = 0, chunk_access = {bad_addr = 94067081799808, offset = 140731094059664, chunk_begin = 135961362961568, chunk_size = 94067078436710, user_requested_alignment = 2768, access_type = 0, alloc_type = 3}}, stack = {addr = 139809686878103, tid = 57391548660993, offset = 16926448570432, frame_pc = 65535, access_size = 94067081799808, frame_descr = 0x7ffe82deca90 "\320\312\336\202\376\177"}, global = {addr = 139809686878103, static kMaxGlobals = 4, globals = {{beg = 57391548660993, size = 16926448570432, size_with_redzone = 65535, name = 0x558db2fee880 "%s:%s() ", module_name = 0x7ffe82deca90 "\320\312\336\202\376\177", has_dynamic_init = 135961362961568, gcc_location = 0x558db2cb9766 <btd_debug+358>, odr_indicator = 140731094059728}, {beg = 139809686260034, size = 19375508176, size_with_redzone = 87, name = 0x7f27fab9198c "sendmsg", module_name = 0xa54391f1e23e5f00 <error: Cannot access memory at address 0xa54391f1e23e5f00>, has_dynamic_init = 1, gcc_location = 0x7b27f7c60940, odr_indicator = 16926448861440}, {beg = 94067080604871, size = 135407433941079, size_with_redzone = 140731094059824, name = 0xf64fef8c100 <error: Cannot access memory at address 0xf64fef8c100>, module_name = 0x7b27f7c60850 "", has_dynamic_init = 140731094060096, gcc_location = 0xa54391f1e23e5f00, odr_indicator = 16926448715730}, {beg = 3990578735385332552, size = 94067081799744, size_with_redzone = 94067081808736, name = 0x7b67f8c006d0 "\177\t", module_name = 0xa96fb <error: Cannot access memory at address 0xa96fb>, has_dynamic_init = 135411588563232, gcc_location = 0xa54391f1e23e5f00, odr_indicator = 67}}, reg_sites = {2195639208, 32766, 2195639456, 32766}, access_size = 139809673182122, size = 116 't'}, wild = {addr = 139809686878103, access_size = 57391548660993}}}}}, Generic = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\360^\202\376\177\000\0002\000\000\000\000\000\000\000\240\202\242\367'{\000\0001\000\000\000\000\000\000\000\230\310\336\202\376\177\000\000\240\202\242\367'{\000\000\000\300\336\202\376\177\000\000\037\333\243\372'\177\000\000\001\000\000\000\000\000\000\000\240\202\242\367'{\000\000P\310\336\202\376\177\000\000\322u\262\372'\177\000\000`\300\336\202\376\177\000\00087\244\372\036\000\000\0000\300\336\202\376\177\000\000\003\000\000\000\000\000\000\000\020v\262\372'\177\000\000\217\373\347\371'\177\000\000\273\261\354\262\215U\000\000\020\313\336\202"...}, tid = 0}, addr_description = {data = {kind = __asan::kAddressKindHeap, {shadow = {addr = 135686485182180, kind = __asan::kShadowKindLow, shadow_byte = 0 '\000'}, heap = {addr = 135686485182180, alloc_tid = 0, free_tid = 0, alloc_stack_id = 1845, free_stack_id = 2431, chunk_access = {bad_addr = 135686485182180, offset = 20, chunk_begin = 135686485182160, chunk_size = 40, user_requested_alignment = 8, access_type = 2, alloc_type = 1}}, stack = {addr = 135686485182180, tid = 0, offset = 0, frame_pc = 10441065498421, access_size = 135686485182180, frame_descr = 0x14 <error: Cannot access memory at address 0x14>}, global = {addr = 135686485182180, static kMaxGlobals = 4, globals = {{beg = 0, size = 0, size_with_redzone = 10441065498421, name = 0x7b67f8c006e4 "", module_name = 0x14 <error: Cannot access memory at address 0x14>, has_dynamic_init = 135686485182160, gcc_location = 0x28, odr_indicator = 62884811792392}, {beg = 11908522307766607616, size = 16, size_with_redzone = 139809674524290, name = 0x7ffe82dec627 "", module_name = 0xf <error: Cannot access memory at address 0xf>, has_dynamic_init = 140731094058535, gcc_location = 0x3000000010, odr_indicator = 140731094060032}, {beg = 140731094059792, size = 139809674730976, size_with_redzone = 139809673554787, name = 0x7b97f8beba10 "_", module_name = 0xa54391f1e23e5f00 <error: Cannot access memory at address 0xa54391f1e23e5f00>, has_dynamic_init = 140728898420736, gcc_location = 0x7ffe82dec640, odr_indicator = 128}, {beg = 135411588563488, size = 140731094058560, size_with_redzone = 49, name = 0x7ffe82dec550 "\240\202\242\367'{", module_name = 0x7f27f9e4c43c <__GI___dprintf+156> "H\213\225H\377\377\377dH+\024%(", has_dynamic_init = 206158430240, gcc_location = 0x7ffe82dec560, odr_indicator = 140731094058144}}, reg_sites = {3795738368, 2772668913, 2195638848, 32766}, access_size = 0, size = 84 'T'}, wild = {addr = 135686485182180, access_size = 0}}}}, pc = 94067077665507, bp = 140731094060016, sp = 140731094060000, access_size = 4, bug_descr = 0x7f27fab8f797 "heap-use-after-free", is_write = true, shadow_val = 253 '\375'}}}, halt_on_error_ = true}
error = {<__asan::ErrorBase> = {scariness = {score = 46, descr = "4-byte-write-heap-use-after-free\000\000\000\0002\000\000\000\000\000\000\000\000\360^\202\376\177\000\0002\000\000\000\000\000\000\000\240\202\242\367'{\000\0001\000\000\000\000\000\000\000\230\310\336\202\376\177\000\000\240\202\242\367'{\000\000\000\300\336\202\376\177\000\000\037\333\243\372'\177\000\000\001\000\000\000\000\000\000\000\240\202\242\367'{\000\000P\310\336\202\376\177\000\000\322u\262\372'\177\000\000`\300\336\202\376\177\000\00087\244\372\036\000\000\0000\300\336\202\376\177\000\000\003\000\000\000\000\000\000\000\020v\262\372'\177\000\000\217\373\347\371'\177\000\000\273\261\354\262\215U\000\000\020\313\336\202"...}, tid = 0}, addr_description = {data = {kind = __asan::kAddressKindHeap, {shadow = {addr = 135686485182180, kind = __asan::kShadowKindLow, shadow_byte = 0 '\000'}, heap = {addr = 135686485182180, alloc_tid = 0, free_tid = 0, alloc_stack_id = 1845, free_stack_id = 2431, chunk_access = {bad_addr = 135686485182180, offset = 20, chunk_begin = 135686485182160, chunk_size = 40, user_requested_alignment = 8, access_type = 2, alloc_type = 1}}, stack = {addr = 135686485182180, tid = 0, offset = 0, frame_pc = 10441065498421, access_size = 135686485182180, frame_descr = 0x14 <error: Cannot access memory at address 0x14>}, global = {addr = 135686485182180, static kMaxGlobals = 4, globals = {{beg = 0, size = 0, size_with_redzone = 10441065498421, name = 0x7b67f8c006e4 "", module_name = 0x14 <error: Cannot access memory at address 0x14>, has_dynamic_init = 135686485182160, gcc_location = 0x28, odr_indicator = 62884811792392}, {beg = 11908522307766607616, size = 16, size_with_redzone = 139809674524290, name = 0x7ffe82dec627 "", module_name = 0xf <error: Cannot access memory at address 0xf>, has_dynamic_init = 140731094058535, gcc_location = 0x3000000010, odr_indicator = 140731094060032}, {beg = 140731094059792, size = 139809674730976, size_with_redzone = 139809673554787, name = 0x7b97f8beba10 "_", module_name = 0xa54391f1e23e5f00 <error: Cannot access memory at address 0xa54391f1e23e5f00>, has_dynamic_init = 140728898420736, gcc_location = 0x7ffe82dec640, odr_indicator = 128}, {beg = 135411588563488, size = 140731094058560, size_with_redzone = 49, name = 0x7ffe82dec550 "\240\202\242\367'{", module_name = 0x7f27f9e4c43c <__GI___dprintf+156> "H\213\225H\377\377\377dH+\024%(", has_dynamic_init = 206158430240, gcc_location = 0x7ffe82dec560, odr_indicator = 140731094058144}}, reg_sites = {3795738368, 2772668913, 2195638848, 32766}, access_size = 0, size = 84 'T'}, wild = {addr = 135686485182180, access_size = 0}}}}, pc = 94067077665507, bp = 140731094060016, sp = 140731094060000, access_size = 4, bug_descr = 0x7f27fab8f797 "heap-use-after-free", is_write = true, shadow_val = 253 '\375'}
#9 0x00007f27fab33f8d in __asan::ReportGenericError (pc=<optimized out>, bp=bp@entry=140731094060016, sp=sp@entry=140731094060000, addr=<optimized out>, is_write=is_write@entry=true, access_size=access_size@entry=4, exp=<optimized out>, fatal=true) at ../../../../src/libsanitizer/asan/asan_report.cpp:536
in_report = <optimized out>
error = <optimized out>
enable_fp = <optimized out>
#10 0x00007f27fab3585c in __asan::__asan_report_store4 (addr=<optimized out>) at ../../../../src/libsanitizer/asan/asan_rtl.cpp:135
bp = 140731094060016
pc = <optimized out>
local_stack = 94067080268848
sp = 140731094060000
#11 0x0000558db2bfd2e3 in report_notify_destroy (user_data=<optimized out>) at profiles/input/hog-lib.c:359
report = <optimized out>
__func__ = "report_notify_destroy"
#12 0x0000558db2ca0052 in attrib_callbacks_destroy (data=0x7b87f8bf2560) at attrib/gattrib.c:130
cb = 0x7b87f8bf2560
#13 0x0000558db2e8f51b in notify_data_unref (data=<optimized out>) at src/shared/gatt-client.c:256
notify_data = <optimized out>
#14 notify_data_unref (data=<optimized out>) at src/shared/gatt-client.c:248
notify_data = <optimized out>
#15 0x0000558db2e8a3e0 in destroy_write_op (data=0x7b57f8c02a20) at src/shared/gatt-client.c:3189
op = 0x7b57f8c02a20
#16 0x0000558db2e9a153 in request_unref (data=0x7b67f8c07250) at src/shared/gatt-client.c:201
req = 0x7b67f8c07250
client = 0x7c37f8be1080
#17 0x0000558db2e791a4 in destroy_att_send_op (data=0x7b87f8bf3f40) at src/shared/att.c:215
op = 0x7b87f8bf3f40
#18 0x0000558db2e82fe0 in bt_att_cancel (att=<optimized out>, id=<optimized out>) at src/shared/att.c:1925
entry = 0x0
op = <optimized out>
#19 0x0000558db2e8ecc3 in cancel_request (req=<optimized out>) at src/shared/gatt-client.c:2783
No locals.
#20 0x0000558db2e39b32 in queue_remove_all (queue=0x7b57f8be9820, function=function@entry=0x0, user_data=user_data@entry=0x0, destroy=destroy@entry=0x558db2e8f230 <cancel_pending>) at src/shared/queue.c:341
tmp = 0x7b47f8c0c6d0
entry = 0x0
count = <optimized out>
#21 0x0000558db2e95d3f in bt_gatt_client_cancel_all (client=client@entry=0x7c37f8be1080) at src/shared/gatt-client.c:2811
No locals.
#22 0x0000558db2e95fdd in bt_gatt_client_free (client=0x7c37f8be1080) at src/shared/gatt-client.c:2290
No locals.
#23 0x0000558db2e97d1c in bt_gatt_client_unref (client=<optimized out>) at src/shared/gatt-client.c:2605
No locals.
#24 0x0000558db2ca15ed in g_attrib_unref (attrib=0x7ba7f8be1420) at attrib/gattrib.c:158
__func__ = "g_attrib_unref"
#25 0x0000558db2da552e in attio_cleanup (device=<optimized out>) at src/device.c:874
attrib = <optimized out>
#26 0x0000558db2da5a77 in device_free (user_data=0x7c97f8be0080) at src/device.c:918
device = 0x7c97f8be0080
__func__ = "device_free"
#27 0x0000558db2e2368a in remove_interface (data=0x7b97f8be4ee0, name=name@entry=0x558db302fae0 "org.bluez.Device1") at gdbus/object.c:742
iface = 0x7b87f8be5ae0
#28 0x0000558db2e2624c in g_dbus_unregister_interface (connection=<optimized out>, path=<optimized out>, name=<optimized out>) at gdbus/object.c:1499
data = <optimized out>
#29 0x0000558db2d60d48 in adapter_remove (adapter=adapter@entry=0x7c57f8be0200) at src/adapter.c:7321
device = 0x7c97f8be0080
db = <optimized out>
ranging_manager = <optimized out>
__func__ = "adapter_remove"
#30 0x0000558db2d61888 in adapter_cleanup () at src/adapter.c:11274
adapter = 0x7c57f8be0200
#31 0x0000558db2b12330 in main (argc=<optimized out>, argv=<optimized out>) at src/main.c:1723
context = <optimized out>
err = <optimized out>
sdp_mtu = 0
sdp_flags = <optimized out>
gdbus_flags = <optimized out>
__func__ = "main""
https://github.com/bluez/bluez/pull/2577
---
Regards,
Linux Bluetooth
^ permalink raw reply [flat|nested] 14+ messages in thread
* [PATCH BlueZ v3 0/9] Add HID over GATT functional tests
@ 2026-09-24 15:46 Luiz Augusto von Dentz
2026-09-24 15:46 ` [PATCH BlueZ v3 1/9] shared/gatt-client: Fix calling destroy after unregistering notify Luiz Augusto von Dentz
` (9 more replies)
0 siblings, 10 replies; 14+ messages in thread
From: Luiz Augusto von Dentz @ 2026-09-24 15:46 UTC (permalink / raw)
To: linux-bluetooth
From: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
This adds functional tests for HID over GATT (HoG), with bluetoothctl
registering a HID Service acting as a keyboard, with and without
Shorter Connection Interval (SCI) support, using the new
client/scripts/hog-device*.bt scripts, and the HID host:
- checking HID Information, HID SCI Mode and HID SCI Information over
GATT with gatt.select-attribute/gatt.read
- receiving a few Input Reports notified by the HID device
- with SCI support, changing the SCI mode, followed by the connection
rate with mgmt.conn-subrate, and receiving the notification from
the HID device confirming the mode has been changed
The tests are documented in doc/functional-hog.rst.
To support them:
- bluetoothctl can now set descriptor values from scripts, and prints
the MGMT Connection Subrate event
- btvirt defaults to the latest BR/EDR+LE version (6.2), so Shorter
Connection Intervals are supported by the emulated controllers,
with the new -C/--core option to emulate older versions
Also, with -n auto, the number of functional test workers is now
limited by the memory available instead of one per CPU, since running
out of memory with so many VM instances made tests fail at random, and
check-functional uses -n auto by default (override with
CHECK_FUNCTIONAL_JOBS).
v2:
- Add "attrib: Fix unregistering notifications registered with
bt_gatt_client", fixing the heap-use-after-free in
report_notify_destroy reported by TestFunctional on the HoG tests:
g_attrib_unregister did not unregister the notifications registered
with bt_gatt_client, so their destroy callback was called after
HoG had freed its reports.
v3:
- Add "shared/gatt-client: Fix calling destroy after unregistering
notify", fixing the heap-use-after-free in report_notify_destroy
still reported by TestFunctional on the HoG tests with v2: once
unregistered, the destroy callback of the notification was still
called later if the write of the CCC disabling it was pending, after
HoG had freed its reports.
Luiz Augusto von Dentz (9):
shared/gatt-client: Fix calling destroy after unregistering notify
attrib: Fix unregistering notifications registered with bt_gatt_client
client/gatt: Fix setting descriptor value from scripts
client/mgmt: Print Connection Subrate event
emulator: Default to the latest BR/EDR+LE version
client/scripts: Add HoG device scripts
doc: Add functional-hog documentation
test: functional: add HoG tests
test: functional: limit the workers by the memory available
Makefile.am | 8 +-
attrib/gattrib.c | 90 +++++++----
client/gatt.c | 25 ++-
client/mgmt.c | 31 ++++
client/scripts/hog-device-sci.bt | 49 ++++++
client/scripts/hog-device.bt | 38 +++++
doc/functional-hog.rst | 188 +++++++++++++++++++++++
doc/functional-testing.rst | 1 +
doc/test-functional.rst | 25 +++
emulator/main.c | 54 ++++++-
emulator/server.c | 15 +-
emulator/server.h | 2 +
src/shared/gatt-client.c | 9 ++
test/functional/conftest.py | 46 ++++++
test/functional/test_hog.py | 252 +++++++++++++++++++++++++++++++
15 files changed, 794 insertions(+), 39 deletions(-)
create mode 100644 client/scripts/hog-device-sci.bt
create mode 100644 client/scripts/hog-device.bt
create mode 100644 doc/functional-hog.rst
create mode 100644 test/functional/test_hog.py
--
2.55.0
^ permalink raw reply [flat|nested] 14+ messages in thread
* [PATCH BlueZ v3 1/9] shared/gatt-client: Fix calling destroy after unregistering notify
2026-09-24 15:46 [PATCH BlueZ v3 0/9] Add HID over GATT functional tests Luiz Augusto von Dentz
@ 2026-09-24 15:46 ` Luiz Augusto von Dentz
2026-09-24 19:16 ` Add HID over GATT functional tests bluez.test.bot
2026-09-24 15:46 ` [PATCH BlueZ v3 2/9] attrib: Fix unregistering notifications registered with bt_gatt_client Luiz Augusto von Dentz
` (8 subsequent siblings)
9 siblings, 1 reply; 14+ messages in thread
From: Luiz Augusto von Dentz @ 2026-09-24 15:46 UTC (permalink / raw)
To: linux-bluetooth
From: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
bt_gatt_client_unregister_notify resets the callbacks of the
notification but not its destroy callback, which is called once the
notify_data is freed. If a procedure is still pending at that point,
e.g. the write of the CCC to disable the notifications, it holds a
reference to notify_data so destroy is called later, once the user data
may have been freed, e.g. the reports of HoG:
ERROR: AddressSanitizer: heap-use-after-free
#11 report_notify_destroy profiles/input/hog-lib.c:359
#12 attrib_callbacks_destroy attrib/gattrib.c:130
#13 notify_data_unref src/shared/gatt-client.c:256
#15 destroy_write_op src/shared/gatt-client.c:3189
#16 request_unref src/shared/gatt-client.c:201
#17 destroy_att_send_op src/shared/att.c:215
#18 bt_att_cancel src/shared/att.c:1925
#19 cancel_request src/shared/gatt-client.c:2783
...
#21 bt_gatt_client_cancel_all src/shared/gatt-client.c:2811
#22 bt_gatt_client_free src/shared/gatt-client.c:2290
Call destroy when unregistering instead.
---
src/shared/gatt-client.c | 9 +++++++++
1 file changed, 9 insertions(+)
diff --git a/src/shared/gatt-client.c b/src/shared/gatt-client.c
index 92ad7c39c115..cd4270291827 100644
--- a/src/shared/gatt-client.c
+++ b/src/shared/gatt-client.c
@@ -3858,6 +3858,15 @@ bool bt_gatt_client_unregister_notify(struct bt_gatt_client *client,
notify_data->callback = NULL;
notify_data->notify = NULL;
+ /* Call destroy now as the user data may be freed once unregistered,
+ * while notify_data may still be referenced by a pending procedure,
+ * e.g. the write of the CCC.
+ */
+ if (notify_data->destroy) {
+ notify_data->destroy(notify_data->user_data);
+ notify_data->destroy = NULL;
+ }
+
complete_unregister_notify(notify_data);
return true;
}
--
2.55.0
^ permalink raw reply related [flat|nested] 14+ messages in thread
* [PATCH BlueZ v3 2/9] attrib: Fix unregistering notifications registered with bt_gatt_client
2026-09-24 15:46 [PATCH BlueZ v3 0/9] Add HID over GATT functional tests Luiz Augusto von Dentz
2026-09-24 15:46 ` [PATCH BlueZ v3 1/9] shared/gatt-client: Fix calling destroy after unregistering notify Luiz Augusto von Dentz
@ 2026-09-24 15:46 ` Luiz Augusto von Dentz
2026-09-24 15:46 ` [PATCH BlueZ v3 3/9] client/gatt: Fix setting descriptor value from scripts Luiz Augusto von Dentz
` (7 subsequent siblings)
9 siblings, 0 replies; 14+ messages in thread
From: Luiz Augusto von Dentz @ 2026-09-24 15:46 UTC (permalink / raw)
To: linux-bluetooth
From: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
g_attrib_register registers ATT_OP_HANDLE_NOTIFY with bt_gatt_client,
when there is one, returning its id, but g_attrib_unregister always
unregisters with bt_att, so the notification was never unregistered
and its destroy callback was called once bt_gatt_client was freed,
after the user data was freed, e.g. the reports of HoG:
ERROR: AddressSanitizer: heap-use-after-free
#11 report_notify_destroy profiles/input/hog-lib.c:359
#12 attrib_callbacks_destroy attrib/gattrib.c:126
#13 notify_data_unref src/shared/gatt-client.c:256
...
#17 bt_gatt_client_free src/shared/gatt-client.c:2293
#18 bt_gatt_client_unref src/shared/gatt-client.c:2605
#19 g_attrib_unref attrib/gattrib.c:154
#20 attio_cleanup src/device.c:874
Give out ids of our own, keeping track of how each one was registered
so it is unregistered accordingly.
---
attrib/gattrib.c | 90 +++++++++++++++++++++++++++++++++---------------
1 file changed, 63 insertions(+), 27 deletions(-)
diff --git a/attrib/gattrib.c b/attrib/gattrib.c
index 3a988e131e94..05a17ba9393f 100644
--- a/attrib/gattrib.c
+++ b/attrib/gattrib.c
@@ -45,6 +45,7 @@ struct _GAttrib {
uint8_t *buf;
int buflen;
struct queue *track_ids;
+ unsigned int next_reg_id;
};
struct attrib_callbacks {
@@ -55,6 +56,9 @@ struct attrib_callbacks {
gpointer user_data;
GAttrib *parent;
uint16_t notify_handle;
+ unsigned int reg_id;
+ unsigned int att_id;
+ unsigned int client_id;
};
GAttrib *g_attrib_new(GIOChannel *io, guint16 mtu, bool ext_signed)
@@ -363,38 +367,52 @@ guint g_attrib_register(GAttrib *attrib, guint8 opcode, guint16 handle,
GAttribNotifyFunc func, gpointer user_data,
GDestroyNotify notify)
{
- struct attrib_callbacks *cb = NULL;
+ struct attrib_callbacks *cb;
if (!attrib)
return 0;
- if (func || notify) {
- cb = new0(struct attrib_callbacks, 1);
- if (!cb)
- return 0;
- cb->notify_func = func;
- cb->notify_handle = handle;
- cb->user_data = user_data;
- cb->destroy_func = notify;
- cb->parent = attrib;
- queue_push_head(attrib->callbacks, cb);
- }
+ cb = new0(struct attrib_callbacks, 1);
+ if (!cb)
+ return 0;
- if (opcode == ATT_OP_HANDLE_NOTIFY && attrib->client) {
- unsigned int id;
+ cb->notify_func = func;
+ cb->notify_handle = handle;
+ cb->user_data = user_data;
+ cb->destroy_func = notify;
+ cb->parent = attrib;
+ queue_push_head(attrib->callbacks, cb);
- id = bt_gatt_client_register_notify(attrib->client, handle,
- NULL, client_notify_cb, cb,
- attrib_callbacks_remove);
- if (id)
- return id;
- }
-
- if (opcode == GATTRIB_ALL_REQS)
- opcode = BT_ATT_ALL_REQUESTS;
-
- return bt_att_register(attrib->att, opcode, attrib_callback_notify,
+ /* The notifications are registered with bt_gatt_client when there
+ * is one, which uses ids of its own, so give out ids of our own to
+ * know how to unregister them.
+ */
+ if (opcode == ATT_OP_HANDLE_NOTIFY && attrib->client)
+ cb->client_id = bt_gatt_client_register_notify(attrib->client,
+ handle, NULL, client_notify_cb,
cb, attrib_callbacks_remove);
+
+ if (!cb->client_id) {
+ if (opcode == GATTRIB_ALL_REQS)
+ opcode = BT_ATT_ALL_REQUESTS;
+
+ cb->att_id = bt_att_register(attrib->att, opcode,
+ attrib_callback_notify, cb,
+ attrib_callbacks_remove);
+ }
+
+ if (!cb->client_id && !cb->att_id) {
+ queue_remove(attrib->callbacks, cb);
+ free(cb);
+ return 0;
+ }
+
+ if (++attrib->next_reg_id == 0)
+ ++attrib->next_reg_id;
+
+ cb->reg_id = attrib->next_reg_id;
+
+ return cb->reg_id;
}
uint8_t *g_attrib_get_buffer(GAttrib *attrib, size_t *len)
@@ -456,12 +474,30 @@ gboolean g_attrib_attach_client(GAttrib *attrib, struct bt_gatt_client *client)
return TRUE;
}
+static bool match_reg_id(const void *data, const void *match_data)
+{
+ const struct attrib_callbacks *cb = data;
+
+ return cb->reg_id && cb->reg_id == PTR_TO_UINT(match_data);
+}
+
gboolean g_attrib_unregister(GAttrib *attrib, guint id)
{
- if (!attrib)
+ struct attrib_callbacks *cb;
+
+ if (!attrib || !id)
return FALSE;
- return bt_att_unregister(attrib->att, id);
+ cb = queue_find(attrib->callbacks, match_reg_id, UINT_TO_PTR(id));
+ if (!cb)
+ return FALSE;
+
+ /* cb is freed by attrib_callbacks_remove once unregistered */
+ if (cb->client_id)
+ return bt_gatt_client_unregister_notify(attrib->client,
+ cb->client_id);
+
+ return bt_att_unregister(attrib->att, cb->att_id);
}
gboolean g_attrib_unregister_all(GAttrib *attrib)
--
2.55.0
^ permalink raw reply related [flat|nested] 14+ messages in thread
* [PATCH BlueZ v3 3/9] client/gatt: Fix setting descriptor value from scripts
2026-09-24 15:46 [PATCH BlueZ v3 0/9] Add HID over GATT functional tests Luiz Augusto von Dentz
2026-09-24 15:46 ` [PATCH BlueZ v3 1/9] shared/gatt-client: Fix calling destroy after unregistering notify Luiz Augusto von Dentz
2026-09-24 15:46 ` [PATCH BlueZ v3 2/9] attrib: Fix unregistering notifications registered with bt_gatt_client Luiz Augusto von Dentz
@ 2026-09-24 15:46 ` Luiz Augusto von Dentz
2026-09-24 15:46 ` [PATCH BlueZ v3 4/9] client/mgmt: Print Connection Subrate event Luiz Augusto von Dentz
` (6 subsequent siblings)
9 siblings, 0 replies; 14+ messages in thread
From: Luiz Augusto von Dentz @ 2026-09-24 15:46 UTC (permalink / raw)
To: linux-bluetooth
From: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
gatt.register-descriptor completed the command right after prompting
for the value, so when run from a script the line with the value was
executed as a command instead of being passed to the prompt, causing
the descriptor to be unregistered.
Complete the command once the value is set, as done for
characteristics, and parse a copy of the value so the input line is
not truncated by strsep while still in use by the shell.
---
client/gatt.c | 25 ++++++++++++++++++-------
1 file changed, 18 insertions(+), 7 deletions(-)
diff --git a/client/gatt.c b/client/gatt.c
index 6dc80e2a31cd..ebbe4e3c7a32 100644
--- a/client/gatt.c
+++ b/client/gatt.c
@@ -700,13 +700,20 @@ void gatt_read_local_attribute(char *data, int argc, char *argv[])
return bt_shell_noninteractive_quit(EXIT_FAILURE);
}
-static uint8_t *str2bytearray(char *arg, size_t *val_len)
+static uint8_t *str2bytearray(const char *arg, size_t *val_len)
{
uint8_t value[MAX_ATTR_VAL_LEN];
- char *entry;
+ char *str, *next, *entry;
unsigned int i;
- for (i = 0; (entry = strsep(&arg, " \t")) != NULL; i++) {
+ /* Parse a copy as strsep modifies the string, which may still be
+ * in use by the caller, e.g. the shell printing the input line.
+ */
+ str = next = strdup(arg);
+ if (!str)
+ return NULL;
+
+ for (i = 0; (entry = strsep(&next, " \t")) != NULL; i++) {
long val;
char *endptr = NULL;
@@ -715,18 +722,22 @@ static uint8_t *str2bytearray(char *arg, size_t *val_len)
if (i >= G_N_ELEMENTS(value)) {
bt_shell_printf("Too much data\n");
+ free(str);
return NULL;
}
val = strtol(entry, &endptr, 0);
if (!endptr || *endptr != '\0' || val > UINT8_MAX) {
bt_shell_printf("Invalid value at index %d\n", i);
+ free(str);
return NULL;
}
value[i] = val;
}
+ free(str);
+
*val_len = i;
return util_memdup(value, i);
@@ -2788,7 +2799,7 @@ static void chrc_set_value(const char *input, void *user_data)
g_free(chrc->value);
- chrc->value = str2bytearray((char *) input, &chrc->value_len);
+ chrc->value = str2bytearray(input, &chrc->value_len);
if (!chrc->value) {
print_chrc(chrc, COLORED_DEL);
@@ -3078,7 +3089,7 @@ static void desc_set_value(const char *input, void *user_data)
g_free(desc->value);
- desc->value = str2bytearray((char *) input, &desc->value_len);
+ desc->value = str2bytearray(input, &desc->value_len);
if (!desc->value) {
print_desc(desc, COLORED_DEL);
@@ -3086,6 +3097,8 @@ static void desc_set_value(const char *input, void *user_data)
}
desc->max_val_len = desc->value_len;
+
+ return bt_shell_noninteractive_quit(EXIT_SUCCESS);
}
void gatt_register_desc(DBusConnection *conn, GDBusProxy *proxy,
@@ -3134,8 +3147,6 @@ void gatt_register_desc(DBusConnection *conn, GDBusProxy *proxy,
print_desc(desc, COLORED_NEW);
bt_shell_prompt_input(desc->path, "Enter value:", desc_set_value, desc);
-
- return bt_shell_noninteractive_quit(EXIT_SUCCESS);
}
static struct desc *desc_find(const char *pattern)
--
2.55.0
^ permalink raw reply related [flat|nested] 14+ messages in thread
* [PATCH BlueZ v3 4/9] client/mgmt: Print Connection Subrate event
2026-09-24 15:46 [PATCH BlueZ v3 0/9] Add HID over GATT functional tests Luiz Augusto von Dentz
` (2 preceding siblings ...)
2026-09-24 15:46 ` [PATCH BlueZ v3 3/9] client/gatt: Fix setting descriptor value from scripts Luiz Augusto von Dentz
@ 2026-09-24 15:46 ` Luiz Augusto von Dentz
2026-09-24 15:46 ` [PATCH BlueZ v3 5/9] emulator: Default to the latest BR/EDR+LE version Luiz Augusto von Dentz
` (5 subsequent siblings)
9 siblings, 0 replies; 14+ messages in thread
From: Luiz Augusto von Dentz @ 2026-09-24 15:46 UTC (permalink / raw)
To: linux-bluetooth
From: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Print the MGMT Connection Subrate event, generated as a result of a
LE Connection Rate Request, e.g. after mgmt.conn-subrate, or a change
initiated by the remote device, so the new connection rate can be
confirmed.
---
client/mgmt.c | 31 +++++++++++++++++++++++++++++++
1 file changed, 31 insertions(+)
diff --git a/client/mgmt.c b/client/mgmt.c
index cd2ef80221ad..a7069e5bbb37 100644
--- a/client/mgmt.c
+++ b/client/mgmt.c
@@ -499,6 +499,35 @@ static void disconnected(uint16_t index, uint16_t len, const void *param,
index, addr, typestr(ev->addr.type), reason);
}
+static void conn_subrate(uint16_t index, uint16_t len, const void *param,
+ void *user_data)
+{
+ const struct mgmt_ev_conn_subrate *ev = param;
+ char addr[18];
+
+ if (len < sizeof(*ev)) {
+ error("Invalid connection subrate event length (%u bytes)",
+ len);
+ return;
+ }
+
+ ba2str(&ev->addr.bdaddr, addr);
+
+ if (ev->status) {
+ print("hci%u %s type %s connection subrate failed status "
+ "0x%02x (%s)", index, addr, typestr(ev->addr.type),
+ ev->status, mgmt_errstr(ev->status));
+ return;
+ }
+
+ print("hci%u %s type %s connection subrate interval 0x%04x "
+ "subrate 0x%04x latency 0x%04x cont_num 0x%04x timeout 0x%04x",
+ index, addr, typestr(ev->addr.type),
+ le16_to_cpu(ev->interval), le16_to_cpu(ev->subrate),
+ le16_to_cpu(ev->latency), le16_to_cpu(ev->cont_num),
+ le16_to_cpu(ev->supv_timeout));
+}
+
static void conn_failed(uint16_t index, uint16_t len, const void *param,
void *user_data)
{
@@ -6006,6 +6035,8 @@ static void register_mgmt_callbacks(struct mgmt *mgmt, uint16_t index)
NULL, NULL);
mgmt_register(mgmt, MGMT_EV_CONNECT_FAILED, index, conn_failed,
NULL, NULL);
+ mgmt_register(mgmt, MGMT_EV_CONN_SUBRATE, index, conn_subrate,
+ NULL, NULL);
mgmt_register(mgmt, MGMT_EV_AUTH_FAILED, index, auth_failed,
NULL, NULL);
mgmt_register(mgmt, MGMT_EV_CLASS_OF_DEV_CHANGED, index,
--
2.55.0
^ permalink raw reply related [flat|nested] 14+ messages in thread
* [PATCH BlueZ v3 5/9] emulator: Default to the latest BR/EDR+LE version
2026-09-24 15:46 [PATCH BlueZ v3 0/9] Add HID over GATT functional tests Luiz Augusto von Dentz
` (3 preceding siblings ...)
2026-09-24 15:46 ` [PATCH BlueZ v3 4/9] client/mgmt: Print Connection Subrate event Luiz Augusto von Dentz
@ 2026-09-24 15:46 ` Luiz Augusto von Dentz
2026-09-24 15:46 ` [PATCH BlueZ v3 6/9] client/scripts: Add HoG device scripts Luiz Augusto von Dentz
` (4 subsequent siblings)
9 siblings, 0 replies; 14+ messages in thread
From: Luiz Augusto von Dentz @ 2026-09-24 15:46 UTC (permalink / raw)
To: linux-bluetooth
From: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Emulate BR/EDR+LE 6.2 controllers by default, for both local (-l) and
server (--server, --tcp) controllers, so the latest features such as
Shorter Connection Intervals (LE Connection Rate Request) are
supported, e.g. by test-functional which uses --server.
Add the -C/--core=<version> option to emulate older versions instead:
5.0, 5.2, 6.0 or 6.2.
---
emulator/main.c | 54 ++++++++++++++++++++++++++++++++++++++++++++---
emulator/server.c | 15 ++++++++++++-
emulator/server.h | 2 ++
3 files changed, 67 insertions(+), 4 deletions(-)
diff --git a/emulator/main.c b/emulator/main.c
index c21640adc359..b18e77cf191b 100644
--- a/emulator/main.c
+++ b/emulator/main.c
@@ -24,8 +24,8 @@
#include "src/shared/util.h"
#include "serial.h"
-#include "server.h"
#include "btdev.h"
+#include "server.h"
#include "vhci.h"
#include "le.h"
@@ -54,6 +54,9 @@ static void usage(void)
"\t-U[num] Number of test LE controllers\n"
"\t-B Create BR/EDR only controller\n"
"\t-A Create AMP controller\n"
+ "\t-C, --core=<version> Core Specification version of the\n"
+ "\t BR/EDR/LE controllers:\n"
+ "\t 5.0, 5.2, 6.0 or 6.2 (default)\n"
"\t-T[num] Number of test AMP controllers\n"
"\t-h, --help Show help options\n");
}
@@ -67,12 +70,37 @@ static const struct option main_options[] = {
{ "le", no_argument, NULL, 'L' },
{ "bredr", no_argument, NULL, 'B' },
{ "amp", no_argument, NULL, 'A' },
+ { "core", required_argument, NULL, 'C' },
{ "letest", optional_argument, NULL, 'U' },
{ "version", no_argument, NULL, 'v' },
{ "help", no_argument, NULL, 'h' },
{ }
};
+static const struct {
+ const char *version;
+ enum btdev_type type;
+} core_versions[] = {
+ { "5.0", BTDEV_TYPE_BREDRLE50 },
+ { "5.2", BTDEV_TYPE_BREDRLE52 },
+ { "6.0", BTDEV_TYPE_BREDRLE60 },
+ { "6.2", BTDEV_TYPE_BREDRLE62 },
+};
+
+static bool parse_core_version(const char *version, enum btdev_type *type)
+{
+ size_t i;
+
+ for (i = 0; i < ARRAY_SIZE(core_versions); i++) {
+ if (!strcmp(core_versions[i].version, version)) {
+ *type = core_versions[i].type;
+ return true;
+ }
+ }
+
+ return false;
+}
+
static void vhci_debug(const char *str, void *user_data)
{
int i = PTR_TO_UINT(user_data);
@@ -101,7 +129,10 @@ int main(int argc, char *argv[])
bool serial_enabled = false;
int letest_count = 0;
int vhci_count = 0;
- enum btdev_type type = BTDEV_TYPE_BREDRLE60;
+ /* Default to the latest version supported by the emulator */
+ enum btdev_type bredrle_type = BTDEV_TYPE_BREDRLE62;
+ enum btdev_type type;
+ bool type_set = false;
int i;
mainloop_init();
@@ -109,7 +140,7 @@ int main(int argc, char *argv[])
for (;;) {
int opt;
- opt = getopt_long(argc, argv, "dSs::t::l::LBAU::T::vh",
+ opt = getopt_long(argc, argv, "dSs::t::l::LBAC:U::T::vh",
main_options, NULL);
if (opt < 0)
break;
@@ -140,12 +171,22 @@ int main(int argc, char *argv[])
break;
case 'L':
type = BTDEV_TYPE_LE;
+ type_set = true;
break;
case 'B':
type = BTDEV_TYPE_BREDR;
+ type_set = true;
break;
case 'A':
type = BTDEV_TYPE_AMP;
+ type_set = true;
+ break;
+ case 'C':
+ if (!parse_core_version(optarg, &bredrle_type)) {
+ fprintf(stderr, "Unsupported version: %s\n",
+ optarg);
+ return EXIT_FAILURE;
+ }
break;
case 'U':
if (optarg)
@@ -164,6 +205,9 @@ int main(int argc, char *argv[])
}
}
+ if (!type_set)
+ type = bredrle_type;
+
if (letest_count < 1 && vhci_count < 1 && !server_enabled &&
!tcp_port && !serial_enabled) {
fprintf(stderr, "No emulator specified\n");
@@ -214,6 +258,8 @@ int main(int argc, char *argv[])
server1 = server_open_unix(SERVER_TYPE_BREDRLE, path);
if (!server1)
fprintf(stderr, "Failed to open BR/EDR/LE server\n");
+ else
+ server_set_bredrle_type(server1, bredrle_type);
snprintf(path, sizeof(path), "%s/%s", server_path,
"bt-server-bredr");
@@ -255,6 +301,8 @@ int main(int argc, char *argv[])
tcp_server = server_open_tcp(SERVER_TYPE_BREDRLE, tcp_port);
if (!tcp_server)
fprintf(stderr, "Failed to open TCP port\n");
+ else
+ server_set_bredrle_type(tcp_server, bredrle_type);
fprintf(stderr, "Listening TCP on 127.0.0.1:%d\n", tcp_port);
}
diff --git a/emulator/server.c b/emulator/server.c
index e3eda8458ae0..5a827b24531e 100644
--- a/emulator/server.c
+++ b/emulator/server.c
@@ -38,6 +38,7 @@
struct server {
enum server_type type;
+ enum btdev_type bredrle_type;
uint16_t id;
int fd;
struct queue *clients;
@@ -281,7 +282,7 @@ static void server_accept_callback(int fd, uint32_t events, void *user_data)
switch (server->type) {
case SERVER_TYPE_BREDRLE:
- type = BTDEV_TYPE_BREDRLE52;
+ type = server->bredrle_type;
break;
case SERVER_TYPE_BREDR:
type = BTDEV_TYPE_BREDR;
@@ -361,6 +362,7 @@ struct server *server_open_unix(enum server_type type, const char *path)
memset(server, 0, sizeof(*server));
server->type = type;
+ server->bredrle_type = BTDEV_TYPE_BREDRLE62;
server->id = 0x42;
server->fd = open_unix(path);
@@ -429,6 +431,7 @@ struct server *server_open_tcp(enum server_type type, uint16_t port)
memset(server, 0, sizeof(*server));
server->type = type;
+ server->bredrle_type = BTDEV_TYPE_BREDRLE62;
server->id = 0x43;
server->fd = open_tcp(port);
@@ -455,6 +458,16 @@ void server_close(struct server *server)
mainloop_remove_fd(server->fd);
}
+bool server_set_bredrle_type(struct server *server, enum btdev_type type)
+{
+ if (!server || server->type != SERVER_TYPE_BREDRLE)
+ return false;
+
+ server->bredrle_type = type;
+
+ return true;
+}
+
bool server_set_debug(struct server *server, server_debug_func_t callback,
void *user_data, server_destroy_func_t destroy)
{
diff --git a/emulator/server.h b/emulator/server.h
index 1844a9871af1..5fc3a284f53f 100644
--- a/emulator/server.h
+++ b/emulator/server.h
@@ -25,6 +25,8 @@ struct server *server_open_unix(enum server_type type, const char *path);
struct server *server_open_tcp(enum server_type type, uint16_t port);
void server_close(struct server *server);
+bool server_set_bredrle_type(struct server *server, enum btdev_type type);
+
typedef void (*server_debug_func_t)(const char *str, void *user_data);
typedef void (*server_destroy_func_t)(void *user_data);
bool server_set_debug(struct server *server, server_debug_func_t callback,
--
2.55.0
^ permalink raw reply related [flat|nested] 14+ messages in thread
* [PATCH BlueZ v3 6/9] client/scripts: Add HoG device scripts
2026-09-24 15:46 [PATCH BlueZ v3 0/9] Add HID over GATT functional tests Luiz Augusto von Dentz
` (4 preceding siblings ...)
2026-09-24 15:46 ` [PATCH BlueZ v3 5/9] emulator: Default to the latest BR/EDR+LE version Luiz Augusto von Dentz
@ 2026-09-24 15:46 ` Luiz Augusto von Dentz
2026-09-24 15:46 ` [PATCH BlueZ v3 7/9] doc: Add functional-hog documentation Luiz Augusto von Dentz
` (3 subsequent siblings)
9 siblings, 0 replies; 14+ messages in thread
From: Luiz Augusto von Dentz @ 2026-09-24 15:46 UTC (permalink / raw)
To: linux-bluetooth
From: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Add scripts registering a HID Service (HIDS) acting as a HID over GATT
keyboard, with and without Shorter Connection Interval (SCI) support.
HID SCI Mode can be notified so the device can confirm a mode change.
---
client/scripts/hog-device-sci.bt | 49 ++++++++++++++++++++++++++++++++
client/scripts/hog-device.bt | 38 +++++++++++++++++++++++++
2 files changed, 87 insertions(+)
create mode 100644 client/scripts/hog-device-sci.bt
create mode 100644 client/scripts/hog-device.bt
diff --git a/client/scripts/hog-device-sci.bt b/client/scripts/hog-device-sci.bt
new file mode 100644
index 000000000000..1bf3a0a90db7
--- /dev/null
+++ b/client/scripts/hog-device-sci.bt
@@ -0,0 +1,49 @@
+#
+# Register a HID Service (HIDS) acting as a HID over GATT (HoG) keyboard
+# with Shorter Connection Interval (SCI) support.
+#
+gatt.register-service 0x1812
+# Primary
+yes
+#
+# HID Information: bcdHID 1.11, bCountryCode 0x00,
+# Flags: NormallyConnectable and SCI Supported
+gatt.register-characteristic 0x2a4a read
+0x11 0x01 0x00 0x06
+#
+# Report Map: keyboard with Report ID 1
+gatt.register-characteristic 0x2a4b read
+0x05 0x01 0x09 0x06 0xa1 0x01 0x85 0x01 0x05 0x07 0x19 0xe0 0x29 0xe7 0x15 0x00 0x25 0x01 0x75 0x01 0x95 0x08 0x81 0x02 0x95 0x01 0x75 0x08 0x81 0x01 0x95 0x06 0x75 0x08 0x15 0x00 0x25 0x65 0x05 0x07 0x19 0x00 0x29 0x65 0x81 0x00 0xc0
+#
+# Report: Input Report ID 1
+gatt.register-characteristic 0x2a4d read,notify
+0x00 0x00 0x00 0x00 0x00 0x00 0x00 0x00
+# Report Reference: Report ID 1, Input
+gatt.register-descriptor 0x2908 read
+0x01 0x01
+#
+# Protocol Mode: Report Protocol Mode
+gatt.register-characteristic 0x2a4e read,write-without-response
+0x01
+#
+# HID Control Point
+gatt.register-characteristic 0x2a4c write-without-response
+0x00
+#
+# HID SCI Mode: None (0x00), notified when changed
+gatt.register-characteristic 0x2c39 read,write,notify
+0x00
+#
+# HID SCI Information (intervals in units of 0.125 ms):
+# Minimum Supported Connection Interval: 0x08 (1 ms)
+# Number of Supported Subgroups: 1
+# Subgroup[0]: Min 0x0008 (1 ms) Max 0x0050 (10 ms) Stride 0x0008 (1 ms)
+gatt.register-characteristic 0x2c3a read
+0x08 0x01 0x08 0x00 0x50 0x00 0x08 0x00
+#
+gatt.register-application
+#
+# Advertise as a keyboard with HIDS
+advertise.uuids 0x1812
+advertise.appearance 0x03c1
+power on
diff --git a/client/scripts/hog-device.bt b/client/scripts/hog-device.bt
new file mode 100644
index 000000000000..42b324eda020
--- /dev/null
+++ b/client/scripts/hog-device.bt
@@ -0,0 +1,38 @@
+#
+# Register a HID Service (HIDS) acting as a HID over GATT (HoG) keyboard
+# without Shorter Connection Interval (SCI) support.
+#
+gatt.register-service 0x1812
+# Primary
+yes
+#
+# HID Information: bcdHID 1.11, bCountryCode 0x00,
+# Flags: NormallyConnectable
+gatt.register-characteristic 0x2a4a read
+0x11 0x01 0x00 0x02
+#
+# Report Map: keyboard with Report ID 1
+gatt.register-characteristic 0x2a4b read
+0x05 0x01 0x09 0x06 0xa1 0x01 0x85 0x01 0x05 0x07 0x19 0xe0 0x29 0xe7 0x15 0x00 0x25 0x01 0x75 0x01 0x95 0x08 0x81 0x02 0x95 0x01 0x75 0x08 0x81 0x01 0x95 0x06 0x75 0x08 0x15 0x00 0x25 0x65 0x05 0x07 0x19 0x00 0x29 0x65 0x81 0x00 0xc0
+#
+# Report: Input Report ID 1
+gatt.register-characteristic 0x2a4d read,notify
+0x00 0x00 0x00 0x00 0x00 0x00 0x00 0x00
+# Report Reference: Report ID 1, Input
+gatt.register-descriptor 0x2908 read
+0x01 0x01
+#
+# Protocol Mode: Report Protocol Mode
+gatt.register-characteristic 0x2a4e read,write-without-response
+0x01
+#
+# HID Control Point
+gatt.register-characteristic 0x2a4c write-without-response
+0x00
+#
+gatt.register-application
+#
+# Advertise as a keyboard with HIDS
+advertise.uuids 0x1812
+advertise.appearance 0x03c1
+power on
--
2.55.0
^ permalink raw reply related [flat|nested] 14+ messages in thread
* [PATCH BlueZ v3 7/9] doc: Add functional-hog documentation
2026-09-24 15:46 [PATCH BlueZ v3 0/9] Add HID over GATT functional tests Luiz Augusto von Dentz
` (5 preceding siblings ...)
2026-09-24 15:46 ` [PATCH BlueZ v3 6/9] client/scripts: Add HoG device scripts Luiz Augusto von Dentz
@ 2026-09-24 15:46 ` Luiz Augusto von Dentz
2026-09-24 15:46 ` [PATCH BlueZ v3 8/9] test: functional: add HoG tests Luiz Augusto von Dentz
` (2 subsequent siblings)
9 siblings, 0 replies; 14+ messages in thread
From: Luiz Augusto von Dentz @ 2026-09-24 15:46 UTC (permalink / raw)
To: linux-bluetooth
From: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Document the HoG functional tests, where bluetoothctl registers a HID
Service with and without Shorter Connection Interval (SCI) support
using client/scripts/hog-device*.bt, and the HID host:
- checks HID Information, HID SCI Mode and HID SCI Information with
gatt.select-attribute/gatt.read
- receives a few Input Reports notified by the HID device
- changes the SCI mode, followed by the connection rate with
mgmt.conn-subrate, and receives the notification from the HID device
confirming the mode has been changed
---
Makefile.am | 1 +
doc/functional-hog.rst | 188 +++++++++++++++++++++++++++++++++++++
doc/functional-testing.rst | 1 +
3 files changed, 190 insertions(+)
create mode 100644 doc/functional-hog.rst
diff --git a/Makefile.am b/Makefile.am
index 1d46b9b938cf..17348788a30b 100644
--- a/Makefile.am
+++ b/Makefile.am
@@ -501,6 +501,7 @@ EXTRA_DIST += doc/assigned-numbers.rst doc/supported-features.txt \
doc/functional-a2dp.rst \
doc/functional-avrcp.rst \
doc/functional-bap.rst \
+ doc/functional-hog.rst \
doc/functional-mpris-proxy.rst \
doc/functional-obex.rst \
doc/settings-storage.txt
diff --git a/doc/functional-hog.rst b/doc/functional-hog.rst
new file mode 100644
index 000000000000..d748f241a378
--- /dev/null
+++ b/doc/functional-hog.rst
@@ -0,0 +1,188 @@
+==============
+functional-hog
+==============
+
+DESCRIPTION
+===========
+
+HID over GATT (HoG) functional tests, `test/functional/test_hog.py`,
+driven through **bluetoothctl(1)**. See **functional-testing(7)** for
+the conventions used here, and **test-functional(1)** for how to run
+the suite.
+
+SETUP
+=====
+
+Two hosts, connected over LE, both running **bluetoothd(8)** with
+``ControllerMode = le`` and ``ExportClaimedServices = read-write``, as
+the HID Service is claimed by the input plugin of the HID host and
+bluetoothctl has to write HID SCI Mode:
+
+.. code-block::
+
+ +------------------------+ +------------------------+
+ | host0 | LE | host1 |
+ | central | --------------> | peripheral |
+ | bluetoothctl | | bluetoothctl |
+ | HID host | GATT (HIDS) | hog-device[-sci].bt |
+ | | <============== | HID Service |
+ +------------------------+ +------------------------+
+
+ --> connection is initiated by ==> reports flow towards
+
+host1 starts `bluetoothctl` with a script registering a HID Service
+(HIDS, ``00001812-0000-1000-8000-00805f9b34fb``) acting as a keyboard,
+through the ``gatt.register-service``, ``gatt.register-characteristic``
+and ``gatt.register-descriptor`` commands:
+
+``client/scripts/hog-device.bt``
+ HIDS without Shorter Connection Interval (SCI) support:
+
+ - HID Information (0x2A4A): ``11 01 00 02``, i.e. bcdHID 1.11,
+ bCountryCode 0x00 and Flags NormallyConnectable.
+ - Report Map (0x2A4B): keyboard with Report ID 1.
+ - Report (0x2A4D), with a Report Reference descriptor (0x2908)
+ ``01 01``, i.e. Report ID 1, Input Report.
+ - Protocol Mode (0x2A4E): ``01``, i.e. Report Protocol Mode.
+ - HID Control Point (0x2A4C).
+
+``client/scripts/hog-device-sci.bt``
+ Same as above, with SCI support:
+
+ - HID Information (0x2A4A): ``11 01 00 06``, i.e. the SCI
+ Supported flag (0x04) is set as well.
+ - HID SCI Mode (0x2C39): ``00``, i.e. None, with the notify
+ property so the HID device can confirm a mode change.
+ - HID SCI Information (0x2C3A): ``08 01 08 00 50 00 08 00``, i.e.
+ Minimum Supported Connection Interval 1 ms, and one subgroup
+ with Min 1 ms, Max 10 ms and Stride 1 ms (in units of 0.125 ms).
+
+Both scripts set the advertising data to the HIDS UUID and the
+keyboard appearance (0x03C1). The same scripts can be used manually to
+emulate a HoG device:
+
+.. code-block::
+
+ $ bluetoothctl --init-script client/scripts/hog-device-sci.bt
+ [bluetoothctl]> advertise on
+
+host0 runs a plain `bluetoothctl`, and both use
+``-a auto:NoInputNoOutput`` so pairing is Just Works.
+
+TEST CASES
+==========
+
+test_hog[no-sci]
+----------------
+
+:Setup: As above, with ``client/scripts/hog-device.bt`` on host1.
+
+:Steps:
+ 1. host1: start `bluetoothctl` with the script.
+ 2. host0: ``scan on``; host1: ``advertise on``.
+ 3. host0: ``pair <host1 bdaddr>``.
+ 4. host0: ``info <host1 bdaddr>``.
+ 5. host0: ``gatt.select-attribute 2a4a`` and ``gatt.read``.
+ 6. host0: ``gatt.select-attribute 2a4d`` and ``gatt.notify on``.
+ 7. host1: ``gatt.select-attribute local
+ /org/bluez/app/service0/chrc2``, then for each report
+ ``gatt.write "<report>"``: ``00 00 04 00 00 00 00 00`` (a
+ pressed), ``02 00 05 00 00 00 00 00`` (Left Shift + b pressed)
+ and ``00 00 00 00 00 00 00 00`` (released).
+
+:Expected:
+ 1. ``Application registered`` on host1.
+ 2. ``Advertising object registered`` on host1 and the device found
+ on host0.
+ 3. ``Pairing successful`` and ``ServicesResolved: yes``.
+ 4. ``Human Interface Device (00001812-...)`` is listed in the UUIDs.
+ 5. HID Information reads ``11 01 00 02``:
+
+ .. code-block::
+
+ [bluetoothctl]> gatt.select-attribute 2a4a
+ [bluetoothctl]> gatt.read
+ Attempting to read /org/bluez/hci0/dev_XX/service0013/char001e
+ 11 01 00 02 ....
+
+ 6. ``Notify started``, and the Report subscribed on host1
+ (``Notify sock acquired``, as the input plugin already
+ subscribed with AcquireNotify).
+ 7. Each report is notified to host0, in order:
+
+ .. code-block::
+
+ [CHG] Attribute /org/bluez/hci0/dev_XX/service0013/char0018 Value:
+ 00 00 04 00 00 00 00 00 ........
+
+:Notes: The service is checked at the GATT level only, so the test
+ does not depend on the kernel supporting uhid. The HID Service is
+ claimed by the input plugin on host0, but it is still exported
+ read-only over D-Bus by default (see ``ExportClaimedServices`` in
+ **bluetoothd(8)**), so it can be read with bluetoothctl.
+
+test_hog[sci]
+-------------
+
+:Setup: As above, with ``client/scripts/hog-device-sci.bt`` on host1.
+
+:Steps: As for test_hog[no-sci], then:
+
+ 8. host0: ``gatt.select-attribute 2c39`` and ``gatt.read``.
+ 9. host0: ``gatt.select-attribute 2c3a`` and ``gatt.read``.
+ 10. host0: ``gatt.select-attribute 2c39`` and ``gatt.notify on``.
+ 11. host0: ``gatt.write "0x03"``, i.e. SCI Fast Mode.
+ 12. host0: ``mgmt.conn-subrate <host1 bdaddr> 0x0008 0x0010 1 1 0 0
+ 0x01f4``, i.e. interval 1 ms to 2 ms, within the range given in
+ HID SCI Information, no subrating, no latency and 5 s
+ supervision timeout.
+ 13. host1: ``gatt.select-attribute local
+ /org/bluez/app/service0/chrc5`` and ``gatt.write "0x03"``.
+
+:Expected: As for test_hog[no-sci], except HID Information reads
+ ``11 01 00 06``, then:
+
+ 8. HID SCI Mode reads ``00``.
+ 9. HID SCI Information reads ``08 01 08 00 50 00 08 00``.
+ 10. ``Notify started`` and HID SCI Mode subscribed on host1.
+ 11. host1 receives the write:
+
+ .. code-block::
+
+ [/org/bluez/app/service0/chrc5 (HID SCI Mode)] WriteValue: XX offset 0 link LE
+ 03 .
+
+ 12. ``Connection Subrate loaded successfully``, then the MGMT
+ Connection Subrate event with the new interval on both hosts:
+
+ .. code-block::
+
+ hci0 XX type LE Public connection subrate interval 0x0008 subrate 0x0001 latency 0x0000 cont_num 0x0000 timeout 0x01f4
+
+ 13. The new mode is notified to host0, confirming it has been
+ changed:
+
+ .. code-block::
+
+ [CHG] Attribute /org/bluez/hci0/dev_XX/service0015/char0018 Value:
+ 03 .
+
+ .. code-block::
+
+ [bluetoothctl]> gatt.select-attribute 2c39
+ [bluetoothctl]> gatt.read
+ 00 .
+
+ [bluetoothctl]> gatt.select-attribute 2c3a
+ [bluetoothctl]> gatt.read
+ 08 01 08 00 50 00 08 00 ....P...
+
+:Notes: As the SCI Supported flag is set, the input plugin on host0
+ reads HID SCI Mode and HID SCI Information as well, which can be
+ seen in the **bluetoothd(8)** debug output (``SCI Mode:`` and
+ ``SCI Info:``).
+
+ The kernel only issues the LE Connection Rate Request as central,
+ so the connection rate is changed by the HID host. This requires
+ the controllers to support Shorter Connection Intervals, which
+ btvirt emulates as a BR/EDR/LE 6.2 controller.
diff --git a/doc/functional-testing.rst b/doc/functional-testing.rst
index ca7bfa672a76..7b3cad1c66b1 100644
--- a/doc/functional-testing.rst
+++ b/doc/functional-testing.rst
@@ -15,6 +15,7 @@ are documented separately:
- **functional-a2dp(7)**: `test/functional/test_a2dp.py`
- **functional-avrcp(7)**: `test/functional/test_avrcp.py`
- **functional-bap(7)**: `test/functional/test_bap.py`
+- **functional-hog(7)**: `test/functional/test_hog.py`
- **functional-mpris-proxy(7)**: `test/functional/test_mpris_proxy.py`
- **functional-obex(7)**: `test/functional/test_obex.py`
--
2.55.0
^ permalink raw reply related [flat|nested] 14+ messages in thread
* [PATCH BlueZ v3 8/9] test: functional: add HoG tests
2026-09-24 15:46 [PATCH BlueZ v3 0/9] Add HID over GATT functional tests Luiz Augusto von Dentz
` (6 preceding siblings ...)
2026-09-24 15:46 ` [PATCH BlueZ v3 7/9] doc: Add functional-hog documentation Luiz Augusto von Dentz
@ 2026-09-24 15:46 ` Luiz Augusto von Dentz
2026-09-24 15:46 ` [PATCH BlueZ v3 9/9] test: functional: limit the workers by the memory available Luiz Augusto von Dentz
2026-09-29 20:50 ` [PATCH BlueZ v3 0/9] Add HID over GATT functional tests patchwork-bot+bluetooth
9 siblings, 0 replies; 14+ messages in thread
From: Luiz Augusto von Dentz @ 2026-09-24 15:46 UTC (permalink / raw)
To: linux-bluetooth
From: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Add tests where bluetoothctl registers a HID Service, with and without
SCI support, using client/scripts/hog-device*.bt, and the HID host
checks the service, receives Input Reports and, with SCI support,
changes the SCI mode and the connection rate.
See doc/functional-hog.rst for details.
---
test/functional/test_hog.py | 252 ++++++++++++++++++++++++++++++++++++
1 file changed, 252 insertions(+)
create mode 100644 test/functional/test_hog.py
diff --git a/test/functional/test_hog.py b/test/functional/test_hog.py
new file mode 100644
index 000000000000..ea54882d059d
--- /dev/null
+++ b/test/functional/test_hog.py
@@ -0,0 +1,252 @@
+# -*- coding: utf-8; mode: python; eval: (blacken-mode); -*-
+# SPDX-License-Identifier: GPL-2.0-or-later
+"""
+Tests for HID over GATT (HoG) using bluetoothctl in VM instances
+
+The HID device (host1) registers a HID Service (HIDS) with bluetoothctl,
+using client/scripts/hog-device.bt or client/scripts/hog-device-sci.bt,
+and the HID host (host0) pairs with it and checks the service over GATT.
+"""
+
+import warnings
+
+import pytest
+
+from pytest_bluezenv import Bluetoothd, Pexpect, find_exe, host_config
+from pytest_bluezenv.utils import bluez_src_dir
+
+pytestmark = [pytest.mark.vm]
+
+# The HID Service is claimed by the input plugin of the HID host, so it
+# has to be exported read-write for bluetoothctl to write HID SCI Mode
+HOG_CONF = """[General]
+ControllerMode = le
+
+[GATT]
+ExportClaimedServices = read-write
+"""
+
+HIDS_UUID = "00001812-0000-1000-8000-00805f9b34fb"
+
+# Local attributes registered by client/scripts/hog-device*.bt
+LOCAL_REPORT = "/org/bluez/app/service0/chrc2"
+LOCAL_SCI_MODE = "/org/bluez/app/service0/chrc5"
+
+# Keyboard Input Reports: Modifiers, Reserved, then 6 Key Codes
+REPORTS = [
+ "00 00 04 00 00 00 00 00", # a pressed
+ "02 00 05 00 00 00 00 00", # Left Shift + b pressed
+ "00 00 00 00 00 00 00 00", # released
+]
+
+# HID SCI Mode: Fast Mode
+SCI_FAST_MODE = "03"
+
+# LE Connection Rate parameters requested with mgmt.conn-subrate once in
+# SCI Fast Mode: interval 1 ms to 2 ms (units of 0.125 ms), within the
+# range given in HID SCI Information, no subrating, no latency and 5 s
+# supervision timeout (units of 10 ms)
+SCI_RATE = ["0x0008", "0x0010", "1", "1", "0", "0", "0x01f4"]
+
+# Reported when an operation cannot complete, so a test does not have to
+# wait for its timeout to know it is not going to
+FAILURES = [
+ r"(Failed to \w+[^\r\n]*)",
+ r"(Device \S+ not available)",
+ r"(No device connected)",
+ r"(No attribute selected)",
+]
+
+# What a command reports is printed as it runs, unlike what the peers
+# report over the air, so waiting the default timeout for it only makes
+# a failure slower
+REPLY_TIMEOUT = 5
+
+
+def script(name):
+ src = bluez_src_dir()
+ if src is None:
+ pytest.skip("BlueZ source directory not known")
+
+ path = src / "client" / "scripts" / name
+ if not path.exists():
+ pytest.skip(f"{path} not found")
+
+ return str(path)
+
+
+def spawn_bluetoothctl(host, init_script=None):
+ exe = find_exe("client", "bluetoothctl")
+ # Accept pairing and authorize services without prompting, with a
+ # capability pairing Just Works, as there is no one to answer the
+ # entry of a passkey
+ args = [exe, "-a", "auto:NoInputNoOutput"]
+ if init_script:
+ args += ["--init-script", script(init_script)]
+ return host.pexpect.spawn(args)
+
+
+def expect(ctl, patterns, **kwargs):
+ """
+ Expect one of the patterns, failing as soon as one of the failures
+ shows up. Return the index of the pattern matched and its groups.
+ """
+ if isinstance(patterns, str):
+ patterns = [patterns]
+
+ idx, m = ctl.expect(FAILURES + list(patterns), **kwargs)
+ if idx < len(FAILURES):
+ raise AssertionError(m[0].decode("utf-8") if m else "failed")
+
+ return idx - len(FAILURES), m
+
+
+def expect_all(ctl, patterns, **kwargs):
+ """Expect all the given patterns, in any order."""
+ pending = list(patterns)
+
+ while pending:
+ idx, _ = expect(ctl, pending, **kwargs)
+ pending.pop(idx)
+
+
+def pair_le(host0, ctl0, host1, ctl1):
+ ctl0.send("scan on\n")
+ expect(ctl0, f"Controller {host0.bdaddr.upper()} Discovering: yes")
+
+ ctl1.send("advertise on\n")
+ expect(ctl1, "Advertising object registered")
+
+ expect(ctl0, f"Device {host1.bdaddr.upper()}")
+ ctl0.send(f"pair {host1.bdaddr.upper()}\n")
+
+ # See test_bluetoothctl_pair_le: passkey confirmation is handled by
+ # the auto agent, but legacy passkey entry still needs an answer
+ legacy = r"\[agent\].*Passkey:.*m(\d+)"
+ pending = [
+ r"Pairing successful",
+ f"Device {host1.bdaddr.upper()} ServicesResolved: yes",
+ ]
+
+ while pending:
+ idx, m = expect(ctl0, [legacy] + pending)
+ if idx == 0:
+ warnings.warn(
+ "BUG: we got passkey authentication, bluetoothd/kernel "
+ "should be fixed"
+ )
+ ctl1.expect(r"\[agent\] Enter passkey \(number in 0-999999\):")
+ ctl1.send(f"{m[0].decode('utf-8')}\n")
+ continue
+ pending.pop(idx - 1)
+
+ ctl0.send("scan off\n")
+
+
+def read_attribute(ctl, uuid):
+ """Read the given remote attribute, returning its value as hex string."""
+ ctl.send(f"gatt.select-attribute {uuid}\n")
+ ctl.send("gatt.read\n")
+ expect(ctl, r"Attempting to read \S+", timeout=REPLY_TIMEOUT)
+ return expect_hexdump(ctl)
+
+
+def hexbytes(value):
+ """Turn a hex string into the format taken by gatt.write."""
+ return " ".join(f"0x{byte}" for byte in value.split())
+
+
+def expect_hexdump(ctl, **kwargs):
+ """Expect a value printed by bluetoothctl, returning it as hex string."""
+ _, m = expect(ctl, r"((?: [0-9a-f]{2})+) ", **kwargs)
+ return m[0].decode("utf-8").strip()
+
+
+def expect_notification(ctl):
+ """Expect a notification of the remote attribute, returning its value."""
+ expect(ctl, rf"CHG.*? Attribute /\S+ Value:")
+ return expect_hexdump(ctl)
+
+
+def enable_notifications(ctl, device, uuid, local):
+ """Enable notifications of the given attribute, on the HID host."""
+ ctl.send(f"gatt.select-attribute {uuid}\n")
+ ctl.send("gatt.notify on\n")
+ expect(ctl, r"Notify started", timeout=REPLY_TIMEOUT)
+ # Either subscribed with StartNotify, or with AcquireNotify as done by
+ # the input plugin of the HID host for the Input Reports
+ expect(
+ device,
+ rf"Attribute {local} (\S+ )?(notifications enabled|Notify sock acquired)",
+ )
+
+
+def notify(device, local, value):
+ """Notify the given value of a local attribute, on the HID device."""
+ device.send(f"gatt.select-attribute local {local}\n")
+ device.send(f'gatt.write "{hexbytes(value)}"\n')
+ expect(device, rf"Attribute {local} .*written", timeout=REPLY_TIMEOUT)
+
+
+@host_config(
+ [Bluetoothd(conf=HOG_CONF), Pexpect()],
+ [Bluetoothd(conf=HOG_CONF), Pexpect()],
+)
+@pytest.mark.parametrize(
+ "init_script, flags, sci",
+ [
+ ("hog-device.bt", "02", None),
+ ("hog-device-sci.bt", "06", ("00", "08 01 08 00 50 00 08 00")),
+ ],
+ ids=["no-sci", "sci"],
+)
+def test_hog(hosts, init_script, flags, sci):
+ host0, host1 = hosts
+
+ device = spawn_bluetoothctl(host1, init_script)
+ expect(device, "Application registered")
+
+ ctl = spawn_bluetoothctl(host0)
+ pair_le(host0, ctl, host1, device)
+
+ ctl.send(f"info {host1.bdaddr.upper()}\n")
+ expect(ctl, rf"Human Interface Device\s+\({HIDS_UUID}\)", timeout=REPLY_TIMEOUT)
+
+ # HID Information: bcdHID 1.11, bCountryCode 0x00 and Flags
+ assert read_attribute(ctl, "2a4a") == f"11 01 00 {flags}"
+
+ # Input Reports: the HID device notifies a few key presses
+ enable_notifications(ctl, device, "2a4d", LOCAL_REPORT)
+
+ for report in REPORTS:
+ notify(device, LOCAL_REPORT, report)
+ assert expect_notification(ctl) == report
+
+ if sci is None:
+ return
+
+ mode, info = sci
+ assert read_attribute(ctl, "2c39") == mode
+ assert read_attribute(ctl, "2c3a") == info
+
+ # SCI mode change: the HID host writes the new mode to the HID device
+ enable_notifications(ctl, device, "2c39", LOCAL_SCI_MODE)
+
+ ctl.send(f'gatt.write "{hexbytes(SCI_FAST_MODE)}"\n')
+ expect(device, rf"\[{LOCAL_SCI_MODE} .*\] WriteValue:")
+ assert expect_hexdump(device) == SCI_FAST_MODE
+
+ # The HID host, as central, changes the connection rate accordingly
+ ctl.send(f"mgmt.conn-subrate {host1.bdaddr} {' '.join(SCI_RATE)}\n")
+ # The connection rate may change before the command completes, so the
+ # event may be printed before the reply
+ rate = rf"{{}} type .* connection subrate interval {SCI_RATE[0]}"
+ expect_all(
+ ctl,
+ [r"Connection Subrate loaded successfully", rate.format(host1.bdaddr.upper())],
+ )
+ expect(device, rate.format(host0.bdaddr.upper()))
+
+ # Then the HID device confirms the mode has been changed
+ notify(device, LOCAL_SCI_MODE, SCI_FAST_MODE)
+ assert expect_notification(ctl) == SCI_FAST_MODE
--
2.55.0
^ permalink raw reply related [flat|nested] 14+ messages in thread
* [PATCH BlueZ v3 9/9] test: functional: limit the workers by the memory available
2026-09-24 15:46 [PATCH BlueZ v3 0/9] Add HID over GATT functional tests Luiz Augusto von Dentz
` (7 preceding siblings ...)
2026-09-24 15:46 ` [PATCH BlueZ v3 8/9] test: functional: add HoG tests Luiz Augusto von Dentz
@ 2026-09-24 15:46 ` Luiz Augusto von Dentz
2026-09-29 20:50 ` [PATCH BlueZ v3 0/9] Add HID over GATT functional tests patchwork-bot+bluetooth
9 siblings, 0 replies; 14+ messages in thread
From: Luiz Augusto von Dentz @ 2026-09-24 15:46 UTC (permalink / raw)
To: linux-bluetooth
From: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Each worker of pytest-xdist runs VM instances, so using one worker per
CPU could run out of memory, with the OOM killer terminating some of
them and tests failing at random.
With -n auto, limit the number of workers by the memory available,
estimating each worker needs memory for 3 VM instances of 256M of guest
memory plus the overhead of qemu, and use -n auto for check-functional
by default, which can be overridden with CHECK_FUNCTIONAL_JOBS.
---
Makefile.am | 7 +++++-
doc/test-functional.rst | 25 ++++++++++++++++++++
test/functional/conftest.py | 46 +++++++++++++++++++++++++++++++++++++
3 files changed, 77 insertions(+), 1 deletion(-)
diff --git a/Makefile.am b/Makefile.am
index 17348788a30b..e5587c55d2dd 100644
--- a/Makefile.am
+++ b/Makefile.am
@@ -885,9 +885,14 @@ check-TESTS recheck: AM_MAKEFLAGS += -j$(CHECK_JOBS)
# The functional tests are parallelized by pytest-xdist, loadgroup is required
# since pytest-bluezenv groups the tests sharing a host/VM setup together.
+# Each worker runs VM instances, so by default the number of workers is limited
+# by the memory available (see test/functional/conftest.py), override with e.g.
+# CHECK_FUNCTIONAL_JOBS=4.
+CHECK_FUNCTIONAL_JOBS ?= auto
+
check-functional: all
python3 -m pytest "$(srcdir)/test/functional" -v \
- -n $(CHECK_JOBS) --dist loadgroup \
+ -n $(CHECK_FUNCTIONAL_JOBS) --dist loadgroup \
-m "not tester" \
--kernel="$(FUNCTIONAL_TESTING_KERNEL)" \
--bluez-build-dir="$(top_builddir)" \
diff --git a/doc/test-functional.rst b/doc/test-functional.rst
index 3ffcbf6dec5c..9cf0a8bb48e5 100644
--- a/doc/test-functional.rst
+++ b/doc/test-functional.rst
@@ -472,6 +472,31 @@ pytest-xdist is required for parallel execution. To run:
$ test/test-functional -n auto --dist loadgroup
+With ``-n auto`` the number of workers is limited by the memory
+available, rather than using one worker per CPU, as each worker runs
+VM instances and running out of memory makes the OOM killer terminate
+some of them, failing tests at random. Each worker is estimated to need
+memory for 3 VM instances (the maximum used by a test) of 256M of guest
+memory plus the overhead of qemu, see `test/functional/conftest.py`.
+The estimate is printed when starting:
+
+.. code-block::
+
+ Using 9 workers: 22 CPUs, 12159 MiB available, 1218 MiB per worker (3 VMs of 406 MiB)
+
+To use a given number of workers instead:
+
+.. code-block::
+
+ $ test/test-functional -n 4 --dist loadgroup
+
+``make check-functional`` uses ``-n auto`` as well, which can be
+overridden with ``CHECK_FUNCTIONAL_JOBS``:
+
+.. code-block::
+
+ $ make check-functional CHECK_FUNCTIONAL_JOBS=4
+
Logging in to a test VM instance
--------------------------------
diff --git a/test/functional/conftest.py b/test/functional/conftest.py
index 4e0bda882de3..4d4193a95cd9 100644
--- a/test/functional/conftest.py
+++ b/test/functional/conftest.py
@@ -208,6 +208,52 @@ def _setup_progress(config):
)
+# Estimate of the memory used by a VM instance: 256M of guest memory, the
+# default of test-runner as the tests do not set it, plus the overhead of
+# qemu itself
+VM_MEM = (256 + 150) * 1024 * 1024
+
+# Maximum number of VM instances used by a test, i.e. by an xdist worker
+# as it runs one test at a time
+VM_MAX_HOSTS = 3
+
+
+def _mem_available():
+ try:
+ with open("/proc/meminfo") as f:
+ for line in f:
+ if line.startswith("MemAvailable:"):
+ return int(line.split()[1]) * 1024
+ except (OSError, ValueError, IndexError):
+ pass
+
+ return None
+
+
+@pytest.hookimpl(optionalhook=True)
+def pytest_xdist_auto_num_workers(config):
+ """
+ Number of workers used with -n auto: limited by the memory available,
+ so running a VM instance per worker does not end up with the OOM
+ killer terminating some of them, instead of one worker per CPU.
+ """
+ cpus = os.cpu_count() or 1
+ mem = _mem_available()
+ if mem is None:
+ return cpus
+
+ per_worker = VM_MAX_HOSTS * VM_MEM
+ workers = max(1, min(cpus, mem // per_worker))
+
+ sys.stderr.write(
+ f"Using {workers} workers: {cpus} CPUs, {mem >> 20} MiB available,"
+ f" {per_worker >> 20} MiB per worker ({VM_MAX_HOSTS} VMs of"
+ f" {VM_MEM >> 20} MiB)\n"
+ )
+
+ return workers
+
+
def pytest_configure(config):
_setup_progress(config)
--
2.55.0
^ permalink raw reply related [flat|nested] 14+ messages in thread
* RE: Add HID over GATT functional tests
2026-09-24 15:46 ` [PATCH BlueZ v3 1/9] shared/gatt-client: Fix calling destroy after unregistering notify Luiz Augusto von Dentz
@ 2026-09-24 19:16 ` bluez.test.bot
0 siblings, 0 replies; 14+ messages in thread
From: bluez.test.bot @ 2026-09-24 19:16 UTC (permalink / raw)
To: linux-bluetooth, luiz.dentz
[-- Attachment #1: Type: text/plain, Size: 7064 bytes --]
This is automated email and please do not reply to this email!
Dear submitter,
Thank you for submitting the patches to the linux bluetooth mailing list.
This is a CI test results with your patch series:
PW Link:https://patchwork.kernel.org/series/1173252/
---Test result---
Test Summary:
CheckPatch PASS 3.54 seconds
GitLint FAIL 2.94 seconds
BuildEll PASS 16.88 seconds
BluezMake PASS 230.92 seconds
MakeCheck PASS 12.88 seconds
MakeDistcheck PASS 105.89 seconds
CheckValgrind PASS 160.51 seconds
CheckSmatch PASS 166.27 seconds
bluezmakeextell PASS 64.61 seconds
TestFunctional FAIL 815.22 seconds
IncrementalBuild PASS 266.83 seconds
ScanBuild PASS 657.94 seconds
Details
##############################
Test: GitLint - FAIL
Desc: Run gitlint
Output:
[BlueZ,v3,1/9] shared/gatt-client: Fix calling destroy after unregistering notify
1: T1 Title exceeds max length (81>80): "[BlueZ,v3,1/9] shared/gatt-client: Fix calling destroy after unregistering notify"
[BlueZ,v3,2/9] attrib: Fix unregistering notifications registered with bt_gatt_client
1: T1 Title exceeds max length (85>80): "[BlueZ,v3,2/9] attrib: Fix unregistering notifications registered with bt_gatt_client"
##############################
Test: TestFunctional - FAIL
Desc: Run test-functional
Output:
FAIL functional.test_bap::test_bap_unicast_set_transport_created[hosts9-vm3-legacy]: failed on setup with "pytest_bluezenv.rpc.RemoteError: [Errno 32] Broken pipe
Remote traceback:
Traceback (most recent call last):
File "/usr/local/lib/python3.14/dist-packages/pytest_bluezenv/../pytest_bluezenv/rpc.py", line 102, in server_stream
result = method(*msg["a"], **msg["kw"])
File "/usr/local/lib/python3.14/dist-packages/pytest_bluezenv/../pytest_bluezenv/env.py", line 256, in call_plugin
return getattr(self.plugins[name], method)(*a, **kw)
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~^^^^^^^^^^
File "/usr/local/lib/python3.14/dist-packages/pytest_bluezenv/../pytest_bluezenv/host_plugins.py", line 447, in send
return ctl.send(*a, **kw)
~~~~~~~~^^^^^^^^^^
File "/usr/lib/python3/dist-packages/pexpect/popen_spawn.py", line 142, in send
return self.proc.stdin.write(b)
~~~~~~~~~~~~~~~~~~~~~^^^
BrokenPipeError: [Errno 32] Broken pipe"
FAIL functional.test_bap::test_bap_unicast_set_transport_created[hosts9-vm3-legacy]: failed on teardown with "pytest_bluezenv.plugin.CoredumpWarning: Core dump: test-bluezenv-hosts9.2-bluetoothctl-1790276391-121.core
/usr/bin/gdb: warning: Couldn't determine a path for the index cache directory.
[New LWP 121]
[Thread debugging using libthread_db enabled]
Using host libthread_db library "/usr/lib/x86_64-linux-gnu/libthread_db.so.1".
Core was generated by `/home/runner/work/bluez/bluez/src/src/client/bluetoothctl -a auto:NoInputNoOutput --init-script /home/runner/work/bluez/bluez/src/src/test/../client/scripts/bap-sink-lc3-right.bt'.
Program terminated with signal SIGABRT, Aborted.
#0 __pthread_kill_implementation (threadid=<optimized out>, signo=6, no_tid=0) at ./nptl/pthread_kill.c:44
warning: 44 ./nptl/pthread_kill.c: No such file or directory
Thread 1 (Thread 0x7f3293a9ed40 (LWP 121)):
#0 __pthread_kill_implementation (threadid=<optimized out>, signo=6, no_tid=0) at ./nptl/pthread_kill.c:44
tid = <optimized out>
ret = 0
pd = <optimized out>
old_mask = {__val = {140726025679776}}
ret = <optimized out>
#1 __pthread_kill_internal (threadid=<optimized out>, signo=6) at ./nptl/pthread_kill.c:89
No locals.
#2 __GI___pthread_kill (threadid=<optimized out>, signo=signo@entry=6) at ./nptl/pthread_kill.c:100
No locals.
#3 0x00007f32940ddb7e in __GI_raise (sig=sig@entry=6) at ../sysdeps/posix/raise.c:26
ret = <optimized out>
#4 0x00007f32940c08ec in __GI_abort () at ./stdlib/abort.c:77
act = {__sigaction_handler = {sa_handler = 0x7ba292ee1520, sa_sigaction = 0x7ba292ee1520}, sa_mask = {__val = {139855210919203, 140726025679792, 139855209372592, 7791336406271877491, 139855210919072, 140726025679872, 139855220451473, 139855221501984, 139855201496144, 0, 139855210919072, 4294967295, 139855208120320, 140726025679920, 139855209043459, 139855210919072}}, sa_flags = -1829814976, sa_restorer = 0x7c5292ee01c0}
#5 0x00007f329493efe2 in ?? () from /usr/lib/x86_64-linux-gnu/libdbus-1.so.3
No symbol table info available.
#6 0x00007f329496a4c1 in _dbus_warn_check_failed () from /usr/lib/x86_64-linux-gnu/libdbus-1.so.3
No symbol table info available.
#7 0x000055a79cecf02a in cancel_request (conn=<optimized out>, msg=0x7c3292ef3d40, user_data=<optimized out>) at client/agent.c:258
No locals.
#8 0x000055a79cf63ac1 in process_message (connection=0x7c5292ee01c0, message=0x7c3292ef3d40, method=0x55a79d0445e0 <auto_methods+320>, iface_user_data=<optimized out>) at gdbus/object.c:293
reply = <optimized out>
#9 0x00007f329494b0f4 in dbus_connection_dispatch () from /usr/lib/x86_64-linux-gnu/libdbus-1.so.3
No symbol table info available.
#10 0x000055a79cf53728 in message_dispatch (data=0x7c5292ee01c0) at gdbus/mainloop.c:59
conn = 0x7c5292ee01c0
#11 0x00007f32949e2b9b in ?? () from /usr/lib/x86_64-linux-gnu/libglib-2.0.so.0
No symbol table info available.
#12 0x00007f32949e41d7 in ?? () from /usr/lib/x86_64-linux-gnu/libglib-2.0.so.0
No symbol table info available.
#13 0x00007f32949e4577 in g_main_loop_run () from /usr/lib/x86_64-linux-gnu/libglib-2.0.so.0
No symbol table info available.
#14 0x000055a79cf96ec9 in mainloop_run () at src/shared/mainloop-glib.c:65
No locals.
#15 0x000055a79cf977fb in mainloop_run_with_signal (func=func@entry=0x55a79cf8e840 <signal_callback>, user_data=user_data@entry=0x0) at src/shared/mainloop-notify.c:196
data = 0x7b6292ee1810
io = 0x7b7292ee1f90
ret = <optimized out>
#16 0x000055a79cf92a1c in bt_shell_run () at src/shared/shell.c:1476
status = <optimized out>
submenu = <optimized out>
#17 0x000055a79ceb7935 in main (argc=<optimized out>, argv=<optimized out>) at client/main.c:4228
client = 0x7c3292ee0440
status = <optimized out>
timeout = <optimized out>
timeout_id = <optimized out>"
https://github.com/bluez/bluez/pull/2580
---
Regards,
Linux Bluetooth
^ permalink raw reply [flat|nested] 14+ messages in thread
* Re: [PATCH BlueZ v3 0/9] Add HID over GATT functional tests
2026-09-24 15:46 [PATCH BlueZ v3 0/9] Add HID over GATT functional tests Luiz Augusto von Dentz
` (8 preceding siblings ...)
2026-09-24 15:46 ` [PATCH BlueZ v3 9/9] test: functional: limit the workers by the memory available Luiz Augusto von Dentz
@ 2026-09-29 20:50 ` patchwork-bot+bluetooth
9 siblings, 0 replies; 14+ messages in thread
From: patchwork-bot+bluetooth @ 2026-09-29 20:50 UTC (permalink / raw)
To: Luiz Augusto von Dentz; +Cc: linux-bluetooth
Hello:
This series was applied to bluetooth/bluez.git (master)
by Luiz Augusto von Dentz <luiz.von.dentz@intel.com>:
On Thu, 24 Sep 2026 11:46:22 -0400 you wrote:
> From: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
>
> This adds functional tests for HID over GATT (HoG), with bluetoothctl
> registering a HID Service acting as a keyboard, with and without
> Shorter Connection Interval (SCI) support, using the new
> client/scripts/hog-device*.bt scripts, and the HID host:
>
> [...]
Here is the summary with links:
- [BlueZ,v3,1/9] shared/gatt-client: Fix calling destroy after unregistering notify
(no matching commit)
- [BlueZ,v3,2/9] attrib: Fix unregistering notifications registered with bt_gatt_client
(no matching commit)
- [BlueZ,v3,3/9] client/gatt: Fix setting descriptor value from scripts
(no matching commit)
- [BlueZ,v3,4/9] client/mgmt: Print Connection Subrate event
https://git.kernel.org/pub/scm/bluetooth/bluez.git/?id=e96e1d7e6db8
- [BlueZ,v3,5/9] emulator: Default to the latest BR/EDR+LE version
(no matching commit)
- [BlueZ,v3,6/9] client/scripts: Add HoG device scripts
https://git.kernel.org/pub/scm/bluetooth/bluez.git/?id=2604ba5035cd
- [BlueZ,v3,7/9] doc: Add functional-hog documentation
https://git.kernel.org/pub/scm/bluetooth/bluez.git/?id=7b68fecf0599
- [BlueZ,v3,8/9] test: functional: add HoG tests
https://git.kernel.org/pub/scm/bluetooth/bluez.git/?id=c7a2a63a02d6
- [BlueZ,v3,9/9] test: functional: limit the workers by the memory available
(no matching commit)
You are awesome, thank you!
--
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html
^ permalink raw reply [flat|nested] 14+ messages in thread
end of thread, other threads:[~2026-09-29 20:50 UTC | newest]
Thread overview: 14+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-24 15:46 [PATCH BlueZ v3 0/9] Add HID over GATT functional tests Luiz Augusto von Dentz
2026-09-24 15:46 ` [PATCH BlueZ v3 1/9] shared/gatt-client: Fix calling destroy after unregistering notify Luiz Augusto von Dentz
2026-09-24 19:16 ` Add HID over GATT functional tests bluez.test.bot
2026-09-24 15:46 ` [PATCH BlueZ v3 2/9] attrib: Fix unregistering notifications registered with bt_gatt_client Luiz Augusto von Dentz
2026-09-24 15:46 ` [PATCH BlueZ v3 3/9] client/gatt: Fix setting descriptor value from scripts Luiz Augusto von Dentz
2026-09-24 15:46 ` [PATCH BlueZ v3 4/9] client/mgmt: Print Connection Subrate event Luiz Augusto von Dentz
2026-09-24 15:46 ` [PATCH BlueZ v3 5/9] emulator: Default to the latest BR/EDR+LE version Luiz Augusto von Dentz
2026-09-24 15:46 ` [PATCH BlueZ v3 6/9] client/scripts: Add HoG device scripts Luiz Augusto von Dentz
2026-09-24 15:46 ` [PATCH BlueZ v3 7/9] doc: Add functional-hog documentation Luiz Augusto von Dentz
2026-09-24 15:46 ` [PATCH BlueZ v3 8/9] test: functional: add HoG tests Luiz Augusto von Dentz
2026-09-24 15:46 ` [PATCH BlueZ v3 9/9] test: functional: limit the workers by the memory available Luiz Augusto von Dentz
2026-09-29 20:50 ` [PATCH BlueZ v3 0/9] Add HID over GATT functional tests patchwork-bot+bluetooth
-- strict thread matches above, loose matches on Subject: below --
2026-09-24 13:55 [PATCH BlueZ v2 1/8] attrib: Fix unregistering notifications registered with bt_gatt_client Luiz Augusto von Dentz
2026-09-24 15:25 ` Add HID over GATT functional tests bluez.test.bot
2026-09-23 19:31 [PATCH BlueZ v1 1/7] client/gatt: Fix setting descriptor value from scripts Luiz Augusto von Dentz
2026-09-23 22:30 ` Add HID over GATT functional tests bluez.test.bot
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.