Repository navigation
Conversation
Refresh vendored mimalloc from 3.3.2 to 3.4.4, including the upstream fix for free(NULL) before allocator initialization (microsoft/mimalloc#1341). Preserve and document local patches and refresh SBOM and integrity metadata. Signed-off-by: Felix Rath <felixm.rath@gmail.com>
Link an ELF preinit fixture against the production allocator so global interposition is exercised before constructors. Run the regression with the production checks in scripts/test.sh. Signed-off-by: Felix Rath <felixm.rath@gmail.com>
|
Thanks for opening this — it has been seen, and it is queued. This note is automated, but it is not a brush-off: it exists so you know where your PR stands instead of having to guess from silence. Current review status: working through a backlog. What that means for this PR, concretely:
Things that will genuinely speed it up whenever review does happen:
If this fixes a bug, a reproduction we can run is worth more than a description of the symptom. Thanks for contributing, and sorry in advance for the wait. |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What does this PR do?
Fix a Linux startup segfault exposed by glibc 2.44 by updating vendored mimalloc from 3.3.2 to 3.4.4 (upstream commit
1f06f694972279bbc7ec72902e8570f5784d0fc9).During libstdc++ initialization, glibc's
newlocale()can call the globally interposedfree(NULL)before mimalloc's constructor runs. The old release allocator dereferences its uninitialized page map, leading to this SIGSEGV immediately and reproducibly when the cli binary starts:mimalloc 3.4.4, the version this PR updates to, includes the upstream fix:
Changes
include/,src/, andLICENSEfrom the upstream release. The existing reproducible-banner patch is preserved; one macOS comment is reworded to avoid a false positive in the vendored security scanner. Both local differences and the immutable source pin are documented invendored/mimalloc/PATCHES.md.prod_mimalloc.owith production allocator interposition. It callsfree(NULL)before allocator initialization and then checks normal allocation/free inmain. Wire it into the production checks inscripts/test.sh.The normal sanitizer runner does not enable global allocator interposition, so it cannot cover this startup regression. The new fixture fails with SIGSEGV (exit 139) when linked to the original mimalloc 3.3.2 production object, and passes with 3.4.4.
Validation
Tested locally on x86_64 Linux with GCC 16.2.0 and glibc 2.44:
scripts/build.sh; production binary--version.bash tests/test_mimalloc_startup.sh build/c, with the failing old-allocator comparison described above.scripts/test.sh --suites "$(build/tests/test-runner --list-suites)" BUILD_DIR=build/tests(ASan + UBSan build). The log contains 832 assertion-failure lines, many from probe fixtures reporting no graph DB, recovering UBSan diagnostics, and a LeakSanitizer report of 13,399 bytes in 11 allocations. These additional failures have not been compared against clean upstream main; they are not claimed to be baseline failures or unrelated to this change.scripts/smoke-local.sh build/c/codebase-memory-mcp, including indexing, MCP queries, install/uninstall, and daemon cleanup. The UI-only leg was skipped because the frontend was not built.cli --progress index_status --project ...form, against a freshly indexed private fixture rather than an existing user index.scripts/security-audit.shandscripts/security-vendored.sh. The broadermake -f Makefile.cbm securitytarget also passed source, binary-string, source-only UI, sandbox-install, and strace network checks, but stopped on a 10-second MCP fuzz timeout (shell injection semicolon). That exact input passed three isolated retries; the subsequent fullscripts/security-fuzz.shretry passed 32/32. The combined security target itself is not claimed as passing, and built-frontend integrity was not verified.Existing baseline failures
The following checks fail on this branch and were reproduced on a clean checkout of upstream main
bf93f0b7c3b82683b3ac3b00bb0342465878cdf8, with the same local tool versions:bash tests/test_version_metadata_contract.sh: the Scoop manifest pin is0.11.0, equal to the latest stable tag; the contract requires changing that surface's classification frompin:0.11.0toreleaseand dropping itsPIN_REASONSentry. This stops the defaultscripts/test.shbefore the C suites, hence the separate all-suite invocation above.src/mcp/mcp.c:962reports a possible null dereference ofallowed. Reproduced independently withmake -f Makefile.cbm lint-cppcheck LINT_SRCS=src/mcp/mcp.c. The branch's full lint gate also fails; formatting, NOLINT, memory-core checks, and applicable diff-scoped clang-tidy passed.The full
scripts/lint.shaudit additionally encounters GCC-only warning flags passed to Clang and pre-existing findings in unchanged files. This is not a claim that the full unpatched test/lint suite or GitHub CI was run. Baseline failures were not changed or suppressed in this focused allocator fix. The local pre-commit gate was bypassed because these seemed potentially unrelated to me (the human), and I wanted to see what PR CI says/what discussion says.AI disclosure
This contribution and description were prepared with an OpenAI coding agent in Pi on behalf of Felix Rath (
futile). Felix is the accountable human contributor and explicitly authorized the DCO sign-off on every commit. No private agent-session links are included.Checklist
git commit -s);scripts/check-dco.sh upstream/main..HEADpassed for both commits.