================================================================= ==70702==ERROR: AddressSanitizer: heap-buffer-overflow on address 0x60b00030e548 at pc 0x00000365116a bp 0x7ffd67bc8060 sp 0x7ffd67bc8058 READ of size 4 at 0x60b00030e548 thread T0 #0 0x3651169 in seq_retiming_evaluate /home/sergey/Developer/blender/blender/source/blender/sequencer/intern/strip_retiming.cc:132 #1 0x36525e8 in seq_give_frame_index /home/sergey/Developer/blender/blender/source/blender/sequencer/intern/strip_time.c:90 #2 0x3610048 in seq_cache_timeline_frame_to_frame_index /home/sergey/Developer/blender/blender/source/blender/sequencer/intern/image_cache.c:145 #3 0x3612033 in seq_cache_populate_key /home/sergey/Developer/blender/blender/source/blender/sequencer/intern/image_cache.c:524 #4 0x361428a in seq_cache_get /home/sergey/Developer/blender/blender/source/blender/sequencer/intern/image_cache.c:758 #5 0x3639b27 in seq_render_strip /home/sergey/Developer/blender/blender/source/blender/sequencer/intern/render.c:1745 #6 0x363a77b in seq_render_strip_stack /home/sergey/Developer/blender/blender/source/blender/sequencer/intern/render.c:1869 #7 0x363b1ab in SEQ_render_give_ibuf /home/sergey/Developer/blender/blender/source/blender/sequencer/intern/render.c:1970 #8 0x57ce5ce in sequencer_ibuf_get /home/sergey/Developer/blender/blender/source/blender/editors/space_sequencer/sequencer_draw.c:1546 #9 0x57d29b4 in sequencer_draw_preview /home/sergey/Developer/blender/blender/source/blender/editors/space_sequencer/sequencer_draw.c:2161 #10 0x5810860 in sequencer_preview_region_draw /home/sergey/Developer/blender/blender/source/blender/editors/space_sequencer/space_sequencer.c:828 #11 0x357e862 in ED_region_do_draw /home/sergey/Developer/blender/blender/source/blender/editors/screen/area.c:546 #12 0x1fa2fd4 in wm_draw_window_offscreen /home/sergey/Developer/blender/blender/source/blender/windowmanager/intern/wm_draw.c:959 #13 0x1fa3dbf in wm_draw_window /home/sergey/Developer/blender/blender/source/blender/windowmanager/intern/wm_draw.c:1124 #14 0x1fa4f81 in wm_draw_update /home/sergey/Developer/blender/blender/source/blender/windowmanager/intern/wm_draw.c:1384 #15 0x1f97022 in WM_main /home/sergey/Developer/blender/blender/source/blender/windowmanager/intern/wm.c:646 #16 0x676346 in main /home/sergey/Developer/blender/blender/source/creator/creator.c:585 #17 0x7f3159e46189 in __libc_start_call_main ../sysdeps/nptl/libc_start_call_main.h:58 #18 0x7f3159e46244 in __libc_start_main_impl ../csu/libc-start.c:381 #19 0x675a40 in _start (/home/sergey/Developer/blender/build/debug-asan/bin/blender+0x675a40) 0x60b00030e548 is located 0 bytes to the right of 104-byte region [0x60b00030e4e0,0x60b00030e548) allocated by thread T0 here: #0 0x7f31696b83b7 in __interceptor_calloc ../../../../src/libsanitizer/asan/asan_malloc_linux.cpp:77 #1 0x164bcb64 in MEM_lockfree_callocN /home/sergey/Developer/blender/blender/intern/guardedalloc/intern/mallocn_lockfree_impl.c:223 #2 0x365190e in SEQ_retiming_remove_handle /home/sergey/Developer/blender/blender/source/blender/sequencer/intern/strip_retiming.cc:204 #3 0x57ef4b3 in sequencer_retiming_handle_remove_exec /home/sergey/Developer/blender/blender/source/blender/editors/space_sequencer/sequencer_retiming.cc:305 #4 0x57ef843 in sequencer_retiming_handle_remove_invoke /home/sergey/Developer/blender/blender/source/blender/editors/space_sequencer/sequencer_retiming.cc:341 #5 0x1faddbf in wm_operator_invoke /home/sergey/Developer/blender/blender/source/blender/windowmanager/intern/wm_event_system.cc:1474 #6 0x1faeebc in wm_operator_call_internal /home/sergey/Developer/blender/blender/source/blender/windowmanager/intern/wm_event_system.cc:1707 #7 0x1faef82 in WM_operator_name_call_ptr /home/sergey/Developer/blender/blender/source/blender/windowmanager/intern/wm_event_system.cc:1721 #8 0x207968b in WM_gizmo_operator_invoke /home/sergey/Developer/blender/blender/source/blender/windowmanager/gizmo/intern/wm_gizmo.c:243 #9 0x203fa0f in gizmo_tweak_start_and_finish /home/sergey/Developer/blender/blender/source/blender/windowmanager/gizmo/intern/wm_gizmo_group.c:444 #10 0x20406c3 in gizmo_tweak_invoke /home/sergey/Developer/blender/blender/source/blender/windowmanager/gizmo/intern/wm_gizmo_group.c:574 #11 0x1faddbf in wm_operator_invoke /home/sergey/Developer/blender/blender/source/blender/windowmanager/intern/wm_event_system.cc:1474 #12 0x1fb394d in wm_handler_operator_call /home/sergey/Developer/blender/blender/source/blender/windowmanager/intern/wm_event_system.cc:2505 #13 0x1fb631a in wm_handlers_do_keymap_with_gizmo_handler /home/sergey/Developer/blender/blender/source/blender/windowmanager/intern/wm_event_system.cc:2955 #14 0x1fb6fef in wm_handlers_do_gizmo_handler /home/sergey/Developer/blender/blender/source/blender/windowmanager/intern/wm_event_system.cc:3095 #15 0x1fb8718 in wm_handlers_do_intern /home/sergey/Developer/blender/blender/source/blender/windowmanager/intern/wm_event_system.cc:3300 #16 0x1fb8c06 in wm_handlers_do /home/sergey/Developer/blender/blender/source/blender/windowmanager/intern/wm_event_system.cc:3361 #17 0x1fbc46b in wm_event_do_region_handlers /home/sergey/Developer/blender/blender/source/blender/windowmanager/intern/wm_event_system.cc:3780 #18 0x1fbc5f9 in wm_event_do_handlers_area_regions /home/sergey/Developer/blender/blender/source/blender/windowmanager/intern/wm_event_system.cc:3810 #19 0x1fbdb93 in wm_event_do_handlers /home/sergey/Developer/blender/blender/source/blender/windowmanager/intern/wm_event_system.cc:4010 #20 0x1f9700a in WM_main /home/sergey/Developer/blender/blender/source/blender/windowmanager/intern/wm.c:640 #21 0x676346 in main /home/sergey/Developer/blender/blender/source/creator/creator.c:585 #22 0x7f3159e46189 in __libc_start_call_main ../sysdeps/nptl/libc_start_call_main.h:58 SUMMARY: AddressSanitizer: heap-buffer-overflow /home/sergey/Developer/blender/blender/source/blender/sequencer/intern/strip_retiming.cc:132 in seq_retiming_evaluate Shadow bytes around the buggy address: 0x0c1680059c50: fd fa fa fa fa fa fa fa fa fa fd fd fd fd fd fd 0x0c1680059c60: fd fd fd fd fd fd fd fa fa fa fa fa fa fa fa fa 0x0c1680059c70: fd fd fd fd fd fd fd fd fd fd fd fd fd fd fa fa 0x0c1680059c80: fa fa fa fa fa fa fd fd fd fd fd fd fd fd fd fd 0x0c1680059c90: fd fd fd fa fa fa fa fa fa fa fa fa 00 00 00 00 =>0x0c1680059ca0: 00 00 00 00 00 00 00 00 00[fa]fa fa fa fa fa fa 0x0c1680059cb0: fa fa fd fd fd fd fd fd fd fd fd fd fd fd fd fa 0x0c1680059cc0: fa fa fa fa fa fa fa fa fd fd fd fd fd fd fd fd 0x0c1680059cd0: fd fd fd fd fd fa fa fa fa fa fa fa fa fa fd fd 0x0c1680059ce0: fd fd fd fd fd fd fd fd fd fd fd fa fa fa fa fa 0x0c1680059cf0: fa fa fa fa fd fd fd fd fd fd fd fd fd fd fd fd Shadow byte legend (one shadow byte represents 8 application bytes): Addressable: 00 Partially addressable: 01 02 03 04 05 06 07 Heap left redzone: fa Freed heap region: fd Stack left redzone: f1 Stack mid redzone: f2 Stack right redzone: f3 Stack after return: f5 Stack use after scope: f8 Global redzone: f9 Global init order: f6 Poisoned by user: f7 Container overflow: fc Array cookie: ac Intra object redzone: bb ASan internal: fe Left alloca redzone: ca Right alloca redzone: cb ==70702==ABORTING Aborted (core dumped)