================================================================= ==99183==ERROR: AddressSanitizer: heap-buffer-overflow on address 0x613000522e4c at pc 0x56225d886cce bp 0x7ffeafd99e30 sp 0x7ffeafd99e20 READ of size 4 at 0x613000522e4c thread T0 #0 0x56225d886ccd in BKE_curve_bevelList_make /src/blender/source/blender/blenkernel/intern/curve.c:3143 #1 0x56225d944a18 in do_makeDispListCurveTypes /src/blender/source/blender/blenkernel/intern/displist.c:1590 #2 0x56225d94962a in BKE_displist_make_curveTypes /src/blender/source/blender/blenkernel/intern/displist.c:1830 #3 0x56225ddb25ca in BKE_object_handle_data_update /src/blender/source/blender/blenkernel/intern/object_update.c:217 #4 0x56225ddb550d in BKE_object_eval_uber_data /src/blender/source/blender/blenkernel/intern/object_update.c:384 #5 0x5622628faf08 in void std::__invoke_impl(std::__invoke_other, void (*&)(Depsgraph*, Scene*, Object*), Depsgraph*&&, Scene*&, Object*&) /usr/include/c++/10.1.0/bits/invoke.h:60 #6 0x5622628f66be in std::__invoke_result::type std::__invoke(void (*&)(Depsgraph*, Scene*, Object*), Depsgraph*&&, Scene*&, Object*&) /usr/include/c++/10.1.0/bits/invoke.h:95 #7 0x5622628eeed8 in void std::_Bind, Scene*, Object*))(Depsgraph*, Scene*, Object*)>::__call(std::tuple&&, std::_Index_tuple<0ul, 1ul, 2ul>) /usr/include/c++/10.1.0/functional:416 #8 0x5622628e7795 in void std::_Bind, Scene*, Object*))(Depsgraph*, Scene*, Object*)>::operator()(Depsgraph*&&) /usr/include/c++/10.1.0/functional:499 #9 0x5622628de923 in void std::__invoke_impl, Scene*, Object*))(Depsgraph*, Scene*, Object*)>&, Depsgraph*>(std::__invoke_other, std::_Bind, Scene*, Object*))(Depsgraph*, Scene*, Object*)>&, Depsgraph*&&) /usr/include/c++/10.1.0/bits/invoke.h:60 #10 0x5622628d3a2b in std::enable_if, Scene*, Object*))(Depsgraph*, Scene*, Object*)>&, Depsgraph*>, void>::type std::__invoke_r, Scene*, Object*))(Depsgraph*, Scene*, Object*)>&, Depsgraph*>(std::_Bind, Scene*, Object*))(Depsgraph*, Scene*, Object*)>&, Depsgraph*&&) /usr/include/c++/10.1.0/bits/invoke.h:110 #11 0x5622628cb419 in std::_Function_handler, Scene*, Object*))(Depsgraph*, Scene*, Object*)> >::_M_invoke(std::_Any_data const&, Depsgraph*&&) /usr/include/c++/10.1.0/bits/std_function.h:291 #12 0x5622629a7d2e in std::function::operator()(Depsgraph*) const /usr/include/c++/10.1.0/bits/std_function.h:622 #13 0x5622629a2eda in evaluate_node /src/blender/source/blender/depsgraph/intern/eval/deg_eval.cc:114 #14 0x5622629a2f24 in deg_task_run_func /src/blender/source/blender/depsgraph/intern/eval/deg_eval.cc:125 #15 0x5622636d7a7f in Task::operator()() const /src/blender/source/blender/blenlib/intern/task_pool.cc:120 #16 0x5622636d57bf in tbb_task_pool_run /src/blender/source/blender/blenlib/intern/task_pool.cc:226 #17 0x5622636d6b11 in BLI_task_pool_push /src/blender/source/blender/blenlib/intern/task_pool.cc:484 #18 0x5622629a2912 in schedule_node_to_pool /src/blender/source/blender/depsgraph/intern/eval/deg_eval.cc:74 #19 0x5622629a7328 in schedule_node /src/blender/source/blender/depsgraph/intern/eval/deg_eval.cc:274 #20 0x5622629a6202 in schedule_children /src/blender/source/blender/depsgraph/intern/eval/deg_eval.cc:302 #21 0x5622629a7310 in schedule_node /src/blender/source/blender/depsgraph/intern/eval/deg_eval.cc:270 #22 0x5622629a6202 in schedule_children /src/blender/source/blender/depsgraph/intern/eval/deg_eval.cc:302 #23 0x5622629a2f42 in deg_task_run_func /src/blender/source/blender/depsgraph/intern/eval/deg_eval.cc:128 #24 0x5622636d7a7f in Task::operator()() const /src/blender/source/blender/blenlib/intern/task_pool.cc:120 #25 0x5622636d57bf in tbb_task_pool_run /src/blender/source/blender/blenlib/intern/task_pool.cc:226 #26 0x5622636d5a3d in tbb_task_pool_work_and_wait /src/blender/source/blender/blenlib/intern/task_pool.cc:239 #27 0x5622636d6c81 in BLI_task_pool_work_and_wait /src/blender/source/blender/blenlib/intern/task_pool.cc:499 #28 0x5622629a5926 in blender::deg::deg_evaluate_on_refresh(blender::deg::Depsgraph*) /src/blender/source/blender/depsgraph/intern/eval/deg_eval.cc:399 #29 0x5622628342e2 in DEG_evaluate_on_refresh /src/blender/source/blender/depsgraph/intern/depsgraph_eval.cc:63 #30 0x56225df8fe9b in scene_graph_update_tagged /src/blender/source/blender/blenkernel/intern/scene.c:1501 #31 0x56225df8ffb3 in BKE_scene_graph_update_tagged /src/blender/source/blender/blenkernel/intern/scene.c:1540 #32 0x56225d149039 in wm_event_do_depsgraph /src/blender/source/blender/windowmanager/intern/wm_event_system.c:359 #33 0x56225d18749f in wm_file_read_post /src/blender/source/blender/windowmanager/intern/wm_files.c:630 #34 0x56225d18828d in WM_file_read /src/blender/source/blender/windowmanager/intern/wm_files.c:754 #35 0x56225d1937ff in wm_file_read_opwrap /src/blender/source/blender/windowmanager/intern/wm_files.c:2177 #36 0x56225d194c17 in wm_open_mainfile__open /src/blender/source/blender/windowmanager/intern/wm_files.c:2319 #37 0x56225d194ee6 in wm_open_mainfile_exec /src/blender/source/blender/windowmanager/intern/wm_files.c:2355 #38 0x56225d15ed2d in wm_handler_fileselect_do /src/blender/source/blender/windowmanager/intern/wm_event_system.c:2287 #39 0x56225d1607e7 in wm_handler_fileselect_call /src/blender/source/blender/windowmanager/intern/wm_event_system.c:2385 #40 0x56225d165d1b in wm_handlers_do_intern /src/blender/source/blender/windowmanager/intern/wm_event_system.c:2802 #41 0x56225d1660f0 in wm_handlers_do /src/blender/source/blender/windowmanager/intern/wm_event_system.c:2854 #42 0x56225d16c363 in wm_event_do_handlers /src/blender/source/blender/windowmanager/intern/wm_event_system.c:3283 #43 0x56225d13555a in WM_main /src/blender/source/blender/windowmanager/intern/wm.c:475 #44 0x56225d12467c in main /src/blender/source/creator/creator.c:533 #45 0x7f035fc77001 in __libc_start_main (/usr/lib/libc.so.6+0x27001) #46 0x56225d12399d in _start (/src/cmake_debug/bin/blender+0xa3f899d) 0x613000522e4c is located 4 bytes to the right of 328-byte region [0x613000522d00,0x613000522e48) allocated by thread T0 here: #0 0x7f0360d3a639 in __interceptor_calloc /build/gcc/src/gcc/libsanitizer/asan/asan_malloc_linux.cpp:154 #1 0x5622636e8bf0 in MEM_lockfree_callocN /src/blender/intern/guardedalloc/intern/mallocn_lockfree_impl.c:236 #2 0x5622636e8ed6 in MEM_lockfree_calloc_arrayN /src/blender/intern/guardedalloc/intern/mallocn_lockfree_impl.c:268 #3 0x56225d885466 in BKE_curve_bevelList_make /src/blender/source/blender/blenkernel/intern/curve.c:3065 #4 0x56225d944a18 in do_makeDispListCurveTypes /src/blender/source/blender/blenkernel/intern/displist.c:1590 #5 0x56225d94962a in BKE_displist_make_curveTypes /src/blender/source/blender/blenkernel/intern/displist.c:1830 #6 0x56225ddb25ca in BKE_object_handle_data_update /src/blender/source/blender/blenkernel/intern/object_update.c:217 #7 0x56225ddb550d in BKE_object_eval_uber_data /src/blender/source/blender/blenkernel/intern/object_update.c:384 #8 0x5622628faf08 in void std::__invoke_impl(std::__invoke_other, void (*&)(Depsgraph*, Scene*, Object*), Depsgraph*&&, Scene*&, Object*&) /usr/include/c++/10.1.0/bits/invoke.h:60 #9 0x5622628f66be in std::__invoke_result::type std::__invoke(void (*&)(Depsgraph*, Scene*, Object*), Depsgraph*&&, Scene*&, Object*&) /usr/include/c++/10.1.0/bits/invoke.h:95 #10 0x5622628eeed8 in void std::_Bind, Scene*, Object*))(Depsgraph*, Scene*, Object*)>::__call(std::tuple&&, std::_Index_tuple<0ul, 1ul, 2ul>) /usr/include/c++/10.1.0/functional:416 #11 0x5622628e7795 in void std::_Bind, Scene*, Object*))(Depsgraph*, Scene*, Object*)>::operator()(Depsgraph*&&) /usr/include/c++/10.1.0/functional:499 #12 0x5622628de923 in void std::__invoke_impl, Scene*, Object*))(Depsgraph*, Scene*, Object*)>&, Depsgraph*>(std::__invoke_other, std::_Bind, Scene*, Object*))(Depsgraph*, Scene*, Object*)>&, Depsgraph*&&) /usr/include/c++/10.1.0/bits/invoke.h:60 #13 0x5622628d3a2b in std::enable_if, Scene*, Object*))(Depsgraph*, Scene*, Object*)>&, Depsgraph*>, void>::type std::__invoke_r, Scene*, Object*))(Depsgraph*, Scene*, Object*)>&, Depsgraph*>(std::_Bind, Scene*, Object*))(Depsgraph*, Scene*, Object*)>&, Depsgraph*&&) /usr/include/c++/10.1.0/bits/invoke.h:110 #14 0x5622628cb419 in std::_Function_handler, Scene*, Object*))(Depsgraph*, Scene*, Object*)> >::_M_invoke(std::_Any_data const&, Depsgraph*&&) /usr/include/c++/10.1.0/bits/std_function.h:291 #15 0x5622629a7d2e in std::function::operator()(Depsgraph*) const /usr/include/c++/10.1.0/bits/std_function.h:622 #16 0x5622629a2eda in evaluate_node /src/blender/source/blender/depsgraph/intern/eval/deg_eval.cc:114 #17 0x5622629a2f24 in deg_task_run_func /src/blender/source/blender/depsgraph/intern/eval/deg_eval.cc:125 #18 0x5622636d7a7f in Task::operator()() const /src/blender/source/blender/blenlib/intern/task_pool.cc:120 #19 0x5622636d57bf in tbb_task_pool_run /src/blender/source/blender/blenlib/intern/task_pool.cc:226 #20 0x5622636d6b11 in BLI_task_pool_push /src/blender/source/blender/blenlib/intern/task_pool.cc:484 #21 0x5622629a2912 in schedule_node_to_pool /src/blender/source/blender/depsgraph/intern/eval/deg_eval.cc:74 #22 0x5622629a7328 in schedule_node /src/blender/source/blender/depsgraph/intern/eval/deg_eval.cc:274 #23 0x5622629a6202 in schedule_children /src/blender/source/blender/depsgraph/intern/eval/deg_eval.cc:302 #24 0x5622629a7310 in schedule_node /src/blender/source/blender/depsgraph/intern/eval/deg_eval.cc:270 #25 0x5622629a6202 in schedule_children /src/blender/source/blender/depsgraph/intern/eval/deg_eval.cc:302 #26 0x5622629a2f42 in deg_task_run_func /src/blender/source/blender/depsgraph/intern/eval/deg_eval.cc:128 #27 0x5622636d7a7f in Task::operator()() const /src/blender/source/blender/blenlib/intern/task_pool.cc:120 #28 0x5622636d57bf in tbb_task_pool_run /src/blender/source/blender/blenlib/intern/task_pool.cc:226 #29 0x5622636d5a3d in tbb_task_pool_work_and_wait /src/blender/source/blender/blenlib/intern/task_pool.cc:239 SUMMARY: AddressSanitizer: heap-buffer-overflow /src/blender/source/blender/blenkernel/intern/curve.c:3143 in BKE_curve_bevelList_make Shadow bytes around the buggy address: 0x0c268009c570: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0x0c268009c580: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0x0c268009c590: 00 fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa 0x0c268009c5a0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0x0c268009c5b0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 =>0x0c268009c5c0: 00 00 00 00 00 00 00 00 00[fa]fa fa fa fa fa fa 0x0c268009c5d0: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa 0x0c268009c5e0: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa 0x0c268009c5f0: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa 0x0c268009c600: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa 0x0c268009c610: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa Shadow byte legend (one shadow byte represents 8 application bytes): Addressable: 00 Partially addressable: 01 02 03 04 05 06 07 Heap left redzone: fa Freed heap region: fd Stack left redzone: f1 Stack mid redzone: f2 Stack right redzone: f3 Stack after return: f5 Stack use after scope: f8 Global redzone: f9 Global init order: f6 Poisoned by user: f7 Container overflow: fc Array cookie: ac Intra object redzone: bb ASan internal: fe Left alloca redzone: ca Right alloca redzone: cb Shadow gap: cc ==99183==ABORTING fish: '/src/blender/blender.bin' terminated by signal SIGABRT (Abort)