Skip to content

Bisect the Linux arm64 libdispatch crash (not to be merged) - #10

Closed
sinoru wants to merge 3 commits into
developfrom
ci/bisect-arm64-dispatch-crash
Closed

sinoru wants to merge 3 commits into
developfrom
ci/bisect-arm64-dispatch-crash

Conversation

@sinoru

@sinoru sinoru commented Sep 20, 2026

Copy link
Copy Markdown
Owner

Not to be merged. This exists to run .github/workflows/bisect.yml on the runner the crash happens on.

What is being looked for

On the Ubuntu 24.04 · Swift 6.x (arm64) rows, a libdispatch worker dies during the asynchronous locks' measurements:

*** Program crashed: Bad pointer dereference at 0xffffffff89abcdff ***
  0  _dispatch_worker_thread + 540 in libdispatch.so

0xffffffff89abcdef is DISPATCH_OBJECT_LISTLESS: the root queue's head is an item whose do_next was marked as being on no list. Seen since the push that ended at 6eb547f, about one run in two, under both Swift minors, in AsyncMutexPerformanceTests and AsyncRWLockPerformanceTests and never in AsyncSemaphorePerformanceTests; never on x86_64, macOS, or a sanitized row. It does not reproduce locally.

How

Six candidates × two Swift minors, one job each, all on ubuntu-24.04-arm. Each builds the release test binary with the flags swift.yml uses and runs the two suites repeatedly for 35 minutes, or until four runs have failed. The count goes to the run's summary.

Commit
0 b407083 last commit before the push; says whether the crash arrived with it at all
1 627215a AsyncRWLock measurements added
2 861d0db @exclusivity(unchecked), unowned(unsafe)
3 3738fa0 noncopyable wait state
4 6eb547f holder read in place
5 2249809 develop

Temporary, and not to be merged. Every candidate commit is a job under both
Swift minors, and each job runs the asynchronous locks' measurements over and
over for as long as its budget lasts, counting the runs that fail.
Every candidate crashed as often as develop for the time it ran, the one
before the push included, and four of the crashes were inside measurements
that run an actor and none of the package's locks. Give each kind of
measurement a process to itself: the actors, the locks, and the semaphore
suite that has not crashed yet.
The measurements that run an actor and none of the package's locks crashed
fourteen times in 1249 runs, in a process of their own. Reproducer is what
they do as a program that depends on nothing, run the same way, and on x86_64
beside arm64 to say whether the architecture is part of it.
@sinoru

sinoru commented Sep 21, 2026

Copy link
Copy Markdown
Owner Author

Done with: no commit brought the crash, none of the package's code is needed for it, and it is arm64's alone. The three rounds, their numbers and the reproducer are written up in #11.

@sinoru sinoru closed this Sep 21, 2026
@sinoru
sinoru deleted the ci/bisect-arm64-dispatch-crash branch September 21, 2026 15:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant