You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

malloc报错:检测到未对齐tcache块,内存损坏问题排查求助

内存损坏问题排查求助:malloc(): unaligned tcache chunk detected

程序出现内存损坏,调用malloc时触发malloc(): unaligned tcache chunk detected错误。最初错误出现在vector的push_back扩容阶段,给vector提前reserve足够空间后,错误转移到了其他代码行。

相关代码片段

void BVHGenerator::generate(Mesh *mesh) {
    triangles.clear();
    triangle_indices.clear();
    nodes.clear();
    std::vector<t_shader_triangle> shader_triangles = mesh->getShaderTriangles();
    for (int i = 0; i < mesh->triangleCount(); ++i) {
        triangles.push_back(shader_triangles[i]);
    }

    t_bvh root_node = {};

    root_node.triangle_count = triangles.size();
    root_node.triangle_offset = triangle_indices.size();

    for (int triangle_index = 0; triangle_index < triangles.size(); ++triangle_index) {
        triangle_indices.push_back(triangle_index);
    }

    makeBounds(&root_node, getTriangles(&root_node));
    nodes.push_back(root_node);

    std::vector<int> current_nodes = {0};

    for (int i = 0; i < depth; ++i) {
        std::vector<int> new_nodes;
        for (int node_index : current_nodes) {
            t_bvh *node = &nodes[node_index];
            if (node->triangle_count < 2) {
                continue;
            }
            auto [split_side, split_middle] = chooseSplit(node_index);
            std::vector<int> left_triangles;
            std::vector<int> right_triangles;
            left_triangles.reserve(node->triangle_count);
            right_triangles.reserve(node->triangle_count);
            for (int j = 0; j < node->triangle_count; ++j) {
                int triangle_index = triangle_indices[node->triangle_offset + j];
                auto [include_left, include_right] = distributeTriangle(triangles[triangle_index], split_side, split_middle);
                if (include_left) {
                    left_triangles.push_back(triangle_index);
                }
                if (include_right) {
                    right_triangles.push_back(triangle_index);
                }
            }

            t_bvh left_node = {};
            t_bvh right_node = {};

            left_node.triangle_offset = triangle_indices.size();
            for (int triangle_index : left_triangles) {
                triangle_indices.push_back(triangle_index);
            }
            left_node.triangle_count = left_triangles.size();

            right_node.triangle_offset = triangle_indices.size();
            for (int triangle_index : right_triangles) {
                triangle_indices.push_back(triangle_index);
            }
            right_node.triangle_count = right_triangles.size();

            makeBounds(&left_node, getTriangles(&left_node));
            makeBounds(&right_node, getTriangles(&right_node));

            node->left_index = nodes.size();
            new_nodes.push_back(nodes.size());
            nodes.push_back(left_node);
            node->right_index = nodes.size();
            new_nodes.push_back(nodes.size());
            nodes.push_back(right_node);

            node->has_children = true;
        }

        current_nodes = new_nodes; // gl_rays/src/mesh/bvh.cpp:87
    }
}

崩溃情况

当前程序在current_nodes = new_nodes;行崩溃;若移除

left_triangles.reserve(node->triangle_count);
right_triangles.reserve(node->triangle_count);

则崩溃发生在right_triangles.push_back(triangle_index);行(扩容right_triangles时)。

GDB回溯信息

malloc(): unaligned tcache chunk detected

Thread 1 "gl_rays" received signal SIGABRT, Aborted.
__pthread_kill_implementation (threadid=<optimized out>, signo=signo@entry=6, no_tid=no_tid@entry=0) at pthread_kill.c:44
44            return INTERNAL_SYSCALL_ERROR_P (ret) ? INTERNAL_SYSCALL_ERRNO (ret) : 0;
(gdb) bt
#0  __pthread_kill_implementation (threadid=<optimized out>, signo=signo@entry=6, no_tid=no_tid@entry=0) at pthread_kill.c:44
#1  0x00007ffff78a86d3 in __pthread_kill_internal (threadid=<optimized out>, signo=6) at pthread_kill.c:78
#2  0x00007ffff784fc4e in __GI_raise (sig=sig@entry=6) at ../sysdeps/posix/raise.c:26
#3  0x00007ffff7837902 in __GI_abort () at abort.c:79
#4  0x00007ffff7838767 in __libc_message_impl (fmt=fmt@entry=0x7ffff79c2330 "%s
") at ../sysdeps/posix/libc_fatal.c:132
#5  0x00007ffff78b27e5 in malloc_printerr (str=str@entry=0x7ffff79c59b8 "malloc(): unaligned tcache chunk detected") at malloc.c:5772
#6  0x00007ffff78b70e4 in tcache_get_n (tc_idx=<optimized out>, ep=<optimized out>) at malloc.c:3183
#7  tcache_get (tc_idx=<optimized out>) at malloc.c:3199
#8  __GI___libc_malloc (bytes=64) at malloc.c:3320
#9  0x00007ffff7ab83ec in operator new (sz=64) at ../../../../libstdc++-v3/libsupc++/new_op.cc:50
#10 0x000000000040e2c8 in std::__new_allocator<int>::allocate (this=0x7fffffffcfc0, __n=16) at /usr/include/c++/14/bits/new_allocator.h:151
#11 0x000000000040ce83 in std::allocator_traits<std::allocator<int> >::allocate (__a=..., __n=16) at /usr/include/c++/14/bits/alloc_traits.h:478
#12 std::_Vector_base<int, std::allocator<int> >::_M_allocate (this=0x7fffffffcfc0, __n=16) at /usr/include/c++/14/bits/stl_vector.h:380
#13 0x000000000040d032 in std::vector<int, std::allocator<int> >::_M_allocate_and_copy<__gnu_cxx::__normal_iterator<int const*, std::vector<int, std::allocator<int> > > > (this=0x7fffffffcfc0, __n=16, __first=15, __last=18831264)
    at /usr/include/c++/14/bits/stl_vector.h:1621
#14 0x000000000040bde8 in std::vector<int, std::allocator<int> >::operator= (this=0x7fffffffcfc0, __x=std::vector of length 16, capacity 16 = {...}) at /usr/include/c++/14/bits/vector.tcc:238
#15 0x000000000040a8fb in BVHGenerator::generate (this=0x9fb578, mesh=0x7fffffffd140) at /home/aino/Documents/dev/gl_rays/src/mesh/bvh.cpp:87
#16 0x0000000000408891 in Renderer::init (this=0x9fb4f0) at /home/aino/Documents/dev/gl_rays/src/application/renderer.cpp:73
#17 0x0000000000405ed5 in App::init (this=0x7fffffffd3e0) at /home/aino/Documents/dev/gl_rays/src/application/app.cpp:23
#18 0x0000000000409f49 in main (argc=1, argv=0x7fffffffd5b8) at /home/aino/Documents/dev/gl_rays/src/main.cpp:7

排查方向建议

  • 内存越界写入:该错误几乎都是之前的代码写越界破坏了malloc的tcache元数据,重点检查:
    • t_bvh结构体定义:是否存在内存对齐问题,或包含非对齐成员?是否有手动内存操作(如memcpy、指针偏移)导致的越界?
    • makeBounds和getTriangles函数:这两个函数直接操作节点和三角形数据,极易出现越界访问。比如getTriangles是否返回了超出triangle_indices范围的指针?makeBounds是否写入了超出节点结构体的内存?
    • 索引计算:triangle_indices[node->triangle_offset + j]是否存在node->triangle_offset + j超过triangle_indices.size()的情况?chooseSplit或distributeTriangle返回的参数是否异常,导致后续循环越界?
  • vector指针失效问题:nodes是动态扩容的vector,t_bvh *node = &nodes[node_index];获取的指针,在nodes.push_back(left_node)或nodes.push_back(right_node)时,可能因vector扩容重新分配内存而失效,后续写入node->left_index等操作会破坏堆结构,这是高危点。
  • 使用内存检测工具:
    • 用valgrind定位:执行valgrind --leak-check=full --track-origins=yes ./gl_rays,它能精准找出内存越界的具体位置。
    • 开启地址 sanitizer:编译时添加-fsanitize=address选项,运行程序后会直接给出内存错误的详细信息。

内容的提问来源于stack exchange,提问作者AinoSpring

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.16 22:15:55