Skip to content

Crash with an error: munmap_chunk(): invalid pointer #4225

Description

@catcombo

What did you do?

I was faced a problem when using arcade library. It uses Pillow under the hood to work with images. When I tried to draw game score text, I got random crash. I localized the problem and found out that crash is related to the way the Pillow works with font and frees up a resources.

What actually happened?

Crash with an error:

munmap_chunk(): invalid pointer
Process finished with exit code 134 (interrupted by signal 6: SIGABRT)

What are your OS, Python and Pillow versions?

  • OS: Fedora 30
  • Python: 3.7.5
  • Pillow: 6.2.1

Code example

Crashing code example (munmap_chunk(): invalid pointer):

import PIL.Image
import PIL.ImageDraw
import PIL.ImageFont


while True:
    image = PIL.Image.new("RGBA", (10, 10))
    draw = PIL.ImageDraw.Draw(image)
    font = PIL.ImageFont.truetype("Arial.ttf", 12)
    print(draw.multiline_textsize("Sample", font=font))

Works without any problem:

import PIL.Image
import PIL.ImageDraw
import PIL.ImageFont


font = PIL.ImageFont.truetype("Arial.ttf", 12)

while True:
    image = PIL.Image.new("RGBA", (10, 10))
    draw = PIL.ImageDraw.Draw(image)
    
    print(draw.multiline_textsize("Sample", font=font))

Activity

  1. radarhere commented on Nov 21, 2019

    @radarhere
    Member

    How many iterations of the loop does it take to reproduce the problem?

  2. catcombo commented on Nov 22, 2019

    @catcombo
    Author

    @radarhere 28 iterations. Interesting fact: when I changed the code to:

    import PIL.Image
    import PIL.ImageDraw
    import PIL.ImageFont
    
    i = 0
    while True:
        i += 1
        print(i)
        image = PIL.Image.new("RGBA", (10, 10))
        draw = PIL.ImageDraw.Draw(image)
        font = PIL.ImageFont.truetype("Arial.ttf", 12)
        print(draw.multiline_textsize("Sample", font=font))

    it start to crash on 218 iteration.

  3. Poikilos commented on Jan 29, 2020

    @Poikilos

    I can confirm the issue (which is apparently the same) on:

    • OS: Fedora 31
    • Python: 3.7.6
    • Pillow version: 7.0.0

    I can reproduce the issue above using the code above.

    Also, the results below only serve as a confirmation but don't offer new information other than that different types of crashes ("heisenbugs") causing core dumps occur intermittently in practical use.

    details It is hard to reproduce in my case. Considering the original issue report above, the reason mine is hard to reproduce may be that in my library I only load the font object once then cache it (I cache the return of ImageFont.truetype):

    I could get any of the following, but always when using the font to draw (on _d.text( where _d is an ImageDraw.Draw lock, which is after self.blab("* drawing text ' which shows when using the --verbose=True option):

    1. Segmentation fault (core dumped)

    or 2.

    corrupted size vs. prev_size
    Aborted (core dumped)
    

    or 3.

    munmap_chunk(): invalid pointer
    lcd-fb.service: Main process exited, code=dumped, status=6/ABRT
    lcd-fb.service: Failed with result 'core-dump'.
    
  4. cwt commented on Mar 30, 2020

    @cwt

    I have this problem too, but it only happened if I install Pillow from wheel file or just run pip install Pillow, which will use wheel file by default.

    If I install with this command pip install --compile --install-option=-O1 Pillow, it will build from source and the problem is gone. I test it many times still working perfectly.

    My environment: Fedora 31, Python 3.6 (in venv), Pillow 7.0.0

  5. hugovk commented on Mar 30, 2020

    @hugovk
    Member

    I note Fedora is a common factor in these three reports.

  6. cwt commented on Mar 31, 2020

    @cwt

    I note Fedora is a common factor in these three reports.

    It also happened on CentOS 8 too, the problem also gone if I install from source instead of wheel file.

  7. stephenfin commented on Apr 3, 2020

    @stephenfin

    Another Fedora 31 user here with the same issue. CentOS 8 is based off Fedora 28 (like RHEL 8) so I suspect this might affect older Fedora versions. That or something's been backported. As with @cwt, installing the non-binary package (pip install --no-binary=Pillow Pillow==6.2.0 --force) resolves this issue.

    Edit: For anyone else stumbling upon this, I needed to install the following packages to build things correctly:

    sudo dnf install libjpeg-devel zlib-devel freetype-devel
    
  8. simenheg commented on Apr 12, 2020

    @simenheg

    I'm experiencing the same problem on Debian. The original code example crashes on the third iteration here (though with another font: Vera.ttf).

    • OS: Debian bullseye (testing)
    • Python: 3.7.7
    • Pillow: 7.1.1
  9. Borroot commented on Oct 14, 2020

    @Borroot

    I have the same problem on Arch Linux using a Verdana.ttf font.

    • OS: Arch Linux 5.8.14-arch1-1
    • Python: 3.8.6
    • Pillow: 7.2.0

    Solved with compiling myself pip install --compile --install-option=-O1 Pillow.

  10. jonaswinkler commented on Nov 2, 2020

    @jonaswinkler

    Still an issue in 8.0.1. on Python 3.8.6. OS Archlinux, x86_64.

    from PIL import Image, ImageDraw, ImageFont
    
    for try_n in range(100):
        print(try_n+1)
        text = "TEXT"
        img = Image.new("RGBA", (100, 100))
        draw = ImageDraw.Draw(img)
        font = ImageFont.truetype("/usr/share/fonts/liberation/LiberationSerif-Regular.ttf", 15)
        draw.text((5,5), text, font=font)

    Fails consistently on the 3rd try. Font Size or actual text don't matter. If the font is removed, it works. Issue persists with different fonts, although it fails on different tries for each font (but is still consistent for every font I tried, i.e., NimbusSans-Regular fails on second attempt).

    Noteworthy: Works flawlessly on Raspberry Pi 3!

  11. DearRude commented on Nov 16, 2020

    @DearRude

    I also got this issue

    • Pillow 8.0.1.
    • Python 3.8.6.
    • OS Archlinux, x86_64.

    It happens randomly but mostly on 3rd or 4th iteration.

  12. tefimov commented on Nov 21, 2020

    @tefimov

    Also confirm the issue.

    • Pillow 8.0.1
    • Python 3.7.9
    • OS Archlinux, x86_64
  13. wiredfool commented on Nov 21, 2020

    @wiredfool
    Member

    Recent reporters, are you doing this with the shipped wheels or did you compile yourself?

  14. tefimov commented on Nov 21, 2020

    @tefimov

    Shipped. Works fine with pip install --compile --install-option=-O1 Pillow

  15. 4 remaining items

  16. nulano commented on Nov 24, 2020

    @nulano
    Contributor

    If this is only happening with Raqm

    I meant "If a workaround is to use layout_engine=ImageFont.LAYOUT_BASIC".

    It's possible that dynamically linking fribidi would work, but I haven't looked at how complicated that interface is.

    I just had a brief look and I think it might even be simpler than the Raqm interface. I don't see any structs being passed, only typedef-ed ints. There is also one large enum, but the single required value can be hardcoded. There is a single FriBiDi related #ifdef USE_FRIBIDI_EX_API, but it looks easy to detect at load time.

    I can give this a try at some point, but I don't expect to have the time in the next few weeks. See #5062.

  17. pymike00 commented on Dec 30, 2020

    @pymike00

    I can also confirm the issue.

    • Pillow: 8.0.1
    • Python: 3.8.6
    • OS: Manjaro Linux, 64 bit
  18. utamir commented on Jan 3, 2021

    @utamir

    Confirming

    • Pillow 8.1.0
    • Python: 3.7.3
    • OS: Debian 64
  19. wiredfool commented on Jan 3, 2021

    @wiredfool
    Member

    Can you try the wheels from the end of pr #5062 ?

  20. alenpaulvarghese commented on Mar 8, 2021

    @alenpaulvarghese

    I can also confirm the issue.

    • Pillow: 8.0.1
    • Python: 3.9.2
    • OS: Manjaro Linux, 64 bit

    fixed by : pip install --compile --install-option=-O1 Pillow

  21. makew0rld commented on Mar 16, 2021

    @makew0rld

    If this is only happening with Raqm

    I meant "If a workaround is to use layout_engine=ImageFont.LAYOUT_BASIC".

    @nulano I can confirm this fixes the issue for me.

  22. radarhere commented on Apr 1, 2021

    @radarhere
    Member

    A proposed fix has been merged, so this should be retested when Pillow 8.2.0 is released.

  23. radarhere commented on Apr 2, 2021

    @radarhere
    Member

    Pillow 8.2.0 has now been released.

  24. radarhere commented on Apr 6, 2021

    @radarhere
    Member

    @catcombo are you in a position to check this?

  25. catcombo commented on Apr 6, 2021

    @catcombo
    Author

    @radarhere I run the test code and it looks the bug is fixed. Thank you!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions