Bug 12479 - lref overflow in JNIEnv.NewArray<T>(T[]).
Summary: lref overflow in JNIEnv.NewArray<T>(T[]).
Status: VERIFIED FIXED
Alias: None
Product: Android
Classification: Xamarin
Component: Mono runtime / AOT Compiler ()
Version: 4.8.x
Hardware: PC Mac OS
: --- blocker
Target Milestone: ---
Assignee: Jonathan Pryor
URL:
Depends on:
Blocks:
 
Reported: 2013-05-30 14:02 UTC by Jonathan Pryor
Modified: 2013-06-12 06:28 UTC (History)
3 users (show)

Tags:
Is this bug a regression?: ---
Last known good build:


Attachments
Bug.Bxc12479.zip (10.49 KB, application/zip)
2013-05-30 14:06 UTC, Jonathan Pryor
Details


Notice (2018-05-24): bugzilla.xamarin.com is now in read-only mode.

Please join us on Visual Studio Developer Community and in the Xamarin and Mono organizations on GitHub to continue tracking issues. Bugzilla will remain available for reference in read-only mode. We will continue to work on open Bugzilla bugs, copy them to the new locations as needed for follow-up, and add the new items under Related Links.

Our sincere thanks to everyone who has contributed on this bug tracker over the years. Thanks also for your understanding as we make these adjustments and improvements for the future.


Please create a new report on Developer Community or GitHub with your current version information, steps to reproduce, and relevant error messages or log files if you are hitting an issue that looks similar to this resolved bug and you do not yet see a matching new report.

Related Links:
Status:
VERIFIED FIXED

Description Jonathan Pryor 2013-05-30 14:02:11 UTC
(This impacts any multi-dimensional array marshaling.)

JNIEnv.NewArray<T>(T[]) and JNIEnv.NewArray(Array) can suffer from a JNI local reference overflow because "nested" arrays aren't properly released.

	button.Click += delegate {
		button.Text = string.Format ("{0} clicks!", count++);
		int[][] array = new int[][]{
			new int[]{1,2,3,4},
			new int[]{5,6,7,8},
		};

		for (int i = 0; i < 600; ++i) {
			IntPtr l = JNIEnv.NewArray(array);
			JNIEnv.DeleteLocalRef (l);
		}
	};

The result: Dalvik aborts our ass:

> E/dalvikvm( 1742): JNI ERROR (app bug): local reference table overflow (max=512)
> W/dalvikvm( 1742): JNI local reference table (0x797e8558) dump:
> W/dalvikvm( 1742):   Last 10 entries (of 512):
> W/dalvikvm( 1742):       511: 0x423d1908 int[] (4 elements)
> W/dalvikvm( 1742):       510: 0x423d18c0 int[] (4 elements)
> W/dalvikvm( 1742):       509: 0x423d1898 int[] (4 elements)
> W/dalvikvm( 1742):       508: 0x423d1850 int[] (4 elements)
> W/dalvikvm( 1742):       507: 0x423d1828 int[] (4 elements)
> W/dalvikvm( 1742):       506: 0x423d17e0 int[] (4 elements)
> W/dalvikvm( 1742):       505: 0x423d17b8 int[] (4 elements)
> W/dalvikvm( 1742):       504: 0x423d1770 int[] (4 elements)
> W/dalvikvm( 1742):       503: 0x423d1748 int[] (4 elements)
> W/dalvikvm( 1742):       502: 0x423d1700 int[] (4 elements)
> W/dalvikvm( 1742):   Summary:
> W/dalvikvm( 1742):         3 of java.lang.Class (3 unique instances)
> W/dalvikvm( 1742):         2 of java.lang.String (2 unique instances)
> W/dalvikvm( 1742):       503 of int[] (4 elements) (503 unique instances)
> W/dalvikvm( 1742):         1 of java.lang.String[] (2 elements)
> W/dalvikvm( 1742):         1 of int[][] (2 elements)
> W/dalvikvm( 1742):         1 of android.widget.Button
> W/dalvikvm( 1742):         1 of mono.android.view.View_OnClickListenerImplementor
> E/dalvikvm( 1742): Failed adding to JNI local ref table (has 512 entries)
> I/dalvikvm( 1742): "main" prio=5 tid=1 RUNNABLE
> I/dalvikvm( 1742):   | group="main" sCount=0 dsCount=0 obj=0x41b319a0 self=0x41aa1010
> I/dalvikvm( 1742):   | sysTid=1742 nice=0 sched=0/0 cgrp=apps handle=1074086876
> I/dalvikvm( 1742):   | state=R schedstat=( 616622758 97188875 598 ) utm=50 stm=11 core=1
> I/dalvikvm( 1742):   at mono.android.view.View_OnClickListenerImplementor.n_onClick(Native Method)
> I/dalvikvm( 1742):   at mono.android.view.View_OnClickListenerImplementor.onClick(View_OnClickListenerImplementor.java:29)
> I/dalvikvm( 1742):   at android.view.View.performClick(View.java:4204)
> I/dalvikvm( 1742):   at android.view.View$PerformClick.run(View.java:17355)
> I/dalvikvm( 1742):   at android.os.Handler.handleCallback(Handler.java:725)
> I/dalvikvm( 1742):   at android.os.Handler.dispatchMessage(Handler.java:92)
> I/dalvikvm( 1742):   at android.os.Looper.loop(Looper.java:137)
> I/dalvikvm( 1742):   at android.app.ActivityThread.main(ActivityThread.java:5041)
> I/dalvikvm( 1742):   at java.lang.reflect.Method.invokeNative(Native Method)
> I/dalvikvm( 1742):   at java.lang.reflect.Method.invoke(Method.java:511)
> I/dalvikvm( 1742):   at com.android.internal.os.ZygoteInit$MethodAndArgsCaller.run(ZygoteInit.java:793)
> I/dalvikvm( 1742):   at com.android.internal.os.ZygoteInit.main(ZygoteInit.java:560)
> I/dalvikvm( 1742):   at dalvik.system.NativeStart.main(Native Method)
> I/dalvikvm( 1742): 
> E/dalvikvm( 1742): VM aborting
> E/mono-rt ( 1742): Stacktrace:
> E/mono-rt ( 1742): 
> E/mono-rt ( 1742):   at <unknown> <0xffffffff>
> E/mono-rt ( 1742):   at (wrapper managed-to-native) object.wrapper_native_0x407a8c41 (intptr,int) <0xffffffff>
> E/mono-rt ( 1742):   at Android.Runtime.JNIEnv.NewArray (int[]) <0x0004f>
> E/mono-rt ( 1742):   at Android.Runtime.JNIEnv.<CreateCreateManagedToNativeArray>m__BA (System.Array) <0x0005f>
> E/mono-rt ( 1742):   at Android.Runtime.JNIEnv.NewArray (System.Array,System.Type) <0x00173>
> E/mono-rt ( 1742):   at Android.Runtime.JNIEnv.NewArray (System.Array,System.Type) <0x000e7>
> E/mono-rt ( 1742):   at Android.Runtime.JNIEnv.NewArray<T> (T[]) <0x0004f>
> E/mono-rt ( 1742):   at Scratch.Junk2.Activity1/<OnCreate>c__AnonStorey0.<>m__0 (object,System.EventArgs) <0x00133>
> E/mono-rt ( 1742):   at Android.Views.View/IOnClickListenerImplementor.OnClick (Android.Views.View) <0x0005b>
> E/mono-rt ( 1742):   at Android.Views.View/IOnClickListenerInvoker.n_OnClick_Landroid_view_View_ (intptr,intptr,intptr) <0x0005b>
> E/mono-rt ( 1742):   at (wrapper dynamic-method) object.d614dd7d-3d8a-49cc-8149-846938e4083d (intptr,intptr,intptr) <0x00043>
> E/mono-rt ( 1742):   at (wrapper native-to-managed) object.d614dd7d-3d8a-49cc-8149-846938e4083d (intptr,intptr,intptr) <0xffffffff>
> E/mono-rt ( 1742): 
> E/mono-rt ( 1742): =================================================================
> E/mono-rt ( 1742): Got a SIGSEGV while executing native code. This usually indicates
> E/mono-rt ( 1742): a fatal error in the mono runtime or one of the native libraries 
> E/mono-rt ( 1742): used by your application.
> E/mono-rt ( 1742): =================================================================
> E/mono-rt ( 1742):
Comment 1 Jonathan Pryor 2013-05-30 14:06:22 UTC
Created attachment 4046 [details]
Bug.Bxc12479.zip

Test case.
Comment 2 Jonathan Pryor 2013-05-30 14:55:02 UTC
Fixed in master/faabd20c and 4.6.x/029dcd1c.
Comment 3 narayanp 2013-06-12 06:28:21 UTC
Today we have checked this issue with following builds:

All Mac and Windows
X.S 4.0.9(build 3)
Xamarin.Android 4.7.9-1

We have build and run attached project and it is working fine.

Changing the status of this issue to Verified.