==23672== Memcheck, a memory error detector. ==23672== Copyright (C) 2002-2006, and GNU GPL'd, by Julian Seward et al. ==23672== Using LibVEX rev 1658, a library for dynamic binary translation. ==23672== Copyright (C) 2004-2006, and GNU GPL'd, by OpenWorks LLP. ==23672== Using valgrind-3.2.1, a dynamic binary instrumentation framework. ==23672== Copyright (C) 2000-2006, and GNU GPL'd, by Julian Seward et al. ==23672== For more details, rerun with: -v ==23672== ==23672== My PID = 23672, parent PID = 23635. Prog and args are: ==23672== asterisk ==23672== -vvvvcg ==23672== ==23672== Invalid read of size 1 ==23672== at 0xBA43DD: _dl_close (in /lib/ld-2.5.so) ==23672== by 0xCF9CE3: dlclose_doit (in /lib/libdl-2.5.so) ==23672== by 0xB9EE25: _dl_catch_error (in /lib/ld-2.5.so) ==23672== by 0xCFA2CB: _dlerror_run (in /lib/libdl-2.5.so) ==23672== by 0xCF9D19: dlclose (in /lib/libdl-2.5.so) ==23672== by 0x80E6F85: load_dynamic_module (loader.c:402) ==23672== by 0x80E7B4F: load_resource (loader.c:651) ==23672== by 0x80E8501: load_modules (loader.c:866) ==23672== by 0x807F667: main (asterisk.c:3623) ==23672== Address 0x5154204 is 516 bytes inside a block of size 653 free'd ==23672== at 0x4004FDA: free (vg_replace_malloc.c:233) ==23672== by 0xBA3F8C: _dl_close_worker (in /lib/ld-2.5.so) ==23672== by 0xBA4406: _dl_close (in /lib/ld-2.5.so) ==23672== by 0xCF9CE3: dlclose_doit (in /lib/libdl-2.5.so) ==23672== by 0xB9EE25: _dl_catch_error (in /lib/ld-2.5.so) ==23672== by 0xCFA2CB: _dlerror_run (in /lib/libdl-2.5.so) ==23672== by 0xCF9D19: dlclose (in /lib/libdl-2.5.so) ==23672== by 0x80E6F85: load_dynamic_module (loader.c:402) ==23672== by 0x80E7B4F: load_resource (loader.c:651) ==23672== by 0x80E8501: load_modules (loader.c:866) ==23672== by 0x807F667: main (asterisk.c:3623) ==23672== ==23672== Invalid read of size 4 ==23672== at 0xBA43E6: _dl_close (in /lib/ld-2.5.so) ==23672== by 0xCF9CE3: dlclose_doit (in /lib/libdl-2.5.so) ==23672== by 0xB9EE25: _dl_catch_error (in /lib/ld-2.5.so) ==23672== by 0xCFA2CB: _dlerror_run (in /lib/libdl-2.5.so) ==23672== by 0xCF9D19: dlclose (in /lib/libdl-2.5.so) ==23672== by 0x80E6F85: load_dynamic_module (loader.c:402) ==23672== by 0x80E7B4F: load_resource (loader.c:651) ==23672== by 0x80E8501: load_modules (loader.c:866) ==23672== by 0x807F667: main (asterisk.c:3623) ==23672== Address 0x5154188 is 392 bytes inside a block of size 653 free'd ==23672== at 0x4004FDA: free (vg_replace_malloc.c:233) ==23672== by 0xBA3F8C: _dl_close_worker (in /lib/ld-2.5.so) ==23672== by 0xBA4406: _dl_close (in /lib/ld-2.5.so) ==23672== by 0xCF9CE3: dlclose_doit (in /lib/libdl-2.5.so) ==23672== by 0xB9EE25: _dl_catch_error (in /lib/ld-2.5.so) ==23672== by 0xCFA2CB: _dlerror_run (in /lib/libdl-2.5.so) ==23672== by 0xCF9D19: dlclose (in /lib/libdl-2.5.so) ==23672== by 0x80E6F85: load_dynamic_module (loader.c:402) ==23672== by 0x80E7B4F: load_resource (loader.c:651) ==23672== by 0x80E8501: load_modules (loader.c:866) ==23672== by 0x807F667: main (asterisk.c:3623) ==23672== ==23672== Invalid read of size 4 ==23672== at 0xBA441D: _dl_close (in /lib/ld-2.5.so) ==23672== by 0xCF9CE3: dlclose_doit (in /lib/libdl-2.5.so) ==23672== by 0xB9EE25: _dl_catch_error (in /lib/ld-2.5.so) ==23672== by 0xCFA2CB: _dlerror_run (in /lib/libdl-2.5.so) ==23672== by 0xCF9D19: dlclose (in /lib/libdl-2.5.so) ==23672== by 0x80E6F85: load_dynamic_module (loader.c:402) ==23672== by 0x80E7B4F: load_resource (loader.c:651) ==23672== by 0x80E8501: load_modules (loader.c:866) ==23672== by 0x807F667: main (asterisk.c:3623) ==23672== Address 0x5154004 is 4 bytes inside a block of size 653 free'd ==23672== at 0x4004FDA: free (vg_replace_malloc.c:233) ==23672== by 0xBA3F8C: _dl_close_worker (in /lib/ld-2.5.so) ==23672== by 0xBA4406: _dl_close (in /lib/ld-2.5.so) ==23672== by 0xCF9CE3: dlclose_doit (in /lib/libdl-2.5.so) ==23672== by 0xB9EE25: _dl_catch_error (in /lib/ld-2.5.so) ==23672== by 0xCFA2CB: _dlerror_run (in /lib/libdl-2.5.so) ==23672== by 0xCF9D19: dlclose (in /lib/libdl-2.5.so) ==23672== by 0x80E6F85: load_dynamic_module (loader.c:402) ==23672== by 0x80E7B4F: load_resource (loader.c:651) ==23672== by 0x80E8501: load_modules (loader.c:866) ==23672== by 0x807F667: main (asterisk.c:3623) ==23672== ==23672== Invalid read of size 1 ==23672== at 0x4006258: strlen (mc_replace_strmem.c:247) ==23672== by 0xB9EF21: _dl_signal_error (in /lib/ld-2.5.so) ==23672== by 0xBA4432: _dl_close (in /lib/ld-2.5.so) ==23672== by 0xCF9CE3: dlclose_doit (in /lib/libdl-2.5.so) ==23672== by 0xB9EE25: _dl_catch_error (in /lib/ld-2.5.so) ==23672== by 0xCFA2CB: _dlerror_run (in /lib/libdl-2.5.so) ==23672== by 0xCF9D19: dlclose (in /lib/libdl-2.5.so) ==23672== by 0x80E6F85: load_dynamic_module (loader.c:402) ==23672== by 0x80E7B4F: load_resource (loader.c:651) ==23672== by 0x80E8501: load_modules (loader.c:866) ==23672== by 0x807F667: main (asterisk.c:3623) ==23672== Address 0x5153FA0 is 0 bytes inside a block of size 45 free'd ==23672== at 0x4004FDA: free (vg_replace_malloc.c:233) ==23672== by 0xBA3F05: _dl_close_worker (in /lib/ld-2.5.so) ==23672== by 0xBA4406: _dl_close (in /lib/ld-2.5.so) ==23672== by 0xCF9CE3: dlclose_doit (in /lib/libdl-2.5.so) ==23672== by 0xB9EE25: _dl_catch_error (in /lib/ld-2.5.so) ==23672== by 0xCFA2CB: _dlerror_run (in /lib/libdl-2.5.so) ==23672== by 0xCF9D19: dlclose (in /lib/libdl-2.5.so) ==23672== by 0x80E6F85: load_dynamic_module (loader.c:402) ==23672== by 0x80E7B4F: load_resource (loader.c:651) ==23672== by 0x80E8501: load_modules (loader.c:866) ==23672== by 0x807F667: main (asterisk.c:3623) ==23672== ==23672== Invalid read of size 1 ==23672== at 0x4006263: strlen (mc_replace_strmem.c:247) ==23672== by 0xB9EF21: _dl_signal_error (in /lib/ld-2.5.so) ==23672== by 0xBA4432: _dl_close (in /lib/ld-2.5.so) ==23672== by 0xCF9CE3: dlclose_doit (in /lib/libdl-2.5.so) ==23672== by 0xB9EE25: _dl_catch_error (in /lib/ld-2.5.so) ==23672== by 0xCFA2CB: _dlerror_run (in /lib/libdl-2.5.so) ==23672== by 0xCF9D19: dlclose (in /lib/libdl-2.5.so) ==23672== by 0x80E6F85: load_dynamic_module (loader.c:402) ==23672== by 0x80E7B4F: load_resource (loader.c:651) ==23672== by 0x80E8501: load_modules (loader.c:866) ==23672== by 0x807F667: main (asterisk.c:3623) ==23672== Address 0x5153FA1 is 1 bytes inside a block of size 45 free'd ==23672== at 0x4004FDA: free (vg_replace_malloc.c:233) ==23672== by 0xBA3F05: _dl_close_worker (in /lib/ld-2.5.so) ==23672== by 0xBA4406: _dl_close (in /lib/ld-2.5.so) ==23672== by 0xCF9CE3: dlclose_doit (in /lib/libdl-2.5.so) ==23672== by 0xB9EE25: _dl_catch_error (in /lib/ld-2.5.so) ==23672== by 0xCFA2CB: _dlerror_run (in /lib/libdl-2.5.so) ==23672== by 0xCF9D19: dlclose (in /lib/libdl-2.5.so) ==23672== by 0x80E6F85: load_dynamic_module (loader.c:402) ==23672== by 0x80E7B4F: load_resource (loader.c:651) ==23672== by 0x80E8501: load_modules (loader.c:866) ==23672== by 0x807F667: main (asterisk.c:3623) ==23672== ==23672== Invalid read of size 1 ==23672== at 0xBA6CF5: memcpy (in /lib/ld-2.5.so) ==23672== by 0xBA4432: _dl_close (in /lib/ld-2.5.so) ==23672== by 0xCF9CE3: dlclose_doit (in /lib/libdl-2.5.so) ==23672== by 0xB9EE25: _dl_catch_error (in /lib/ld-2.5.so) ==23672== by 0xCFA2CB: _dlerror_run (in /lib/libdl-2.5.so) ==23672== by 0xCF9D19: dlclose (in /lib/libdl-2.5.so) ==23672== by 0x80E6F85: load_dynamic_module (loader.c:402) ==23672== by 0x80E7B4F: load_resource (loader.c:651) ==23672== by 0x80E8501: load_modules (loader.c:866) ==23672== by 0x807F667: main (asterisk.c:3623) ==23672== Address 0x5153FA0 is 0 bytes inside a block of size 45 free'd ==23672== at 0x4004FDA: free (vg_replace_malloc.c:233) ==23672== by 0xBA3F05: _dl_close_worker (in /lib/ld-2.5.so) ==23672== by 0xBA4406: _dl_close (in /lib/ld-2.5.so) ==23672== by 0xCF9CE3: dlclose_doit (in /lib/libdl-2.5.so) ==23672== by 0xB9EE25: _dl_catch_error (in /lib/ld-2.5.so) ==23672== by 0xCFA2CB: _dlerror_run (in /lib/libdl-2.5.so) ==23672== by 0xCF9D19: dlclose (in /lib/libdl-2.5.so) ==23672== by 0x80E6F85: load_dynamic_module (loader.c:402) ==23672== by 0x80E7B4F: load_resource (loader.c:651) ==23672== by 0x80E8501: load_modules (loader.c:866) ==23672== by 0x807F667: main (asterisk.c:3623) ==23672== ==23672== Invalid read of size 4 ==23672== at 0xBA6CFC: memcpy (in /lib/ld-2.5.so) ==23672== by 0xBA4432: _dl_close (in /lib/ld-2.5.so) ==23672== by 0xCF9CE3: dlclose_doit (in /lib/libdl-2.5.so) ==23672== by 0xB9EE25: _dl_catch_error (in /lib/ld-2.5.so) ==23672== by 0xCFA2CB: _dlerror_run (in /lib/libdl-2.5.so) ==23672== by 0xCF9D19: dlclose (in /lib/libdl-2.5.so) ==23672== by 0x80E6F85: load_dynamic_module (loader.c:402) ==23672== by 0x80E7B4F: load_resource (loader.c:651) ==23672== by 0x80E8501: load_modules (loader.c:866) ==23672== by 0x807F667: main (asterisk.c:3623) ==23672== Address 0x5153FA1 is 1 bytes inside a block of size 45 free'd ==23672== at 0x4004FDA: free (vg_replace_malloc.c:233) ==23672== by 0xBA3F05: _dl_close_worker (in /lib/ld-2.5.so) ==23672== by 0xBA4406: _dl_close (in /lib/ld-2.5.so) ==23672== by 0xCF9CE3: dlclose_doit (in /lib/libdl-2.5.so) ==23672== by 0xB9EE25: _dl_catch_error (in /lib/ld-2.5.so) ==23672== by 0xCFA2CB: _dlerror_run (in /lib/libdl-2.5.so) ==23672== by 0xCF9D19: dlclose (in /lib/libdl-2.5.so) ==23672== by 0x80E6F85: load_dynamic_module (loader.c:402) ==23672== by 0x80E7B4F: load_resource (loader.c:651) ==23672== by 0x80E8501: load_modules (loader.c:866) ==23672== by 0x807F667: main (asterisk.c:3623) ==23672== ==23672== Invalid read of size 2 ==23672== at 0xBA6CFA: memcpy (in /lib/ld-2.5.so) ==23672== by 0xBA4432: _dl_close (in /lib/ld-2.5.so) ==23672== by 0xCF9CE3: dlclose_doit (in /lib/libdl-2.5.so) ==23672== by 0xB9EE25: _dl_catch_error (in /lib/ld-2.5.so) ==23672== by 0xCFA2CB: _dlerror_run (in /lib/libdl-2.5.so) ==23672== by 0xCF9D19: dlclose (in /lib/libdl-2.5.so) ==23672== by 0x80E6F85: load_dynamic_module (loader.c:402) ==23672== by 0x80E7B4F: load_resource (loader.c:651) ==23672== by 0x80E8501: load_modules (loader.c:866) ==23672== by 0x807F667: main (asterisk.c:3623) ==23672== Address 0x51551B0 is 0 bytes inside a block of size 38 free'd ==23672== at 0x4004FDA: free (vg_replace_malloc.c:233) ==23672== by 0xBA3F05: _dl_close_worker (in /lib/ld-2.5.so) ==23672== by 0xBA4406: _dl_close (in /lib/ld-2.5.so) ==23672== by 0xCF9CE3: dlclose_doit (in /lib/libdl-2.5.so) ==23672== by 0xB9EE25: _dl_catch_error (in /lib/ld-2.5.so) ==23672== by 0xCFA2CB: _dlerror_run (in /lib/libdl-2.5.so) ==23672== by 0xCF9D19: dlclose (in /lib/libdl-2.5.so) ==23672== by 0x80E6F85: load_dynamic_module (loader.c:402) ==23672== by 0x80E7B4F: load_resource (loader.c:651) ==23672== by 0x80E8501: load_modules (loader.c:866) ==23672== by 0x807F667: main (asterisk.c:3623) ==23672== ==23672== Conditional jump or move depends on uninitialised value(s) ==23672== at 0x5AD1F8D: sqlchar_as_sqlwchar (in /usr/lib/libmyodbc5-5.1.5.so) ==23672== by 0x5ABC71C: SQLConnect (in /usr/lib/libmyodbc5-5.1.5.so) ==23672== by 0x59186DB: SQLConnect (SQLConnect.c:3884) ==23672== by 0x58FB918: odbc_obj_connect (res_odbc.c:1440) ==23672== by 0x58FAFA0: ast_odbc_request_obj2 (res_odbc.c:1268) ==23672== by 0x58FB3D2: ast_odbc_request_obj (res_odbc.c:1334) ==23672== by 0x58F9C38: odbc_register_class (res_odbc.c:965) ==23672== by 0x58F95F5: load_odbc_config (res_odbc.c:860) ==23672== by 0x58FC74B: load_module (res_odbc.c:1681) ==23672== by 0x80E7C88: load_resource (loader.c:682) ==23672== by 0x80E8501: load_modules (loader.c:866) ==23672== by 0x807F667: main (asterisk.c:3623) ==23672== ==23672== Conditional jump or move depends on uninitialised value(s) ==23672== at 0x5AD1F8D: sqlchar_as_sqlwchar (in /usr/lib/libmyodbc5-5.1.5.so) ==23672== by 0x5ABC731: SQLConnect (in /usr/lib/libmyodbc5-5.1.5.so) ==23672== by 0x59186DB: SQLConnect (SQLConnect.c:3884) ==23672== by 0x58FB918: odbc_obj_connect (res_odbc.c:1440) ==23672== by 0x58FAFA0: ast_odbc_request_obj2 (res_odbc.c:1268) ==23672== by 0x58FB3D2: ast_odbc_request_obj (res_odbc.c:1334) ==23672== by 0x58F9C38: odbc_register_class (res_odbc.c:965) ==23672== by 0x58F95F5: load_odbc_config (res_odbc.c:860) ==23672== by 0x58FC74B: load_module (res_odbc.c:1681) ==23672== by 0x80E7C88: load_resource (loader.c:682) ==23672== by 0x80E8501: load_modules (loader.c:866) ==23672== by 0x807F667: main (asterisk.c:3623) ==23672== ==23672== Conditional jump or move depends on uninitialised value(s) ==23672== at 0x5AD1F8D: sqlchar_as_sqlwchar (in /usr/lib/libmyodbc5-5.1.5.so) ==23672== by 0x5ABC748: SQLConnect (in /usr/lib/libmyodbc5-5.1.5.so) ==23672== by 0x59186DB: SQLConnect (SQLConnect.c:3884) ==23672== by 0x58FB918: odbc_obj_connect (res_odbc.c:1440) ==23672== by 0x58FAFA0: ast_odbc_request_obj2 (res_odbc.c:1268) ==23672== by 0x58FB3D2: ast_odbc_request_obj (res_odbc.c:1334) ==23672== by 0x58F9C38: odbc_register_class (res_odbc.c:965) ==23672== by 0x58F95F5: load_odbc_config (res_odbc.c:860) ==23672== by 0x58FC74B: load_module (res_odbc.c:1681) ==23672== by 0x80E7C88: load_resource (loader.c:682) ==23672== by 0x80E8501: load_modules (loader.c:866) ==23672== by 0x807F667: main (asterisk.c:3623) ==23672== ==23672== Conditional jump or move depends on uninitialised value(s) ==23672== at 0x928892C: speex_decode_int (speex.c:167) ==23672== by 0x94A3327: speextolin_framein (codec_speex.c:196) ==23672== by 0x8150249: framein (translate.c:194) ==23672== by 0x8150E10: calc_cost (translate.c:421) ==23672== by 0x8151F12: __ast_register_translator (translate.c:681) ==23672== by 0x94A4935: load_module (codec_speex.c:458) ==23672== by 0x80E7C88: load_resource (loader.c:682) ==23672== by 0x80E8663: load_modules (loader.c:886) ==23672== by 0x807F667: main (asterisk.c:3623) ==23672== ==23672== Conditional jump or move depends on uninitialised value(s) ==23672== at 0x9288935: speex_decode_int (speex.c:169) ==23672== by 0x94A3327: speextolin_framein (codec_speex.c:196) ==23672== by 0x8150249: framein (translate.c:194) ==23672== by 0x8150E10: calc_cost (translate.c:421) ==23672== by 0x8151F12: __ast_register_translator (translate.c:681) ==23672== by 0x94A4935: load_module (codec_speex.c:458) ==23672== by 0x80E7C88: load_resource (loader.c:682) ==23672== by 0x80E8663: load_modules (loader.c:886) ==23672== by 0x807F667: main (asterisk.c:3623) ==23672== Warning: noted but unhandled ioctl 0xDA34 with no size/direction hints ==23672== This could cause spurious value errors to appear. ==23672== See README_MISSING_SYSCALL_OR_IOCTL for guidance on writing a proper wrapper. ==23672== Warning: noted but unhandled ioctl 0xDA34 with no size/direction hints ==23672== This could cause spurious value errors to appear. ==23672== See README_MISSING_SYSCALL_OR_IOCTL for guidance on writing a proper wrapper. ==23672== Warning: noted but unhandled ioctl 0xDA35 with no size/direction hints ==23672== This could cause spurious value errors to appear. ==23672== See README_MISSING_SYSCALL_OR_IOCTL for guidance on writing a proper wrapper. ==23672== ==23672== Thread 42: ==23672== Invalid read of size 1 ==23672== at 0xC245C9: strcasecmp (in /lib/libc-2.5.so) ==23672== by 0x70359D8: moh_class_cmp (res_musiconhold.c:1640) ==23672== by 0x8081B88: __ao2_callback (astobj2.c:663) ==23672== by 0x8081E65: _ao2_callback (astobj2.c:729) ==23672== by 0x8081F81: _ao2_find (astobj2.c:756) ==23672== by 0x7031FD1: get_mohbyname (res_musiconhold.c:724) ==23672== by 0x70337FF: local_ast_moh_start (res_musiconhold.c:1153) ==23672== by 0x80A2D56: ast_moh_start (channel.c:5181) ==23672== by 0x92C8AE5: queue_exec (app_queue.c:5033) ==23672== by 0x80FACCF: pbx_exec (pbx.c:1342) ==23672== by 0x8102995: pbx_extension_helper (pbx.c:3684) ==23672== by 0x8103D12: ast_spawn_extension (pbx.c:4137) ==23672== Address 0x69BFF58 is 168 bytes inside a block of size 908 free'd ==23672== at 0x4004FDA: free (vg_replace_malloc.c:233) ==23672== by 0x807FD4F: __ast_free_region (astmm.c:192) ==23672== by 0x80800F9: __ast_free (astmm.c:226) ==23672== by 0x8081382: __ao2_ref (astobj2.c:296) ==23672== by 0x8081293: _ao2_ref (astobj2.c:257) ==23672== by 0x7030121: moh_files_release (res_musiconhold.c:217) ==23672== by 0x8098263: ast_deactivate_generator (channel.c:1870) ==23672== by 0x70347B5: local_ast_moh_stop (res_musiconhold.c:1332) ==23672== by 0x80A2E13: ast_moh_stop (channel.c:5192) ==23672== by 0x92C32BC: try_calling (app_queue.c:3851) ==23672== by 0x92C8D70: queue_exec (app_queue.c:5088) ==23672== by 0x80FACCF: pbx_exec (pbx.c:1342) ==23672== ==23672== Invalid read of size 4 ==23672== at 0x8080FE8: INTERNAL_OBJ (astobj2.c:115) ==23672== by 0x808126F: _ao2_ref (astobj2.c:252) ==23672== by 0x8081C1F: __ao2_callback (astobj2.c:680) ==23672== by 0x8081E65: _ao2_callback (astobj2.c:729) ==23672== by 0x8081F81: _ao2_find (astobj2.c:756) ==23672== by 0x7031FD1: get_mohbyname (res_musiconhold.c:724) ==23672== by 0x70337FF: local_ast_moh_start (res_musiconhold.c:1153) ==23672== by 0x80A2D56: ast_moh_start (channel.c:5181) ==23672== by 0x92C8AE5: queue_exec (app_queue.c:5033) ==23672== by 0x80FACCF: pbx_exec (pbx.c:1342) ==23672== by 0x8102995: pbx_extension_helper (pbx.c:3684) ==23672== by 0x8103D12: ast_spawn_extension (pbx.c:4137) ==23672== Address 0x69BFF54 is 164 bytes inside a block of size 908 free'd ==23672== at 0x4004FDA: free (vg_replace_malloc.c:233) ==23672== by 0x807FD4F: __ast_free_region (astmm.c:192) ==23672== by 0x80800F9: __ast_free (astmm.c:226) ==23672== by 0x8081382: __ao2_ref (astobj2.c:296) ==23672== by 0x8081293: _ao2_ref (astobj2.c:257) ==23672== by 0x7030121: moh_files_release (res_musiconhold.c:217) ==23672== by 0x8098263: ast_deactivate_generator (channel.c:1870) ==23672== by 0x70347B5: local_ast_moh_stop (res_musiconhold.c:1332) ==23672== by 0x80A2E13: ast_moh_stop (channel.c:5192) ==23672== by 0x92C32BC: try_calling (app_queue.c:3851) ==23672== by 0x92C8D70: queue_exec (app_queue.c:5088) ==23672== by 0x80FACCF: pbx_exec (pbx.c:1342) ==23672== ==23672== Invalid read of size 4 ==23672== at 0x8080FE8: INTERNAL_OBJ (astobj2.c:115) ==23672== by 0x80812AC: __ao2_ref (astobj2.c:262) ==23672== by 0x8081293: _ao2_ref (astobj2.c:257) ==23672== by 0x8081C1F: __ao2_callback (astobj2.c:680) ==23672== by 0x8081E65: _ao2_callback (astobj2.c:729) ==23672== by 0x8081F81: _ao2_find (astobj2.c:756) ==23672== by 0x7031FD1: get_mohbyname (res_musiconhold.c:724) ==23672== by 0x70337FF: local_ast_moh_start (res_musiconhold.c:1153) ==23672== by 0x80A2D56: ast_moh_start (channel.c:5181) ==23672== by 0x92C8AE5: queue_exec (app_queue.c:5033) ==23672== by 0x80FACCF: pbx_exec (pbx.c:1342) ==23672== by 0x8102995: pbx_extension_helper (pbx.c:3684) ==23672== Address 0x69BFF54 is 164 bytes inside a block of size 908 free'd ==23672== at 0x4004FDA: free (vg_replace_malloc.c:233) ==23672== by 0x807FD4F: __ast_free_region (astmm.c:192) ==23672== by 0x80800F9: __ast_free (astmm.c:226) ==23672== by 0x8081382: __ao2_ref (astobj2.c:296) ==23672== by 0x8081293: _ao2_ref (astobj2.c:257) ==23672== by 0x7030121: moh_files_release (res_musiconhold.c:217) ==23672== by 0x8098263: ast_deactivate_generator (channel.c:1870) ==23672== by 0x70347B5: local_ast_moh_stop (res_musiconhold.c:1332) ==23672== by 0x80A2E13: ast_moh_stop (channel.c:5192) ==23672== by 0x92C32BC: try_calling (app_queue.c:3851) ==23672== by 0x92C8D70: queue_exec (app_queue.c:5088) ==23672== by 0x80FACCF: pbx_exec (pbx.c:1342) ==23672== ==23672== Invalid read of size 4 ==23672== at 0x81567C4: ast_atomic_fetchadd_int (lock.h:1745) ==23672== by 0x80812DA: __ao2_ref (astobj2.c:271) ==23672== by 0x8081293: _ao2_ref (astobj2.c:257) ==23672== by 0x8081C1F: __ao2_callback (astobj2.c:680) ==23672== by 0x8081E65: _ao2_callback (astobj2.c:729) ==23672== by 0x8081F81: _ao2_find (astobj2.c:756) ==23672== by 0x7031FD1: get_mohbyname (res_musiconhold.c:724) ==23672== by 0x70337FF: local_ast_moh_start (res_musiconhold.c:1153) ==23672== by 0x80A2D56: ast_moh_start (channel.c:5181) ==23672== by 0x92C8AE5: queue_exec (app_queue.c:5033) ==23672== by 0x80FACCF: pbx_exec (pbx.c:1342) ==23672== by 0x8102995: pbx_extension_helper (pbx.c:3684) ==23672== Address 0x69BFF48 is 152 bytes inside a block of size 908 free'd ==23672== at 0x4004FDA: free (vg_replace_malloc.c:233) ==23672== by 0x807FD4F: __ast_free_region (astmm.c:192) ==23672== by 0x80800F9: __ast_free (astmm.c:226) ==23672== by 0x8081382: __ao2_ref (astobj2.c:296) ==23672== by 0x8081293: _ao2_ref (astobj2.c:257) ==23672== by 0x7030121: moh_files_release (res_musiconhold.c:217) ==23672== by 0x8098263: ast_deactivate_generator (channel.c:1870) ==23672== by 0x70347B5: local_ast_moh_stop (res_musiconhold.c:1332) ==23672== by 0x80A2E13: ast_moh_stop (channel.c:5192) ==23672== by 0x92C32BC: try_calling (app_queue.c:3851) ==23672== by 0x92C8D70: queue_exec (app_queue.c:5088) ==23672== by 0x80FACCF: pbx_exec (pbx.c:1342) ==23672== ==23672== Invalid read of size 4 ==23672== at 0x70346EA: local_ast_moh_start (res_musiconhold.c:1317) ==23672== by 0x80A2D56: ast_moh_start (channel.c:5181) ==23672== by 0x92C8AE5: queue_exec (app_queue.c:5033) ==23672== by 0x80FACCF: pbx_exec (pbx.c:1342) ==23672== by 0x8102995: pbx_extension_helper (pbx.c:3684) ==23672== by 0x8103D12: ast_spawn_extension (pbx.c:4137) ==23672== by 0x81043B6: __ast_pbx_run (pbx.c:4227) ==23672== by 0x8105856: pbx_thread (pbx.c:4514) ==23672== by 0x81579DA: dummy_start (utils.c:968) ==23672== by 0xD2D46A: start_thread (in /lib/libpthread-2.5.so) ==23672== by 0xC84DBD: clone (in /lib/libc-2.5.so) ==23672== Address 0x69C0204 is 852 bytes inside a block of size 908 free'd ==23672== at 0x4004FDA: free (vg_replace_malloc.c:233) ==23672== by 0x807FD4F: __ast_free_region (astmm.c:192) ==23672== by 0x80800F9: __ast_free (astmm.c:226) ==23672== by 0x8081382: __ao2_ref (astobj2.c:296) ==23672== by 0x8081293: _ao2_ref (astobj2.c:257) ==23672== by 0x7030121: moh_files_release (res_musiconhold.c:217) ==23672== by 0x8098263: ast_deactivate_generator (channel.c:1870) ==23672== by 0x70347B5: local_ast_moh_stop (res_musiconhold.c:1332) ==23672== by 0x80A2E13: ast_moh_stop (channel.c:5192) ==23672== by 0x92C32BC: try_calling (app_queue.c:3851) ==23672== by 0x92C8D70: queue_exec (app_queue.c:5088) ==23672== by 0x80FACCF: pbx_exec (pbx.c:1342) ==23672== ==23672== Invalid read of size 4 ==23672== at 0x7030730: moh_files_alloc (res_musiconhold.c:328) ==23672== by 0x8098517: ast_activate_generator (channel.c:1923) ==23672== by 0x703470F: local_ast_moh_start (res_musiconhold.c:1318) ==23672== by 0x80A2D56: ast_moh_start (channel.c:5181) ==23672== by 0x92C8AE5: queue_exec (app_queue.c:5033) ==23672== by 0x80FACCF: pbx_exec (pbx.c:1342) ==23672== by 0x8102995: pbx_extension_helper (pbx.c:3684) ==23672== by 0x8103D12: ast_spawn_extension (pbx.c:4137) ==23672== by 0x81043B6: __ast_pbx_run (pbx.c:4227) ==23672== by 0x8105856: pbx_thread (pbx.c:4514) ==23672== by 0x81579DA: dummy_start (utils.c:968) ==23672== by 0xD2D46A: start_thread (in /lib/libpthread-2.5.so) ==23672== Address 0x69C0208 is 856 bytes inside a block of size 908 free'd ==23672== at 0x4004FDA: free (vg_replace_malloc.c:233) ==23672== by 0x807FD4F: __ast_free_region (astmm.c:192) ==23672== by 0x80800F9: __ast_free (astmm.c:226) ==23672== by 0x8081382: __ao2_ref (astobj2.c:296) ==23672== by 0x8081293: _ao2_ref (astobj2.c:257) ==23672== by 0x7030121: moh_files_release (res_musiconhold.c:217) ==23672== by 0x8098263: ast_deactivate_generator (channel.c:1870) ==23672== by 0x70347B5: local_ast_moh_stop (res_musiconhold.c:1332) ==23672== by 0x80A2E13: ast_moh_stop (channel.c:5192) ==23672== by 0x92C32BC: try_calling (app_queue.c:3851) ==23672== by 0x92C8D70: queue_exec (app_queue.c:5088) ==23672== by 0x80FACCF: pbx_exec (pbx.c:1342) ==23672== ==23672== Invalid read of size 4 ==23672== at 0x7030743: moh_files_alloc (res_musiconhold.c:328) ==23672== by 0x8098517: ast_activate_generator (channel.c:1923) ==23672== by 0x703470F: local_ast_moh_start (res_musiconhold.c:1318) ==23672== by 0x80A2D56: ast_moh_start (channel.c:5181) ==23672== by 0x92C8AE5: queue_exec (app_queue.c:5033) ==23672== by 0x80FACCF: pbx_exec (pbx.c:1342) ==23672== by 0x8102995: pbx_extension_helper (pbx.c:3684) ==23672== by 0x8103D12: ast_spawn_extension (pbx.c:4137) ==23672== by 0x81043B6: __ast_pbx_run (pbx.c:4227) ==23672== by 0x8105856: pbx_thread (pbx.c:4514) ==23672== by 0x81579DA: dummy_start (utils.c:968) ==23672== by 0xD2D46A: start_thread (in /lib/libpthread-2.5.so) ==23672== Address 0x69C0208 is 856 bytes inside a block of size 908 free'd ==23672== at 0x4004FDA: free (vg_replace_malloc.c:233) ==23672== by 0x807FD4F: __ast_free_region (astmm.c:192) ==23672== by 0x80800F9: __ast_free (astmm.c:226) ==23672== by 0x8081382: __ao2_ref (astobj2.c:296) ==23672== by 0x8081293: _ao2_ref (astobj2.c:257) ==23672== by 0x7030121: moh_files_release (res_musiconhold.c:217) ==23672== by 0x8098263: ast_deactivate_generator (channel.c:1870) ==23672== by 0x70347B5: local_ast_moh_stop (res_musiconhold.c:1332) ==23672== by 0x80A2E13: ast_moh_stop (channel.c:5192) ==23672== by 0x92C32BC: try_calling (app_queue.c:3851) ==23672== by 0x92C8D70: queue_exec (app_queue.c:5088) ==23672== by 0x80FACCF: pbx_exec (pbx.c:1342) ==23672== ==23672== Invalid read of size 4 ==23672== at 0x8080FE8: INTERNAL_OBJ (astobj2.c:115) ==23672== by 0x808126F: _ao2_ref (astobj2.c:252) ==23672== by 0x703078E: moh_files_alloc (res_musiconhold.c:333) ==23672== by 0x8098517: ast_activate_generator (channel.c:1923) ==23672== by 0x703470F: local_ast_moh_start (res_musiconhold.c:1318) ==23672== by 0x80A2D56: ast_moh_start (channel.c:5181) ==23672== by 0x92C8AE5: queue_exec (app_queue.c:5033) ==23672== by 0x80FACCF: pbx_exec (pbx.c:1342) ==23672== by 0x8102995: pbx_extension_helper (pbx.c:3684) ==23672== by 0x8103D12: ast_spawn_extension (pbx.c:4137) ==23672== by 0x81043B6: __ast_pbx_run (pbx.c:4227) ==23672== by 0x8105856: pbx_thread (pbx.c:4514) ==23672== Address 0x69BFF54 is 164 bytes inside a block of size 908 free'd ==23672== at 0x4004FDA: free (vg_replace_malloc.c:233) ==23672== by 0x807FD4F: __ast_free_region (astmm.c:192) ==23672== by 0x80800F9: __ast_free (astmm.c:226) ==23672== by 0x8081382: __ao2_ref (astobj2.c:296) ==23672== by 0x8081293: _ao2_ref (astobj2.c:257) ==23672== by 0x7030121: moh_files_release (res_musiconhold.c:217) ==23672== by 0x8098263: ast_deactivate_generator (channel.c:1870) ==23672== by 0x70347B5: local_ast_moh_stop (res_musiconhold.c:1332) ==23672== by 0x80A2E13: ast_moh_stop (channel.c:5192) ==23672== by 0x92C32BC: try_calling (app_queue.c:3851) ==23672== by 0x92C8D70: queue_exec (app_queue.c:5088) ==23672== by 0x80FACCF: pbx_exec (pbx.c:1342) ==23672== ==23672== Invalid read of size 4 ==23672== at 0x8080FE8: INTERNAL_OBJ (astobj2.c:115) ==23672== by 0x80812AC: __ao2_ref (astobj2.c:262) ==23672== by 0x8081293: _ao2_ref (astobj2.c:257) ==23672== by 0x703078E: moh_files_alloc (res_musiconhold.c:333) ==23672== by 0x8098517: ast_activate_generator (channel.c:1923) ==23672== by 0x703470F: local_ast_moh_start (res_musiconhold.c:1318) ==23672== by 0x80A2D56: ast_moh_start (channel.c:5181) ==23672== by 0x92C8AE5: queue_exec (app_queue.c:5033) ==23672== by 0x80FACCF: pbx_exec (pbx.c:1342) ==23672== by 0x8102995: pbx_extension_helper (pbx.c:3684) ==23672== by 0x8103D12: ast_spawn_extension (pbx.c:4137) ==23672== by 0x81043B6: __ast_pbx_run (pbx.c:4227) ==23672== Address 0x69BFF54 is 164 bytes inside a block of size 908 free'd ==23672== at 0x4004FDA: free (vg_replace_malloc.c:233) ==23672== by 0x807FD4F: __ast_free_region (astmm.c:192) ==23672== by 0x80800F9: __ast_free (astmm.c:226) ==23672== by 0x8081382: __ao2_ref (astobj2.c:296) ==23672== by 0x8081293: _ao2_ref (astobj2.c:257) ==23672== by 0x7030121: moh_files_release (res_musiconhold.c:217) ==23672== by 0x8098263: ast_deactivate_generator (channel.c:1870) ==23672== by 0x70347B5: local_ast_moh_stop (res_musiconhold.c:1332) ==23672== by 0x80A2E13: ast_moh_stop (channel.c:5192) ==23672== by 0x92C32BC: try_calling (app_queue.c:3851) ==23672== by 0x92C8D70: queue_exec (app_queue.c:5088) ==23672== by 0x80FACCF: pbx_exec (pbx.c:1342) ==23672== ==23672== Invalid read of size 4 ==23672== at 0x81567C4: ast_atomic_fetchadd_int (lock.h:1745) ==23672== by 0x80812DA: __ao2_ref (astobj2.c:271) ==23672== by 0x8081293: _ao2_ref (astobj2.c:257) ==23672== by 0x703078E: moh_files_alloc (res_musiconhold.c:333) ==23672== by 0x8098517: ast_activate_generator (channel.c:1923) ==23672== by 0x703470F: local_ast_moh_start (res_musiconhold.c:1318) ==23672== by 0x80A2D56: ast_moh_start (channel.c:5181) ==23672== by 0x92C8AE5: queue_exec (app_queue.c:5033) ==23672== by 0x80FACCF: pbx_exec (pbx.c:1342) ==23672== by 0x8102995: pbx_extension_helper (pbx.c:3684) ==23672== by 0x8103D12: ast_spawn_extension (pbx.c:4137) ==23672== by 0x81043B6: __ast_pbx_run (pbx.c:4227) ==23672== Address 0x69BFF48 is 152 bytes inside a block of size 908 free'd ==23672== at 0x4004FDA: free (vg_replace_malloc.c:233) ==23672== by 0x807FD4F: __ast_free_region (astmm.c:192) ==23672== by 0x80800F9: __ast_free (astmm.c:226) ==23672== by 0x8081382: __ao2_ref (astobj2.c:296) ==23672== by 0x8081293: _ao2_ref (astobj2.c:257) ==23672== by 0x7030121: moh_files_release (res_musiconhold.c:217) ==23672== by 0x8098263: ast_deactivate_generator (channel.c:1870) ==23672== by 0x70347B5: local_ast_moh_stop (res_musiconhold.c:1332) ==23672== by 0x80A2E13: ast_moh_stop (channel.c:5192) ==23672== by 0x92C32BC: try_calling (app_queue.c:3851) ==23672== by 0x92C8D70: queue_exec (app_queue.c:5088) ==23672== by 0x80FACCF: pbx_exec (pbx.c:1342) ==23672== ==23672== Invalid read of size 1 ==23672== at 0x4006238: strlen (mc_replace_strmem.c:246) ==23672== by 0xBF384D: vfprintf (in /lib/libc-2.5.so) ==23672== by 0xC13FD3: vsnprintf (in /lib/libc-2.5.so) ==23672== by 0x81494F3: __ast_debug_str_helper (strings.c:72) ==23672== by 0x8156F78: ast_str_set_va (strings.h:745) ==23672== by 0x80EC00E: __ast_verbose_ap (logger.c:1273) ==23672== by 0x80EC180: __ast_verbose (logger.c:1305) ==23672== by 0x7030823: moh_files_alloc (res_musiconhold.c:336) ==23672== by 0x8098517: ast_activate_generator (channel.c:1923) ==23672== by 0x703470F: local_ast_moh_start (res_musiconhold.c:1318) ==23672== by 0x80A2D56: ast_moh_start (channel.c:5181) ==23672== by 0x92C8AE5: queue_exec (app_queue.c:5033) ==23672== Address 0x69BFF58 is 168 bytes inside a block of size 908 free'd ==23672== at 0x4004FDA: free (vg_replace_malloc.c:233) ==23672== by 0x807FD4F: __ast_free_region (astmm.c:192) ==23672== by 0x80800F9: __ast_free (astmm.c:226) ==23672== by 0x8081382: __ao2_ref (astobj2.c:296) ==23672== by 0x8081293: _ao2_ref (astobj2.c:257) ==23672== by 0x7030121: moh_files_release (res_musiconhold.c:217) ==23672== by 0x8098263: ast_deactivate_generator (channel.c:1870) ==23672== by 0x70347B5: local_ast_moh_stop (res_musiconhold.c:1332) ==23672== by 0x80A2E13: ast_moh_stop (channel.c:5192) ==23672== by 0x92C32BC: try_calling (app_queue.c:3851) ==23672== by 0x92C8D70: queue_exec (app_queue.c:5088) ==23672== by 0x80FACCF: pbx_exec (pbx.c:1342) ==23672== ==23672== Invalid read of size 1 ==23672== at 0x4006243: strlen (mc_replace_strmem.c:246) ==23672== by 0xBF384D: vfprintf (in /lib/libc-2.5.so) ==23672== by 0xC13FD3: vsnprintf (in /lib/libc-2.5.so) ==23672== by 0x81494F3: __ast_debug_str_helper (strings.c:72) ==23672== by 0x8156F78: ast_str_set_va (strings.h:745) ==23672== by 0x80EC00E: __ast_verbose_ap (logger.c:1273) ==23672== by 0x80EC180: __ast_verbose (logger.c:1305) ==23672== by 0x7030823: moh_files_alloc (res_musiconhold.c:336) ==23672== by 0x8098517: ast_activate_generator (channel.c:1923) ==23672== by 0x703470F: local_ast_moh_start (res_musiconhold.c:1318) ==23672== by 0x80A2D56: ast_moh_start (channel.c:5181) ==23672== by 0x92C8AE5: queue_exec (app_queue.c:5033) ==23672== Address 0x69BFF59 is 169 bytes inside a block of size 908 free'd ==23672== at 0x4004FDA: free (vg_replace_malloc.c:233) ==23672== by 0x807FD4F: __ast_free_region (astmm.c:192) ==23672== by 0x80800F9: __ast_free (astmm.c:226) ==23672== by 0x8081382: __ao2_ref (astobj2.c:296) ==23672== by 0x8081293: _ao2_ref (astobj2.c:257) ==23672== by 0x7030121: moh_files_release (res_musiconhold.c:217) ==23672== by 0x8098263: ast_deactivate_generator (channel.c:1870) ==23672== by 0x70347B5: local_ast_moh_stop (res_musiconhold.c:1332) ==23672== by 0x80A2E13: ast_moh_stop (channel.c:5192) ==23672== by 0x92C32BC: try_calling (app_queue.c:3851) ==23672== by 0x92C8D70: queue_exec (app_queue.c:5088) ==23672== by 0x80FACCF: pbx_exec (pbx.c:1342) ==23672== ==23672== Invalid read of size 1 ==23672== at 0xC191D0: _IO_default_xsputn (in /lib/libc-2.5.so) ==23672== by 0xBF3375: vfprintf (in /lib/libc-2.5.so) ==23672== by 0xC13FD3: vsnprintf (in /lib/libc-2.5.so) ==23672== by 0x81494F3: __ast_debug_str_helper (strings.c:72) ==23672== by 0x8156F78: ast_str_set_va (strings.h:745) ==23672== by 0x80EC00E: __ast_verbose_ap (logger.c:1273) ==23672== by 0x80EC180: __ast_verbose (logger.c:1305) ==23672== by 0x7030823: moh_files_alloc (res_musiconhold.c:336) ==23672== by 0x8098517: ast_activate_generator (channel.c:1923) ==23672== by 0x703470F: local_ast_moh_start (res_musiconhold.c:1318) ==23672== by 0x80A2D56: ast_moh_start (channel.c:5181) ==23672== by 0x92C8AE5: queue_exec (app_queue.c:5033) ==23672== Address 0x69BFF58 is 168 bytes inside a block of size 908 free'd ==23672== at 0x4004FDA: free (vg_replace_malloc.c:233) ==23672== by 0x807FD4F: __ast_free_region (astmm.c:192) ==23672== by 0x80800F9: __ast_free (astmm.c:226) ==23672== by 0x8081382: __ao2_ref (astobj2.c:296) ==23672== by 0x8081293: _ao2_ref (astobj2.c:257) ==23672== by 0x7030121: moh_files_release (res_musiconhold.c:217) ==23672== by 0x8098263: ast_deactivate_generator (channel.c:1870) ==23672== by 0x70347B5: local_ast_moh_stop (res_musiconhold.c:1332) ==23672== by 0x80A2E13: ast_moh_stop (channel.c:5192) ==23672== by 0x92C32BC: try_calling (app_queue.c:3851) ==23672== by 0x92C8D70: queue_exec (app_queue.c:5088) ==23672== by 0x80FACCF: pbx_exec (pbx.c:1342) ==23672== ==23672== Invalid read of size 1 ==23672== at 0xC191E0: _IO_default_xsputn (in /lib/libc-2.5.so) ==23672== by 0xBF3375: vfprintf (in /lib/libc-2.5.so) ==23672== by 0xC13FD3: vsnprintf (in /lib/libc-2.5.so) ==23672== by 0x81494F3: __ast_debug_str_helper (strings.c:72) ==23672== by 0x8156F78: ast_str_set_va (strings.h:745) ==23672== by 0x80EC00E: __ast_verbose_ap (logger.c:1273) ==23672== by 0x80EC180: __ast_verbose (logger.c:1305) ==23672== by 0x7030823: moh_files_alloc (res_musiconhold.c:336) ==23672== by 0x8098517: ast_activate_generator (channel.c:1923) ==23672== by 0x703470F: local_ast_moh_start (res_musiconhold.c:1318) ==23672== by 0x80A2D56: ast_moh_start (channel.c:5181) ==23672== by 0x92C8AE5: queue_exec (app_queue.c:5033) ==23672== Address 0x69BFF5A is 170 bytes inside a block of size 908 free'd ==23672== at 0x4004FDA: free (vg_replace_malloc.c:233) ==23672== by 0x807FD4F: __ast_free_region (astmm.c:192) ==23672== by 0x80800F9: __ast_free (astmm.c:226) ==23672== by 0x8081382: __ao2_ref (astobj2.c:296) ==23672== by 0x8081293: _ao2_ref (astobj2.c:257) ==23672== by 0x7030121: moh_files_release (res_musiconhold.c:217) ==23672== by 0x8098263: ast_deactivate_generator (channel.c:1870) ==23672== by 0x70347B5: local_ast_moh_stop (res_musiconhold.c:1332) ==23672== by 0x80A2E13: ast_moh_stop (channel.c:5192) ==23672== by 0x92C32BC: try_calling (app_queue.c:3851) ==23672== by 0x92C8D70: queue_exec (app_queue.c:5088) ==23672== by 0x80FACCF: pbx_exec (pbx.c:1342) ==23672== ==23672== Invalid read of size 4 ==23672== at 0x8080FE8: INTERNAL_OBJ (astobj2.c:115) ==23672== by 0x808126F: _ao2_ref (astobj2.c:252) ==23672== by 0x7034746: local_ast_moh_start (res_musiconhold.c:1323) ==23672== by 0x80A2D56: ast_moh_start (channel.c:5181) ==23672== by 0x92C8AE5: queue_exec (app_queue.c:5033) ==23672== by 0x80FACCF: pbx_exec (pbx.c:1342) ==23672== by 0x8102995: pbx_extension_helper (pbx.c:3684) ==23672== by 0x8103D12: ast_spawn_extension (pbx.c:4137) ==23672== by 0x81043B6: __ast_pbx_run (pbx.c:4227) ==23672== by 0x8105856: pbx_thread (pbx.c:4514) ==23672== by 0x81579DA: dummy_start (utils.c:968) ==23672== by 0xD2D46A: start_thread (in /lib/libpthread-2.5.so) ==23672== Address 0x69BFF54 is 164 bytes inside a block of size 908 free'd ==23672== at 0x4004FDA: free (vg_replace_malloc.c:233) ==23672== by 0x807FD4F: __ast_free_region (astmm.c:192) ==23672== by 0x80800F9: __ast_free (astmm.c:226) ==23672== by 0x8081382: __ao2_ref (astobj2.c:296) ==23672== by 0x8081293: _ao2_ref (astobj2.c:257) ==23672== by 0x7030121: moh_files_release (res_musiconhold.c:217) ==23672== by 0x8098263: ast_deactivate_generator (channel.c:1870) ==23672== by 0x70347B5: local_ast_moh_stop (res_musiconhold.c:1332) ==23672== by 0x80A2E13: ast_moh_stop (channel.c:5192) ==23672== by 0x92C32BC: try_calling (app_queue.c:3851) ==23672== by 0x92C8D70: queue_exec (app_queue.c:5088) ==23672== by 0x80FACCF: pbx_exec (pbx.c:1342) ==23672== ==23672== Invalid read of size 4 ==23672== at 0x8080FE8: INTERNAL_OBJ (astobj2.c:115) ==23672== by 0x80812AC: __ao2_ref (astobj2.c:262) ==23672== by 0x8081293: _ao2_ref (astobj2.c:257) ==23672== by 0x7034746: local_ast_moh_start (res_musiconhold.c:1323) ==23672== by 0x80A2D56: ast_moh_start (channel.c:5181) ==23672== by 0x92C8AE5: queue_exec (app_queue.c:5033) ==23672== by 0x80FACCF: pbx_exec (pbx.c:1342) ==23672== by 0x8102995: pbx_extension_helper (pbx.c:3684) ==23672== by 0x8103D12: ast_spawn_extension (pbx.c:4137) ==23672== by 0x81043B6: __ast_pbx_run (pbx.c:4227) ==23672== by 0x8105856: pbx_thread (pbx.c:4514) ==23672== by 0x81579DA: dummy_start (utils.c:968) ==23672== Address 0x69BFF54 is 164 bytes inside a block of size 908 free'd ==23672== at 0x4004FDA: free (vg_replace_malloc.c:233) ==23672== by 0x807FD4F: __ast_free_region (astmm.c:192) ==23672== by 0x80800F9: __ast_free (astmm.c:226) ==23672== by 0x8081382: __ao2_ref (astobj2.c:296) ==23672== by 0x8081293: _ao2_ref (astobj2.c:257) ==23672== by 0x7030121: moh_files_release (res_musiconhold.c:217) ==23672== by 0x8098263: ast_deactivate_generator (channel.c:1870) ==23672== by 0x70347B5: local_ast_moh_stop (res_musiconhold.c:1332) ==23672== by 0x80A2E13: ast_moh_stop (channel.c:5192) ==23672== by 0x92C32BC: try_calling (app_queue.c:3851) ==23672== by 0x92C8D70: queue_exec (app_queue.c:5088) ==23672== by 0x80FACCF: pbx_exec (pbx.c:1342) ==23672== ==23672== Invalid read of size 4 ==23672== at 0x81567C4: ast_atomic_fetchadd_int (lock.h:1745) ==23672== by 0x80812DA: __ao2_ref (astobj2.c:271) ==23672== by 0x8081293: _ao2_ref (astobj2.c:257) ==23672== by 0x7034746: local_ast_moh_start (res_musiconhold.c:1323) ==23672== by 0x80A2D56: ast_moh_start (channel.c:5181) ==23672== by 0x92C8AE5: queue_exec (app_queue.c:5033) ==23672== by 0x80FACCF: pbx_exec (pbx.c:1342) ==23672== by 0x8102995: pbx_extension_helper (pbx.c:3684) ==23672== by 0x8103D12: ast_spawn_extension (pbx.c:4137) ==23672== by 0x81043B6: __ast_pbx_run (pbx.c:4227) ==23672== by 0x8105856: pbx_thread (pbx.c:4514) ==23672== by 0x81579DA: dummy_start (utils.c:968) ==23672== Address 0x69BFF48 is 152 bytes inside a block of size 908 free'd ==23672== at 0x4004FDA: free (vg_replace_malloc.c:233) ==23672== by 0x807FD4F: __ast_free_region (astmm.c:192) ==23672== by 0x80800F9: __ast_free (astmm.c:226) ==23672== by 0x8081382: __ao2_ref (astobj2.c:296) ==23672== by 0x8081293: _ao2_ref (astobj2.c:257) ==23672== by 0x7030121: moh_files_release (res_musiconhold.c:217) ==23672== by 0x8098263: ast_deactivate_generator (channel.c:1870) ==23672== by 0x70347B5: local_ast_moh_stop (res_musiconhold.c:1332) ==23672== by 0x80A2E13: ast_moh_stop (channel.c:5192) ==23672== by 0x92C32BC: try_calling (app_queue.c:3851) ==23672== by 0x92C8D70: queue_exec (app_queue.c:5088) ==23672== by 0x80FACCF: pbx_exec (pbx.c:1342) ==23672== ==23672== Invalid read of size 4 ==23672== at 0x703016A: ast_moh_files_next (res_musiconhold.c:231) ==23672== by 0x703052E: moh_files_readframe (res_musiconhold.c:280) ==23672== by 0x7030596: moh_files_generator (res_musiconhold.c:296) ==23672== by 0x8098401: generator_force (channel.c:1898) ==23672== by 0x8099CA9: __ast_read (channel.c:2602) ==23672== by 0x809B5F6: ast_read (channel.c:2964) ==23672== by 0x92C0522: wait_for_answer (app_queue.c:2983) ==23672== by 0x92C2933: try_calling (app_queue.c:3735) ==23672== by 0x92C8D70: queue_exec (app_queue.c:5088) ==23672== by 0x80FACCF: pbx_exec (pbx.c:1342) ==23672== by 0x8102995: pbx_extension_helper (pbx.c:3684) ==23672== by 0x8103D12: ast_spawn_extension (pbx.c:4137) ==23672== Address 0x69C0204 is 852 bytes inside a block of size 908 free'd ==23672== at 0x4004FDA: free (vg_replace_malloc.c:233) ==23672== by 0x807FD4F: __ast_free_region (astmm.c:192) ==23672== by 0x80800F9: __ast_free (astmm.c:226) ==23672== by 0x8081382: __ao2_ref (astobj2.c:296) ==23672== by 0x8081293: _ao2_ref (astobj2.c:257) ==23672== by 0x7030121: moh_files_release (res_musiconhold.c:217) ==23672== by 0x8098263: ast_deactivate_generator (channel.c:1870) ==23672== by 0x70347B5: local_ast_moh_stop (res_musiconhold.c:1332) ==23672== by 0x80A2E13: ast_moh_stop (channel.c:5192) ==23672== by 0x92C32BC: try_calling (app_queue.c:3851) ==23672== by 0x92C8D70: queue_exec (app_queue.c:5088) ==23672== by 0x80FACCF: pbx_exec (pbx.c:1342) ==23672== ==23672== Invalid read of size 4 ==23672== at 0x70301D0: ast_moh_files_next (res_musiconhold.c:237) ==23672== by 0x703052E: moh_files_readframe (res_musiconhold.c:280) ==23672== by 0x7030596: moh_files_generator (res_musiconhold.c:296) ==23672== by 0x8098401: generator_force (channel.c:1898) ==23672== by 0x8099CA9: __ast_read (channel.c:2602) ==23672== by 0x809B5F6: ast_read (channel.c:2964) ==23672== by 0x92C0522: wait_for_answer (app_queue.c:2983) ==23672== by 0x92C2933: try_calling (app_queue.c:3735) ==23672== by 0x92C8D70: queue_exec (app_queue.c:5088) ==23672== by 0x80FACCF: pbx_exec (pbx.c:1342) ==23672== by 0x8102995: pbx_extension_helper (pbx.c:3684) ==23672== by 0x8103D12: ast_spawn_extension (pbx.c:4137) ==23672== Address 0x69C0204 is 852 bytes inside a block of size 908 free'd ==23672== at 0x4004FDA: free (vg_replace_malloc.c:233) ==23672== by 0x807FD4F: __ast_free_region (astmm.c:192) ==23672== by 0x80800F9: __ast_free (astmm.c:226) ==23672== by 0x8081382: __ao2_ref (astobj2.c:296) ==23672== by 0x8081293: _ao2_ref (astobj2.c:257) ==23672== by 0x7030121: moh_files_release (res_musiconhold.c:217) ==23672== by 0x8098263: ast_deactivate_generator (channel.c:1870) ==23672== by 0x70347B5: local_ast_moh_stop (res_musiconhold.c:1332) ==23672== by 0x80A2E13: ast_moh_stop (channel.c:5192) ==23672== by 0x92C32BC: try_calling (app_queue.c:3851) ==23672== by 0x92C8D70: queue_exec (app_queue.c:5088) ==23672== by 0x80FACCF: pbx_exec (pbx.c:1342) ==23672== ==23672== Invalid read of size 4 ==23672== at 0x70301DF: ast_moh_files_next (res_musiconhold.c:237) ==23672== by 0x703052E: moh_files_readframe (res_musiconhold.c:280) ==23672== by 0x7030596: moh_files_generator (res_musiconhold.c:296) ==23672== by 0x8098401: generator_force (channel.c:1898) ==23672== by 0x8099CA9: __ast_read (channel.c:2602) ==23672== by 0x809B5F6: ast_read (channel.c:2964) ==23672== by 0x92C0522: wait_for_answer (app_queue.c:2983) ==23672== by 0x92C2933: try_calling (app_queue.c:3735) ==23672== by 0x92C8D70: queue_exec (app_queue.c:5088) ==23672== by 0x80FACCF: pbx_exec (pbx.c:1342) ==23672== by 0x8102995: pbx_extension_helper (pbx.c:3684) ==23672== by 0x8103D12: ast_spawn_extension (pbx.c:4137) ==23672== Address 0x69C01FC is 844 bytes inside a block of size 908 free'd ==23672== at 0x4004FDA: free (vg_replace_malloc.c:233) ==23672== by 0x807FD4F: __ast_free_region (astmm.c:192) ==23672== by 0x80800F9: __ast_free (astmm.c:226) ==23672== by 0x8081382: __ao2_ref (astobj2.c:296) ==23672== by 0x8081293: _ao2_ref (astobj2.c:257) ==23672== by 0x7030121: moh_files_release (res_musiconhold.c:217) ==23672== by 0x8098263: ast_deactivate_generator (channel.c:1870) ==23672== by 0x70347B5: local_ast_moh_stop (res_musiconhold.c:1332) ==23672== by 0x80A2E13: ast_moh_stop (channel.c:5192) ==23672== by 0x92C32BC: try_calling (app_queue.c:3851) ==23672== by 0x92C8D70: queue_exec (app_queue.c:5088) ==23672== by 0x80FACCF: pbx_exec (pbx.c:1342) ==23672== ==23672== Invalid read of size 4 ==23672== at 0x70301F1: ast_moh_files_next (res_musiconhold.c:237) ==23672== by 0x703052E: moh_files_readframe (res_musiconhold.c:280) ==23672== by 0x7030596: moh_files_generator (res_musiconhold.c:296) ==23672== by 0x8098401: generator_force (channel.c:1898) ==23672== by 0x8099CA9: __ast_read (channel.c:2602) ==23672== by 0x809B5F6: ast_read (channel.c:2964) ==23672== by 0x92C0522: wait_for_answer (app_queue.c:2983) ==23672== by 0x92C2933: try_calling (app_queue.c:3735) ==23672== by 0x92C8D70: queue_exec (app_queue.c:5088) ==23672== by 0x80FACCF: pbx_exec (pbx.c:1342) ==23672== by 0x8102995: pbx_extension_helper (pbx.c:3684) ==23672== by 0x8103D12: ast_spawn_extension (pbx.c:4137) ==23672== Address 0x0 is not stack'd, malloc'd or (recently) free'd ==23672== ==23672== Process terminating with default action of signal 11 (SIGSEGV): dumping core ==23672== Access not within mapped region at address 0x0 ==23672== at 0x70301F1: ast_moh_files_next (res_musiconhold.c:237) ==23672== by 0x703052E: moh_files_readframe (res_musiconhold.c:280) ==23672== by 0x7030596: moh_files_generator (res_musiconhold.c:296) ==23672== by 0x8098401: generator_force (channel.c:1898) ==23672== by 0x8099CA9: __ast_read (channel.c:2602) ==23672== by 0x809B5F6: ast_read (channel.c:2964) ==23672== by 0x92C0522: wait_for_answer (app_queue.c:2983) ==23672== by 0x92C2933: try_calling (app_queue.c:3735) ==23672== by 0x92C8D70: queue_exec (app_queue.c:5088) ==23672== by 0x80FACCF: pbx_exec (pbx.c:1342) ==23672== by 0x8102995: pbx_extension_helper (pbx.c:3684) ==23672== by 0x8103D12: ast_spawn_extension (pbx.c:4137) ==23672== ==23672== ERROR SUMMARY: 37337 errors from 34 contexts (suppressed: 2059 from 1) ==23672== malloc/free: in use at exit: 4,886,126 bytes in 47,127 blocks. ==23672== malloc/free: 200,859 allocs, 153,732 frees, 22,197,650 bytes allocated. ==23672== For counts of detected errors, rerun with: -v ==23672== searching for pointers to 47,127 not-freed blocks. ==23672== checked 21,982,272 bytes. ==23672== ==23672== LEAK SUMMARY: ==23672== definitely lost: 669 bytes in 36 blocks. ==23672== possibly lost: 8,578 bytes in 122 blocks. ==23672== still reachable: 4,876,879 bytes in 46,969 blocks. ==23672== suppressed: 0 bytes in 0 blocks. ==23672== Use --leak-check=full to see details of leaked memory.