==20631== Memcheck, a memory error detector. ==20631== Copyright (C) 2002-2007, and GNU GPL'd, by Julian Seward et al. ==20631== Using LibVEX rev 1854, a library for dynamic binary translation. ==20631== Copyright (C) 2004-2007, and GNU GPL'd, by OpenWorks LLP. ==20631== Using valgrind-3.3.1-Debian, a dynamic binary instrumentation framework. ==20631== Copyright (C) 2000-2007, and GNU GPL'd, by Julian Seward et al. ==20631== For more details, rerun with: -v ==20631== ==20631== Invalid read of size 1 ==20631== at 0x401323D: _dl_close (in /lib/ld-2.7.so) ==20631== by 0x4443CD3: dlclose_doit (dlclose.c:37) ==20631== by 0x400DA15: _dl_catch_error (in /lib/ld-2.7.so) ==20631== by 0x44440EB: _dlerror_run (dlerror.c:164) ==20631== by 0x4443D09: dlclose (dlclose.c:48) ==20631== by 0x8100F91: load_dynamic_module (loader.c:412) ==20631== by 0x810227A: load_resource (loader.c:813) ==20631== by 0x81026C9: load_resource_list (loader.c:927) ==20631== by 0x8102E7B: load_modules (loader.c:1098) ==20631== by 0x808208B: main (asterisk.c:3606) ==20631== Address 0x527f0e0 is 512 bytes inside a block of size 650 free'd ==20631== at 0x4022B8A: free (vg_replace_malloc.c:323) ==20631== by 0x4012DEE: _dl_close_worker (in /lib/ld-2.7.so) ==20631== by 0x4013266: _dl_close (in /lib/ld-2.7.so) ==20631== by 0x4443CD3: dlclose_doit (dlclose.c:37) ==20631== by 0x400DA15: _dl_catch_error (in /lib/ld-2.7.so) ==20631== by 0x44440EB: _dlerror_run (dlerror.c:164) ==20631== by 0x4443D09: dlclose (dlclose.c:48) ==20631== by 0x8100F91: load_dynamic_module (loader.c:412) ==20631== by 0x810227A: load_resource (loader.c:813) ==20631== by 0x81026C9: load_resource_list (loader.c:927) ==20631== by 0x8102E7B: load_modules (loader.c:1098) ==20631== by 0x808208B: main (asterisk.c:3606) ==20631== ==20631== Invalid read of size 4 ==20631== at 0x4013246: _dl_close (in /lib/ld-2.7.so) ==20631== by 0x4443CD3: dlclose_doit (dlclose.c:37) ==20631== by 0x400DA15: _dl_catch_error (in /lib/ld-2.7.so) ==20631== by 0x44440EB: _dlerror_run (dlerror.c:164) ==20631== by 0x4443D09: dlclose (dlclose.c:48) ==20631== by 0x8100F91: load_dynamic_module (loader.c:412) ==20631== by 0x810227A: load_resource (loader.c:813) ==20631== by 0x81026C9: load_resource_list (loader.c:927) ==20631== by 0x8102E7B: load_modules (loader.c:1098) ==20631== by 0x808208B: main (asterisk.c:3606) ==20631== Address 0x527f070 is 400 bytes inside a block of size 650 free'd ==20631== at 0x4022B8A: free (vg_replace_malloc.c:323) ==20631== by 0x4012DEE: _dl_close_worker (in /lib/ld-2.7.so) ==20631== by 0x4013266: _dl_close (in /lib/ld-2.7.so) ==20631== by 0x4443CD3: dlclose_doit (dlclose.c:37) ==20631== by 0x400DA15: _dl_catch_error (in /lib/ld-2.7.so) ==20631== by 0x44440EB: _dlerror_run (dlerror.c:164) ==20631== by 0x4443D09: dlclose (dlclose.c:48) ==20631== by 0x8100F91: load_dynamic_module (loader.c:412) ==20631== by 0x810227A: load_resource (loader.c:813) ==20631== by 0x81026C9: load_resource_list (loader.c:927) ==20631== by 0x8102E7B: load_modules (loader.c:1098) ==20631== by 0x808208B: main (asterisk.c:3606) ==20631== ==20631== Invalid read of size 4 ==20631== at 0x40132B0: _dl_close (in /lib/ld-2.7.so) ==20631== by 0x4443CD3: dlclose_doit (dlclose.c:37) ==20631== by 0x400DA15: _dl_catch_error (in /lib/ld-2.7.so) ==20631== by 0x44440EB: _dlerror_run (dlerror.c:164) ==20631== by 0x4443D09: dlclose (dlclose.c:48) ==20631== by 0x8100F91: load_dynamic_module (loader.c:412) ==20631== by 0x810227A: load_resource (loader.c:813) ==20631== by 0x81026C9: load_resource_list (loader.c:927) ==20631== by 0x8102E7B: load_modules (loader.c:1098) ==20631== by 0x808208B: main (asterisk.c:3606) ==20631== Address 0x527eee4 is 4 bytes inside a block of size 650 free'd ==20631== at 0x4022B8A: free (vg_replace_malloc.c:323) ==20631== by 0x4012DEE: _dl_close_worker (in /lib/ld-2.7.so) ==20631== by 0x4013266: _dl_close (in /lib/ld-2.7.so) ==20631== by 0x4443CD3: dlclose_doit (dlclose.c:37) ==20631== by 0x400DA15: _dl_catch_error (in /lib/ld-2.7.so) ==20631== by 0x44440EB: _dlerror_run (dlerror.c:164) ==20631== by 0x4443D09: dlclose (dlclose.c:48) ==20631== by 0x8100F91: load_dynamic_module (loader.c:412) ==20631== by 0x810227A: load_resource (loader.c:813) ==20631== by 0x81026C9: load_resource_list (loader.c:927) ==20631== by 0x8102E7B: load_modules (loader.c:1098) ==20631== by 0x808208B: main (asterisk.c:3606) ==20631== ==20631== Invalid read of size 1 ==20631== at 0x4024498: strlen (mc_replace_strmem.c:243) ==20631== by 0x400DAFB: _dl_signal_error (in /lib/ld-2.7.so) ==20631== by 0x40132C5: _dl_close (in /lib/ld-2.7.so) ==20631== by 0x4443CD3: dlclose_doit (dlclose.c:37) ==20631== by 0x400DA15: _dl_catch_error (in /lib/ld-2.7.so) ==20631== by 0x44440EB: _dlerror_run (dlerror.c:164) ==20631== by 0x4443D09: dlclose (dlclose.c:48) ==20631== by 0x8100F91: load_dynamic_module (loader.c:412) ==20631== by 0x810227A: load_resource (loader.c:813) ==20631== by 0x81026C9: load_resource_list (loader.c:927) ==20631== by 0x8102E7B: load_modules (loader.c:1098) ==20631== by 0x808208B: main (asterisk.c:3606) ==20631== Address 0x527ee80 is 0 bytes inside a block of size 46 free'd ==20631== at 0x4022B8A: free (vg_replace_malloc.c:323) ==20631== by 0x4012D70: _dl_close_worker (in /lib/ld-2.7.so) ==20631== by 0x4013266: _dl_close (in /lib/ld-2.7.so) ==20631== by 0x4443CD3: dlclose_doit (dlclose.c:37) ==20631== by 0x400DA15: _dl_catch_error (in /lib/ld-2.7.so) ==20631== by 0x44440EB: _dlerror_run (dlerror.c:164) ==20631== by 0x4443D09: dlclose (dlclose.c:48) ==20631== by 0x8100F91: load_dynamic_module (loader.c:412) ==20631== by 0x810227A: load_resource (loader.c:813) ==20631== by 0x81026C9: load_resource_list (loader.c:927) ==20631== by 0x8102E7B: load_modules (loader.c:1098) ==20631== by 0x808208B: main (asterisk.c:3606) ==20631== ==20631== Invalid read of size 1 ==20631== at 0x40244A3: strlen (mc_replace_strmem.c:243) ==20631== by 0x400DAFB: _dl_signal_error (in /lib/ld-2.7.so) ==20631== by 0x40132C5: _dl_close (in /lib/ld-2.7.so) ==20631== by 0x4443CD3: dlclose_doit (dlclose.c:37) ==20631== by 0x400DA15: _dl_catch_error (in /lib/ld-2.7.so) ==20631== by 0x44440EB: _dlerror_run (dlerror.c:164) ==20631== by 0x4443D09: dlclose (dlclose.c:48) ==20631== by 0x8100F91: load_dynamic_module (loader.c:412) ==20631== by 0x810227A: load_resource (loader.c:813) ==20631== by 0x81026C9: load_resource_list (loader.c:927) ==20631== by 0x8102E7B: load_modules (loader.c:1098) ==20631== by 0x808208B: main (asterisk.c:3606) ==20631== Address 0x527ee81 is 1 bytes inside a block of size 46 free'd ==20631== at 0x4022B8A: free (vg_replace_malloc.c:323) ==20631== by 0x4012D70: _dl_close_worker (in /lib/ld-2.7.so) ==20631== by 0x4013266: _dl_close (in /lib/ld-2.7.so) ==20631== by 0x4443CD3: dlclose_doit (dlclose.c:37) ==20631== by 0x400DA15: _dl_catch_error (in /lib/ld-2.7.so) ==20631== by 0x44440EB: _dlerror_run (dlerror.c:164) ==20631== by 0x4443D09: dlclose (dlclose.c:48) ==20631== by 0x8100F91: load_dynamic_module (loader.c:412) ==20631== by 0x810227A: load_resource (loader.c:813) ==20631== by 0x81026C9: load_resource_list (loader.c:927) ==20631== by 0x8102E7B: load_modules (loader.c:1098) ==20631== by 0x808208B: main (asterisk.c:3606) ==20631== ==20631== Invalid read of size 1 ==20631== at 0x4015CA7: memcpy (in /lib/ld-2.7.so) ==20631== by 0x400DB59: _dl_signal_error (in /lib/ld-2.7.so) ==20631== by 0x40132C5: _dl_close (in /lib/ld-2.7.so) ==20631== by 0x4443CD3: dlclose_doit (dlclose.c:37) ==20631== by 0x400DA15: _dl_catch_error (in /lib/ld-2.7.so) ==20631== by 0x44440EB: _dlerror_run (dlerror.c:164) ==20631== by 0x4443D09: dlclose (dlclose.c:48) ==20631== by 0x8100F91: load_dynamic_module (loader.c:412) ==20631== by 0x810227A: load_resource (loader.c:813) ==20631== by 0x81026C9: load_resource_list (loader.c:927) ==20631== by 0x8102E7B: load_modules (loader.c:1098) ==20631== by 0x808208B: main (asterisk.c:3606) ==20631== Address 0x527ee80 is 0 bytes inside a block of size 46 free'd ==20631== at 0x4022B8A: free (vg_replace_malloc.c:323) ==20631== by 0x4012D70: _dl_close_worker (in /lib/ld-2.7.so) ==20631== by 0x4013266: _dl_close (in /lib/ld-2.7.so) ==20631== by 0x4443CD3: dlclose_doit (dlclose.c:37) ==20631== by 0x400DA15: _dl_catch_error (in /lib/ld-2.7.so) ==20631== by 0x44440EB: _dlerror_run (dlerror.c:164) ==20631== by 0x4443D09: dlclose (dlclose.c:48) ==20631== by 0x8100F91: load_dynamic_module (loader.c:412) ==20631== by 0x810227A: load_resource (loader.c:813) ==20631== by 0x81026C9: load_resource_list (loader.c:927) ==20631== by 0x8102E7B: load_modules (loader.c:1098) ==20631== by 0x808208B: main (asterisk.c:3606) ==20631== ==20631== Invalid read of size 1 ==20631== at 0x4015CB7: memcpy (in /lib/ld-2.7.so) ==20631== by 0x400DB59: _dl_signal_error (in /lib/ld-2.7.so) ==20631== by 0x40132C5: _dl_close (in /lib/ld-2.7.so) ==20631== by 0x4443CD3: dlclose_doit (dlclose.c:37) ==20631== by 0x400DA15: _dl_catch_error (in /lib/ld-2.7.so) ==20631== by 0x44440EB: _dlerror_run (dlerror.c:164) ==20631== by 0x4443D09: dlclose (dlclose.c:48) ==20631== by 0x8100F91: load_dynamic_module (loader.c:412) ==20631== by 0x810227A: load_resource (loader.c:813) ==20631== by 0x81026C9: load_resource_list (loader.c:927) ==20631== by 0x8102E7B: load_modules (loader.c:1098) ==20631== by 0x808208B: main (asterisk.c:3606) ==20631== Address 0x527eead is 45 bytes inside a block of size 46 free'd ==20631== at 0x4022B8A: free (vg_replace_malloc.c:323) ==20631== by 0x4012D70: _dl_close_worker (in /lib/ld-2.7.so) ==20631== by 0x4013266: _dl_close (in /lib/ld-2.7.so) ==20631== by 0x4443CD3: dlclose_doit (dlclose.c:37) ==20631== by 0x400DA15: _dl_catch_error (in /lib/ld-2.7.so) ==20631== by 0x44440EB: _dlerror_run (dlerror.c:164) ==20631== by 0x4443D09: dlclose (dlclose.c:48) ==20631== by 0x8100F91: load_dynamic_module (loader.c:412) ==20631== by 0x810227A: load_resource (loader.c:813) ==20631== by 0x81026C9: load_resource_list (loader.c:927) ==20631== by 0x8102E7B: load_modules (loader.c:1098) ==20631== by 0x808208B: main (asterisk.c:3606) ==20631== ==20631== Source and destination overlap in strcpy(0xBEFF8D41, 0xBEFF8D42) ==20631== at 0x402457D: strcpy (mc_replace_strmem.c:268) ==20631== by 0x80BF296: process_text_line (config.c:1067) ==20631== by 0x80C08CD: config_text_file_load (config.c:1416) ==20631== by 0x80C2BDB: ast_config_internal_load (config.c:2080) ==20631== by 0x80C2C6C: ast_config_load2 (config.c:2099) ==20631== by 0x5FB6D93: pbx_load_config (pbx_config.c:1384) ==20631== by 0x5FB8DAA: pbx_load_module (pbx_config.c:1720) ==20631== by 0x5FB8E6E: load_module (pbx_config.c:1741) ==20631== by 0x8101FC3: start_resource (loader.c:762) ==20631== by 0x8102874: load_resource_list (loader.c:950) ==20631== by 0x8102E9E: load_modules (loader.c:1103) ==20631== by 0x80822F9: main (asterisk.c:3680) ==20631== ==20631== Syscall param ioctl(generic) points to uninitialised byte(s) ==20631== at 0x428F5B4: ioctl (in /usr/lib/debug/libc-2.7.so) ==20631== by 0x5B36DED: build_channels (chan_dahdi.c:15747) ==20631== by 0x5B374EF: process_dahdi (chan_dahdi.c:15844) ==20631== by 0x5B3C98E: setup_dahdi (chan_dahdi.c:16932) ==20631== by 0x5B3CF85: load_module (chan_dahdi.c:17074) ==20631== by 0x8101FC3: start_resource (loader.c:762) ==20631== by 0x8102874: load_resource_list (loader.c:950) ==20631== by 0x8102E9E: load_modules (loader.c:1103) ==20631== by 0x80822F9: main (asterisk.c:3680) ==20631== Address 0xbeff6968 is on thread 1's stack ==20631== Warning: noted but unhandled ioctl 0xda34 with no size/direction hints ==20631== This could cause spurious value errors to appear. ==20631== See README_MISSING_SYSCALL_OR_IOCTL for guidance on writing a proper wrapper. ==20631== Warning: noted but unhandled ioctl 0xda35 with no size/direction hints ==20631== This could cause spurious value errors to appear. ==20631== See README_MISSING_SYSCALL_OR_IOCTL for guidance on writing a proper wrapper. ==20631== Warning: noted but unhandled ioctl 0xda34 with no size/direction hints ==20631== This could cause spurious value errors to appear. ==20631== See README_MISSING_SYSCALL_OR_IOCTL for guidance on writing a proper wrapper. ==20631== ==20631== Thread 51: ==20631== Invalid read of size 4 ==20631== at 0x80828E5: INTERNAL_OBJ (astobj2.c:115) ==20631== by 0x8082BA9: __ao2_ref (astobj2.c:251) ==20631== by 0x8083304: __ao2_link (astobj2.c:544) ==20631== by 0x80AE09E: ast_do_masquerade (channel.c:5488) ==20631== by 0x80A33C5: ast_waitfor_nandfds (channel.c:2549) ==20631== by 0x80A3BB7: ast_waitfor_n (channel.c:2863) ==20631== by 0x80AE9F2: ast_generic_bridge (channel.c:5687) ==20631== by 0x80B0B36: ast_channel_bridge (channel.c:6121) ==20631== by 0x80E1E2F: ast_bridge_call (features.c:3104) ==20631== by 0x6031788: dial_exec_full (app_dial.c:2428) ==20631== by 0x603217C: dial_exec (app_dial.c:2521) ==20631== by 0x811BCA1: pbx_exec (pbx.c:1395) ==20631== Address 0x75130fc is 36 bytes inside a block of size 1,072 free'd ==20631== at 0x4022B8A: free (vg_replace_malloc.c:323) ==20631== by 0x8082D02: internal_ao2_ref (astobj2.c:298) ==20631== by 0x8082BCD: __ao2_ref (astobj2.c:256) ==20631== by 0x80A0A23: ast_channel_release (channel.c:1478) ==20631== by 0x80A296B: ast_hangup (channel.c:2270) ==20631== by 0x6031D10: dial_exec_full (app_dial.c:2469) ==20631== by 0x603217C: dial_exec (app_dial.c:2521) ==20631== by 0x811BCA1: pbx_exec (pbx.c:1395) ==20631== by 0x8125497: pbx_extension_helper (pbx.c:4069) ==20631== by 0x8126B53: ast_spawn_extension (pbx.c:4549) ==20631== by 0x81271FC: __ast_pbx_run (pbx.c:4643) ==20631== by 0x8128718: pbx_thread (pbx.c:4930) ==20631== ==20631== Invalid read of size 4 ==20631== at 0x80828E5: INTERNAL_OBJ (astobj2.c:115) ==20631== by 0x8082BE6: internal_ao2_ref (astobj2.c:261) ==20631== by 0x8082BCD: __ao2_ref (astobj2.c:256) ==20631== by 0x8083304: __ao2_link (astobj2.c:544) ==20631== by 0x80AE09E: ast_do_masquerade (channel.c:5488) ==20631== by 0x80A33C5: ast_waitfor_nandfds (channel.c:2549) ==20631== by 0x80A3BB7: ast_waitfor_n (channel.c:2863) ==20631== by 0x80AE9F2: ast_generic_bridge (channel.c:5687) ==20631== by 0x80B0B36: ast_channel_bridge (channel.c:6121) ==20631== by 0x80E1E2F: ast_bridge_call (features.c:3104) ==20631== by 0x6031788: dial_exec_full (app_dial.c:2428) ==20631== by 0x603217C: dial_exec (app_dial.c:2521) ==20631== Address 0x75130fc is 36 bytes inside a block of size 1,072 free'd ==20631== at 0x4022B8A: free (vg_replace_malloc.c:323) ==20631== by 0x8082D02: internal_ao2_ref (astobj2.c:298) ==20631== by 0x8082BCD: __ao2_ref (astobj2.c:256) ==20631== by 0x80A0A23: ast_channel_release (channel.c:1478) ==20631== by 0x80A296B: ast_hangup (channel.c:2270) ==20631== by 0x6031D10: dial_exec_full (app_dial.c:2469) ==20631== by 0x603217C: dial_exec (app_dial.c:2521) ==20631== by 0x811BCA1: pbx_exec (pbx.c:1395) ==20631== by 0x8125497: pbx_extension_helper (pbx.c:4069) ==20631== by 0x8126B53: ast_spawn_extension (pbx.c:4549) ==20631== by 0x81271FC: __ast_pbx_run (pbx.c:4643) ==20631== by 0x8128718: pbx_thread (pbx.c:4930) ==20631== ==20631== Invalid read of size 4 ==20631== at 0x8178F95: ast_atomic_fetchadd_int (lock.h:1962) ==20631== by 0x8082C26: internal_ao2_ref (astobj2.c:273) ==20631== by 0x8082BCD: __ao2_ref (astobj2.c:256) ==20631== by 0x8083304: __ao2_link (astobj2.c:544) ==20631== by 0x80AE09E: ast_do_masquerade (channel.c:5488) ==20631== by 0x80A33C5: ast_waitfor_nandfds (channel.c:2549) ==20631== by 0x80A3BB7: ast_waitfor_n (channel.c:2863) ==20631== by 0x80AE9F2: ast_generic_bridge (channel.c:5687) ==20631== by 0x80B0B36: ast_channel_bridge (channel.c:6121) ==20631== by 0x80E1E2F: ast_bridge_call (features.c:3104) ==20631== by 0x6031788: dial_exec_full (app_dial.c:2428) ==20631== by 0x603217C: dial_exec (app_dial.c:2521) ==20631== Address 0x75130f0 is 24 bytes inside a block of size 1,072 free'd ==20631== at 0x4022B8A: free (vg_replace_malloc.c:323) ==20631== by 0x8082D02: internal_ao2_ref (astobj2.c:298) ==20631== by 0x8082BCD: __ao2_ref (astobj2.c:256) ==20631== by 0x80A0A23: ast_channel_release (channel.c:1478) ==20631== by 0x80A296B: ast_hangup (channel.c:2270) ==20631== by 0x6031D10: dial_exec_full (app_dial.c:2469) ==20631== by 0x603217C: dial_exec (app_dial.c:2521) ==20631== by 0x811BCA1: pbx_exec (pbx.c:1395) ==20631== by 0x8125497: pbx_extension_helper (pbx.c:4069) ==20631== by 0x8126B53: ast_spawn_extension (pbx.c:4549) ==20631== by 0x81271FC: __ast_pbx_run (pbx.c:4643) ==20631== by 0x8128718: pbx_thread (pbx.c:4930) ==20631== ==20631== Invalid read of size 4 ==20631== at 0x80828E5: INTERNAL_OBJ (astobj2.c:115) ==20631== by 0x808285E: ao2_lock (astobj2.c:152) ==20631== by 0x80A0254: ast_channel_cmp_cb (channel.c:1325) ==20631== by 0x80836B1: internal_ao2_callback (astobj2.c:693) ==20631== by 0x8083A52: __ao2_callback (astobj2.c:789) ==20631== by 0x8083B6E: __ao2_find (astobj2.c:816) ==20631== by 0x80A0783: ast_channel_get_full (channel.c:1393) ==20631== by 0x80A07C1: ast_channel_get_by_name (channel.c:1399) ==20631== by 0x80E3289: ast_bridge_call (features.c:3416) ==20631== by 0x6031788: dial_exec_full (app_dial.c:2428) ==20631== by 0x603217C: dial_exec (app_dial.c:2521) ==20631== by 0x811BCA1: pbx_exec (pbx.c:1395) ==20631== Address 0x75130fc is 36 bytes inside a block of size 1,072 free'd ==20631== at 0x4022B8A: free (vg_replace_malloc.c:323) ==20631== by 0x8082D02: internal_ao2_ref (astobj2.c:298) ==20631== by 0x8082BCD: __ao2_ref (astobj2.c:256) ==20631== by 0x80A0A23: ast_channel_release (channel.c:1478) ==20631== by 0x80A296B: ast_hangup (channel.c:2270) ==20631== by 0x6031D10: dial_exec_full (app_dial.c:2469) ==20631== by 0x603217C: dial_exec (app_dial.c:2521) ==20631== by 0x811BCA1: pbx_exec (pbx.c:1395) ==20631== by 0x8125497: pbx_extension_helper (pbx.c:4069) ==20631== by 0x8126B53: ast_spawn_extension (pbx.c:4549) ==20631== by 0x81271FC: __ast_pbx_run (pbx.c:4643) ==20631== by 0x8128718: pbx_thread (pbx.c:4930) ==20631== ==20631== Invalid read of size 4 ==20631== at 0x444E2A0: pthread_mutex_lock (pthread_mutex_lock.c:51) ==20631== by 0x42A2C65: pthread_mutex_lock (forward.c:182) ==20631== by 0x808294E: ast_mutex_lock (lock.h:1720) ==20631== by 0x808288F: ao2_lock (astobj2.c:162) ==20631== by 0x80A0254: ast_channel_cmp_cb (channel.c:1325) ==20631== by 0x80836B1: internal_ao2_callback (astobj2.c:693) ==20631== by 0x8083A52: __ao2_callback (astobj2.c:789) ==20631== by 0x8083B6E: __ao2_find (astobj2.c:816) ==20631== by 0x80A0783: ast_channel_get_full (channel.c:1393) ==20631== by 0x80A07C1: ast_channel_get_by_name (channel.c:1399) ==20631== by 0x80E3289: ast_bridge_call (features.c:3416) ==20631== by 0x6031788: dial_exec_full (app_dial.c:2428) ==20631== Address 0x75130e4 is 12 bytes inside a block of size 1,072 free'd ==20631== at 0x4022B8A: free (vg_replace_malloc.c:323) ==20631== by 0x8082D02: internal_ao2_ref (astobj2.c:298) ==20631== by 0x8082BCD: __ao2_ref (astobj2.c:256) ==20631== by 0x80A0A23: ast_channel_release (channel.c:1478) ==20631== by 0x80A296B: ast_hangup (channel.c:2270) ==20631== by 0x6031D10: dial_exec_full (app_dial.c:2469) ==20631== by 0x603217C: dial_exec (app_dial.c:2521) ==20631== by 0x811BCA1: pbx_exec (pbx.c:1395) ==20631== by 0x8125497: pbx_extension_helper (pbx.c:4069) ==20631== by 0x8126B53: ast_spawn_extension (pbx.c:4549) ==20631== by 0x81271FC: __ast_pbx_run (pbx.c:4643) ==20631== by 0x8128718: pbx_thread (pbx.c:4930) ==20631== ==20631== Invalid read of size 4 ==20631== at 0x80A0501: ast_channel_cmp_cb (channel.c:1342) ==20631== by 0x80836B1: internal_ao2_callback (astobj2.c:693) ==20631== by 0x8083A52: __ao2_callback (astobj2.c:789) ==20631== by 0x8083B6E: __ao2_find (astobj2.c:816) ==20631== by 0x80A0783: ast_channel_get_full (channel.c:1393) ==20631== by 0x80A07C1: ast_channel_get_by_name (channel.c:1399) ==20631== by 0x80E3289: ast_bridge_call (features.c:3416) ==20631== by 0x6031788: dial_exec_full (app_dial.c:2428) ==20631== by 0x603217C: dial_exec (app_dial.c:2521) ==20631== by 0x811BCA1: pbx_exec (pbx.c:1395) ==20631== by 0x8125497: pbx_extension_helper (pbx.c:4069) ==20631== by 0x8126B53: ast_spawn_extension (pbx.c:4549) ==20631== Address 0x751317c is 164 bytes inside a block of size 1,072 free'd ==20631== at 0x4022B8A: free (vg_replace_malloc.c:323) ==20631== by 0x8082D02: internal_ao2_ref (astobj2.c:298) ==20631== by 0x8082BCD: __ao2_ref (astobj2.c:256) ==20631== by 0x80A0A23: ast_channel_release (channel.c:1478) ==20631== by 0x80A296B: ast_hangup (channel.c:2270) ==20631== by 0x6031D10: dial_exec_full (app_dial.c:2469) ==20631== by 0x603217C: dial_exec (app_dial.c:2521) ==20631== by 0x811BCA1: pbx_exec (pbx.c:1395) ==20631== by 0x8125497: pbx_extension_helper (pbx.c:4069) ==20631== by 0x8126B53: ast_spawn_extension (pbx.c:4549) ==20631== by 0x81271FC: __ast_pbx_run (pbx.c:4643) ==20631== by 0x8128718: pbx_thread (pbx.c:4930) ==20631== ==20631== Invalid read of size 4 ==20631== at 0x80828E5: INTERNAL_OBJ (astobj2.c:115) ==20631== by 0x8082961: ao2_unlock (astobj2.c:174) ==20631== by 0x80A0557: ast_channel_cmp_cb (channel.c:1350) ==20631== by 0x80836B1: internal_ao2_callback (astobj2.c:693) ==20631== by 0x8083A52: __ao2_callback (astobj2.c:789) ==20631== by 0x8083B6E: __ao2_find (astobj2.c:816) ==20631== by 0x80A0783: ast_channel_get_full (channel.c:1393) ==20631== by 0x80A07C1: ast_channel_get_by_name (channel.c:1399) ==20631== by 0x80E3289: ast_bridge_call (features.c:3416) ==20631== by 0x6031788: dial_exec_full (app_dial.c:2428) ==20631== by 0x603217C: dial_exec (app_dial.c:2521) ==20631== by 0x811BCA1: pbx_exec (pbx.c:1395) ==20631== Address 0x75130fc is 36 bytes inside a block of size 1,072 free'd ==20631== at 0x4022B8A: free (vg_replace_malloc.c:323) ==20631== by 0x8082D02: internal_ao2_ref (astobj2.c:298) ==20631== by 0x8082BCD: __ao2_ref (astobj2.c:256) ==20631== by 0x80A0A23: ast_channel_release (channel.c:1478) ==20631== by 0x80A296B: ast_hangup (channel.c:2270) ==20631== by 0x6031D10: dial_exec_full (app_dial.c:2469) ==20631== by 0x603217C: dial_exec (app_dial.c:2521) ==20631== by 0x811BCA1: pbx_exec (pbx.c:1395) ==20631== by 0x8125497: pbx_extension_helper (pbx.c:4069) ==20631== by 0x8126B53: ast_spawn_extension (pbx.c:4549) ==20631== by 0x81271FC: __ast_pbx_run (pbx.c:4643) ==20631== by 0x8128718: pbx_thread (pbx.c:4930) ==20631== ==20631== Invalid read of size 4 ==20631== at 0x444F904: __pthread_mutex_unlock_usercnt (pthread_mutex_unlock.c:35) ==20631== by 0x42A2CA5: pthread_mutex_unlock (forward.c:184) ==20631== by 0x80829AB: ast_mutex_unlock (lock.h:1710) ==20631== by 0x8082992: ao2_unlock (astobj2.c:184) ==20631== by 0x80A0557: ast_channel_cmp_cb (channel.c:1350) ==20631== by 0x80836B1: internal_ao2_callback (astobj2.c:693) ==20631== by 0x8083A52: __ao2_callback (astobj2.c:789) ==20631== by 0x8083B6E: __ao2_find (astobj2.c:816) ==20631== by 0x80A0783: ast_channel_get_full (channel.c:1393) ==20631== by 0x80A07C1: ast_channel_get_by_name (channel.c:1399) ==20631== by 0x80E3289: ast_bridge_call (features.c:3416) ==20631== by 0x6031788: dial_exec_full (app_dial.c:2428) ==20631== Address 0x75130e4 is 12 bytes inside a block of size 1,072 free'd ==20631== at 0x4022B8A: free (vg_replace_malloc.c:323) ==20631== by 0x8082D02: internal_ao2_ref (astobj2.c:298) ==20631== by 0x8082BCD: __ao2_ref (astobj2.c:256) ==20631== by 0x80A0A23: ast_channel_release (channel.c:1478) ==20631== by 0x80A296B: ast_hangup (channel.c:2270) ==20631== by 0x6031D10: dial_exec_full (app_dial.c:2469) ==20631== by 0x603217C: dial_exec (app_dial.c:2521) ==20631== by 0x811BCA1: pbx_exec (pbx.c:1395) ==20631== by 0x8125497: pbx_extension_helper (pbx.c:4069) ==20631== by 0x8126B53: ast_spawn_extension (pbx.c:4549) ==20631== by 0x81271FC: __ast_pbx_run (pbx.c:4643) ==20631== by 0x8128718: pbx_thread (pbx.c:4930) ==20631== ==20631== Thread 6: ==20631== Invalid read of size 4 ==20631== at 0x80A030F: ast_channel_cmp_cb (channel.c:1328) ==20631== by 0x80836B1: internal_ao2_callback (astobj2.c:693) ==20631== by 0x8083A52: __ao2_callback (astobj2.c:789) ==20631== by 0x8083B6E: __ao2_find (astobj2.c:816) ==20631== by 0x80A06DB: ast_channel_get_full (channel.c:1375) ==20631== by 0x80A07EB: ast_channel_get_by_name_prefix (channel.c:1404) ==20631== by 0x80C66C8: ast_parse_device_state (devicestate.c:273) ==20631== by 0x80C69BF: _ast_device_state (devicestate.c:344) ==20631== by 0x80C6DFD: do_state_change (devicestate.c:454) ==20631== by 0x80C70C1: do_devstate_changes (devicestate.c:545) ==20631== by 0x817A10C: dummy_start (utils.c:971) ==20631== by 0x444CF3A: start_thread (pthread_create.c:297) ==20631== Address 0x7513160 is 136 bytes inside a block of size 1,072 free'd ==20631== at 0x4022B8A: free (vg_replace_malloc.c:323) ==20631== by 0x8082D02: internal_ao2_ref (astobj2.c:298) ==20631== by 0x8082BCD: __ao2_ref (astobj2.c:256) ==20631== by 0x80A0A23: ast_channel_release (channel.c:1478) ==20631== by 0x80A296B: ast_hangup (channel.c:2270) ==20631== by 0x6031D10: dial_exec_full (app_dial.c:2469) ==20631== by 0x603217C: dial_exec (app_dial.c:2521) ==20631== by 0x811BCA1: pbx_exec (pbx.c:1395) ==20631== by 0x8125497: pbx_extension_helper (pbx.c:4069) ==20631== by 0x8126B53: ast_spawn_extension (pbx.c:4549) ==20631== by 0x81271FC: __ast_pbx_run (pbx.c:4643) ==20631== by 0x8128718: pbx_thread (pbx.c:4930) ==20631== ==20631== Invalid read of size 4 ==20631== at 0x80A0523: ast_channel_cmp_cb (channel.c:1342) ==20631== by 0x80836B1: internal_ao2_callback (astobj2.c:693) ==20631== by 0x8083A52: __ao2_callback (astobj2.c:789) ==20631== by 0x8083B6E: __ao2_find (astobj2.c:816) ==20631== by 0x80A0783: ast_channel_get_full (channel.c:1393) ==20631== by 0x80A07EB: ast_channel_get_by_name_prefix (channel.c:1404) ==20631== by 0x80C66C8: ast_parse_device_state (devicestate.c:273) ==20631== by 0x80C69BF: _ast_device_state (devicestate.c:344) ==20631== by 0x80C6DFD: do_state_change (devicestate.c:454) ==20631== by 0x80C70C1: do_devstate_changes (devicestate.c:545) ==20631== by 0x817A10C: dummy_start (utils.c:971) ==20631== by 0x444CF3A: start_thread (pthread_create.c:297) ==20631== Address 0x751317c is 164 bytes inside a block of size 1,072 free'd ==20631== at 0x4022B8A: free (vg_replace_malloc.c:323) ==20631== by 0x8082D02: internal_ao2_ref (astobj2.c:298) ==20631== by 0x8082BCD: __ao2_ref (astobj2.c:256) ==20631== by 0x80A0A23: ast_channel_release (channel.c:1478) ==20631== by 0x80A296B: ast_hangup (channel.c:2270) ==20631== by 0x6031D10: dial_exec_full (app_dial.c:2469) ==20631== by 0x603217C: dial_exec (app_dial.c:2521) ==20631== by 0x811BCA1: pbx_exec (pbx.c:1395) ==20631== by 0x8125497: pbx_extension_helper (pbx.c:4069) ==20631== by 0x8126B53: ast_spawn_extension (pbx.c:4549) ==20631== by 0x81271FC: __ast_pbx_run (pbx.c:4643) ==20631== by 0x8128718: pbx_thread (pbx.c:4930)