[llvm-bugs] [Bug 28691] New: Crash on invalid C++ code on x86_64-linux-gnu (Segmentation fault, clang::Sema::ActOnCallExpr)

via llvm-bugs llvm-bugs at lists.llvm.org
Sun Jul 24 19:15:30 PDT 2016


https://llvm.org/bugs/show_bug.cgi?id=28691

            Bug ID: 28691
           Summary: Crash on invalid C++ code on x86_64-linux-gnu
                    (Segmentation fault, clang::Sema::ActOnCallExpr)
           Product: clang
           Version: trunk
          Hardware: PC
                OS: All
            Status: NEW
          Severity: normal
          Priority: P
         Component: C++
          Assignee: unassignedclangbugs at nondot.org
          Reporter: chengniansun at gmail.com
                CC: dgregor at apple.com, llvm-bugs at lists.llvm.org
    Classification: Unclassified

$ clang++-trunk -v
clang version 4.0.0 (trunk 276133)
Target: x86_64-unknown-linux-gnu
Thread model: posix
InstalledDir: /usr/bin
Found candidate GCC installation: /usr/bin/../lib/gcc/x86_64-linux-gnu/4.8
Found candidate GCC installation: /usr/bin/../lib/gcc/x86_64-linux-gnu/4.8.4
Found candidate GCC installation: /usr/bin/../lib/gcc/x86_64-linux-gnu/4.9
Found candidate GCC installation: /usr/bin/../lib/gcc/x86_64-linux-gnu/4.9.3
Found candidate GCC installation: /usr/bin/../lib/gcc/x86_64-linux-gnu/5
Found candidate GCC installation: /usr/bin/../lib/gcc/x86_64-linux-gnu/5.4.0
Found candidate GCC installation: /usr/bin/../lib/gcc/x86_64-linux-gnu/6
Found candidate GCC installation: /usr/bin/../lib/gcc/x86_64-linux-gnu/6.1.1
Found candidate GCC installation: /usr/lib/gcc/x86_64-linux-gnu/4.8
Found candidate GCC installation: /usr/lib/gcc/x86_64-linux-gnu/4.8.4
Found candidate GCC installation: /usr/lib/gcc/x86_64-linux-gnu/4.9
Found candidate GCC installation: /usr/lib/gcc/x86_64-linux-gnu/4.9.3
Found candidate GCC installation: /usr/lib/gcc/x86_64-linux-gnu/5
Found candidate GCC installation: /usr/lib/gcc/x86_64-linux-gnu/5.4.0
Found candidate GCC installation: /usr/lib/gcc/x86_64-linux-gnu/6
Found candidate GCC installation: /usr/lib/gcc/x86_64-linux-gnu/6.1.1
Selected GCC installation: /usr/bin/../lib/gcc/x86_64-linux-gnu/5.4.0
Candidate multilib: .;@m64
Candidate multilib: 32;@m32
Candidate multilib: x32;@mx32
Selected multilib: .;@m64
$ 
$ clang++-trunk -std=c++11 small.C
#0 0x0000000001b23f85 llvm::sys::PrintStackTrace(llvm::raw_ostream&)
(/usr/local/clang-trunk/bin/clang-4.0+0x1b23f85)
#1 0x0000000001b21cae llvm::sys::RunSignalHandlers()
(/usr/local/clang-trunk/bin/clang-4.0+0x1b21cae)
#2 0x0000000001b21e12 SignalHandler(int)
(/usr/local/clang-trunk/bin/clang-4.0+0x1b21e12)
#3 0x00007fd96aa08ed0 __restore_rt
(/lib/x86_64-linux-gnu/libpthread.so.0+0x10ed0)
#4 0x0000000002901899 clang::Sema::ActOnCallExpr(clang::Scope*, clang::Expr*,
clang::SourceLocation, llvm::MutableArrayRef<clang::Expr*>,
clang::SourceLocation, clang::Expr*, bool)
(/usr/local/clang-trunk/bin/clang-4.0+0x2901899)
#5 0x0000000002945d24 (anonymous
namespace)::TransformTypos::RebuildCallExpr(clang::Expr*,
clang::SourceLocation, llvm::MutableArrayRef<clang::Expr*>,
clang::SourceLocation, clang::Expr*)
(/usr/local/clang-trunk/bin/clang-4.0+0x2945d24)
#6 0x0000000002960325 clang::TreeTransform<(anonymous
namespace)::TransformTypos>::TransformCallExpr(clang::CallExpr*)
(/usr/local/clang-trunk/bin/clang-4.0+0x2960325)
#7 0x000000000294fd5b clang::TreeTransform<(anonymous
namespace)::TransformTypos>::TransformExpr(clang::Expr*)
(/usr/local/clang-trunk/bin/clang-4.0+0x294fd5b)
#8 0x000000000294cfe8 clang::Sema::CorrectDelayedTyposInExpr(clang::Expr*,
clang::VarDecl*, llvm::function_ref<clang::ActionResult<clang::Expr*, true>
(clang::Expr*)>) (/usr/local/clang-trunk/bin/clang-4.0+0x294cfe8)
#9 0x000000000294e61c clang::Sema::ActOnFinishFullExpr(clang::Expr*,
clang::SourceLocation, bool, bool, bool)
(/usr/local/clang-trunk/bin/clang-4.0+0x294e61c)
#10 0x0000000002a67e40
clang::Sema::ActOnExprStmt(clang::ActionResult<clang::Expr*, true>)
(/usr/local/clang-trunk/bin/clang-4.0+0x2a67e40)
#11 0x00000000025fc5ed clang::Parser::ParseExprStatement()
(/usr/local/clang-trunk/bin/clang-4.0+0x25fc5ed)
#12 0x00000000025f9f6f
clang::Parser::ParseStatementOrDeclarationAfterAttributes(llvm::SmallVector<clang::Stmt*,
32u>&, clang::Parser::AllowedContsructsKind, clang::SourceLocation*,
clang::Parser::ParsedAttributesWithRange&)
(/usr/local/clang-trunk/bin/clang-4.0+0x25f9f6f)
#13 0x00000000025fa0ce
clang::Parser::ParseStatementOrDeclaration(llvm::SmallVector<clang::Stmt*,
32u>&, clang::Parser::AllowedContsructsKind, clang::SourceLocation*)
(/usr/local/clang-trunk/bin/clang-4.0+0x25fa0ce)
#14 0x00000000025fe887 clang::Parser::ParseCompoundStatementBody(bool)
(/usr/local/clang-trunk/bin/clang-4.0+0x25fe887)
#15 0x0000000002600b99 clang::Parser::ParseFunctionStatementBody(clang::Decl*,
clang::Parser::ParseScope&) (/usr/local/clang-trunk/bin/clang-4.0+0x2600b99)
#16 0x0000000002588519
clang::Parser::ParseLexedMethodDef(clang::Parser::LexedMethod&)
(/usr/local/clang-trunk/bin/clang-4.0+0x2588519)
#17 0x000000000258826e
clang::Parser::ParseLexedMethodDefs(clang::Parser::ParsingClass&)
(/usr/local/clang-trunk/bin/clang-4.0+0x258826e)
#18 0x00000000025b7b69
clang::Parser::ParseCXXMemberSpecification(clang::SourceLocation,
clang::SourceLocation, clang::Parser::ParsedAttributesWithRange&, unsigned int,
clang::Decl*) (/usr/local/clang-trunk/bin/clang-4.0+0x25b7b69)
#19 0x00000000025b87bc
clang::Parser::ParseClassSpecifier(clang::tok::TokenKind,
clang::SourceLocation, clang::DeclSpec&, clang::Parser::ParsedTemplateInfo
const&, clang::AccessSpecifier, bool, clang::Parser::DeclSpecContext,
clang::Parser::ParsedAttributesWithRange&)
(/usr/local/clang-trunk/bin/clang-4.0+0x25b87bc)
#20 0x000000000259ba98
clang::Parser::ParseDeclarationSpecifiers(clang::DeclSpec&,
clang::Parser::ParsedTemplateInfo const&, clang::AccessSpecifier,
clang::Parser::DeclSpecContext, clang::Parser::LateParsedAttrList*)
(/usr/local/clang-trunk/bin/clang-4.0+0x259ba98)
#21 0x0000000002581764
clang::Parser::ParseDeclOrFunctionDefInternal(clang::Parser::ParsedAttributesWithRange&,
clang::ParsingDeclSpec&, clang::AccessSpecifier)
(/usr/local/clang-trunk/bin/clang-4.0+0x2581764)
#22 0x0000000002581ee1
clang::Parser::ParseDeclarationOrFunctionDefinition(clang::Parser::ParsedAttributesWithRange&,
clang::ParsingDeclSpec*, clang::AccessSpecifier) [clone .part.158] [clone
.constprop.181] (/usr/local/clang-trunk/bin/clang-4.0+0x2581ee1)
#23 0x0000000002581f2f
clang::Parser::ParseDeclarationOrFunctionDefinition(clang::Parser::ParsedAttributesWithRange&,
clang::ParsingDeclSpec*, clang::AccessSpecifier)
(/usr/local/clang-trunk/bin/clang-4.0+0x2581f2f)
#24 0x000000000258735f
clang::Parser::ParseExternalDeclaration(clang::Parser::ParsedAttributesWithRange&,
clang::ParsingDeclSpec*) (/usr/local/clang-trunk/bin/clang-4.0+0x258735f)
#25 0x0000000002587c99
clang::Parser::ParseTopLevelDecl(clang::OpaquePtr<clang::DeclGroupRef>&)
(/usr/local/clang-trunk/bin/clang-4.0+0x2587c99)
#26 0x000000000257d3c0 clang::ParseAST(clang::Sema&, bool, bool)
(/usr/local/clang-trunk/bin/clang-4.0+0x257d3c0)
#27 0x000000000226e2e7 clang::CodeGenAction::ExecuteAction()
(/usr/local/clang-trunk/bin/clang-4.0+0x226e2e7)
#28 0x0000000001f98956 clang::FrontendAction::Execute()
(/usr/local/clang-trunk/bin/clang-4.0+0x1f98956)
#29 0x0000000001f6cd76
clang::CompilerInstance::ExecuteAction(clang::FrontendAction&)
(/usr/local/clang-trunk/bin/clang-4.0+0x1f6cd76)
#30 0x000000000201c5a7
clang::ExecuteCompilerInvocation(clang::CompilerInstance*)
(/usr/local/clang-trunk/bin/clang-4.0+0x201c5a7)
#31 0x0000000000937bb0 cc1_main(llvm::ArrayRef<char const*>, char const*,
void*) (/usr/local/clang-trunk/bin/clang-4.0+0x937bb0)
#32 0x00000000008d6d40 main (/usr/local/clang-trunk/bin/clang-4.0+0x8d6d40)
#33 0x00007fd96958b730 __libc_start_main
(/lib/x86_64-linux-gnu/libc.so.6+0x20730)
#34 0x0000000000934499 _start (/usr/local/clang-trunk/bin/clang-4.0+0x934499)
Stack dump:
0.    Program arguments: /usr/local/clang-trunk/bin/clang-4.0 -cc1 -triple
x86_64-unknown-linux-gnu -emit-obj -mrelax-all -disable-free -main-file-name
small.C -mrelocation-model static -mthread-model posix -mdisable-fp-elim
-fmath-errno -masm-verbose -mconstructor-aliases -munwind-tables
-fuse-init-array -target-cpu x86-64 -dwarf-column-info -debugger-tuning=gdb
-resource-dir /usr/local/clang-trunk/bin/../lib/clang/4.0.0 -c-isystem .
-c-isystem /usr/local/include/csmith -internal-isystem
/usr/bin/../lib/gcc/x86_64-linux-gnu/5.4.0/../../../../include/c++/5.4.0
-internal-isystem
/usr/bin/../lib/gcc/x86_64-linux-gnu/5.4.0/../../../../include/x86_64-linux-gnu/c++/5.4.0
-internal-isystem
/usr/bin/../lib/gcc/x86_64-linux-gnu/5.4.0/../../../../include/x86_64-linux-gnu/c++/5.4.0
-internal-isystem
/usr/bin/../lib/gcc/x86_64-linux-gnu/5.4.0/../../../../include/c++/5.4.0/backward
-internal-isystem /usr/local/include -internal-isystem
/usr/local/clang-trunk/bin/../lib/clang/4.0.0/include -internal-externc-isystem
/usr/include/x86_64-linux-gnu -internal-externc-isystem /include
-internal-externc-isystem /usr/include -std=c++11 -fdeprecated-macro
-fdebug-compilation-dir
/home/cnsun/workspace/meta-compiler/error-fuzzer/temp-runs/IdentifierSubstituionFuzzingEngine/crash/20160628-clang++-trunk--O3-c-Weverything-std=c++14-build-025359
-ferror-limit 19 -fmessage-length 273 -fobjc-runtime=gcc -fcxx-exceptions
-fexceptions -fdiagnostics-show-option -fcolor-diagnostics -o
/tmp/small-365034.o -x c++ small.C 
1.    small.C:4:3: current parser token '}'
2.    small.C:1:1: parsing struct/union/class body 'D'
3.    small.C:2:55: parsing function body 'D::_M_construct'
4.    small.C:2:55: in compound statement ('{}')
clang-4.0: error: unable to execute command: Segmentation fault
clang-4.0: error: clang frontend command failed due to signal (use -v to see
invocation)
clang version 4.0.0 (trunk 276133)
Target: x86_64-unknown-linux-gnu
Thread model: posix
InstalledDir: /usr/bin
clang-4.0: note: diagnostic msg: PLEASE submit a bug report to
http://llvm.org/bugs/ and include the crash backtrace, preprocessed source, and
associated run script.
clang-4.0: note: diagnostic msg: 
********************

PLEASE ATTACH THE FOLLOWING FILES TO THE BUG REPORT:
Preprocessed source(s) and associated run script(s) are located at:
clang-4.0: note: diagnostic msg: /tmp/small-688112.cpp
clang-4.0: note: diagnostic msg: /tmp/small-688112.sh
clang-4.0: note: diagnostic msg: 

********************
$ 
$ cat small.C
struct D {
  template <typename T> void _M_construct(unsigned n) {
    __builtin_memcpy(0, &_M_construct_aux, n);
  }
};
$

-- 
You are receiving this mail because:
You are on the CC list for the bug.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.llvm.org/pipermail/llvm-bugs/attachments/20160725/e1784629/attachment-0001.html>


More information about the llvm-bugs mailing list