<table border="1" cellspacing="0" cellpadding="8">
<tr>
<th>Issue</th>
<td>
<a href=https://github.com/llvm/llvm-project/issues/61830>61830</a>
</td>
</tr>
<tr>
<th>Summary</th>
<td>
AArch64 backend crash with -fsanitize=memtag-stack -mspeculative-load-hardening
</td>
</tr>
<tr>
<th>Labels</th>
<td>
backend:AArch64,
crash
</td>
</tr>
<tr>
<th>Assignees</th>
<td>
</td>
</tr>
<tr>
<th>Reporter</th>
<td>
ostannard
</td>
</tr>
</table>
<pre>
This code causes a crash in the AArch64 backend when compiled with `-fsanitize=memtag-stack -mspeculative-load-hardening`:
```
void b(int*);
void c() {
int d[48];
b(d);
}
```
```
$ /work/llvm/build/bin/clang --target=aarch64--none-eabi -march=armv8.5-a+memtag -c test.c -O1 -fsanitize=memtag-stack -mspeculative-load-hardening
clang: /work/llvm/llvm-project/llvm/lib/Target/AArch64/AArch64SpeculationHardening.cpp:212: bool {anonymous}::AArch64SpeculationHardening::endsWithCondControlFlow(llvm::MachineBasicBlock&, llvm::MachineBasicBlock*&, llvm::MachineBasicBlock*&, llvm::AArch64CC::CondCode&) const: Assertion `analyzeBranchCondCode.size() == 1 && "unknown Cond array format"' failed.
PLEASE submit a bug report to https://github.com/llvm/llvm-project/issues/ and include the crash backtrace, preprocessed source, and associated run script.
Stack dump:
0. Program arguments: /work/llvm/build/bin/clang --target=aarch64--none-eabi -march=armv8.5-a+memtag -c test.c -O1 -fsanitize=memtag-stack -mspeculative-load-hardening
1. <eof> parser at end of file
2. Code generation
3. Running pass 'Function Pass Manager' on module 'test.c'.
4. Running pass 'AArch64 speculation hardening pass' on function '@c'
#0 0x0000557dde7bfb3f llvm::sys::PrintStackTrace(llvm::raw_ostream&, int) (/work/llvm/build/bin/clang+0x7f61b3f)
#1 0x0000557dde7bd87c llvm::sys::CleanupOnSignal(unsigned long) (/work/llvm/build/bin/clang+0x7f5f87c)
#2 0x0000557dde7015f8 CrashRecoverySignalHandler(int) CrashRecoveryContext.cpp:0:0
#3 0x00007fcb91e0e420 __restore_rt (/lib/x86_64-linux-gnu/libpthread.so.0+0x14420)
#4 0x00007fcb918ab00b raise /build/glibc-SzIz7B/glibc-2.31/signal/../sysdeps/unix/sysv/linux/raise.c:51:1
#5 0x00007fcb9188a859 abort /build/glibc-SzIz7B/glibc-2.31/stdlib/abort.c:81:7
#6 0x00007fcb9188a729 get_sysdep_segment_value /build/glibc-SzIz7B/glibc-2.31/intl/loadmsgcat.c:509:8
#7 0x00007fcb9188a729 _nl_load_domain /build/glibc-SzIz7B/glibc-2.31/intl/loadmsgcat.c:970:34
#8 0x00007fcb9189bfd6 (/lib/x86_64-linux-gnu/libc.so.6+0x33fd6)
#9 0x0000557ddbe70762 (anonymous namespace)::AArch64SpeculationHardening::instrumentControlFlow(llvm::MachineBasicBlock&, bool&) (.constprop.0) AArch64SpeculationHardening.cpp:0:0
#10 0x0000557ddbe70de7 (anonymous namespace)::AArch64SpeculationHardening::runOnMachineFunction(llvm::MachineFunction&) AArch64SpeculationHardening.cpp:0:0
#11 0x0000557dddb1e65e llvm::MachineFunctionPass::runOnFunction(llvm::Function&) (.part.0) MachineFunctionPass.cpp:0:0
#12 0x0000557dde0d9875 llvm::FPPassManager::runOnFunction(llvm::Function&) (/work/llvm/build/bin/clang+0x787b875)
#13 0x0000557dde0d9ab9 llvm::FPPassManager::runOnModule(llvm::Module&) (/work/llvm/build/bin/clang+0x787bab9)
#14 0x0000557dde0da332 llvm::legacy::PassManagerImpl::run(llvm::Module&) (/work/llvm/build/bin/clang+0x787c332)
#15 0x0000557ddee59a1e clang::EmitBackendOutput(clang::DiagnosticsEngine&, clang::HeaderSearchOptions const&, clang::CodeGenOptions const&, clang::TargetOptions const&, clang::LangOptions const&, llvm::StringRef, llvm::Module*, clang::BackendAction, llvm::IntrusiveRefCntPtr<llvm::vfs::FileSystem>, std::unique_ptr<llvm::raw_pwrite_stream, std::default_delete<llvm::raw_pwrite_stream>>) (/work/llvm/build/bin/clang+0x85fba1e)
#16 0x0000557ddf5b32bc clang::BackendConsumer::HandleTranslationUnit(clang::ASTContext&) CodeGenAction.cpp:0:0
#17 0x0000557de0f09129 clang::ParseAST(clang::Sema&, bool, bool) (/work/llvm/build/bin/clang+0xa6ab129)
#18 0x0000557ddf5b1bf8 clang::CodeGenAction::ExecuteAction() (/work/llvm/build/bin/clang+0x8d53bf8)
#19 0x0000557ddf487329 clang::FrontendAction::Execute() (/work/llvm/build/bin/clang+0x8c29329)
#20 0x0000557ddf4091f6 clang::CompilerInstance::ExecuteAction(clang::FrontendAction&) (/work/llvm/build/bin/clang+0x8bab1f6)
#21 0x0000557ddf578d87 clang::ExecuteCompilerInvocation(clang::CompilerInstance*) (/work/llvm/build/bin/clang+0x8d1ad87)
#22 0x0000557ddbc7bbc6 cc1_main(llvm::ArrayRef<char const*>, char const*, void*) (/work/llvm/build/bin/clang+0x541dbc6)
#23 0x0000557ddbc7725a ExecuteCC1Tool(llvm::SmallVectorImpl<char const*>&, llvm::ToolContext const&) driver.cpp:0:0
#24 0x0000557ddf2708fd void llvm::function_ref<void ()>::callback_fn<clang::driver::CC1Command::Execute(llvm::ArrayRef<std::optional<llvm::StringRef>>, std::__cxx11::basic_string<char, std::char_traits<char>, std::allocator<char>>*, bool*) const::'lambda'()>(long) Job.cpp:0:0
#25 0x0000557dde701ae0 llvm::CrashRecoveryContext::RunSafely(llvm::function_ref<void ()>) (/work/llvm/build/bin/clang+0x7ea3ae0)
#26 0x0000557ddf2711bf clang::driver::CC1Command::Execute(llvm::ArrayRef<std::optional<llvm::StringRef>>, std::__cxx11::basic_string<char, std::char_traits<char>, std::allocator<char>>*, bool*) const (.part.0) Job.cpp:0:0
#27 0x0000557ddf23525c clang::driver::Compilation::ExecuteCommand(clang::driver::Command const&, clang::driver::Command const*&, bool) const (/work/llvm/build/bin/clang+0x89d725c)
#28 0x0000557ddf235cfd clang::driver::Compilation::ExecuteJobs(clang::driver::JobList const&, llvm::SmallVectorImpl<std::pair<int, clang::driver::Command const*>>&, bool) const (/work/llvm/build/bin/clang+0x89d7cfd)
#29 0x0000557ddf23d9bd clang::driver::Driver::ExecuteCompilation(clang::driver::Compilation&, llvm::SmallVectorImpl<std::pair<int, clang::driver::Command const*>>&) (/work/llvm/build/bin/clang+0x89df9bd)
#30 0x0000557ddbc798e0 clang_main(int, char**, llvm::ToolContext const&) (/work/llvm/build/bin/clang+0x541b8e0)
#31 0x0000557ddbc89b15 main (/work/llvm/build/bin/clang+0x542bb15)
#32 0x00007fcb9188c083 __libc_start_main /build/glibc-SzIz7B/glibc-2.31/csu/../csu/libc-start.c:342:3
#33 0x0000557ddbc71f6e _start (/work/llvm/build/bin/clang+0x5413f6e)
clang: error: clang frontend command failed with exit code 134 (use -v to see invocation)
clang version 17.0.0 (git@github.com:llvm/llvm-project.git 478bd0735fc094d3af37e9791df5118a402ae7a7)
Target: aarch64-unknown-none-eabi
Thread model: posix
InstalledDir: /work/llvm/build/bin
clang: note: diagnostic msg:
********************
PLEASE ATTACH THE FOLLOWING FILES TO THE BUG REPORT:
Preprocessed source(s) and associated run script(s) are located at:
clang: note: diagnostic msg: /tmp/test-4bd2d1.c
clang: note: diagnostic msg: /tmp/test-4bd2d1.sh
clang: note: diagnostic msg:
********************
```
</pre>
<img width="1px" height="1px" alt="" src="http://email.email.llvm.org/o/eJzkWltv2zgW_jXMC2FDIq3bQx4UJ5520NkETWbn0eBNNrcSqSUpN-mvX5CSbcl12jgdLBbYIk0s8ZDn47mTx8RauVFCXIPkBiS3V6RzW22utXVEKWL4FdX85fppKy1kmgvISGeFhQQyQ-wWSgXdVsCyNGybLiAl7ItQHH7dCgWZblpZCw6_SreFII1mlSVKOvlNAHzbiMaRzcw6wr7AWWNbwbqaOLkTs1oTPtsSw4WSagPSCOASRLcg2v9Oo-EnPO605JAClEvlACoBKgC-GQ0xgHKACgiy4S2EUjnIQXKzyEFye6CGYRU-XgBkt2d5nn-JFhCg1VdtvgC0qutdA9CKdrLm_q9UAK1YTdQGzmaOmI1wAN8SEiQ3mymtxEwQKuGs8e_8mGl2-TyZEYBuenHBGYNOWDdncHYfw3cKNIANSAAuv0fs_8xao_8lmBu9lRSg1VOPG60GjR8_Pe75afVhz2nO2hbgEsXIM6Ja114JRGn10ujOeuHiEuDyB0v0BEJx-5d026VWfKmVM7pe1forQHlAF2j-IGwrlbghVrKbWrMvAKUALeEPKcr3EQ2Al8v-sYfFRaArINPKOr_j0lph_Ha89RNF6pdv4sYQxbb7GXPrlTfYJ74F-BbGMCyTQoBQp74o_VVBTw6JMeQFVto0xAGEAMpgRbyDzXuNPny6Kx_voO1oIx0kkHYbaESrjYNOw61zrfVw0Qqg1Ua6bUfnTDev6l1a2wkL0AoSxaFUrO64CN7eu773dWcIE140rRGt0UxYKzi0ujP9az-TWKuZJE5waDoFLTOydQPkx2CsvGvag4tHc_hg9MaQBhKz6RqhnD1rpv-rjhXPYfgH8FLoCuA72BJjhYHEQR8bdQUrWYueGM2hNwO4EUqYYPn9ezws8rlTfmXYEmshQNmqUywY1IN_8QdRZCOMtwStYKN5VwtP1e8EoGwQ8-KV1fZh2x4dDx52E6iGpas9W4AysIj80kPIBAhHMHqOoihKkoxzkdGK4mrkK_bF9h8ejFQuaPypN5uR8xryda2tM4I0g7OFYF7A4Bs_1zxAN9FzVqUxxZWP3wdw8Qk4nmfsHLhlLYjq2nv1KDeK1ADlnQqZkcNa-_UvhZJUecYmUNAUShQnVQ6X3pc-C6Z3wrz0vD8QxWuv1XyQwYTGhz_x7IbQGoX_BxZ4YJFVjBaxiMQCRXC9NsI6bcTauGETfTB_ztN1upjVUnXPs43q-oHWbY0gfG71PAp7iRcLFE12spiwyQmNIgoNkdZb30Emm1pSNnv89vFbdnN4RHMcA7Syg5RX87l_erFctD7WdEo-9y92AY3q_GNYes4ALpMY4DI-IkmmSHKSJwUkVIedvg2J4700wqzAJPdMRgaenjLJUAE3wq173GsrNj5MrXek7t4sAamc37-PII3dMNKzTqLCAzjyzs7xXqt67SeuuW6IVL_Gssi8EeHFkWc-5VnQiqdvMBzmTSYNJoNxxdOJyRRj46cii7IU-TUPxQBUpBG2DYGheGNZIJV1JqSIS4sCX4sM2RqgfB4ydmt0602-gD8vaUZ-54NMdLo7LrJf3p3p1L0aNrCP--c2dxxL3wV-EiI5jUWaiO8Loj0Xn3hG-M4CO0HkJdwS43rhnlnvPK5pvIx4kWfJCNfqwU_dp8CLEb09lOcZzbPkYM0eGj6FRmjxBmh_hAw91eHw6l2wCC0msBYnsAjGaASrFhvCXoZkfAT4sWnrA8i_DRzDGE3AJRNwIilILOD-FAJweddId9OfH-8713YOoHw0fCvJRmnrJLN3aiOVGDx5RPJBEC7Mo_BV3n3r1W2HWvw7Ul90_SbUT6j6085PiD4RtTlHchTjozNSbT6L6uSkMUi3PFlwEEI5GOx4ykflTGflTnwW1VK5B2cAXh6Hd9XgmitZi8cX60QD8J1fwjrej3RK_rsT6_Zkpq-_2q9GOrHeV2GjSVxUpKvdmotaOPGTifgu8LzMYPKkoiQWE4NJxwZTJRQjys7IaamV7Zq9n_XF05MhyvbB708lTyypfHwaiqjBsgdj6AV-PhZlIywiqqIi9ue845oPvsQvH5-mnB5FQyYJZ__3MuGQlNAYTV09PxFOTKv8jIEPRtQ72LNgnRN7u8ov1hFPMK3yCYxJWq8WeYanclkZL-mDMY9xvAcBQwWeCgJFUwRREVfpVBDhFsp8VNYRxcR5WbwO-fLgl1NC4yqdoIyn6spynmeT4NfjOYLdaUa-x_bdZsJ114VajAnPswm6SaalLKOUpZCxeO2ry0lGKI0hLz6S4SXbErMPeOUQZqbv0BLutOTvAJksYk7ZVIT4BGSGEgL3clvGT8GxRlAfG1LX_xTM6SHDnUF8Eqj9GkNoGIXyAnIjd8KcjQxoknMrlEV5xcO2R-vuj89rEyQXRnvzD9HSkzBS15SwL-tKeaRHlfe8B_Uv46VuGqL4qSed1dAhfuuQnkg9idzHrDRE7FHAX6_Z83Mc9w_UF88-uofKNEhxQuxfrJ0h0tn98MlypK69OWszGvck5TEiluOLs3BNldWkoZwAlB1FhfL9Yfx3Tc_rIzk9ZRMRjVRx7izdj3zu1COpRP0yEeePVXdpWSQIJiKamHV6Yj9xTCv4_6z_k-PCq4rOpoLDCUrYq4ILcZN8l4P20pwE2ZOJnuC12u8HpOUk8Y_29vZIXfAMJWxiLfnpplnFL93075ra13f8u6afpHWvlbLfBdWDklsivX7DndXbhTRYwt8gKlbxiaiKE1Hxgr4qqtvR50kqPpODXxPxf1FUF2b8glcFnQhnemdLWVbkIuqB7HP-Hlzw9nLw1Z-nyguzPM2n4XB6X0tZXtA4gcMl1yUrI0rjyZn9cP26v0ljUY7hel1L6oMbMW59yV0as93-9rL_GAbDOuFWDS-Q_31kf1q-xFUqYM_4UqHhKj2elA59PGGMD7Blr0ZYDWUsZIMd9b2ivhkrnqXr-7kxXnj2nRVwtoNOQysElKPyc8wG7oSxUisYZ_NoHvmJG-nAIhq1k3B5pp0030gHF1lOeZThpGJRseCYVDgTRVbEvEriOCeLCBGRkWNpOjQbcQn3zZyhH3bs6QyE4cYaNpqL2pO32srnfihUynUt-K00P20jTQWqtD_rlpAfbh5gY_uW6aDVX_gZdZGHvl359FQuP8CnD3dwdf_p0_1fH__xG1x9_HT3CJ_uw-ubP3-Dn-8e7j8_HbplD-f6brn1nvhq7-1AYAQMeVlwSNxhybfsH61c0_rfwrrZgnLE4zn7tel2e6n4_y4l7Jv4V_wa8wIX5Epcx2kexWm2wNHV9holaEF4lmaEJyzHPg1nuMhSSpOCoVxcyWsUIRxhHEVFHOFonuQRWkRJnqU5wriIwSISDZH13BvdXJvNVeiuXqdxjqOrmlBR2_ANDISGr1AcL4hDq3cJEAptV_-U3F6Z6-BetNtYsIhqaZ09ru2kq8X16Xcy-q5tcP_3tTevOlNfv7-NHPb6nwAAAP__Ng1wgA">