<table border="1" cellspacing="0" cellpadding="8">
<tr>
<th>Issue</th>
<td>
<a href=https://github.com/llvm/llvm-project/issues/137417>137417</a>
</td>
</tr>
<tr>
<th>Summary</th>
<td>
Static analyzer crashes using std::bit_cast expression
</td>
</tr>
<tr>
<th>Labels</th>
<td>
new issue
</td>
</tr>
<tr>
<th>Assignees</th>
<td>
</td>
</tr>
<tr>
<th>Reporter</th>
<td>
ddkilzer
</td>
</tr>
</table>
<pre>
The clang static analyzer crashes using a `std::bit_cast` expression:
```
#include <string>
static bool crash(std::string* x)
{
return x == std::bit_cast<std::string*>(static_cast<intptr_t>(-1));
}
```
Godbolt: <https://godbolt.org/z/8PYYEW156>
```
clang++: warning: argument unused during compilation: '-S' [-Wunused-command-line-argument]
PLEASE submit a bug report to https://github.com/llvm/llvm-project/issues/ and include the crash backtrace, preprocessed source, and associated run script.
Stack dump:
0. Program arguments: /opt/compiler-explorer/clang-20.1.0/bin/clang++ -gdwarf-4 -g -o /app/output.s -mllvm --x86-asm-syntax=intel -fno-verbose-asm -S --gcc-toolchain=/opt/compiler-explorer/gcc-14.2.0 -fcolor-diagnostics -fno-crash-diagnostics -std=c++2a -stdlib=libc++ --analyze <source>
1. <eof> parser at end of file
2. While analyzing stack:
#0 Calling crash(std::string *)
3. <source>:5:12: Error evaluating statement
4. <source>:5:12: Error evaluating statement
#0 0x0000000003a59568 llvm::sys::PrintStackTrace(llvm::raw_ostream&, int) (/opt/compiler-explorer/clang-20.1.0/bin/clang+++0x3a59568)
#1 0x0000000003a576ac llvm::sys::CleanupOnSignal(unsigned long) (/opt/compiler-explorer/clang-20.1.0/bin/clang+++0x3a576ac)
#2 0x00000000039a69e8 CrashRecoverySignalHandler(int) CrashRecoveryContext.cpp:0:0
#3 0x0000702688642520 (/lib/x86_64-linux-gnu/libc.so.6+0x42520)
#4 0x0000000006255ab7 (anonymous namespace)::SimpleSValBuilder::evalBinOpLN(llvm::IntrusiveRefCntPtr<clang::ento::ProgramState const>, clang::BinaryOperatorKind, clang::ento::Loc, clang::ento::NonLoc, clang::QualType) SimpleSValBuilder.cpp:0:0
#5 0x0000000006266819 clang::ento::SValBuilder::evalBinOp(llvm::IntrusiveRefCntPtr<clang::ento::ProgramState const>, clang::BinaryOperatorKind, clang::ento::SVal, clang::ento::SVal, clang::QualType) (/opt/compiler-explorer/clang-20.1.0/bin/clang+++0x6266819)
#6 0x0000000006198abf clang::ento::ExprEngine::VisitBinaryOperator(clang::BinaryOperator const*, clang::ento::ExplodedNode*, clang::ento::ExplodedNodeSet&) (/opt/compiler-explorer/clang-20.1.0/bin/clang+++0x6198abf)
#7 0x000000000617d177 clang::ento::ExprEngine::Visit(clang::Stmt const*, clang::ento::ExplodedNode*, clang::ento::ExplodedNodeSet&) (/opt/compiler-explorer/clang-20.1.0/bin/clang+++0x617d177)
#8 0x000000000617d4f5 clang::ento::ExprEngine::ProcessStmt(clang::Stmt const*, clang::ento::ExplodedNode*) (/opt/compiler-explorer/clang-20.1.0/bin/clang+++0x617d4f5)
#9 0x000000000618bc72 clang::ento::ExprEngine::processCFGElement(clang::CFGElement, clang::ento::ExplodedNode*, unsigned int, clang::ento::NodeBuilderContext*) (/opt/compiler-explorer/clang-20.1.0/bin/clang+++0x618bc72)
#10 0x00000000061361fd clang::ento::CoreEngine::dispatchWorkItem(clang::ento::ExplodedNode*, clang::ProgramPoint, clang::ento::WorkListUnit const&) (/opt/compiler-explorer/clang-20.1.0/bin/clang+++0x61361fd)
#11 0x0000000006136444 clang::ento::CoreEngine::ExecuteWorkList(clang::LocationContext const*, unsigned int, llvm::IntrusiveRefCntPtr<clang::ento::ProgramState const>) (/opt/compiler-explorer/clang-20.1.0/bin/clang+++0x6136444)
#12 0x0000000005d3331d (anonymous namespace)::AnalysisConsumer::HandleCode(clang::Decl*, unsigned int, clang::ento::ExprEngine::InliningModes, llvm::DenseSet<clang::Decl const*, llvm::DenseMapInfo<clang::Decl const*, void>>*) AnalysisConsumer.cpp:0:0
#13 0x0000000005d34449 (anonymous namespace)::AnalysisConsumer::HandleTranslationUnit(clang::ASTContext&) AnalysisConsumer.cpp:0:0
#14 0x00000000062c3aec clang::ParseAST(clang::Sema&, bool, bool) (/opt/compiler-explorer/clang-20.1.0/bin/clang+++0x62c3aec)
#15 0x0000000004682ca1 clang::FrontendAction::Execute() (/opt/compiler-explorer/clang-20.1.0/bin/clang+++0x4682ca1)
#16 0x000000000460260b clang::CompilerInstance::ExecuteAction(clang::FrontendAction&) (/opt/compiler-explorer/clang-20.1.0/bin/clang+++0x460260b)
#17 0x000000000476e173 clang::ExecuteCompilerInvocation(clang::CompilerInstance*) (/opt/compiler-explorer/clang-20.1.0/bin/clang+++0x476e173)
#18 0x0000000000d116c1 cc1_main(llvm::ArrayRef<char const*>, char const*, void*) (/opt/compiler-explorer/clang-20.1.0/bin/clang+++0xd116c1)
#19 0x0000000000d09eed ExecuteCC1Tool(llvm::SmallVectorImpl<char const*>&, llvm::ToolContext const&) driver.cpp:0:0
#20 0x00000000043f5b49 void llvm::function_ref<void ()>::callback_fn<clang::driver::CC1Command::Execute(llvm::ArrayRef<std::optional<llvm::StringRef>>, std::__cxx11::basic_string<char, std::char_traits<char>, std::allocator<char>>*, bool*) const::'lambda'()>(long) Job.cpp:0:0
#21 0x00000000039a6e13 llvm::CrashRecoveryContext::RunSafely(llvm::function_ref<void ()>) (/opt/compiler-explorer/clang-20.1.0/bin/clang+++0x39a6e13)
#22 0x00000000043f5d69 clang::driver::CC1Command::Execute(llvm::ArrayRef<std::optional<llvm::StringRef>>, std::__cxx11::basic_string<char, std::char_traits<char>, std::allocator<char>>*, bool*) const (.part.0) Job.cpp:0:0
#23 0x00000000043b9ebd clang::driver::Compilation::ExecuteCommand(clang::driver::Command const&, clang::driver::Command const*&, bool) const (/opt/compiler-explorer/clang-20.1.0/bin/clang+++0x43b9ebd)
#24 0x00000000043bae51 clang::driver::Compilation::ExecuteJobs(clang::driver::JobList const&, llvm::SmallVectorImpl<std::pair<int, clang::driver::Command const*>>&, bool) const (/opt/compiler-explorer/clang-20.1.0/bin/clang+++0x43bae51)
#25 0x00000000043c51ec clang::driver::Driver::ExecuteCompilation(clang::driver::Compilation&, llvm::SmallVectorImpl<std::pair<int, clang::driver::Command const*>>&) (/opt/compiler-explorer/clang-20.1.0/bin/clang+++0x43c51ec)
#26 0x0000000000d0e391 clang_main(int, char**, llvm::ToolContext const&) (/opt/compiler-explorer/clang-20.1.0/bin/clang+++0xd0e391)
#27 0x0000000000bd3bc4 main (/opt/compiler-explorer/clang-20.1.0/bin/clang+++0xbd3bc4)
#28 0x0000702688629d90 (/lib/x86_64-linux-gnu/libc.so.6+0x29d90)
#29 0x0000702688629e40 __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x29e40)
#30 0x0000000000d09985 _start (/opt/compiler-explorer/clang-20.1.0/bin/clang+++0xd09985)
clang++: error: clang frontend command failed with exit code 139 (use -v to see invocation)
Compiler returned: 139
```
Also tracked as <rdar://144714840>.
</pre>
<img width="1" height="1" alt="" src="http://email.email.llvm.org/o/eJzkWttyIynSfhp8Q5Siijpf-KIsS_P3_D0z3pZ3OuZKQQGSWSOoAMotz9NvQJVch5Y99ox2Yze2Qx22OWR--ZGZJCBsDN9Lxq5BegPS2yvc2gelryl95OJ3pq9qRZ-v7x8YJALLPTQWW04gllg8_840JBqbB2Zga7jcQwxBFhpLQVyBuKq53RJsLMhCyI6NZsZwJV1f6D9Z2H_CCqCYSyJayiCIl8ZqLvcgXnUDe521UqLTB1DxoqQfiyp4BKh0E_IbEFYQQqiZbbWERwjiWxDfwu-BOVVzOU6tk-90nkZxaRurt7brCyKnCZUgvvH6bufGhNUPitZKWBBXzp4Haxvj1KA1QOt917dQeg_Q-neA1sXdb7-tvkZp9mLyWJwnHqAb94kr-A1r6dmpINb79sCkha1sDaOQts4GSNSh4QLbjmwIUB5sAMohSG-Cr93QgKjDAUsaCC5ZcJIDUmfK3edVtVlB09YHbiGGdbuHmjVKW2gVnNnC7UNbL4g6ALQW4un0I2i0-gcjFqA1N6ZlBqA1xJLC0ypb51FuLWGNyaPVmDCAlrDRrNGKMOPMMarVXbObiY1RhGPLKNSthIZo3tgFCKuNxeQR0vbQdK4VLkBY3mm11_jwQpHpmFirxmHqGGI6YMdGKM20a3M0ByhcRIsQoHXN5amx4x4Ge_oN612QwGAPA-Wk4aZxMlvbtHZhYHBwtsMgOBZZgM0hMM_S4iOIb7m0TMBgJ1XwxHStDHP9MNjAINgTElilBHnAXDpXfQulGxwlC7QIYbAjSigdUI73UhnLiek0eF6nzd7Nb0lnCcK-QfAaxLeC1-RkYNCHtY_BjnzvkJFjFMRLpnYgXsEGa8M0xBYySaHawR0XDIQVcsO-PnDB-vzAu4RBHj35zrFLgOIQLrEQ3lHPBzN0UehjOe4VD2DiKgVxFSEncaW10pA9YdFi2-uyzDtyWCV_fir0IMNjePoX47RMswJ6B--APpvulzvNpfUeeN_5cDEM0vjbVhmrGT4AlDk_5tICVEKAir_kigDdhMceVEeUgxzNIOcZJucgLwXDsm1-kRu-l1gAVLTS7wEUCuVUXA6ggzAARBOAJc5KVsCl84EvjKgnpp87RP-HJRVOT9HzNRmzVNKyo12QxsV76P938uNefh6irCiyBKUo7E1xvo7WxyLbZonLee0x2Mu26yALoxaZh-ynDICTMeAMpSmucycQSyWfD6o1UOIDM41f-LJjd8MPjWCbX7G4abmgTHfNztVuuPyl-fzzxEc-Satbw5_YF7ZbSntnNYiXHZPdPGnVydN8Rts4R4VESdPtRks4Gn3DJdbPvzRMY6v0_3NJZwMGcZ8VebXvZyW_7_5bi8X9c-Mshd8ZeWY10il5WVZE5Xl1r5P1n0GVw_eRzjFTF4mknr3BMbMJt1FZ4Hp3Ht7q2OiV3HPJur9_5Ybbqe0AFa_y0rPn8vEr9q-cLZTRnxVl7x23YdYnxEvR0xEw0JNP6clplOcfoGdKyMYe7H8JDd7QgYZiTkOyS99Hw11XgznTL0LGBS1MdulgYTm1sKhJjt5nYV9lLtc_rES370_sHLe_f8Vf9lH-xjw3vs92_VZ2WYo8Cf1RCMVROKUozqIdPQ9sqTQbU0S5abAlD1-Vfvxk2WHK0Htdv8_Fd-otTpyKz9zYv0v-4l6XDAxv9cBJNOckSZL3cbI6MtJadsI7peSzIv7Q1S_rJE7mrnHBbe2CLCVJMrA0KddSGsdxRP-o-qlc3W-4WSpp2sNpP-8KuqX3jzFht4yIj4TOPIg_ScHdWfgnRd0Jc8zqLZPGJ9gJl07hZFlmE37CzSe5U38w6Ulx6g8Uqz5y51bPqiFHZjwjM0mS8q-Qea-xNN0Z3wXNlNdqc_-SWrJ3ApzVuiTGjEzi2B36qs39bD9gB9yfbWqlxPDzYpWPBzI45aSqTLICERyNYa61M1zSivTXH0PQekAXwtVrHnBlU1whysJ6jGvZa_okjcWSTNNJD3bC7MyQC6bDHt2AfVIuJXnGojweY-9RDiY89YlutmfOTbzgttajGjBPapuQRlFGIkhItD1gJ2B0bKi0xs9f2M4F9QMeVbT9kWDSdoruC0LvsA3IyynysGSMwhPFy-jeh88I_-aAhfiVEav0p0MjzpqRTXOZkzHbhLz7UM2fzgU_mhQJSbxL66T0RIyE7lrpXXGrPZe-twup7nIFxBXBQtSYPG53cppCO8W9myyjZXf5OI_Os2v2cjekGqcdOwJG5PgLIz9y1S_oy4TtlhyPUdRf-WLDyfZ0sewpnAx2DVurMbfm1D0Th4Vwbq_0qL_fAU5JzztNvzFX_o40F_hQUwxQPlCFitM1y4-qPrMY0fyahEXxaB3OXYZ0PV9aucE7Jp4nXL69bhe77Olwvrg5QnOXotnk-P8_5xKO50WDtXUsvrb28ZS1umQ1fZW1yTX_JE97KifJeTbRDRilhuUbOsZDq8lePzLsAhm-M3ZwoGRGBWZp9FEqflS1eZ2HH1XtivgJD2_l3Zd1bzDX3avQR6jrneNfSKCjaCBwWirFJI2mFd0Y7O3o98l2f2aff434fyOBl6oqOlIGyrLZ3szisve5U11xguyTRfXdKeK1nfcylYTHM6Cd1G1hTeOaJNDhvIy6TuCgrpher6OSlh-8XvdTBoHlXCBLQrjdujlbY7G225Ex71bBkkHF9BnHFVtlkcJO-KXWxInsFM4eapnWbmeo-pfzXV_Qw_7pFe4wF4zCb9w-QHb0Fx-UwSj23tIaBoMnaBU0jEE-KrmdplOp3T9xMxdWbub3D9GVMApajckjoxAbCOKlpthHmH_AjZIkj5IiCUG8WoCwuqLXMS3jEl-x6yhP0gzFaV5ePVzv2A6XYYgiVjOc5KTMcJZlcZHmdUHzJL_i1yhEaZig1AVSVC4odSeNEBUYZ0URFiAJ2QFzsXDhslB6f-Wfhq-jOE-i_Ergmgnjv4aAkGTfoO8FCIH09kpf-1flut0bkISCG2sGMZZbwa43b34z4bu3_9E3Eq5aLa7__Lt2j__pGv0zAAD__-gJCJo">