<table border="1" cellspacing="0" cellpadding="8">
<tr>
<th>Issue</th>
<td>
<a href=https://github.com/llvm/llvm-project/issues/150198>150198</a>
</td>
</tr>
<tr>
<th>Summary</th>
<td>
[analyzer] Assertion `rhs.getKind() == nonloc::PointerToMemberKind && "Both SVals should have pointer-to-member-type"' failed
</td>
</tr>
<tr>
<th>Labels</th>
<td>
clang:static analyzer,
crash
</td>
</tr>
<tr>
<th>Assignees</th>
<td>
</td>
</tr>
<tr>
<th>Reporter</th>
<td>
k-arrows
</td>
</tr>
</table>
<pre>
Reproducer:
https://godbolt.org/z/absq3T5Tj
```cpp
#define ADJUST_PTRFN(func, virt) ((void (*)())(func))
#include <cstddef>
struct S{ };
struct ptrmemfunc
{
void (*ptr) ();
ptrdiff_t adj;
};
typedef void (S::*sp)();
int main ()
{
sp x;
sp y;
ptrmemfunc *yp = (ptrmemfunc *) &y;
x = 0;
y = x;
if (yp->ptr != ADJUST_PTRFN (16, 1))
return 9;
}
```
Backtrace:
```console
clang++: /root/llvm-project/llvm/tools/clang/lib/StaticAnalyzer/Core/SimpleSValBuilder.cpp:468: virtual clang::ento::SVal {anonymous}::SimpleSValBuilder::evalBinOpNN(clang::ento::ProgramStateRef, clang::BinaryOperator::Opcode, clang::ento::NonLoc, clang::ento::NonLoc, clang::QualType): Assertion `rhs.getKind() == nonloc::PointerToMemberKind && "Both SVals should have pointer-to-member-type"' failed.
PLEASE submit a bug report to https://github.com/llvm/llvm-project/issues/ and include the crash backtrace, preprocessed source, and associated run script.
Stack dump:
0. Program arguments: /opt/compiler-explorer/clang-assertions-trunk/bin/clang++ -gdwarf-4 -g -o /app/output.s -mllvm --x86-asm-syntax=intel -fno-verbose-asm -S --gcc-toolchain=/opt/compiler-explorer/gcc-snapshot -fcolor-diagnostics -fno-crash-diagnostics --analyze <source>
1. <eof> parser at end of file
2. While analyzing stack:
#0 Calling main()
3. <source>:23:7: Error evaluating statement
4. <source>:23:7: Error evaluating statement
#0 0x0000000003fc9168 llvm::sys::PrintStackTrace(llvm::raw_ostream&, int) (/opt/compiler-explorer/clang-assertions-trunk/bin/clang+++0x3fc9168)
#1 0x0000000003fc6594 llvm::sys::CleanupOnSignal(unsigned long) (/opt/compiler-explorer/clang-assertions-trunk/bin/clang+++0x3fc6594)
#2 0x0000000003f0ad68 CrashRecoverySignalHandler(int) CrashRecoveryContext.cpp:0:0
#3 0x0000711db0242520 (/lib/x86_64-linux-gnu/libc.so.6+0x42520)
#4 0x0000711db02969fc pthread_kill (/lib/x86_64-linux-gnu/libc.so.6+0x969fc)
#5 0x0000711db0242476 gsignal (/lib/x86_64-linux-gnu/libc.so.6+0x42476)
#6 0x0000711db02287f3 abort (/lib/x86_64-linux-gnu/libc.so.6+0x287f3)
#7 0x0000711db022871b (/lib/x86_64-linux-gnu/libc.so.6+0x2871b)
#8 0x0000711db0239e96 (/lib/x86_64-linux-gnu/libc.so.6+0x39e96)
#9 0x00000000065f7aa5 (anonymous namespace)::SimpleSValBuilder::evalBinOpNN(llvm::IntrusiveRefCntPtr<clang::ento::ProgramState const>, clang::BinaryOperatorKind, clang::ento::NonLoc, clang::ento::NonLoc, clang::QualType) SimpleSValBuilder.cpp:0:0
#10 0x00000000066083e0 clang::ento::SValBuilder::evalBinOp(llvm::IntrusiveRefCntPtr<clang::ento::ProgramState const>, clang::BinaryOperatorKind, clang::ento::SVal, clang::ento::SVal, clang::QualType) (/opt/compiler-explorer/clang-assertions-trunk/bin/clang+++0x66083e0)
#11 0x000000000654689f clang::ento::ExprEngine::VisitBinaryOperator(clang::BinaryOperator const*, clang::ento::ExplodedNode*, clang::ento::ExplodedNodeSet&) (/opt/compiler-explorer/clang-assertions-trunk/bin/clang+++0x654689f)
#12 0x00000000065325b3 clang::ento::ExprEngine::Visit(clang::Stmt const*, clang::ento::ExplodedNode*, clang::ento::ExplodedNodeSet&) (/opt/compiler-explorer/clang-assertions-trunk/bin/clang+++0x65325b3)
#13 0x0000000006532e7d clang::ento::ExprEngine::ProcessStmt(clang::Stmt const*, clang::ento::ExplodedNode*) (/opt/compiler-explorer/clang-assertions-trunk/bin/clang+++0x6532e7d)
#14 0x00000000064e7c6b clang::ento::CoreEngine::HandlePostStmt(clang::CFGBlock const*, unsigned int, clang::ento::ExplodedNode*) (/opt/compiler-explorer/clang-assertions-trunk/bin/clang+++0x64e7c6b)
#15 0x00000000064e8358 clang::ento::CoreEngine::dispatchWorkItem(clang::ento::ExplodedNode*, clang::ProgramPoint, clang::ento::WorkListUnit const&) (/opt/compiler-explorer/clang-assertions-trunk/bin/clang+++0x64e8358)
#16 0x00000000064e86c1 clang::ento::CoreEngine::ExecuteWorkList(clang::LocationContext const*, unsigned int, llvm::IntrusiveRefCntPtr<clang::ento::ProgramState const>) (/opt/compiler-explorer/clang-assertions-trunk/bin/clang+++0x64e86c1)
#17 0x00000000060af7d7 (anonymous namespace)::AnalysisConsumer::HandleCode(clang::Decl*, unsigned int, clang::ento::ExprEngine::InliningModes, llvm::DenseSet<clang::Decl const*, llvm::DenseMapInfo<clang::Decl const*, void>>*) AnalysisConsumer.cpp:0:0
#18 0x00000000060b140e (anonymous namespace)::AnalysisConsumer::HandleDeclsCallGraph(unsigned int) AnalysisConsumer.cpp:0:0
#19 0x00000000060b2e13 (anonymous namespace)::AnalysisConsumer::HandleTranslationUnit(clang::ASTContext&) AnalysisConsumer.cpp:0:0
#20 0x000000000666d5bc clang::ParseAST(clang::Sema&, bool, bool) (/opt/compiler-explorer/clang-assertions-trunk/bin/clang+++0x666d5bc)
#21 0x0000000004c69e45 clang::FrontendAction::Execute() (/opt/compiler-explorer/clang-assertions-trunk/bin/clang+++0x4c69e45)
#22 0x0000000004be6b3e clang::CompilerInstance::ExecuteAction(clang::FrontendAction&) (/opt/compiler-explorer/clang-assertions-trunk/bin/clang+++0x4be6b3e)
#23 0x0000000004d5db71 clang::ExecuteCompilerInvocation(clang::CompilerInstance*) (/opt/compiler-explorer/clang-assertions-trunk/bin/clang+++0x4d5db71)
#24 0x0000000000d9fd9f cc1_main(llvm::ArrayRef<char const*>, char const*, void*) (/opt/compiler-explorer/clang-assertions-trunk/bin/clang+++0xd9fd9f)
#25 0x0000000000d969fa ExecuteCC1Tool(llvm::SmallVectorImpl<char const*>&, llvm::ToolContext const&) driver.cpp:0:0
#26 0x00000000049de109 void llvm::function_ref<void ()>::callback_fn<clang::driver::CC1Command::Execute(llvm::ArrayRef<std::optional<llvm::StringRef>>, std::__cxx11::basic_string<char, std::char_traits<char>, std::allocator<char>>*, bool*) const::'lambda'()>(long) Job.cpp:0:0
#27 0x0000000003f0b204 llvm::CrashRecoveryContext::RunSafely(llvm::function_ref<void ()>) (/opt/compiler-explorer/clang-assertions-trunk/bin/clang+++0x3f0b204)
#28 0x00000000049de71f clang::driver::CC1Command::Execute(llvm::ArrayRef<std::optional<llvm::StringRef>>, std::__cxx11::basic_string<char, std::char_traits<char>, std::allocator<char>>*, bool*) const (.part.0) Job.cpp:0:0
#29 0x00000000049a0ced clang::driver::Compilation::ExecuteCommand(clang::driver::Command const&, clang::driver::Command const*&, bool) const (/opt/compiler-explorer/clang-assertions-trunk/bin/clang+++0x49a0ced)
#30 0x00000000049a1d7e clang::driver::Compilation::ExecuteJobs(clang::driver::JobList const&, llvm::SmallVectorImpl<std::pair<int, clang::driver::Command const*>>&, bool) const (/opt/compiler-explorer/clang-assertions-trunk/bin/clang+++0x49a1d7e)
#31 0x00000000049a9de5 clang::driver::Driver::ExecuteCompilation(clang::driver::Compilation&, llvm::SmallVectorImpl<std::pair<int, clang::driver::Command const*>>&) (/opt/compiler-explorer/clang-assertions-trunk/bin/clang+++0x49a9de5)
#32 0x0000000000d9c24f clang_main(int, char**, llvm::ToolContext const&) (/opt/compiler-explorer/clang-assertions-trunk/bin/clang+++0xd9c24f)
#33 0x0000000000c50784 main (/opt/compiler-explorer/clang-assertions-trunk/bin/clang+++0xc50784)
#34 0x0000711db0229d90 (/lib/x86_64-linux-gnu/libc.so.6+0x29d90)
#35 0x0000711db0229e40 __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x29e40)
#36 0x0000000000d964a5 _start (/opt/compiler-explorer/clang-assertions-trunk/bin/clang+++0xd964a5)
clang++: error: clang frontend command failed with exit code 134 (use -v to see invocation)
Compiler returned: 134
```
</pre>
<img width="1" height="1" alt="" src="http://email.email.llvm.org/o/eJzkWltz2zYW_jXwC4YaEryJD36gZaubbJpkLbd91IAAKCEmAS4AOlJ__Q5ASrzEduLW7nZnM8qYJICD73znggMSWGu-E4xdgvgKxNcXuDV7qS7vPayU_KovCkmPl7esUZK2hCkQ5sDP98Y02l6iNUDrnaSFrMxCqh1A698BWuNC_zu8i---AD8Hid_9SNPYWxRSVnLBYH79_pfN3fbz3e36I0DLshUEoBV84MoAlEGAlgAtHySn3WUOUOYusu6i6-9unFQuSNVSBkG4ItpQykoQ3tgmP9dGtcTADUivIEivQXg1ed4YVbPayfNzkNpGCEcTN0adAWXdYGgHUV6WWwMx_dJLHIk2x4ZRVp7FbCxblrBcN4Mip95cGFhjLk5zDDB0Aw-nKXUDj_31ABkClB8bCMJrO3j6vEOdHM_zQHhwPf2TyKO7PYw68NLKOTYeCG8aoyBAge0yNpbtECTWVsHZABBCqJhplYDZwMbI-p38K0zujcKEdX40-IYUWlYM-DmpsNgBdGV_YQ4BWispDUDrqnqovUbJL4ycbgFaGykrDdC6H7aueAHQemOw4SQXuDr-zhRA65VUzD7ndVOxza-4ump5RZlaWKcM8yhZ2sms67W4gp0wZzAmjOyu7CgI0isspDjWstXO3K5lLrUf-oCrKy4-NR-tez8q87OSO4VrC5fdstJSOup3xQVWx08NU9jIXuinhkjKZh0HgR-l-CDJy5r_1eLq7tgw55A5zLVmynApIEh8tdeLHTP_5IJ2rmn9xfqDkKKSpNdCcmGYupM_s7pgyna2bgdQAgFCV9LsoSVHQ72XbUXhHj8w2HSDPCO92g3zjMOAAEphiXnF6AL4-ecPN_nmBuq2qLmBGBbtDirWSGWgkXCWh7jZt8WCyHrwj5nXcK1bZv0FYkHhKWWYPYNEYb2Hxdk_0Qo2yqY9wrRmFGrZqu6xHYm1loRjwyhUrYCaKN4Yi3djMLmHtK2bzsP9BfCz3swQq11bM2F079mysZiIrBteMeWxQ1NJ5fzVmcfDJ1Noz6hW3AO0LrgYvN0GCfR29CtWpRdBbwc9aeXiprHSW9O0ZqGhV1sWoOcdlomHde3pozD4AMJra4IKeqWQ3gNThdTMtkNvAz1vR4hno4vsMRfW6s_htZ21wI3eSwO9kshKKo9yvBNSG050N4fjePrYw12Q2rTdU-yydmB5A-GKSZvGYYOVZgpiA5mgUJaw5C5bINvttz2vGOwEcbGD2trAUWxzTgZQ6MMVrirbZrPsOcmG_STDxGGOQhDmqR19o5RU0EZxi00v1zBrP-Dn0R8fCh0g_-Cf_oUlyYJkCZ3LuojSR31KEFwY51N3nVcuh04Kf91KbRTDtYu2FeRiWDlfxbkAuvIPPbw-zwMUBjPwSZxFj4FfVQyLtvkkNnwncAXQshWu2KCwknaKt4BqwQxQ0RSqj2myhCvrhreMyAemjh22f2BBKzvjsudw0mclhWEH0y8WvvvfyQ97-WkQ0MJHEYqR3yvVrUSHZbJNIq_ioj14O9F2DWSh5SJxkN2QAXA0FZglWUlgY_aKYbq951X1Mulu_CA9nsON0gTutKPgpbCjNBkEJ1PBaJmWIcSFTdMvEusGDmLTb8QGxYsFBsUgcDkVGGYsS14m0A0ZBGZjB0viMsU4tgLPVQIUuGa6ccGbvaBeGOLpnTCq1fzBVggrYT4bZUvc75UT0JZUxiam54qKbmF_m2ICPlVtnQLIppJJIkwSfxky_-n663G-_h5sWXwvaRwz9cppsOfxvDUKgqmXRskyKx8HenNo1I3YccG6-1-55mZWiE6K2Wlbz6PdejzBxI3VijL60ZWxP9Zvw4xb4V6fqI6KgSg0JSpEcRG-gKgpNRtTm_85QpzKAyHhnBCW0h8j5HNXOlsSXoWWN9GVpXTQNZroGrGUJMXj4Ox2cqxrVz58ltp8q-5q_dNVJcn9ROVzIeTKjf8eBZ2SAwXxjIJlGC9_jALKdYMN2f8m1f07w-qntrzPu3ufk92O8kle7BQfuDa_CH52pDcJhk7_gZ1kzk5Cgh9j5-bASGvYCfmUnA-SYIunLzOfdZRXXOjehK-EBANf6YQvH5cpTb9XHLmXNprrlRS6rU9rfRdgK-czY-quGaleGFKTJPVOVFxwsftZUqan_F4zoV2inbBqJ5wYaDbgZ9y8E6X8zqAHyanbM970cT3X-pFKaTklswgin_0ZMi0obbfFPync7Mebs34L9AOYshkmxILwz2C6U1joygWDDe6prfPNXR8hfbh_HyCalZcJjQsyyTdYaZZv7mYrFKtxv6UupKyGv29QqTlI55BBk0otIknGongMeK0sBYLmxIqfJJfTC7rXRdhjGBBOSqSoYEkRsjHCVT_nO6ENFmSaAHvYE7ZnKr1JKu9xDlpM6pqIxrRIJ6m8xzso89An6dniPlf2TZbpHt-AflKp-DQrqa3nSbDtX28NSSlXCh9vWWkT0h6P6vN-qzN5dspMb6JEh3LQIZ7pkGQlhifaV8GdC7iRJpsaV9WvjBip3tVN9ahCyTQjWxmzRdU5F1X84dF0MVngo4yywM-6TziD0LIVzlG3yrE6fCfKureAIMwJrqoCk_ttKaYLQTdx7zqrYCXrGgs6j-JHradN3082dnZsCRiRYxQXu9vum1dn2vOA7ZYcDkHQ3RRYc7LVrntP4aSzfbA1CnOjT80zcbiqbChINWrv17FTmnTu0xca3VevtMJ1QTFA6UAVWp7eAr6XxSPGSGfv7grkj18zPvaGrmu5bcUGl6w6Trh83m5v8S7SIR4cfjl3rjSYbML_75zDMr5osDIL_2kvyKasYZ8w-iRrzmr4m5XxROUkdc8G2g6jJLF6Zo5x13xSJ4wUe9X836l9dqXp54MowwFN2UtJeS8L_TQj72VhNyoTRp7LxWcPaDC3xv-2CH-WxN5N_hIqLVkDlcGMyoyy-CnY16PrSYHwSGXwlAn-Qipfvw7p6BnIQ7M1nKCoT2mnSuQE3qWS_Js901Mr9KvXHhbZgHtS_fkk9tNlNDqA8XoTd6KHiWefd1BGsxd-L3JDBoHxXCCLfLjd2jFbbbAy25FaPzwFi0ZTJPNCLcIx7IS_vp2s8G7q2UEQppQ7A9G5Fyz7TQMkvf93RwbgV272kB3ciyHKYBBGFmOrGfQeoJFQMwb5qJi3M52K-P4AC7PhZ0eOD6hc0MuQZmGGL9hlkMYhSsI4iC_2l37hRzFaEhoVNCYlCxmhyxBFJfJRSFhxwS-Rj2I_RaGfhcswXsTYDwKf0KDIAkpJBiKf1ZhXCxsWC6l2F-6UwmUQ-0G2vKhwwSrtjmchdEoC2h1w6b95W6YRQCvbbosiexdfX6hLd_ihaHcaRH7FtdHDFIabyp35OouIr_9GRz8uWlVd_vHTHT11D5foPwEAAP__uzDi1g">