miscompile writing to bitfield at -Os
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
gcc |
Invalid
|
Medium
|
|||
gcc-4.5 (Ubuntu) |
New
|
Undecided
|
Unassigned |
Bug Description
The attached preprocessed file was extracted out of a file from LLVM. When it was compiled by g++-4.5 at -Os, and LLVM's test suite was run, it resulted in the assert in PointerType's constructor firing:
llvm::PointerTy
This was the invocation I used:
g++-4.5 -Os -fPIC -g -pedantic -Wno-long-long -fno-exceptions -o lib/VMCore/
Further details here:
http://
ProblemType: Bug
DistroRelease: Ubuntu 11.04
Package: g++-4.5 4.5.2-8ubuntu4
Uname: Linux 3.1.0-custom x86_64
Architecture: amd64
Date: Tue Dec 27 22:11:40 2011
InstallationMedia: Ubuntu 11.04 "Natty Narwhal" - Release amd64 (20110427.1)
ProcEnviron:
LANGUAGE=en_US:en
PATH=(custom, user)
LANG=en_US.UTF-8
SHELL=/bin/bash
SourcePackage: gcc-4.5
UpgradeStatus: No upgrade log present (probably fresh install)
Changed in gcc: | |
importance: | Unknown → Medium |
status: | Unknown → Confirmed |
Changed in gcc: | |
status: | Confirmed → In Progress |
Changed in gcc: | |
status: | In Progress → Invalid |
To be more specific. These two member variables are at offset 0x8:
unsigned ID : 8;
unsigned SubclassData : 24;
When setSubclassData() isn't inlined, it's called with the address of 'SubclassData' in %rdi...:
0x00007ffff7 6d684f <+71>: lea 0x9(%rdi),%r12 6d6853 <+75>: or $0x1,%esi 6d6856 <+78>: mov %r12,%rdi 6d6859 <+81>: callq 0x7ffff76d6774 <llvm:: Type::setSubcla ssData( unsigned int)>
0x00007ffff7
0x00007ffff7
0x00007ffff7
...but then, it writes more than 24 bits to that address, writing zeroes into the next member:
0x00007ffff7 6d6774 <+0>: mov %esi,%eax 6d6776 <+2>: sub $0x8,%rsp 6d677a <+6>: and $0xffffff,%eax 6d677f <+11>: cmp %esi,%eax 6d6781 <+13>: mov %eax,(%rdi) # corruption
0x00007ffff7
0x00007ffff7
0x00007ffff7
0x00007ffff7