Compiling the attached preprocessed file with this:
g++-4.5 -Os -fPIC -g -pedantic -Wno-long-long -fno-exceptions -o Type2.cpp.o -c Type2.ii
Results in writing 32 bits to a 24-bit bitfield, overwriting the first byte of the next member variable.
These two members of class Type are (on x86_64) at offset 0x8:
TypeID ID : 8;
unsigned SubclassData : 24;
When setSubclassData() isn't inlined, it's called (from StructType::setBody() and PointerType's constructor) with the address of 'SubclassData' in %rdi...:
Compiling the attached preprocessed file with this:
g++-4.5 -Os -fPIC -g -pedantic -Wno-long-long -fno-exceptions -o Type2.cpp.o -c Type2.ii
Results in writing 32 bits to a 24-bit bitfield, overwriting the first byte of the next member variable.
These two members of class Type are (on x86_64) at offset 0x8:
TypeID ID : 8;
unsigned SubclassData : 24;
When setSubclassData() isn't inlined, it's called (from StructType: :setBody( ) and PointerType's constructor) with the address of 'SubclassData' in %rdi...:
0x00007ffff7 6d684f <+71>: lea 0x9(%rdi),%r12 6d6853 <+75>: or $0x1,%esi 6d6856 <+78>: mov %r12,%rdi 6d6859 <+81>: callq 0x7ffff76d6774 <llvm:: Type::setSubcla ssData( unsigned int)>
0x00007ffff7
0x00007ffff7
0x00007ffff7
...but then, setSubclassData writes more than 24 bits to that address:
0x00007ffff7 6d6774 <+0>: mov %esi,%eax 6d6776 <+2>: sub $0x8,%rsp 6d677a <+6>: and $0xffffff,%eax 6d677f <+11>: cmp %esi,%eax 6d6781 <+13>: mov %eax,(%rdi) # corruption
0x00007ffff7
0x00007ffff7
0x00007ffff7
0x00007ffff7