局部栈变量地址无效触发SIGSEGV,LLDB调试异常求助
局部栈变量地址无效触发SIGSEGV故障
问题概述
代码开发中遇到局部栈变量地址无效的bug,使用LLDB调试时发现:
- 局部变量
&dominance_frontier的地址为0x0000000000000001,调用hash_table_init(dominators.c第121行)时触发SIGSEGV - 同函数内的
&dominator_tree_adj地址正常(0x000000016fdfef38)
编译配置:使用make DEBUG=yes编译,编译器为Apple clang 15.0.0,崩溃发生在_hash_table_init的table->size = size行(map.c第21行)。
调试会话片段
Process 70998 stopped * thread #1, queue = 'com.apple.main-thread', stop reason = step over frame #0: 0x0000000100006fd0 ir`ComputeDominanceFrontier(function=0x00006000030f8000) at dominators.c:121:9 111 struct Array postorder_traversal = postorder (function->entry_basic_block); 112 struct DFAConfiguration config = DominatorDFAConfiguration (function); 113 struct DFAResult result = run_DFA (&config, function); 114 115 HashTable dominator_tree_adj = ComputeDominatorTree (function, &result); 116 printf("%p\n", &dominator_tree_adj); 117 HashTable dominance_frontier; 118 printf("%ld\n", sizeof(dominance_frontier)); 119 120 -> 121 hash_table_init (&dominance_frontier); 122 // Compute the transpose graph from the dominator tree adjacency list 123 // Each node is guaranteed to have only one direct predecessor, since 124 // each node can only have one immediate dominator. We will need this 125 // in the DF algorithm below 126 HashTable dominator_tree_transpose; 127 hash_table_init (&dominator_tree_transpose); 128 129 struct HashTableEntry *entry; 130 size_t entry_iter = 0; 131 Target 0: (ir) stopped. (lldb) p &dominance_frontier (HashTable *) 0x0000000000000001 (lldb) p &dominator_tree_adj (HashTable *) 0x000000016fdfef38
崩溃位置代码
Process 10619 stopped * thread #1, queue = 'com.apple.main-thread', stop reason = EXC_BAD_ACCESS (code=1, address=0x9) frame #0: 0x0000000100005060 ir`_hash_table_init(table=0x0000000000000001, size=10) at map.c:21:21 11 // Open addressing, linear probe hash table. 12 13 unsigned long uint64_t_hash_function (uint64_t key) 14 { 15 // Simple hash function for demonstration 16 return key; 17 } 18 19 void _hash_table_init (HashTable *table, size_t size) 20 { -> 21 table->size = size; 22 table->count = 0; 23 table->buckets = ir_calloc (table->size, sizeof (HashTableEntry)); 24 } 25 void hash_table_init (HashTable *table) 26 { 27 _hash_table_init (table, MAP_INIT_SIZE_CNT); 28 } 29 30 // Create a new hash table 31 HashTable *hash_table_create (size_t size) Target 0: (ir) stopped.
Makefile配置
OPT = -O3 FLAGS = -Wall -Wextra CC = cc OBJECTS = ir_parser.o \ main.o \ threeaddr_parser.o \ instruction.o \ function.o \ basicblock.o \ constant.o \ utils.o \ value.o \ array.o \ mem.o \ map.o \ dfa.o \ dominators.o ifdef DEBUG OPT = -g else OPT = -O3 endif all: $(OBJECTS) $(CC) $(OPT) $(FLAGS) $^ -o ir %.o: %.c *.h $(CC) $(OPT) $(FLAGS) -c $< -o $@ clean: rm *.o
输入测试文件
fn test4(%1, %2) { alloca %9, 5 add %3, %1, %2 store %9, %3 cmp %4, %1, %2 jumpif 1, %4 sub %5, %3, 1 jumpif 2, %5 1: add %6, %1, 20 jump 3 2: add %7, %2, 30 3: sub %8, %3, %3 }
运行命令
./ir -f path/to/input/file
内容的提问来源于stack exchange,提问作者David Yue
相关产品推荐
相关产品推荐

