You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

局部栈变量地址无效触发SIGSEGV,LLDB调试异常求助

局部栈变量地址无效触发SIGSEGV故障

问题概述

代码开发中遇到局部栈变量地址无效的bug,使用LLDB调试时发现:

  • 局部变量&dominance_frontier的地址为0x0000000000000001,调用hash_table_init(dominators.c第121行)时触发SIGSEGV
  • 同函数内的&dominator_tree_adj地址正常(0x000000016fdfef38)

编译配置:使用make DEBUG=yes编译,编译器为Apple clang 15.0.0,崩溃发生在_hash_table_init的table->size = size行(map.c第21行)。

调试会话片段

Process 70998 stopped
* thread #1, queue = 'com.apple.main-thread', stop reason = step over
    frame #0: 0x0000000100006fd0 ir`ComputeDominanceFrontier(function=0x00006000030f8000) at dominators.c:121:9
   111          struct Array postorder_traversal = postorder (function->entry_basic_block);
   112          struct DFAConfiguration config = DominatorDFAConfiguration (function);
   113          struct DFAResult result = run_DFA (&config, function);
   114  
   115          HashTable dominator_tree_adj = ComputeDominatorTree (function, &result);
   116          printf("%p\n", &dominator_tree_adj);
   117          HashTable dominance_frontier;
   118          printf("%ld\n", sizeof(dominance_frontier));
   119  
   120  
-> 121          hash_table_init (&dominance_frontier);
   122          // Compute the transpose graph from the dominator tree adjacency list
   123          // Each node is guaranteed to have only one direct predecessor, since
   124          // each node can only have one immediate dominator. We will need this
   125          // in the DF algorithm below
   126          HashTable dominator_tree_transpose;
   127          hash_table_init (&dominator_tree_transpose);
   128  
   129          struct HashTableEntry *entry;
   130          size_t entry_iter = 0;
   131  
Target 0: (ir) stopped.
(lldb) p &dominance_frontier
(HashTable *) 0x0000000000000001
(lldb) p &dominator_tree_adj
(HashTable *) 0x000000016fdfef38

崩溃位置代码

Process 10619 stopped
* thread #1, queue = 'com.apple.main-thread', stop reason = EXC_BAD_ACCESS (code=1, address=0x9)
    frame #0: 0x0000000100005060 ir`_hash_table_init(table=0x0000000000000001, size=10) at map.c:21:21
   11   // Open addressing, linear probe hash table.
   12   
   13   unsigned long uint64_t_hash_function (uint64_t key)
   14   {
   15           // Simple hash function for demonstration
   16           return key;
   17   }
   18   
   19   void _hash_table_init (HashTable *table, size_t size)
   20   {
-> 21           table->size = size;
   22           table->count = 0;
   23           table->buckets = ir_calloc (table->size, sizeof (HashTableEntry));
   24   }
   25   void hash_table_init (HashTable *table)
   26   {
   27           _hash_table_init (table, MAP_INIT_SIZE_CNT);
   28   }
   29   
   30   // Create a new hash table
   31   HashTable *hash_table_create (size_t size)
Target 0: (ir) stopped.

Makefile配置

OPT = -O3
FLAGS = -Wall -Wextra
CC = cc
OBJECTS =   ir_parser.o \
            main.o \
            threeaddr_parser.o \
            instruction.o \
            function.o \
            basicblock.o \
            constant.o \
            utils.o \
            value.o \
            array.o \
            mem.o \
            map.o \
            dfa.o \
            dominators.o


ifdef DEBUG
    OPT = -g
else
    OPT = -O3
endif


all: $(OBJECTS)
    $(CC) $(OPT) $(FLAGS) $^ -o ir

%.o: %.c *.h
    $(CC) $(OPT) $(FLAGS) -c $< -o $@


clean:
    rm *.o

输入测试文件

fn test4(%1, %2) {

    alloca %9, 5
    add %3, %1, %2 
    store %9, %3
    cmp %4, %1, %2 
    jumpif 1, %4


    sub %5, %3, 1  
    jumpif 2, %5   

1:
    add %6, %1, 20 
    jump 3    


2:
    add %7, %2, 30 

    
3:
    sub %8, %3, %3 
}

运行命令

./ir -f path/to/input/file

内容的提问来源于stack exchange,提问作者David Yue

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.21 22:04:53