<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugzilla.yoctoproject.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.6"
          urlbase="https://bugzilla.yoctoproject.org/"
          
          maintainer="it-coreprojects-helpdesk@linuxfoundation.org"
>

    <bug>
          <bug_id>7116</bug_id>
          
          <creation_ts>2015-01-06 20:00:25 +0000</creation_ts>
          <short_desc>GCC with ARM hard float and -mapcs-frame generates bad tailcall code</short_desc>
          <delta_ts>2015-01-22 16:09:07 +0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>7</classification_id>
          <classification>Build System, Metadata &amp; Runtime</classification>
          <product>OE-Core</product>
          <component>devtools / tool chain</component>
          <version>1.7</version>
          <rep_platform>Other</rep_platform>
          <op_sys>arm</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>WONTFIX</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>Medium</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>1.7.1</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Donn Seeley">donn.seeley</reporter>
          <assigned_to name="Khem Raj">raj.khem</assigned_to>
          <cc>meta.mr.watcher</cc>
    
    <cc>meta.watcher</cc>
    
    <cc>sgw</cc>
          
          
          <cf_os>---</cf_os>
          <cf_regression_type>---</cf_regression_type>
          
          <cf_docchange>No (bug/feature does not impact docs)</cf_docchange>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>47756</commentid>
    <comment_count>0</comment_count>
      <attachid>2313</attachid>
    <who name="Donn Seeley">donn.seeley</who>
    <bug_when>2015-01-06 20:00:25 +0000</bug_when>
    <thetext>Created attachment 2313
content.i

This problem has already been submitted to the GCC bugzilla:

  https://gcc.gnu.org/bugzilla/show_bug.cgi?id=64379

Mark Hatle suggested that I should submit it here too, since it shows up with dizzy.

The overall summary: If you build for ARM with VFP/NEON, -O2 and -mapcs-frame, then a function that saves a VFP register and performs an optimized indirect tailcall may get bad code in its function epilogue that can cause segfaults.  We discovered this problem when xfsdump (and gdb) segfaulted in WR Linux 7 in a similar configuration.  I have a test program simplified from xfsdump that shows the same issue in dizzy / 1.7.

The bad code looks like this:

        sub     ip, fp, #44
        [...]
        fldmfdd ip!, {d8}
        sub     sp, fp, #36
        ldmfd   sp, {r4, r5, r6, r7, r8, r9, fp, sp, lr}
        bx      ip      @ indirect register sibling call

GCC chooses IP to hold the function pointer for an optimized indirect tailcall, but the epilogue code for -mapcs-frame explicitly uses IP to handle VFP/NEON register restores, so that when we make the indirect function call, IP has a stack address in it rather than the function pointer, and we segfault.  (The function pointer load has been optimized out.)

To re-create the problem on dizzy, I added the following to conf/local.conf:

  MACHINE = &quot;qemuarm&quot;
  DEFAULTTUNE = &quot;armv7at-neon&quot;
  DEBUG_BUILD = &quot;1&quot;
  DEBUG_OPTIMIZATION = &quot;-O2 -pipe -g -feliminate-unused-debug-types -fno-omit-frame-pointer -fvisibility=default -mapcs-frame&quot;

The modified DEBUG_OPTIMIZATION line just forces -O2, so that the tailcall optimization pass gets run.  You can generate the bad code with just &apos;-O1 -foptimize-sibling-calls&apos; rather than -O2.

Put the following in conf/machine/qemuarm.conf:

  require conf/machine/include/qemu.inc
  require conf/machine/include/tune-cortexa9.inc
  KERNEL_IMAGETYPE = &quot;zImage&quot;
  SERIAL_CONSOLE = &quot;115200 ttyAMA0&quot;

This change just switches to tune-cortexa9.inc so that armv7at-neon is a valid tuning.

I then ran a build.  I added the following to my environment (cut and pasted from &apos;bitbake -e bash&apos;):

  export CC=&quot;arm-poky-linux-gnueabi-gcc  -march=armv7-a -marm -mthumb-interwork -mfloat-abi=softfp -mfpu=neon --sysroot=/home/donn/c/yocto/poky/build/tmp/sysroots/qemuarm&quot;
  export CFLAGS=&quot; -O2 -pipe -g -feliminate-unused-debug-types -fno-omit-frame-pointer -fvisibility=default -mapcs-frame&quot;
  export PATH=&quot;/home/donn/c/yocto/poky/scripts:/home/donn/c/yocto/poky/build/tmp/sysroots/x86_64-linux/usr/bin/arm-poky-linux-gnueabi:/home/donn/c/yocto/poky/build/tmp/sysroots/qemuarm/usr/bin/crossscripts:/home/donn/c/yocto/poky/build/tmp/sysroots/x86_64-linux/usr/sbin:/home/donn/c/yocto/poky/build/tmp/sysroots/x86_64-linux/usr/bin:/home/donn/c/yocto/poky/build/tmp/sysroots/x86_64-linux/sbin:/home/donn/c/yocto/poky/build/tmp/sysroots/x86_64-linux/bin:/home/donn/c/yocto/poky/scripts:/home/donn/c/yocto/poky/bitbake/bin:/home/donn/c/git/bin:/home/donn/bin:/usr/contrib/mh/bin:/sbin:/usr/sbin:/usr/contrib/sbin:/usr/lib64/ccache:/usr/local/bin:/usr/bin:/usr/local/sbin:/usr/sbin&quot;

I built the attached content.i file (reduced from dump/content.c in xfsdump) using:

  $CC $CFLAGS -S content.i

Examining the resulting content.s file shows that the bad code is present.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>47896</commentid>
    <comment_count>1</comment_count>
    <who name="Donn Seeley">donn.seeley</who>
    <bug_when>2015-01-13 21:14:33 +0000</bug_when>
    <thetext>The feedback that I got from GCC developers is that -mapcs-frame is obsolete.  It doesn&apos;t appear that Yocto uses -mapcs-frame by default, so we&apos;ll stop using it with WR Linux and we&apos;ll see what happens.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>48196</commentid>
    <comment_count>2</comment_count>
    <who name="Saul Wold">sgw</who>
    <bug_when>2015-01-22 16:09:07 +0000</bug_when>
    <thetext>See prior comment</thetext>
  </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="0"
              isprivate="0"
          >
            <attachid>2313</attachid>
            <date>2015-01-06 20:00:25 +0000</date>
            <delta_ts>2015-01-06 20:00:25 +0000</delta_ts>
            <desc>content.i</desc>
            <filename>content2.i</filename>
            <type>application/octet-stream</type>
            <size>1757</size>
            <attacher name="Donn Seeley">donn.seeley</attacher>
            
              <data encoding="base64">dHlwZWRlZiB1bnNpZ25lZCBpbnQgc2l6ZV90Owp0eXBlZGVmIGxvbmcgbG9uZyBvZmY2NF90Owp0
eXBlZGVmIGludCBpbnQzMl90Owp0eXBlZGVmIGludCBib29sX3Q7CnR5cGVkZWYgdW5zaWduZWQg
bG9uZyBsb25nIHhmc19pbm9fdDsKdHlwZWRlZiBpbnQgaW50Z2VuX3Q7CgpleHRlcm4gdm9pZCAq
Y2FsbG9jIChzaXplX3QgX19ubWVtYiwgc2l6ZV90IF9fc2l6ZSk7CgpzdHJ1Y3Qgc3RhcnRwdCB7
CiB4ZnNfaW5vX3Qgc3BfaW5vOwogb2ZmNjRfdCBzcF9vZmZzZXQ7CiBpbnQzMl90IHNwX2ZsYWdz
OwogaW50MzJfdCBzcF9wYWQxOwp9OwoKdHlwZWRlZiBzdHJ1Y3Qgc3RhcnRwdCBzdGFydHB0X3Q7
CgpleHRlcm4gdm9pZCBtbG9nKCBpbnRnZW5fdCBsZXZlbCwgY2hhciAqZm10LCAuLi4gKTsKCnR5
cGVkZWYgb2ZmNjRfdCBkcml2ZV9tYXJrX3Q7CgpzdHJ1Y3QgZHJpdmVfbWFya3JlYzsKdHlwZWRl
ZiB2b2lkICggKiBkcml2ZV9tY2JmcF90ICkoIHZvaWQgKmNvbnRleHRfdCwKICAgICAgc3RydWN0
IGRyaXZlX21hcmtyZWMgKm1hcmtyZWNwLAogICAgICBib29sX3QgY29tbWl0dGVkICk7CgpzdHJ1
Y3QgZHJpdmVfbWFya3JlYyB7CiBkcml2ZV9tYXJrX3QgZG1fbG9nOwogZHJpdmVfbWNiZnBfdCBk
bV9jYmZ1bmNwOwogdm9pZCAqZG1fY2Jjb250ZXh0cDsKIHN0cnVjdCBkcml2ZV9tYXJrcmVjICpk
bV9uZXh0cDsKfTsKCnR5cGVkZWYgc3RydWN0IGRyaXZlX21hcmtyZWMgZHJpdmVfbWFya3JlY190
OwoKc3RydWN0IGRyaXZlX29wczsKCnN0cnVjdCBkcml2ZSB7CiB2b2lkICpkX3N0cmF0ZWd5cDsK
IHN0cnVjdCBkcml2ZV9vcHMgKmRfb3BzcDsKIGludCBkX2luZGV4Owp9OwoKdHlwZWRlZiBzdHJ1
Y3QgZHJpdmUgZHJpdmVfdDsKCnN0cnVjdCBkcml2ZV9vcHMgewogYm9vbF90ICggKiBkb19pbml0
ICkoIGRyaXZlX3QgKmRyaXZlcCApOwogdm9pZCAoICogZG9fc2V0X21hcmsgKSggZHJpdmVfdCAq
ZHJpdmVwLAogICAgZHJpdmVfbWNiZnBfdCBjYmZ1bmNwLAogICAgdm9pZCAqY2Jjb250ZXh0cCwK
ICAgIGRyaXZlX21hcmtyZWNfdCAqbWFya3JlY3AgKTsKfTsKCnR5cGVkZWYgc3RydWN0IGRyaXZl
X29wcyBkcml2ZV9vcHNfdDsKCnN0cnVjdCBtYXJrIHsKIGRyaXZlX21hcmtyZWNfdCBkbTsKIHN0
YXJ0cHRfdCBzdGFydHB0Owp9OwoKdHlwZWRlZiBzdHJ1Y3QgbWFyayBtYXJrX3Q7Cgp2b2lkIG1h
cmtfY2FsbGJhY2soIHZvaWQgKiwgZHJpdmVfbWFya3JlY190ICosIGJvb2xfdCApOwoKdm9pZApt
YXJrX3NldCggZHJpdmVfdCAqZHJpdmVwLCB4ZnNfaW5vX3QgaW5vLCBvZmY2NF90IG9mZnNldCwg
aW50MzJfdCBmbGFncyApCnsKIGRyaXZlX29wc190ICpkb3AgPSBkcml2ZXAtPmRfb3BzcDsKIG1h
cmtfdCAqbWFya3AgPSAoIG1hcmtfdCAqICljYWxsb2MoIDEsIHNpemVvZiggbWFya190ICkpOwoK
IGlmICggZmxhZ3MgPT0gMCApIHsKICBtbG9nKCAzLAogICAgICAgICJzZXR0aW5nIG1lZGlhIG1h
cmsiCiAgICAgICAgIiBmb3Igb2Zmc2V0ICVsbGRcbiIsCiAgICAgICAgb2Zmc2V0ICk7CiB9Cgog
bWFya3AtPnN0YXJ0cHQuc3BfaW5vID0gaW5vOwogbWFya3AtPnN0YXJ0cHQuc3Bfb2Zmc2V0ID0g
b2Zmc2V0OwogbWFya3AtPnN0YXJ0cHQuc3BfZmxhZ3MgPSBmbGFnczsKICggKiBkb3AtPmRvX3Nl
dF9tYXJrICkoIGRyaXZlcCwKICAgIG1hcmtfY2FsbGJhY2ssCiAgICAoIHZvaWQgKiApZHJpdmVw
LT5kX2luZGV4LAogICAgKCBkcml2ZV9tYXJrcmVjX3QgKiApbWFya3AgKTsKfQo=
</data>

          </attachment>
      

    </bug>

</bugzilla>