Bug 15803

Summary: AB-INT: segfault during clang-native build
Product: [Build System, Metadata & Runtime] OE-Core Reporter: Mathieu Dubois-Briand <mathieu.dubois-briand>
Component: devtools / tool chainAssignee: Yoann Congal <yoann.congal>
Status: RESOLVED FIXED QA Contact:
Severity: normal    
Priority: Medium CC: meta.mr.watcher, meta.watcher, raj.khem, randy.macleod, ross.burton, sundeep.kokkonda, yoann.congal
Version: 5.99   
Target Milestone: 5.3   
Hardware: x86   
OS: Multiple   
Whiteboard: AB-INT
OS type for building Yocto: --- Type of Regression: ---
Verified: Documentation change: No (bug/feature does not impact docs)

Description Mathieu Dubois-Briand 2025-03-18 09:49:55 UTC
I feel like I already saw a similar issue in the past, this Dexp.cpp file remond me something. Yet I did not find anything on bugzilla.

  16926 ERROR: clang-native-19.1.7-r0 do_compile: Execution of '/srv/pokybuild/yocto-worker/meta-clang/build/build/tmp/work/x86_64-linux/clang-native/19.1.7/temp/run.do_compile.2964406' failed with exit code 1
  16927 ERROR: Logfile of failure stored in: /srv/pokybuild/yocto-worker/meta-clang/build/build/tmp/work/x86_64-linux/clang-native/19.1.7/temp/log.do_compile.2964406
  16928 Log data follows:
  16929 | DEBUG: Executing shell function do_compile
  16930 | NOTE: VERBOSE=1 cmake --build /srv/pokybuild/yocto-worker/meta-clang/build/build/tmp/work/x86_64-linux/clang-native/19.1.7/build --target all --
  16931 | Change Dir: '/srv/pokybuild/yocto-worker/meta-clang/build/build/tmp/work/x86_64-linux/clang-native/19.1.7/build'
  16932 | 
  16933 | Run Build Command(s): ninja -v -j 16 all
...
  23500 | /srv/pokybuild/yocto-worker/meta-clang/build/build/tmp/work-shared/llvm-project-source-19.1.7-r0/llvm-project-19.1.7.src/clang-tools-extra/clangd/index/dex/dexp/Dexp.cpp: In substitution of ‘template<class _Functor, class, class> std::function<std::unique_ptr<clang::clangd::{anonymous}::Command>()>::function(_Functor) [with _Functor = <missing>; <template-parameter-1-2> =
  23500  <missing>; <template-parameter-1-3> = <missing>]’:
  23501 | /srv/pokybuild/yocto-worker/meta-clang/build/build/tmp/work-shared/llvm-project-source-19.1.7-r0/llvm-project-19.1.7.src/clang-tools-extra/clangd/index/dex/dexp/Dexp.cpp:372:1:   required from here
  23502 | /srv/pokybuild/yocto-worker/meta-clang/build/build/tmp/work-shared/llvm-project-source-19.1.7-r0/llvm-project-19.1.7.src/clang-tools-extra/clangd/index/dex/dexp/Dexp.cpp:372:1: internal compiler error: Segmentation fault
  23503 |   372 | };
  23504 |       | ^
  23505 | 0x7f6766789dcf ???
  23506 |       ./signal/../sysdeps/unix/sysv/linux/x86_64/sigaction.c:0
  23507 | 0x7f6766774d79 __libc_start_main
  23508 |       ../csu/libc-start.c:308
  23509 | Please submit a full bug report,
  23510 | with preprocessed source if appropriate.
  23511 | Please include the complete backtrace with any bug report.
  23512 | See <file:///usr/share/doc/gcc-10/README.Bugs> for instructions.
Comment 1 Mathieu Dubois-Briand 2025-03-18 09:53:06 UTC
meta-clang debian11-vk-2 master-next completed at 2025-03-17T21:05:05Z
https://autobuilder.yoctoproject.org/valkyrie/#/builders/18/builds/623/steps/11/logs/stdio
Comment 2 Randy MacLeod 2025-03-20 14:44:24 UTC
Only seen once on master-next. Wait to see if it happens again.

but we might need to test the build on Debian 11 since sstate may hid the issue.
Comment 3 Yoann Congal 2025-03-20 17:41:11 UTC
I could reproduce it locally on the first try (an extract of my log.do_compile below) using a Debian 11 yocto/CROPS docker container:
[5975/6471] $TOPDIR/tmp/hosttools/g++ -D_GNU_SOURCE -D__STDC_CONSTANT_MACROS -D__STDC_FORMAT_MACROS -D__STDC_LIMIT_MACROS -I$TOPDIR/tmp/work/x86_64-linux/clang-native/19.1.7/build/tools/clang/tools/extra/clangd/index/dex/dexp -I$TOPDIR/tmp/work-shared/llvm-project-source-19.1.7-r0/llvm-project-19.1.7.src/clang-tools-extra/clangd/index/dex/dexp -I$TOPDIR/tmp/work-shared/llvm-project-source-19.1.7-r0/llvm-project-19.1.7.src/clang-tools-extra/clangd/../include-cleaner/include -I$TOPDIR/tmp/work/x86_64-linux/clang-native/19.1.7/build/tools/clang/tools/extra/clangd/../clang-tidy -I$TOPDIR/tmp/work-shared/llvm-project-source-19.1.7-r0/llvm-project-19.1.7.src/clang/include -I$TOPDIR/tmp/work/x86_64-linux/clang-native/19.1.7/build/tools/clang/include -I$TOPDIR/tmp/work/x86_64-linux/clang-native/19.1.7/build/include -I$TOPDIR/tmp/work-shared/llvm-project-source-19.1.7-r0/llvm-project-19.1.7.src/llvm/include -I$TOPDIR/tmp/work-shared/llvm-project-source-19.1.7-r0/llvm-project-19.1.7.src/clang-tools-extra/clangd -I$TOPDIR/tmp/work/x86_64-linux/clang-native/19.1.7/build/tools/clang/tools/extra/clangd -isystem$TOPDIR/tmp/work/x86_64-linux/clang-native/19.1.7/recipe-sysroot-native/usr/include -O2 -pipe   -fvisibility-inlines-hidden -fPIC -fno-semantic-interposition -fvisibility-inlines-hidden -Werror=date-time -fno-lifetime-dse -Wall -Wextra -Wno-unused-parameter -Wwrite-strings -Wcast-qual -Wno-missing-field-initializers -pedantic -Wno-long-long -Wimplicit-fallthrough -Wno-uninitialized -Wno-nonnull -Wno-class-memaccess -Wno-redundant-move -Wno-pessimizing-move -Wno-noexcept-type -Wdelete-non-virtual-dtor -Wsuggest-override -Wno-comment -Wno-misleading-indentation -fdiagnostics-color -ffunction-sections -fdata-sections -fno-common -Woverloaded-virtual -fno-strict-aliasing -isystem$TOPDIR/tmp/work/x86_64-linux/clang-native/19.1.7/recipe-sysroot-native/usr/include -O2 -pipe   -fvisibility-inlines-hidden -DNDEBUG -g0 -std=c++17 -MD -MT tools/clang/tools/extra/clangd/index/dex/dexp/CMakeFiles/dexp.dir/Dexp.cpp.o -MF tools/clang/tools/extra/clangd/index/dex/dexp/CMakeFiles/dexp.dir/Dexp.cpp.o.d -o tools/clang/tools/extra/clangd/index/dex/dexp/CMakeFiles/dexp.dir/Dexp.cpp.o -c $TOPDIR/tmp/work-shared/llvm-project-source-19.1.7-r0/llvm-project-19.1.7.src/clang-tools-extra/clangd/index/dex/dexp/Dexp.cpp
FAILED: tools/clang/tools/extra/clangd/index/dex/dexp/CMakeFiles/dexp.dir/Dexp.cpp.o 
$TOPDIR/tmp/hosttools/g++ -D_GNU_SOURCE -D__STDC_CONSTANT_MACROS -D__STDC_FORMAT_MACROS -D__STDC_LIMIT_MACROS -I$TOPDIR/tmp/work/x86_64-linux/clang-native/19.1.7/build/tools/clang/tools/extra/clangd/index/dex/dexp -I$TOPDIR/tmp/work-shared/llvm-project-source-19.1.7-r0/llvm-project-19.1.7.src/clang-tools-extra/clangd/index/dex/dexp -I$TOPDIR/tmp/work-shared/llvm-project-source-19.1.7-r0/llvm-project-19.1.7.src/clang-tools-extra/clangd/../include-cleaner/include -I$TOPDIR/tmp/work/x86_64-linux/clang-native/19.1.7/build/tools/clang/tools/extra/clangd/../clang-tidy -I$TOPDIR/tmp/work-shared/llvm-project-source-19.1.7-r0/llvm-project-19.1.7.src/clang/include -I$TOPDIR/tmp/work/x86_64-linux/clang-native/19.1.7/build/tools/clang/include -I$TOPDIR/tmp/work/x86_64-linux/clang-native/19.1.7/build/include -I$TOPDIR/tmp/work-shared/llvm-project-source-19.1.7-r0/llvm-project-19.1.7.src/llvm/include -I$TOPDIR/tmp/work-shared/llvm-project-source-19.1.7-r0/llvm-project-19.1.7.src/clang-tools-extra/clangd -I$TOPDIR/tmp/work/x86_64-linux/clang-native/19.1.7/build/tools/clang/tools/extra/clangd -isystem$TOPDIR/tmp/work/x86_64-linux/clang-native/19.1.7/recipe-sysroot-native/usr/include -O2 -pipe   -fvisibility-inlines-hidden -fPIC -fno-semantic-interposition -fvisibility-inlines-hidden -Werror=date-time -fno-lifetime-dse -Wall -Wextra -Wno-unused-parameter -Wwrite-strings -Wcast-qual -Wno-missing-field-initializers -pedantic -Wno-long-long -Wimplicit-fallthrough -Wno-uninitialized -Wno-nonnull -Wno-class-memaccess -Wno-redundant-move -Wno-pessimizing-move -Wno-noexcept-type -Wdelete-non-virtual-dtor -Wsuggest-override -Wno-comment -Wno-misleading-indentation -fdiagnostics-color -ffunction-sections -fdata-sections -fno-common -Woverloaded-virtual -fno-strict-aliasing -isystem$TOPDIR/tmp/work/x86_64-linux/clang-native/19.1.7/recipe-sysroot-native/usr/include -O2 -pipe   -fvisibility-inlines-hidden -DNDEBUG -g0 -std=c++17 -MD -MT tools/clang/tools/extra/clangd/index/dex/dexp/CMakeFiles/dexp.dir/Dexp.cpp.o -MF tools/clang/tools/extra/clangd/index/dex/dexp/CMakeFiles/dexp.dir/Dexp.cpp.o.d -o tools/clang/tools/extra/clangd/index/dex/dexp/CMakeFiles/dexp.dir/Dexp.cpp.o -c $TOPDIR/tmp/work-shared/llvm-project-source-19.1.7-r0/llvm-project-19.1.7.src/clang-tools-extra/clangd/index/dex/dexp/Dexp.cpp
$TOPDIR/tmp/work-shared/llvm-project-source-19.1.7-r0/llvm-project-19.1.7.src/clang-tools-extra/clangd/index/dex/dexp/Dexp.cpp: In substitution of ‘template<class _Functor, class, class> std::function<std::unique_ptr<clang::clangd::{anonymous}::Command>()>::function(_Functor) [with _Functor = <missing>; <template-parameter-1-2> = <missing>; <template-parameter-1-3> = <missing>]’:
$TOPDIR/tmp/work-shared/llvm-project-source-19.1.7-r0/llvm-project-19.1.7.src/clang-tools-extra/clangd/index/dex/dexp/Dexp.cpp:372:1:   required from here
$TOPDIR/tmp/work-shared/llvm-project-source-19.1.7-r0/llvm-project-19.1.7.src/clang-tools-extra/clangd/index/dex/dexp/Dexp.cpp:372:1: internal compiler error: Segmentation fault
  372 | };
      | ^
Please submit a full bug report,
with preprocessed source if appropriate.
See <file:///usr/share/doc/gcc-10/README.Bugs> for instructions.
Comment 4 Yoann Congal 2025-03-21 09:55:40 UTC
While trying to extract a reproducer (currently a 7MB preprocessed C++ file (!)), I found that the segfault does not happens every time. My test loop is currently at 20 tries and usually catch the segfault on try 1-10.
Comment 5 Randy MacLeod 2025-03-21 19:49:30 UTC
FYI:
There is a tool called c-reduce:
   C-Reduce is a tool that takes a large C or C++ program 
   that has a property of interest (such as triggering a compiler bug) 
   and automatically produces a much smaller C/C++ program that 
   has the same property.

c-reduce now has a faster python wrapper called cvise as mentioned in https://wiki.gentoo.org/wiki/GCC_ICE_reporting_guide#.5Bbonus.5D_minimize_self-contained_source_using_cvise

I've only used c-reduce one years ago but maybe this info will help you get a smaller reproducer.
Comment 6 Yoann Congal 2025-03-21 23:00:29 UTC
Thanks Randy, I stumble on creduce this morning and ran it today. It simplified the reproducer to (it has gone from 7MB to 12 lines, I got down to 10, I have the last word ;) ):

--- bug.cpp ---
class a {
  template <typename b> a(b);
};
template <typename c> typename c ::j d();
class e;
struct {
  a h;
} i {
  d<e>
}
--------

I also simplified the g++ command line:
  g++ -std=c++17 -o /dev/null -c bug.cpp

This gives randomly 2 outputs (around 50% of the times)
---- output 1 ----
bug.cpp:10:1: error: cannot resolve overloaded function ‘d’ based on conversion to type ‘a’
   10 | }
      | ^
------------------
(No segfault)

---- output 2 ----
bug.cpp: In substitution of ‘template<class b> a::a(b) [with b = <missing>]’:
bug.cpp:10:1:   required from here
bug.cpp:10:1: internal compiler error: Segmentation fault
   10 | }
      | ^
Please submit a full bug report,
with preprocessed source if appropriate.
See <file:///usr/share/doc/gcc-10/README.Bugs> for instructions.
------------------
(segfault)

Some things to note:
* Debian 11 is on GCC 10.2
   $ g++ --version
   g++ (Debian 10.2.1-6) 10.2.1 20210110
* gcc 10 is not maintained anymore by upstream  (maintained: 12.x and up)
* This bug does not reproduce on Debian12 (gcc 12.2)
* While the compiler should not segfault on bad code, maybe we can fix the upstream code to avoid triggering the compiler bug that seems to be related to the code "badness"?
Comment 7 Yoann Congal 2025-03-21 23:40:45 UTC
The Dexp.cpp file triggering the compiler bug has this header:
  // This file implements a simple interactive tool which can be used to manually
  // evaluate symbol search quality of Clangd index.

Sound like something not critical that we can maybe not compile?
Comment 8 Yoann Congal 2025-03-23 14:28:42 UTC
CC'ing Khem, he may have an idea on how to fix/workaround this.
Comment 9 Khem Raj 2025-03-24 01:10:54 UTC
Thanks for the reproducer. I tried it with gcc10 from ubuntu 20.04 which I have quick access to, and the segfault does not happen, in few iterations I have tried. However, I can see it in debian11 almost half the times as you said.

GCC on 20.04 is
gcc version 10.2.0 (Ubuntu 10.2.0-5ubuntu1~20.04)

The default is gcc-9 but they do have gcc-10 available optionally.

GCC on debian-11

gcc version 10.2.1 20210110 (Debian 10.2.1-6)


I could reproduce it on a vanilla debian 11 system as well. At this point, it seems its specific to debian11's gcc10.2 when C++17 is enabled, now there are many template related fixes around template argument deduction etc. We can look into what broke in debian11 but I am not sure if they will respin the toolchain if it was fixed since debian11 is oldstable and currently on final LTS stretch for another year.

- One solution would be to force -std=c++14 with g++
- other solution is to use newer gcc ( if available for debian 11 )
- Use buildtools tarball
- Bar AB to build clang on debian-11 workers
- Clang is upgraded to 20.1 on master this week, its possible that
we do not see this failure with clang-20 and all is hunky dory ( in other words sweep under the carpet )
Comment 10 Ross Burton 2025-03-25 15:37:33 UTC
Assuming that Dexp.cpp is the only place that we can crash gcc when building clang, the file says this:

// This file implements a simple interactive tool which can be used to manually
// evaluate symbol search quality of Clangd index.

and

"This is an **experimental** interactive tool to process user-provided search queries over given symbol collection obtained via clangd-indexer. The tool can be used to evaluate search quality of existing index implementations and manually construct non-trivial test cases."

To me that doesn't sound that essential, so one option would be to just patch it out of clang-native builds?
Comment 11 Khem Raj 2025-03-25 15:40:24 UTC
yes, after we ensure that clangd does not rely on it in some fashion.
Comment 12 Yoann Congal 2025-03-25 15:41:16 UTC
Next steps (discussed at tech call 20250325):
* Try to reproduce with sister distros (Ubuntu 20.04, 20.10 also on GCC 10.x)
* Report a bug on Debian 11 (little hope to get a fix, but we never know...)
* Try on latest clang 20.1.1 (merged on meta-clang yesterday)
* Find out whether the "dexp" tool (where the bug appears) is used in clang. If not, disable it.
Comment 13 Ross Burton 2025-03-25 15:58:00 UTC
Some data:

clang-tools-extra/clangd/index/dex/dexp/CMakeLists.txt builds Dexp.cpp into a dexp binary:

add_clang_executable(dexp
  Dexp.cpp
  )

Searching the clang-tools-extra repository for references "dexp" that are not in dexp itself:

clangd/CMakeLists.txt:add_subdirectory(index/dex/dexp)

This is the line we'd patch out.

clangd/test/CMakeLists.txt:  dexp
clangd/test/index-serialization/version-is-correct.test:# RUN: dexp %/S/Inputs/sample.idx -c="find B" | grep Bar || not grep -v '^#' %s

If we ran the tests we'd need to patch these out, but we don't.

clang-include-fixer/find-all-symbols/STLPostfixHeaderMap.cpp:      {"include/wordexp.h$", "<wordexp.h>"},
clang-tidy/abseil/StringFindStartswithCheck.cpp:                      ignoringParenImpCasts(StringFind.bind("findexpr"))))
clang-tidy/abseil/StringFindStartswithCheck.cpp:                      ignoringParenImpCasts(StringRFind.bind("findexpr"))))
clang-tidy/abseil/StringFindStartswithCheck.cpp:  const Expr *Haystack = Result.Nodes.getNodeAs<CXXMemberCallExpr>("findexpr")
clang-tidy/concurrency/MtUnsafeCheck.cpp:    "::wordexp",
clang-tidy/performance/TypePromotionInMathFnCheck.cpp:                                    "::fmin", "::fmod", "::hypot", "::ldexp",
clangd/index/CanonicalIncludes.cpp:    {"include/wordexp.h", "<wordexp.h>"},
test/clang-tidy/checkers/bugprone/suspicious-string-compare.c:int condexpr_wrapper(const char* a, const char* b) {
test/clang-tidy/checkers/performance/type-promotion-in-math-fn.cpp:double ldexp(double, double);
test/clang-tidy/checkers/performance/type-promotion-in-math-fn.cpp:  ldexp(a, b);
test/clang-tidy/checkers/performance/type-promotion-in-math-fn.cpp:  // CHECK-MESSAGES: :[[@LINE-1]]:3: warning: call to 'ldexp'
test/clang-tidy/checkers/performance/type-promotion-in-math-fn.cpp:  // CHECK-FIXES: {{^}}  std::ldexp(a, b);{{$}}

False-positives.

I think patching out add_subdirectory(index/dex/dexp) is a worthy experiment to try.
Comment 14 Randy MacLeod 2025-03-25 16:05:57 UTC
FYI, trying bug.cpp on a variety of toolchains (most of the 10.x ones!) using the flags:
   -O -std=c++17
on:
   https://godbolt.org/

never produced an ICE but rather always produced:
   <source>:10:1: error: cannot resolve overloaded function 'd' based on conversion to type 'a'
      10 | }
         | ^
   Compiler returned: 1

There's even this version:
arm-none-eabi-g++ (GNU Arm Embedded Toolchain 10-2020-q4-major) 10.2.1 20201103 (release)
which has a similar version number (but not date) as Debian 11.
Comment 15 Yoann Congal 2025-03-25 16:35:21 UTC
Bug reported to Debian : https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1101322

Ubuntu 20.04 *NOT* impacted.
Comment 16 Yoann Congal 2025-03-25 18:37:25 UTC
The recent 20.1.1 clang update is also impacted : On AB[0] and I've reproduced this locally (by looping on "touch .../Dexp.cpp && temp/run.do_compile")

[0]: https://autobuilder.yoctoproject.org/valkyrie/#/builders/18/builds/642

The last thing left to do now is to disable dexp from being built.
Comment 17 Khem Raj 2025-03-25 21:23:52 UTC
(In reply to Yoann Congal from comment #16)
> The recent 20.1.1 clang update is also impacted : On AB[0] and I've
> reproduced this locally (by looping on "touch .../Dexp.cpp &&
> temp/run.do_compile")
> 
> [0]: https://autobuilder.yoctoproject.org/valkyrie/#/builders/18/builds/642
> 
> The last thing left to do now is to disable dexp from being built.

if we want to modify this in clang-tools-extra then adding a cmake option to ebale/disable dexp would be a good approach. It can than be controlled from recipe via packageconfig. Secondly, icing on cake would be to submit such a patch to upstream.
Comment 18 Yoann Congal 2025-03-26 00:10:56 UTC
Fix PR in meta-clang: https://github.com/kraj/meta-clang/pull/1066

Still need to submit the patch upstream.
Comment 19 Mathieu Dubois-Briand 2025-03-26 17:27:54 UTC
meta-clang debian11-vk-3 master-next completed at 2025-03-25T16:07:34Z
https://autobuilder.yoctoproject.org/valkyrie/#/builders/18/builds/642/steps/11/logs/stdio
Comment 20 Yoann Congal 2025-03-27 22:16:01 UTC
Workaround merged in meta-clang: https://github.com/kraj/meta-clang/commit/fa1b780b8b9fafed08204719ab94a56e20d6a03a
(disable building dexp)

FWIW: Upstream PR is https://github.com/llvm/llvm-project/pull/133124
Comment 21 Yoann Congal 2025-03-28 16:05:53 UTC
For the curious: the bug was already reported to Debian, upstreamed to gcc and fixed:

#980429 - g++-10: spurious c++17 mode segmentation fault in append_to_statement_list_1 (tree-iterator.c:65) - Debian Bug report logs
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=980429

98790 – [10/11 Regression] ICE in append_to_statement_list_1 (Segmentation Fault)
https://gcc.gnu.org/bugzilla/show_bug.cgi?id=98790

Debian closed the bug as fixed in gcc-10/10.2.1-16 (in sid) but debian-11 is stuck in gcc-10/10.2.1-6 (has been for 4 years).
Comment 22 Ross Burton 2025-09-11 19:43:12 UTC
I asked Yoann to reproduce with current master as it has clang 21.1.0, and he reports that it's still a problem with the workaround disabled.
Comment 23 Khem Raj 2025-09-11 19:55:12 UTC
(In reply to Ross Burton from comment #22)
> I asked Yoann to reproduce with current master as it has clang 21.1.0, and
> he reports that it's still a problem with the workaround disabled.

Drop debian-11 for master on AB and then we can unbolt the workaround atleast for future releases.
Comment 24 Ross Burton 2025-09-11 19:57:44 UTC
That's exactly why I was asking, and I've already sent the patch ;)