https://gcc.gnu.org/bugzilla/show_bug.cgi?id=118455

            Bug ID: 118455
           Summary: The program crashes when synchronization with C-i/o is
                    enabled; does not crash when it is disabled.
           Product: gcc
           Version: 11.4.0
            Status: UNCONFIRMED
          Severity: normal
          Priority: P3
         Component: c++
          Assignee: unassigned at gcc dot gnu.org
          Reporter: lluis.alemany.puig at gmail dot com
  Target Milestone: ---

Created attachment 60137
  --> https://gcc.gnu.org/bugzilla/attachment.cgi?id=60137&action=edit
The program

I would like to report a possible bug, in a program that purposefully tries to
access an out-of-bounds memory position in a std::vector.

I know that accessing in such a position is UB, and so there is no guarantee
concerning the behaviour of the program. Here I want to report that the program
crashes only when synchronization between C and C++ i/o standard streams is
disabled.

GCC info at the end. The program is attached as a preprocessed file (main.ii)
and the Makefile is
```
all: nosync sync
nosync: main.cpp
        g++ -DNOSYNC main.cpp -o nosync
sync: main.cpp
        g++ main.cpp -o sync
```

In a terminal, run `make`, and then run
```
$ ./sync   # crashes
$ ./nosync # does not crash
```

The program crashes with the following error message:
```
sync: malloc.c:2617: sysmalloc: Assertion `(old_top == initial_top (av) &&
old_size == 0) || ((unsigned long) (old_size) >= MINSIZE && prev_inuse
(old_top) && ((unsigned long) old_end & (pagesize - 1)) == 0)' failed.
Aborted (core dumped)
```


The program (as a plain .cpp file, i.e., not as a preprocessed file) is:
```
#include <iostream>
#include <vector>
using namespace std;

int main() {
#if defined NOSYNC
    std::ios_base::sync_with_stdio(false);
#endif

    // this vector is not large enough to cause the crash
    // vector<int> v{1,2,3,4,5,6,2,3,4};

    vector<int> v{1,2,3,4,5,6,2,3,4,5};
    vector<int> r(v.size(), 0);

    for (int i = 0; i <= v.size(); ++i) {
        r[i] = v[i];
    }

    for (int i = 0; i < r.size(); ++i) {
        cout << r[i] << ' ';
    }
    cout << '\n';
}
```


GCC info:

    Using built-in specs.
    COLLECT_GCC=gcc
    COLLECT_LTO_WRAPPER=/usr/lib/gcc/x86_64-linux-gnu/11/lto-wrapper
    OFFLOAD_TARGET_NAMES=nvptx-none:amdgcn-amdhsa
    OFFLOAD_TARGET_DEFAULT=1
    Target: x86_64-linux-gnu
    Configured with: ../src/configure -v --with-pkgversion='Ubuntu
11.4.0-1ubuntu1~22.04' --with-bugurl=file:///usr/share/doc/gcc-11/README.Bugs
--enable-languages=c,ada,c++,go,brig,d,fortran,objc,obj-c++,m2 --prefix=/usr
--with-gcc-major-version-only --program-suffix=-11
--program-prefix=x86_64-linux-gnu- --enable-shared --enable-linker-build-id
--libexecdir=/usr/lib --without-included-gettext --enable-threads=posix
--libdir=/usr/lib --enable-nls --enable-bootstrap --enable-clocale=gnu
--enable-libstdcxx-debug --enable-libstdcxx-time=yes
--with-default-libstdcxx-abi=new --enable-gnu-unique-object
--disable-vtable-verify --enable-plugin --enable-default-pie --with-system-zlib
--enable-libphobos-checking=release --with-target-system-zlib=auto
--enable-objc-gc=auto --enable-multiarch --disable-werror --enable-cet
--with-arch-32=i686 --with-abi=m64 --with-multilib-list=m32,m64,mx32
--enable-multilib --with-tune=generic
--enable-offload-targets=nvptx-none=/build/gcc-11-XeT9lY/gcc-11-11.4.0/debian/tmp-nvptx/usr,amdgcn-amdhsa=/build/gcc-11-XeT9lY/gcc-11-11.4.0/debian/tmp-gcn/usr
--without-cuda-driver --enable-checking=release --build=x86_64-linux-gnu
--host=x86_64-linux-gnu --target=x86_64-linux-gnu
--with-build-config=bootstrap-lto-lean --enable-link-serialization=2
    Thread model: posix
    Supported LTO compression algorithms: zlib zstd
    gcc version 11.4.0 (Ubuntu 11.4.0-1ubuntu1~22.04)

Reply via email to