Fedora Account System
Red Hat Associate
Red Hat Customer
Veusz fails to build in koji on s390x with a segmentation fault crash starting the self test: + PYTHONPATH=/builddir/build/BUILD/veusz-4.2.1-build/BUILDROOT/usr/lib64/python3.15/site-packages + QT_QPA_PLATFORM=minimal + /usr/bin/python3 tests/runselftest.py /var/tmp/rpm-tmp.qpZIi7: line 65: 3738 Segmentation fault (core dumped) PYTHONPATH=/builddir/build/BUILD/veusz-4.2.1-build/BUILDROOT/usr/lib64/python3.15/site-packages QT_QPA_PLATFORM=minimal /usr/bin/python3 tests/runselftest.py error: Bad exit status from /var/tmp/rpm-tmp.qpZIi7 (%check) RPM build errors: Bad exit status from /var/tmp/rpm-tmp.qpZIi7 (%check) Child return code was: 1 Reproducible: Always
This is clearly GCC 16 related. On F-44 (with gcc 16) both version 4.2.1 and 4.2 will crash. But when gcc15 package is installed and the compiler is overridden like "CC=gcc-15 CXX=g++-15", then the build runs OK and the tests are successful. It also corresponds with the build results in koji.
The backtrace is ... Core was generated by `/usr/bin/python3 tests/runselftest.py'. Program terminated with signal SIGSEGV, Segmentation fault. #0 0x000003fdcf983c5e in Cntr_trace () from /home/sharkcz/veusz/veusz-4.2.1-build/BUILDROOT/usr/lib64/python3.14/site-packages/veusz/helpers/_nc_cntr.cpython-314-s390x-linux-gnu.so (gdb) where #0 0x000003fdcf983c5e in Cntr_trace () from /home/sharkcz/veusz/veusz-4.2.1-build/BUILDROOT/usr/lib64/python3.14/site-packages/veusz/helpers/_nc_cntr.cpython-314-s390x-linux-gnu.so #1 0x000003ffbe297a76 in method_vectorcall_VARARGS_KEYWORDS (func=0x3fdcfa2ee80, args=0x3ffef676340, nargsf=<optimized out>, kwnames=<optimized out>) at /usr/src/debug/python3.14-3.14.6-1.fc44.s390x/Objects/descrobject.c:359 #2 0x000003ffbe25c11a in _PyObject_VectorcallTstate (kwnames=0x0, tstate=0x3ffbe7435e0 <_PyRuntime+315584>, callable=0x3fdcfa2ee80, args=0x3ffef676340, nargsf=9223372036854775810) at /usr/src/debug/python3.14-3.14.6-1.fc44.s390x/Include/internal/pycore_call.h:177 #3 PyObject_Vectorcall (kwnames=0x0, callable=0x3fdcfa2ee80, args=0x3ffef676340, nargsf=9223372036854775810) at /usr/src/debug/python3.14-3.14.6-1.fc44.s390x/Objects/call.c:327 #4 _PyEval_EvalFrameDefault (tstate=<optimized out>, frame=0x3ffbe85bc60, throwflag=<optimized out>) at /usr/src/debug/python3.14-3.14.6-1.fc44.s390x/Python/generated_cases.c.h:1621 #5 0x000003ffbe24f2fc in _PyEval_EvalFrame (throwflag=0, tstate=0x3ffbe7435e0 <_PyRuntime+315584>, frame=0x3ffbe85b020) at /usr/src/debug/python3.14-3.14.6-1.fc44.s390x/Include/internal/pycore_ceval.h:120 #6 _PyEval_Vector.constprop.0 (tstate=tstate@entry=0x3ffbe7435e0 <_PyRuntime+315584>, func=func@entry=0x3ffbdb9f270, locals=locals@entry=0x3ffbdb310c0, kwnames=0x0, argcount=0, args=0x0) at /usr/src/debug/python3.14-3.14.6-1.fc44.s390x/Python/ceval.c:2110 #7 0x000003ffbe39ba12 in PyEval_EvalCode (co=<optimized out>, globals=<optimized out>, locals=<optimized out>) at /usr/src/debug/python3.14-3.14.6-1.fc44.s390x/Python/ceval.c:982 #8 0x000003ffbe407bda in run_mod (mod=mod@entry=0x2aa24f094b0, filename=filename@entry=0x3ffbdb472f0, globals=globals@entry=0x3ffbdb310c0, locals=0x5, locals@entry=0x3ffbdb310c0, flags=flags@entry=0x3ffef676a20, arena=0x3ffbdc1bdf0, interactive_src=0x0, generate_new_source=0) at /usr/src/debug/python3.14-3.14.6-1.fc44.s390x/Python/pythonrun.c:1460 #9 0x000003ffbe406f2a in pyrun_file (fp=fp@entry=0x2aa24d4d350, filename=filename@entry=0x3ffbdb472f0, start=start@entry=257, globals=globals@entry=0x3ffbdb310c0, locals=locals@entry=0x3ffbdb310c0, closeit=1, flags=0x3ffef676a20) at /usr/src/debug/python3.14-3.14.6-1.fc44.s390x/Python/pythonrun.c:1294 #10 0x000003ffbe405fc4 in _PyRun_SimpleFileObject (fp=fp@entry=0x2aa24d4d350, filename=filename@entry=0x3ffbdb472f0, closeit=0, closeit@entry=1, flags=0x3ffbe6c3e79 <_Py_NoneStruct+1>, flags@entry=0x3ffef676a20) at /usr/src/debug/python3.14-3.14.6-1.fc44.s390x/Python/pythonrun.c:521 #11 0x000003ffbe405cf8 in _PyRun_AnyFileObject (fp=0x2aa24d4d350, filename=0x3ffbdb472f0, closeit=1, flags=0x3ffef676a20) at /usr/src/debug/python3.14-3.14.6-1.fc44.s390x/Python/pythonrun.c:81 #12 0x000003ffbe37f060 in pymain_run_file_obj (program_name=0x3ffbdb31130, filename=0x3ffbdb472f0, skip_source_first_line=0) at /usr/src/debug/python3.14-3.14.6-1.fc44.s390x/Modules/main.c:410 #13 pymain_run_file (config=0x3ffbe70e6a0 <_PyRuntime+98688>) at /usr/src/debug/python3.14-3.14.6-1.fc44.s390x/Modules/main.c:429 #14 pymain_run_python (exitcode=0x3ffef676a14) at /usr/src/debug/python3.14-3.14.6-1.fc44.s390x/Modules/main.c:695 #15 Py_RunMain () at /usr/src/debug/python3.14-3.14.6-1.fc44.s390x/Modules/main.c:776 #16 0x000003ffbe377e9c in Py_BytesMain (argc=<optimized out>, argv=<optimized out>) at /usr/src/debug/python3.14-3.14.6-1.fc44.s390x/Modules/main.c:830 #17 0x000003ffbdf34adc in __libc_start_call_main (main=0x2aa24300880 <main>, main@entry=0x5, argc=argc@entry=2, argv=argv@entry=0x3ffef676e98) at ../sysdeps/nptl/libc_start_call_main.h:59 #18 0x000003ffbdf34c36 in __libc_start_main_impl (main=0x5, argc=2, argv=0x3ffef676e98, init=<optimized out>, fini=<optimized out>, rtld_fini=0x3ffbe885af0 <_dl_fini>, stack_end=0x3ffef676de0) at ../csu/libc-start.c:360 #19 0x000002aa24300790 in _start ()
compiling veusz-4.2.1/src/nc_cntr/_nc_cntr.c with -O1 makes the tests pass, so either GCC 16 is miscompiling the file or it relies eg. on an undefined behaviour ... moving to the gcc team for further analysis ...
further debugging points to the cntr_trace() function (https://github.com/veusz/veusz/blob/master/src/nc_cntr/_nc_cntr.c#L1467) that needs "-O1" to allow the tests to pass
a slightly better backtrace from the default -O2 build Core was generated by `/usr/bin/python3 tests/runselftest.py'. Program terminated with signal SIGSEGV, Segmentation fault. #0 0x000003fd9c683c1e in cntr_trace (site=<optimized out>, levels=<optimized out>, nlevels=<optimized out>, points=<optimized out>, nchunk=<optimized out>) at src/nc_cntr/_nc_cntr.c:1535 1535 nseg0[iseg] = n; (gdb) where #0 0x000003fd9c683c1e in cntr_trace (site=<optimized out>, levels=<optimized out>, nlevels=<optimized out>, points=<optimized out>, nchunk=<optimized out>) at src/nc_cntr/_nc_cntr.c:1535 #1 Cntr_trace (self=<optimized out>, args=<optimized out>, kwds=<optimized out>) at src/nc_cntr/_nc_cntr.c:1735 #2 0x000003ff8af97a76 in method_vectorcall_VARARGS_KEYWORDS (func=0x3fd9c72aca0, args=0x3ffc4d76880, nargsf=<optimized out>, kwnames=<optimized out>) at /usr/src/debug/python3.14-3.14.6-1.fc44.s390x/Objects/descrobject.c:359 #3 0x000003ff8af5c11a in _PyObject_VectorcallTstate (kwnames=0x0, tstate=0x3ff8b4435e0 <_PyRuntime+315584>, callable=0x3fd9c72aca0, args=0x3ffc4d76880, nargsf=9223372036854775810) at /usr/src/debug/python3.14-3.14.6-1.fc44.s390x/Include/internal/pycore_call.h:177 #4 PyObject_Vectorcall (kwnames=0x0, callable=0x3fd9c72aca0, args=0x3ffc4d76880, nargsf=9223372036854775810) at /usr/src/debug/python3.14-3.14.6-1.fc44.s390x/Objects/call.c:327 #5 _PyEval_EvalFrameDefault (tstate=<optimized out>, frame=0x3ff8b55bc60, throwflag=<optimized out>) at /usr/src/debug/python3.14-3.14.6-1.fc44.s390x/Python/generated_cases.c.h:1621 #6 0x000003ff8af4f2fc in _PyEval_EvalFrame (throwflag=0, tstate=0x3ff8b4435e0 <_PyRuntime+315584>, frame=0x3ff8b55b020) at /usr/src/debug/python3.14-3.14.6-1.fc44.s390x/Include/internal/pycore_ceval.h:120 #7 _PyEval_Vector.constprop.0 (tstate=tstate@entry=0x3ff8b4435e0 <_PyRuntime+315584>, func=func@entry=0x3ff8a89f1c0, locals=locals@entry=0x3ff8a830e00, kwnames=0x0, argcount=0, args=0x0) at /usr/src/debug/python3.14-3.14.6-1.fc44.s390x/Python/ceval.c:2110 #8 0x000003ff8b09ba12 in PyEval_EvalCode (co=<optimized out>, globals=<optimized out>, locals=<optimized out>) at /usr/src/debug/python3.14-3.14.6-1.fc44.s390x/Python/ceval.c:982 #9 0x000003ff8b107bda in run_mod (mod=mod@entry=0x2aa173bcc40, filename=filename@entry=0x3ff8a8472f0, globals=globals@entry=0x3ff8a830e00, locals=0x5, locals@entry=0x3ff8a830e00, flags=flags@entry=0x3ffc4d76f60, arena=0x3ff8a91bdf0, interactive_src=0x0, generate_new_source=0) at /usr/src/debug/python3.14-3.14.6-1.fc44.s390x/Python/pythonrun.c:1460 #10 0x000003ff8b106f2a in pyrun_file (fp=fp@entry=0x2aa17200350, filename=filename@entry=0x3ff8a8472f0, start=start@entry=257, globals=globals@entry=0x3ff8a830e00, locals=locals@entry=0x3ff8a830e00, closeit=1, flags=0x3ffc4d76f60) at /usr/src/debug/python3.14-3.14.6-1.fc44.s390x/Python/pythonrun.c:1294 #11 0x000003ff8b105fc4 in _PyRun_SimpleFileObject (fp=fp@entry=0x2aa17200350, filename=filename@entry=0x3ff8a8472f0, closeit=0, closeit@entry=1, flags=0x3ff8b3c3e79 <_Py_NoneStruct+1>, flags@entry=0x3ffc4d76f60) at /usr/src/debug/python3.14-3.14.6-1.fc44.s390x/Python/pythonrun.c:521 #12 0x000003ff8b105cf8 in _PyRun_AnyFileObject (fp=0x2aa17200350, filename=0x3ff8a8472f0, closeit=1, flags=0x3ffc4d76f60) at /usr/src/debug/python3.14-3.14.6-1.fc44.s390x/Python/pythonrun.c:81 #13 0x000003ff8b07f060 in pymain_run_file_obj (program_name=0x3ff8a830e70, filename=0x3ff8a8472f0, skip_source_first_line=0) at /usr/src/debug/python3.14-3.14.6-1.fc44.s390x/Modules/main.c:410 #14 pymain_run_file (config=0x3ff8b40e6a0 <_PyRuntime+98688>) at /usr/src/debug/python3.14-3.14.6-1.fc44.s390x/Modules/main.c:429 #15 pymain_run_python (exitcode=0x3ffc4d76f54) at /usr/src/debug/python3.14-3.14.6-1.fc44.s390x/Modules/main.c:695 #16 Py_RunMain () at /usr/src/debug/python3.14-3.14.6-1.fc44.s390x/Modules/main.c:776 #17 0x000003ff8b077e9c in Py_BytesMain (argc=<optimized out>, argv=<optimized out>) at /usr/src/debug/python3.14-3.14.6-1.fc44.s390x/Modules/main.c:830 #18 0x000003ff8ac34adc in __libc_start_call_main (main=0x2aa16000880 <main>, main@entry=0x5, argc=argc@entry=2, argv=argv@entry=0x3ffc4d773d8) at ../sysdeps/nptl/libc_start_call_main.h:59 #19 0x000003ff8ac34c36 in __libc_start_main_impl (main=0x5, argc=2, argv=0x3ffc4d773d8, init=<optimized out>, fini=<optimized out>, rtld_fini=0x3ff8b585af0 <_dl_fini>, stack_end=0x3ffc4d77320) at ../csu/libc-start.c:360 #20 0x000002aa16000790 in _start () (gdb) l 1530 if (n == 0) 1531 break; 1532 if (n > 0) 1533 { 1534 /* could add array bounds checking */ 1535 nseg0[iseg] = n; 1536 site->xcp += n; 1537 site->ycp += n; 1538 ntotal2 += n; 1539 nparts2++;
this warning from GCC 16 also seems to be relevant, because it's incorrect IMO, GCC 15 produces no such warning gcc -O2 -flto=auto -ffat-lto-objects -fexceptions -g -grecord-gcc-switches -pipe -Wall -Werror=format-security -Wp,-U_FORTIFY_SOURCE,-D_FORTIFY_SOURCE=3 -Wp,-D_GLIBCXX_ASSERTIONS -specs=/u sr/lib/rpm/redhat/redhat-hardened-cc1 -fstack-protector-strong -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -march=z13 -mtune=z14 -fasynchronous-unwind-tables -fstack-clash-protection -fPIC -I/usr/lib64/python3.14/site-packages/numpy/_core/include -Isrc/nc_cntr -I/usr/include/python3.14 -c src/nc_cntr/_nc_cntr.c -o build/temp.linux-s390x-cpython-314/src/nc_cntr/_nc_cntr.o src/nc_cntr/_nc_cntr.c: In function ‘cntr_trace’: src/nc_cntr/_nc_cntr.c:1479:10: warning: variable ‘nparts2’ set but not used [-Wunused-but-set-variable=] 1479 | long nparts2 = 0; | ^~~~~~~
Created attachment 2146335 [details] preprocessed source
Created attachment 2146336 [details] helper script build script to compile the affected python module and run the tests, to be run after "fedpkg local"
(In reply to Dan Horák from comment #6) > this warning from GCC 16 also seems to be relevant, because it's incorrect > IMO, GCC 15 produces no such warning > > gcc -O2 -flto=auto -ffat-lto-objects -fexceptions -g -grecord-gcc-switches > -pipe -Wall -Werror=format-security > -Wp,-U_FORTIFY_SOURCE,-D_FORTIFY_SOURCE=3 -Wp,-D_GLIBCXX_ASSERTIONS -specs=/u > sr/lib/rpm/redhat/redhat-hardened-cc1 -fstack-protector-strong > -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -march=z13 -mtune=z14 > -fasynchronous-unwind-tables -fstack-clash-protection > -fPIC -I/usr/lib64/python3.14/site-packages/numpy/_core/include > -Isrc/nc_cntr -I/usr/include/python3.14 -c src/nc_cntr/_nc_cntr.c -o > build/temp.linux-s390x-cpython-314/src/nc_cntr/_nc_cntr.o > src/nc_cntr/_nc_cntr.c: In function ‘cntr_trace’: > src/nc_cntr/_nc_cntr.c:1479:10: warning: variable ‘nparts2’ set but not > used [-Wunused-but-set-variable=] > 1479 | long nparts2 = 0; > | ^~~~~~~ The warning is certainly correct. See https://gcc.gnu.org/gcc-16/porting_to.html#changes-to-wunused for more details. The source mentions nparts2 just in long nparts2 = 0; and nparts2++; so the variable is completely useless.
The code generation change bisected to https://gcc.gnu.org/r16-3301 - the assembly difference between 3300 and 3301 is --- _nc_cntr.s_ 2026-06-25 18:58:46.027920462 +0200 +++ _nc_cntr.s 2026-06-25 18:59:11.754606327 +0200 @@ -5196,9 +5196,9 @@ Cntr_trace: .LVL586: .L572: .loc 1 1530 12 view .LVU2010 - cgije %r2,0,.L573 + je .L573 .loc 1 1532 12 view .LVU2011 - cgijle %r2,0,.L574 + jle .L574 .loc 1 1536 23 view .LVU2012 sllg %r1,%r2,3 .loc 1 1535 25 view .LVU2013 (reproduces even without -flto). The first difference is during late_combine1, +trying to parallelize insn 1319 and insn 1337 +successfully matched this instruction to *tstdi_extimm: +(parallel [ + (set (reg:CCS 33 %cc) + (compare:CCS (reg:DI 514 [ k ]) + (const_int 0 [0]))) + (set (reg/v:DI 258 [ k ]) + (reg:DI 514 [ k ])) + ]) +original cost = 4 + 4 (weighted: 49.397539), replacement cost = 4 (weighted: 24.238356); keeping replacement +rescanning insn with uid = 1337. +moving insn 1337 after insn 1319 +deleting insn with uid = 1337. +scanning new insn with uid = 1337. +deleting insn 1319 +deleting insn with uid = 1319. and -(insn 1319 2376 1320 134 (set (reg/v:DI 258 [ k ]) - (reg:DI 514 [ k ])) "src/nc_cntr/_nc_cntr.c":1523:13 1860 {*movdi_64} - (expr_list:REG_DEAD (reg:DI 514 [ k ]) - (nil))) -(debug_insn 1320 1319 1321 134 (var_location:DI n (reg/v:DI 258 [ k ])) "src/nc_cntr/_nc_cntr.c":1523:13 discrim 1 -1 +(insn 1337 2376 1320 134 (parallel [ + (set (reg:CCS 33 %cc) + (compare:CCS (reg:DI 514 [ k ]) + (const_int 0 [0]))) + (set (reg/v:DI 258 [ k ]) + (reg:DI 514 [ k ])) + ]) "src/nc_cntr/_nc_cntr.c":1530:12 1788 {*tstdi_extimm} + (nil)) +(debug_insn 1320 1337 1321 134 (var_location:DI n (reg/v:DI 258 [ k ])) "src/nc_cntr/_nc_cntr.c":1523:13 discrim 1 -1 and -(debug_insn 1336 1335 1337 136 (debug_marker) "src/nc_cntr/_nc_cntr.c":1530:9 -1 - (nil)) -(insn 1337 1336 1338 136 (parallel [ - (set (reg:CCS 33 %cc) - (compare:CCS (reg/v:DI 258 [ k ]) - (const_int 0 [0]))) - (clobber (scratch:DI)) - ]) "src/nc_cntr/_nc_cntr.c":1530:12 1790 {*tstdi_cconly_extimm} +(debug_insn 1336 1335 1338 136 (debug_marker) "src/nc_cntr/_nc_cntr.c":1530:9 -1
Bisection also stopped for me at r16-3301. Reduced it using 3300 and 3301 to long Cntr_n, Cntr_ntotal2; long curve_tracer(); void Cntr() { long ntotal; for (;;) { ntotal += Cntr_n; Cntr_n = curve_tracer(); if (Cntr_ntotal2 + Cntr_n > ntotal) goto error; if (Cntr_n == 0) break; if (Cntr_n > 0) Cntr_ntotal2 += Cntr_n; } error: } which has the same characteristics as the initial one: diff 3300.s 3301.s 58c58 < cgije %r2,0,.L1 --- > je .L1 60c60 < cgijle %r2,0,.L2 --- > jle .L2
I think the bug is in the *brx_stage1_<GPR:mode> define_insn_and_split. It doesn't have (clobber (reg:CC CC_REGNUM)) in the pattern, but splits into something that clobbers it, without any kind of checking whether CC isn't live across that insn. Which it is due to the late combine r16-3301 change in this case.
Unfortunately --- gcc/config/s390/s390.md.jj 2026-06-02 08:15:04.576141861 +0200 +++ gcc/config/s390/s390.md 2026-06-26 00:02:26.023204330 +0200 @@ -10256,7 +10256,8 @@ (pc))) (set (match_operand:GPR 4 "nonimmediate_operand" "") (plus:GPR (match_dup 1) (match_dup 2))) - (clobber (match_scratch:GPR 5 ""))] + (clobber (match_scratch:GPR 5 "")) + (clobber (reg:CC CC_REGNUM))] "" "#" "!reload_completed && !reload_in_progress" doesn't fix this, while it is matched properly, we get into an infinite loop trying to split this.
--- gcc/config/s390/s390.md.jj 2026-06-02 08:15:04.576141861 +0200 +++ gcc/config/s390/s390.md 2026-06-26 01:23:35.038623318 +0200 @@ -10256,6 +10256,7 @@ (define_insn_and_split "*brx_stage1_<GPR (pc))) (set (match_operand:GPR 4 "nonimmediate_operand" "") (plus:GPR (match_dup 1) (match_dup 2))) + (clobber (reg:CC CC_REGNUM)) (clobber (match_scratch:GPR 5 ""))] "" "#" does fix it though (is matched too, and split just once, not forever).
Based on the upstream bug report and current builds of gcc, I think this should have been fixed in Rawhide. I do not believe a corresponding backport/build was made in F44.
This bug appears to have been reported against 'rawhide' during the Fedora Linux 45 development cycle. Changing version to 45.