Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 622775 - segmentation fault when js engine is built with -Os && -fexceptions
segmentation fault when js engine is built with -Os && -fexceptions
Product: Fedora
Classification: Fedora
Component: gcc (Show other bugs)
i686 Linux
low Severity medium
: ---
: ---
Assigned To: Jakub Jelinek
Fedora Extras Quality Assurance
Depends On:
  Show dependency treegraph
Reported: 2010-08-10 07:56 EDT by Martin Stransky
Modified: 2011-02-14 09:10 EST (History)
1 user (show)

See Also:
Fixed In Version: gcc-4.5.1-1.fc14
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2011-02-14 09:10:57 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)
gcc testcase (1.47 MB, application/x-gzip)
2010-08-17 12:49 EDT, Martin Stransky
no flags Details

  None (edit)
Description Martin Stransky 2010-08-10 07:56:38 EDT
Description of problem:
If mozilla (xulrunner/thunderbird) is built with "-Os -fexceptions" gcc flags, the built binary crashes with segmentation fault. Works if it's build with -O2 or w/o -fexceptions.

broken build (gcc-4.5.0-4.fc14):

correct build (gcc-4.4.4-8.fc14):

(the different package versions are not important, with gcc-4.5.0-4.fc14.i686 it fails to build all mozilla packages).

It happens on i686 only, x86_64 is okay. 

Version-Release number of selected component (if applicable):

How reproducible:

Steps to Reproduce:
1. download thunderbird from git
2. fedpkg local
3. see the log
Note: We catch it in Thunderbird because it's built with -Os -fexceptions. Firefox is built with -O2 -fexceptions so it's fine.
Comment 1 Jakub Jelinek 2010-08-11 02:49:02 EDT
Could you please narrow this down to say one particular .o file using binary search (mixing -O2 -fexceptions and -Os -fexceptions objects until you find what matters)?  For miscompilations (which often could be just package bugs relying on undefined behavior etc.) I'd very much prefer something shorter than the whole thunderbird.
Comment 2 Martin Stransky 2010-08-12 05:08:20 EDT
It seems to affect whole js engine. If I try to run trace test, some of them fails. Will try to find the affected .o file.
Comment 3 Martin Stransky 2010-08-12 11:16:37 EDT
The another flag which has to be set is -fPIC. So it crashes when "-Os -fexceptions -fPIC" is set. I tried to identify the affected module but it even depends on module order during linking. When .o files are in some on g++ command line it does not crash.
Comment 5 Martin Stransky 2010-08-17 12:49:39 EDT
Created attachment 439161 [details]
gcc testcase

There's the tescase attached. Run it by _test shell script, it should assert. It affects i686. Look for JSString::unitStringTable[] in jsstr.cpp.
Comment 8 Jakub Jelinek 2010-08-18 06:12:29 EDT
This is http://gcc.gnu.org/PR45112, which is fixed in gcc-4.5.1-1.fc14.  Unfortunately it is stuck in testing for f14, you might give it karma points and mention how urgent it is...
Comment 9 Martin Stransky 2011-02-14 09:10:57 EST
Already fixed.

Note You need to log in before you can comment on or make changes to this bug.