llvm / llvm/llvm-project

[clang-check][syntax] Crash in TreeBuilder::assignRole: Assertion `It->second->getRole() == NodeRole::Detached && "re-assigning role for a child"' ` failed.

Open
#207,599 0 comments 0 reactions 0 assignees View on GitHub
clang-tools-extra crash generated by fuzzer
Dominant language
LLVM
Stars
40.5k
Forks
18.7k
PR merge metrics
PR metrics pending

Description

This input is generated by a fuzzer.
```cxx
int foo = F(Y, &str);
```

```
clang-check --tokens-dump example.cpp -- -xc++ -std=c++23
```

Interestingly, if you change `str` into other symbols, it does not crash.

```
clang-check: /home/ubuntu2404/llvm-project-196067/clang/lib/Tooling/Syntax/BuildTree.cpp:589: void clang::syntax::TreeBuilder::Forest::assignRole(llvm::ArrayRef, clang::syntax::NodeRole): Assertion `It->second->getRole() == NodeRole::Detached && "re-assigning role for a child"' failed.
#0 0x0000593f26d2b1f1 llvm::sys::PrintStackTrace(llvm::raw_ostream&, int) (/home/ubuntu2404/build-196067-assert/bin/clang-check+0x96d1f1)
#1 0x0000593f26d27dac llvm::sys::RunSignalHandlers() (/home/ubuntu2404/build-196067-assert/bin/clang-check+0x969dac)
#2 0x0000593f26d27f0c SignalHandler(int, siginfo_t*, void*) Signals.cpp:0:0
#3 0x00007df212845330 (/lib/x86_64-linux-gnu/libc.so.6+0x45330)
#4 0x00007df21289eb2c __pthread_kill_implementation ./nptl/pthread_kill.c:44:76
#5 0x00007df21289eb2c __pthread_kill_internal ./nptl/pthread_kill.c:78:10
#6 0x00007df21289eb2c pthread_kill ./nptl/pthread_kill.c:89:10
#7 0x00007df21284527e raise ./signal/../sysdeps/posix/raise.c:27:6
#8 0x00007df2128288ff abort ./stdlib/abort.c:81:7
#9 0x00007df21282881b _nl_load_domain ./intl/loadmsgcat.c:1177:9
#10 0x00007df21283b517 (/lib/x86_64-linux-gnu/libc.so.6+0x3b517)
#11 0x0000593f270bfe53 (/home/ubuntu2404/build-196067-assert/bin/clang-check+0xd01e53)
#12 0x0000593f270dab41 (anonymous namespace)::BuildTreeVisitor::TraverseNestedNameSpecifierLoc(clang::NestedNameSpecifierLoc) BuildTree.cpp:0:0
#13 0x0000593f270dc44e clang::RecursiveASTVisitor<(anonymous namespace)::BuildTreeVisitor>::TraverseDeclRefExpr(clang::DeclRefExpr*, llvm::SmallVectorImpl, llvm::PointerIntPairInfo>>>*) BuildTree.cpp:0:0
#14 0x0000593f270d29be clang::RecursiveASTVisitor<(anonymous namespace)::BuildTreeVisitor>::TraverseStmt(clang::Stmt*, llvm::SmallVectorImpl, llvm::PointerIntPairInfo>>>*) (.constprop.0) BuildTree.cpp:0:0
#15 0x0000593f270d7d4c clang::RecursiveASTVisitor<(anonymous namespace)::BuildTreeVisitor>::TraverseUnaryOperator(clang::UnaryOperator*, llvm::SmallVectorImpl, llvm::PointerIntPairInfo>>>*) BuildTree.cpp:0:0
#16 0x0000593f270d29be clang::RecursiveASTVisitor<(anonymous namespace)::BuildTreeVisitor>::TraverseStmt(clang::Stmt*, llvm::SmallVectorImpl, llvm::PointerIntPairInfo>>>*) (.constprop.0) BuildTree.cpp:0:0
#17 0x0000593f270d7a2d clang::RecursiveASTVisitor<(anonymous namespace)::BuildTreeVisitor>::TraverseObjCBoxedExpr(clang::ObjCBoxedExpr*, llvm::SmallVectorImpl, llvm::PointerIntPairInfo>>>*) BuildTree.cpp:0:0
#18 0x0000593f270d29be clang::RecursiveASTVisitor<(anonymous namespace)::BuildTreeVisitor>::TraverseStmt(clang::Stmt*, llvm::SmallVectorImpl, llvm::PointerIntPairInfo>>>*) (.constprop.0) BuildTree.cpp:0:0
#19 0x0000593f270e2dfb clang::RecursiveASTVisitor<(anonymous namespace)::BuildTreeVisitor>::TraverseVarDecl(clang::VarDecl*) BuildTree.cpp:0:0
#20 0x0000593f270caaea clang::RecursiveASTVisitor<(anonymous namespace)::BuildTreeVisitor>::TraverseDeclContextHelper(clang::DeclContext*) BuildTree.cpp:0:0
#21 0x0000593f270e383b clang::RecursiveASTVisitor<(anonymous namespace)::BuildTreeVisitor>::TraverseTranslationUnitDecl(clang::TranslationUnitDecl*) BuildTree.cpp:0:0
#22 0x0000593f270ca439 clang::syntax::buildSyntaxTree(clang::syntax::Arena&, clang::syntax::TokenBufferTokenManager&, clang::ASTContext&) (/home/ubuntu2404/build-196067-assert/bin/clang-check+0xd0c439)
#23 0x0000593f267be4af (anonymous namespace)::DumpSyntaxTree::CreateASTConsumer(clang::CompilerInstance&, llvm::StringRef)::Consumer::HandleTranslationUnit(clang::ASTContext&) ClangCheck.cpp:0:0
#24 0x0000593f285f4f9c clang::ParseAST(clang::Sema&, bool, bool) (/home/ubuntu2404/build-196067-assert/bin/clang-check+0x2236f9c)
#25 0x0000593f26d82271 clang::FrontendAction::Execute() (/home/ubuntu2404/build-196067-assert/bin/clang-check+0x9c4271)
#26 0x0000593f26dce308 clang::CompilerInstance::ExecuteAction(clang::FrontendAction&) (/home/ubuntu2404/build-196067-assert/bin/clang-check+0xa10308)
#27 0x0000593f270aacb7 clang::tooling::FrontendActionFactory::runInvocation(std::shared_ptr, clang::FileManager*, std::shared_ptr, clang::DiagnosticConsumer*) (/home/ubuntu2404/build-196067-assert/bin/clang-check+0xceccb7)
#28 0x0000593f270a4b2a clang::tooling::ToolInvocation::runInvocation(char const*, clang::driver::Compilation*, std::shared_ptr, std::shared_ptr) (/home/ubuntu2404/build-196067-assert/bin/clang-check+0xce6b2a)
#29 0x0000593f270a71e2 clang::tooling::ToolInvocation::run() (/home/ubuntu2404/build-196067-assert/bin/clang-check+0xce91e2)
#30 0x0000593f270a8e19 clang::tooling::ClangTool::run(clang::tooling::ToolAction*) (/home/ubuntu2404/build-196067-assert/bin/clang-check+0xceae19)
#31 0x0000593f26743405 main (/home/ubuntu2404/build-196067-assert/bin/clang-check+0x385405)
#32 0x00007df21282a1ca __libc_start_call_main ./csu/../sysdeps/nptl/libc_start_call_main.h:74:3
#33 0x00007df21282a28b call_init ./csu/../csu/libc-start.c:128:20
#34 0x00007df21282a28b __libc_start_main ./csu/../csu/libc-start.c:347:5
#35 0x0000593f267bd045 _start (/home/ubuntu2404/build-196067-assert/bin/clang-check+0x3ff045)
```

Contributor guide

Open the contributing guide

Research direction

Reproduce the crash with clang-check --tokens-dump on the provided example.cpp command and inspect clang/lib/Tooling/Syntax/BuildTree.cpp around Forest::assignRole at line 589. Trace the nested-name-specifier and DeclRefExpr traversal shown in the stack trace, then verify that the same input no longer triggers the assertion.

Written by the indexing model from the issue text.

Assessment

Tech stack
cpp
Domain
compilers, tooling
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Clearly specified
Newbie friendliness
52/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.