From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: by sourceware.org (Postfix, from userid 48) id 908363857004; Wed, 23 Dec 2020 22:18:36 +0000 (GMT) DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 908363857004 From: "guez at lmd dot ens.fr" To: gcc-bugs@gcc.gnu.org Subject: [Bug fortran/98433] New: double free detected in tcache 2, after merge of structures Date: Wed, 23 Dec 2020 22:18:36 +0000 X-Bugzilla-Reason: CC X-Bugzilla-Type: new X-Bugzilla-Watch-Reason: None X-Bugzilla-Product: gcc X-Bugzilla-Component: fortran X-Bugzilla-Version: 10.1.0 X-Bugzilla-Keywords: X-Bugzilla-Severity: normal X-Bugzilla-Who: guez at lmd dot ens.fr X-Bugzilla-Status: UNCONFIRMED X-Bugzilla-Resolution: X-Bugzilla-Priority: P3 X-Bugzilla-Assigned-To: unassigned at gcc dot gnu.org X-Bugzilla-Target-Milestone: --- X-Bugzilla-Flags: X-Bugzilla-Changed-Fields: bug_id short_desc product version bug_status bug_severity priority component assigned_to reporter target_milestone Message-ID: Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable X-Bugzilla-URL: http://gcc.gnu.org/bugzilla/ Auto-Submitted: auto-generated MIME-Version: 1.0 X-BeenThere: gcc-bugs@gcc.gnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: Gcc-bugs mailing list List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 23 Dec 2020 22:18:36 -0000 https://gcc.gnu.org/bugzilla/show_bug.cgi?id=3D98433 Bug ID: 98433 Summary: double free detected in tcache 2, after merge of structures Product: gcc Version: 10.1.0 Status: UNCONFIRMED Severity: normal Priority: P3 Component: fortran Assignee: unassigned at gcc dot gnu.org Reporter: guez at lmd dot ens.fr Target Milestone: --- This is the output of `gcc -v` on my machine: Using built-in specs. COLLECT_GCC=3Dgcc COLLECT_LTO_WRAPPER=3D/usr/lib/gcc/x86_64-linux-gnu/9/lto-wrapper OFFLOAD_TARGET_NAMES=3Dnvptx-none:hsa OFFLOAD_TARGET_DEFAULT=3D1 Target: x86_64-linux-gnu Configured with: ../src/configure -v --with-pkgversion=3D'Ubuntu 9.3.0-17ubuntu1~20.04' --with-bugurl=3Dfile:///usr/share/doc/gcc-9/README.B= ugs --enable-languages=3Dc,ada,c++,go,brig,d,fortran,objc,obj-c++,gm2 --prefix= =3D/usr --with-gcc-major-version-only --program-suffix=3D-9 --program-prefix=3Dx86_64-linux-gnu- --enable-shared --enable-linker-build-= id --libexecdir=3D/usr/lib --without-included-gettext --enable-threads=3Dposix --libdir=3D/usr/lib --enable-nls --enable-clocale=3Dgnu --enable-libstdcxx-= debug --enable-libstdcxx-time=3Dyes --with-default-libstdcxx-abi=3Dnew --enable-gnu-unique-object --disable-vtable-verify --enable-plugin --enable-default-pie --with-system-zlib --with-target-system-zlib=3Dauto --enable-objc-gc=3Dauto --enable-multiarch --disable-werror --with-arch-32= =3Di686 --with-abi=3Dm64 --with-multilib-list=3Dm32,m64,mx32 --enable-multilib --with-tune=3Dgeneric --enable-offload-targets=3Dnvptx-none=3D/build/gcc-9-HskZEa/gcc-9-9.3.0/deb= ian/tmp-nvptx/usr,hsa --without-cuda-driver --enable-checking=3Drelease --build=3Dx86_64-linux-gnu --host=3Dx86_64-linux-gnu --target=3Dx86_64-linux-gnu Thread model: posix gcc version 9.3.0 (Ubuntu 9.3.0-17ubuntu1~20.04) Here is a test program for the bug: $ cat test_bug_merge.f90 module bug_merge_m implicit none contains subroutine bug_merge type t real, allocatable:: v(:) end type t type(t) x1, x2, x3 allocate(x1%v(1)) x1%v =3D 1. allocate(x2%v(1)) x2%v =3D 2. x3 =3D merge(x1, x2, .false.) print *, "x3%v =3D ", x3%v end subroutine bug_merge end module bug_merge_m program test_bug_merge use bug_merge_m, only: bug_merge implicit none call bug_merge end program test_bug_merge And here is the result of compilation and execution: $ gfortran test_bug_merge.f90 $ a.out x3%v =3D 2.00000000=20=20=20=20 free(): double free detected in tcache 2 Program received signal SIGABRT: Process abort signal. Backtrace for this error: #0 0x146659050d3a #1 0x14665904fed5 #2 0x146658e7e20f #3 0x146658e7e18b #4 0x146658e5d858 #5 0x146658ec83ed #6 0x146658ed047b #7 0x146658ed20ec #8 0x55a871b8756c #9 0x55a871b8759c #10 0x55a871b875d5 #11 0x146658e5f0b2 #12 0x55a871b8711d #13 0xffffffffffffffff Aborted (core dumped) I think there is nothing wrong in the program. x1 and x2 are well defined. = The error disappears if I replace the merge line with a simple x3 =3D x2. The e= rror also disappears if I inline the content of the subroutine in the main progr= am unit. Also, the program works with the Intel compiler.=