57 Small Programs that Crash Compilers
blog.regehr.org
blog.regehr.org
Unlike the others, this one was actually found in production.
1. http://embed.cs.utah.edu/csmith/
2. http://www.cs.utah.edu/~regehr/papers/pldi12-preprint.pdf
The contribution is techniques for reducing the size of test cases, including test cases that might be generated by csmith (you realize the author of the blog post is one of the csmith authors, right?). From the PDLI'12 paper:
Using randomized differential testing, Csmith automates the construction of programs that trigger compiler bugs. These programs are large out of necessity: we found that bug-finding was most effective when random programs’ average size was 81 KB. In this paper, we use 98 bug-inducing programs created by Csmith as the inputs to several automated program reducers...
Regehr's team is behind both tools.
As a concrete example, EDG (used by ICC) has a strongly typed AST. GCC's AST consists of a single type (tree), which allows you to build absurd trees. You could represent the equivalent of
int x = goto struct { while (1); }
because the data type doesn't prohibit a goto target that happens to be a struct. This will probably explode when it gets to some later compiler stage. If you have distinct goto_node and label_node types, the compiler is less likely to accidentally create such monstrosities. You don't usually get such trees directly from the parser, but from some middle transformation pass.(The clang versions are from fairly early on in clang's development, but i dont' remember how old)
All that said, ICC uses a frontend from a company called EDG. They produce C and C++ frontends. They are a 5 person company, but produce very thorough, very well tested, and very well documented frontends. It is not surprising that they are difficult to crash. Language frontends is all they do.
You can usually figure out if this is true by testing it out against Comeau's online C/C++ compiler. Or at least, you could. Comeau seems not to have updated in a while
If it crashes, it was probably EDG. If it doesn't, it wasn't
The ICC example posted does not crash Comeau, so i doubt it was an EDG issue.
(They are also missing a semicolon on line 2, which EDG doesn't crash on. If you fix this, it still doesn't crash EDG) In fact, all of the programs they posted that contain structs have the same issue. The last member of every struct is missing a semicolon.
Different compilers use different EDG versions, so a bug in one might not be present in another.