Crash on iOS arm64

Started by
15 comments, last by _Engine_ 8 years ago

Hi!

Looks like i found bug in angle script that leads to crashes on iOS arm64. I will try to explain details.

Problematic script is very simple:


void main()
{
    NGUIWidget@ wgt = @scene::inst;
    wgt.alpha = 0.58f;
}

Variable scene::inst are type of NGUISymbol0Instance and it is binded class from C++. NGUIWidget are also binded class from c++.

For NGUISymbol0Instance we register implicitly cast function to NGUIWidget.

Binding of cast function looks like


Machine()->RegisterObjectMethod("NGUISymbol0Instance", "NGUIWidget@ opImplCast()", asFUNCTION(NGUIWidgetCastGeneric));

Cast function looks like:


void NGUIWidgetCastGeneric(asIScriptGeneric *gen)
{
//On iOS arm64 pointer to object are corrupted and this leads to crash
void* obj = gen->GetObject();
}

Bytecode of function main are follow:


asBC_SUSPEND
asBC_PshGPtr
asBC_RefCpyV
asBC_PopPtr
asBC_ClrVPtr
asBC_CmpPtr
asBC_JZ
asBC_PshVPtr
asBC_CALLSYS

On asBC_RefCpyV correct pointer to C++ class copied to (void**)asPWORD(l_fp - asBC_SWORDARG0(l_bc));

On pc pointer address copied to 0x070d6900

On iOS 64 pointer address copied to 0x12802a1f0

On asBC_ClrVPtr on to (void**)asPWORD(l_fp - asBC_SWORDARG0(l_bc)); copied 0.

On pc address is 0x070d68fc and all goes fine because on pc size of pointer is 4.

On iOS 64 address is 0x12802a1ec and this is a moment when all things goes bad. On arm64 size of pointer is 8. So coping 0 to 0x12802a1ec leads to corruption of 0x12802a1f0

On asBC_CALLSYS function NGUIWidgetCastGeneric are called. When we extract object address from asIScriptGeneric we get corrupted pointer.

I hope my explanation enough to investigate problem.

Advertisement

Unfortunately I do not have any iOS 64bit platform to test AngelScript on, but I'll review the code and see if I can figure out what might be wrong.

I'll let you know if I need any more information.

AngelCode.com - game development and more - Reference DB - game developer references
AngelScript - free scripting library - BMFont - free bitmap font generator - Tower - free puzzle game


On iOS 64 address is 0x12802a1ec and this is a moment when all things goes bad. On arm64 size of pointer is 8. So coping 0 to 0x12802a1ec leads to corruption of 0x12802a1f0

This does indeed appear to be the source of the problem. Addresses on 64bit platforms should be 8byte aligned, i.e. end with 0 or 8, but in your case it ends with c (12), which is clearly wrong.

Can you check if a couple of defines are being properly set when compiling AngelScript for iOS 64bit?

  • The define AS_64BIT_PTR should be defined. (on line 393 in angelscript.h).
  • The define AS_PTR_SIZE should be defined as 2. (on line 1698 in angelscript.h)

Also, would it be possible for you to obtain the compiler predefined defines? With gnuc it is done with the following command:

echo . | g++ -dM -E -

I'm sure clang used by Apple has something similar.

AngelCode.com - game development and more - Reference DB - game developer references
AngelScript - free scripting library - BMFont - free bitmap font generator - Tower - free puzzle game

Hi!

Define of angelscript are follow:

AS_MAX_PORTABILITY AS_64BIT_PTR AS_NO_COMPILER AS_NO_THISCALL_FUNCTOR_METHOD ASS_IPHONE

AS_PTR_SIZE defined as 2.

Predefined defines are follow:
#define OBJC_NEW_PROPERTIES 1
#define _LP64 1
#define __APPLE_CC__ 6000
#define __APPLE__ 1
#define __ATOMIC_ACQUIRE 2
#define __ATOMIC_ACQ_REL 4
#define __ATOMIC_CONSUME 1
#define __ATOMIC_RELAXED 0
#define __ATOMIC_RELEASE 3
#define __ATOMIC_SEQ_CST 5
#define __BIGGEST_ALIGNMENT__ 16
#define __BLOCKS__ 1
#define __BYTE_ORDER__ __ORDER_LITTLE_ENDIAN__
#define __CHAR16_TYPE__ unsigned short
#define __CHAR32_TYPE__ unsigned int
#define __CHAR_BIT__ 8
#define __CONSTANT_CFSTRINGS__ 1
#define __DBL_DENORM_MIN__ 4.9406564584124654e-324
#define __DBL_DIG__ 15
#define __DBL_EPSILON__ 2.2204460492503131e-16
#define __DBL_HAS_DENORM__ 1
#define __DBL_HAS_INFINITY__ 1
#define __DBL_HAS_QUIET_NAN__ 1
#define __DBL_MANT_DIG__ 53
#define __DBL_MAX_10_EXP__ 308
#define __DBL_MAX_EXP__ 1024
#define __DBL_MAX__ 1.7976931348623157e+308
#define __DBL_MIN_10_EXP__ (-307)
#define __DBL_MIN_EXP__ (-1021)
#define __DBL_MIN__ 2.2250738585072014e-308
#define __DECIMAL_DIG__ 21
#define __DYNAMIC__ 1
#define __ENVIRONMENT_MAC_OS_X_VERSION_MIN_REQUIRED__ 101100
#define __FINITE_MATH_ONLY__ 0
#define __FLT_DENORM_MIN__ 1.40129846e-45F
#define __FLT_DIG__ 6
#define __FLT_EPSILON__ 1.19209290e-7F
#define __FLT_EVAL_METHOD__ 0
#define __FLT_HAS_DENORM__ 1
#define __FLT_HAS_INFINITY__ 1
#define __FLT_HAS_QUIET_NAN__ 1
#define __FLT_MANT_DIG__ 24
#define __FLT_MAX_10_EXP__ 38
#define __FLT_MAX_EXP__ 128
#define __FLT_MAX__ 3.40282347e+38F
#define __FLT_MIN_10_EXP__ (-37)
#define __FLT_MIN_EXP__ (-125)
#define __FLT_MIN__ 1.17549435e-38F
#define __FLT_RADIX__ 2
#define __GCC_ATOMIC_BOOL_LOCK_FREE 2
#define __GCC_ATOMIC_CHAR16_T_LOCK_FREE 2
#define __GCC_ATOMIC_CHAR32_T_LOCK_FREE 2
#define __GCC_ATOMIC_CHAR_LOCK_FREE 2
#define __GCC_ATOMIC_INT_LOCK_FREE 2
#define __GCC_ATOMIC_LLONG_LOCK_FREE 2
#define __GCC_ATOMIC_LONG_LOCK_FREE 2
#define __GCC_ATOMIC_POINTER_LOCK_FREE 2
#define __GCC_ATOMIC_SHORT_LOCK_FREE 2
#define __GCC_ATOMIC_TEST_AND_SET_TRUEVAL 1
#define __GCC_ATOMIC_WCHAR_T_LOCK_FREE 2
#define __GCC_HAVE_SYNC_COMPARE_AND_SWAP_1 1
#define __GCC_HAVE_SYNC_COMPARE_AND_SWAP_16 1
#define __GCC_HAVE_SYNC_COMPARE_AND_SWAP_2 1
#define __GCC_HAVE_SYNC_COMPARE_AND_SWAP_4 1
#define __GCC_HAVE_SYNC_COMPARE_AND_SWAP_8 1
#define __GNUC_MINOR__ 2
#define __GNUC_PATCHLEVEL__ 1
#define __GNUC_STDC_INLINE__ 1
#define __GNUC__ 4
#define __GXX_ABI_VERSION 1002
#define __GXX_RTTI 1
#define __INT16_C_SUFFIX__
#define __INT16_FMTd__ "hd"
#define __INT16_FMTi__ "hi"
#define __INT16_MAX__ 32767
#define __INT16_TYPE__ short
#define __INT32_C_SUFFIX__
#define __INT32_FMTd__ "d"
#define __INT32_FMTi__ "i"
#define __INT32_MAX__ 2147483647
#define __INT32_TYPE__ int
#define __INT64_C_SUFFIX__ LL
#define __INT64_FMTd__ "lld"
#define __INT64_FMTi__ "lli"
#define __INT64_MAX__ 9223372036854775807LL
#define __INT64_TYPE__ long long int
#define __INT8_C_SUFFIX__
#define __INT8_FMTd__ "hhd"
#define __INT8_FMTi__ "hhi"
#define __INT8_MAX__ 127
#define __INT8_TYPE__ signed char
#define __INTMAX_C_SUFFIX__ L
#define __INTMAX_FMTd__ "ld"
#define __INTMAX_FMTi__ "li"
#define __INTMAX_MAX__ 9223372036854775807L
#define __INTMAX_TYPE__ long int
#define __INTMAX_WIDTH__ 64
#define __INTPTR_FMTd__ "ld"
#define __INTPTR_FMTi__ "li"
#define __INTPTR_MAX__ 9223372036854775807L
#define __INTPTR_TYPE__ long int
#define __INTPTR_WIDTH__ 64
#define __INT_FAST16_FMTd__ "hd"
#define __INT_FAST16_FMTi__ "hi"
#define __INT_FAST16_MAX__ 32767
#define __INT_FAST16_TYPE__ short
#define __INT_FAST32_FMTd__ "d"
#define __INT_FAST32_FMTi__ "i"
#define __INT_FAST32_MAX__ 2147483647
#define __INT_FAST32_TYPE__ int
#define __INT_FAST64_FMTd__ "ld"
#define __INT_FAST64_FMTi__ "li"
#define __INT_FAST64_MAX__ 9223372036854775807L
#define __INT_FAST64_TYPE__ long int
#define __INT_FAST8_FMTd__ "hhd"
#define __INT_FAST8_FMTi__ "hhi"
#define __INT_FAST8_MAX__ 127
#define __INT_FAST8_TYPE__ signed char
#define __INT_LEAST16_FMTd__ "hd"
#define __INT_LEAST16_FMTi__ "hi"
#define __INT_LEAST16_MAX__ 32767
#define __INT_LEAST16_TYPE__ short
#define __INT_LEAST32_FMTd__ "d"
#define __INT_LEAST32_FMTi__ "i"
#define __INT_LEAST32_MAX__ 2147483647
#define __INT_LEAST32_TYPE__ int
#define __INT_LEAST64_FMTd__ "ld"
#define __INT_LEAST64_FMTi__ "li"
#define __INT_LEAST64_MAX__ 9223372036854775807L
#define __INT_LEAST64_TYPE__ long int
#define __INT_LEAST8_FMTd__ "hhd"
#define __INT_LEAST8_FMTi__ "hhi"
#define __INT_LEAST8_MAX__ 127
#define __INT_LEAST8_TYPE__ signed char
#define __INT_MAX__ 2147483647
#define __LDBL_DENORM_MIN__ 3.64519953188247460253e-4951L
#define __LDBL_DIG__ 18
#define __LDBL_EPSILON__ 1.08420217248550443401e-19L
#define __LDBL_HAS_DENORM__ 1
#define __LDBL_HAS_INFINITY__ 1
#define __LDBL_HAS_QUIET_NAN__ 1
#define __LDBL_MANT_DIG__ 64
#define __LDBL_MAX_10_EXP__ 4932
#define __LDBL_MAX_EXP__ 16384
#define __LDBL_MAX__ 1.18973149535723176502e+4932L
#define __LDBL_MIN_10_EXP__ (-4931)
#define __LDBL_MIN_EXP__ (-16381)
#define __LDBL_MIN__ 3.36210314311209350626e-4932L
#define __LITTLE_ENDIAN__ 1
#define __LONG_LONG_MAX__ 9223372036854775807LL
#define __LONG_MAX__ 9223372036854775807L
#define __LP64__ 1
#define __MACH__ 1
#define __MMX__ 1
#define __NO_INLINE__ 1
#define __NO_MATH_INLINES 1
#define __ORDER_BIG_ENDIAN__ 4321
#define __ORDER_LITTLE_ENDIAN__ 1234
#define __ORDER_PDP_ENDIAN__ 3412
#define __PIC__ 2
#define __POINTER_WIDTH__ 64
#define __PRAGMA_REDEFINE_EXTNAME 1
#define __PTRDIFF_FMTd__ "ld"
#define __PTRDIFF_FMTi__ "li"
#define __PTRDIFF_MAX__ 9223372036854775807L
#define __PTRDIFF_TYPE__ long int
#define __PTRDIFF_WIDTH__ 64
#define __REGISTER_PREFIX__
#define __SCHAR_MAX__ 127
#define __SHRT_MAX__ 32767
#define __SIG_ATOMIC_MAX__ 2147483647
#define __SIG_ATOMIC_WIDTH__ 32
#define __SIZEOF_DOUBLE__ 8
#define __SIZEOF_FLOAT__ 4
#define __SIZEOF_INT128__ 16
#define __SIZEOF_INT__ 4
#define __SIZEOF_LONG_DOUBLE__ 16
#define __SIZEOF_LONG_LONG__ 8
#define __SIZEOF_LONG__ 8
#define __SIZEOF_POINTER__ 8
#define __SIZEOF_PTRDIFF_T__ 8
#define __SIZEOF_SHORT__ 2
#define __SIZEOF_SIZE_T__ 8
#define __SIZEOF_WCHAR_T__ 4
#define __SIZEOF_WINT_T__ 4
#define __SIZE_FMTX__ "lX"
#define __SIZE_FMTo__ "lo"
#define __SIZE_FMTu__ "lu"
#define __SIZE_FMTx__ "lx"
#define __SIZE_MAX__ 18446744073709551615UL
#define __SIZE_TYPE__ long unsigned int
#define __SIZE_WIDTH__ 64
#define __SSE2_MATH__ 1
#define __SSE2__ 1
#define __SSE3__ 1
#define __SSE_MATH__ 1
#define __SSE__ 1
#define __SSP__ 1
#define __SSSE3__ 1
#define __STDC_HOSTED__ 1
#define __STDC_UTF_16__ 1
#define __STDC_UTF_32__ 1
#define __STDC_VERSION__ 201112L
#define __STDC__ 1
#define __UINT16_C_SUFFIX__
#define __UINT16_FMTX__ "hX"
#define __UINT16_FMTo__ "ho"
#define __UINT16_FMTu__ "hu"
#define __UINT16_FMTx__ "hx"
#define __UINT16_MAX__ 65535
#define __UINT16_TYPE__ unsigned short
#define __UINT32_C_SUFFIX__ U
#define __UINT32_FMTX__ "X"
#define __UINT32_FMTo__ "o"
#define __UINT32_FMTu__ "u"
#define __UINT32_FMTx__ "x"
#define __UINT32_MAX__ 4294967295U
#define __UINT32_TYPE__ unsigned int
#define __UINT64_C_SUFFIX__ ULL
#define __UINT64_FMTX__ "llX"
#define __UINT64_FMTo__ "llo"
#define __UINT64_FMTu__ "llu"
#define __UINT64_FMTx__ "llx"
#define __UINT64_MAX__ 18446744073709551615ULL
#define __UINT64_TYPE__ long long unsigned int
#define __UINT8_C_SUFFIX__
#define __UINT8_FMTX__ "hhX"
#define __UINT8_FMTo__ "hho"
#define __UINT8_FMTu__ "hhu"
#define __UINT8_FMTx__ "hhx"
#define __UINT8_MAX__ 255
#define __UINT8_TYPE__ unsigned char
#define __UINTMAX_C_SUFFIX__ UL
#define __UINTMAX_FMTX__ "lX"
#define __UINTMAX_FMTo__ "lo"
#define __UINTMAX_FMTu__ "lu"
#define __UINTMAX_FMTx__ "lx"
#define __UINTMAX_MAX__ 18446744073709551615UL
#define __UINTMAX_TYPE__ long unsigned int
#define __UINTMAX_WIDTH__ 64
#define __UINTPTR_FMTX__ "lX"
#define __UINTPTR_FMTo__ "lo"
#define __UINTPTR_FMTu__ "lu"
#define __UINTPTR_FMTx__ "lx"
#define __UINTPTR_MAX__ 18446744073709551615UL
#define __UINTPTR_TYPE__ long unsigned int
#define __UINTPTR_WIDTH__ 64
#define __UINT_FAST16_FMTX__ "hX"
#define __UINT_FAST16_FMTo__ "ho"
#define __UINT_FAST16_FMTu__ "hu"
#define __UINT_FAST16_FMTx__ "hx"
#define __UINT_FAST16_MAX__ 65535
#define __UINT_FAST16_TYPE__ unsigned short
#define __UINT_FAST32_FMTX__ "X"
#define __UINT_FAST32_FMTo__ "o"
#define __UINT_FAST32_FMTu__ "u"
#define __UINT_FAST32_FMTx__ "x"
#define __UINT_FAST32_MAX__ 4294967295U
#define __UINT_FAST32_TYPE__ unsigned int
#define __UINT_FAST64_FMTX__ "lX"
#define __UINT_FAST64_FMTo__ "lo"
#define __UINT_FAST64_FMTu__ "lu"
#define __UINT_FAST64_FMTx__ "lx"
#define __UINT_FAST64_MAX__ 18446744073709551615UL
#define __UINT_FAST64_TYPE__ long unsigned int
#define __UINT_FAST8_FMTX__ "hhX"
#define __UINT_FAST8_FMTo__ "hho"
#define __UINT_FAST8_FMTu__ "hhu"
#define __UINT_FAST8_FMTx__ "hhx"
#define __UINT_FAST8_MAX__ 255
#define __UINT_FAST8_TYPE__ unsigned char
#define __UINT_LEAST16_FMTX__ "hX"
#define __UINT_LEAST16_FMTo__ "ho"
#define __UINT_LEAST16_FMTu__ "hu"
#define __UINT_LEAST16_FMTx__ "hx"
#define __UINT_LEAST16_MAX__ 65535
#define __UINT_LEAST16_TYPE__ unsigned short
#define __UINT_LEAST32_FMTX__ "X"
#define __UINT_LEAST32_FMTo__ "o"
#define __UINT_LEAST32_FMTu__ "u"
#define __UINT_LEAST32_FMTx__ "x"
#define __UINT_LEAST32_MAX__ 4294967295U
#define __UINT_LEAST32_TYPE__ unsigned int
#define __UINT_LEAST64_FMTX__ "lX"
#define __UINT_LEAST64_FMTo__ "lo"
#define __UINT_LEAST64_FMTu__ "lu"
#define __UINT_LEAST64_FMTx__ "lx"
#define __UINT_LEAST64_MAX__ 18446744073709551615UL
#define __UINT_LEAST64_TYPE__ long unsigned int
#define __UINT_LEAST8_FMTX__ "hhX"
#define __UINT_LEAST8_FMTo__ "hho"
#define __UINT_LEAST8_FMTu__ "hhu"
#define __UINT_LEAST8_FMTx__ "hhx"
#define __UINT_LEAST8_MAX__ 255
#define __UINT_LEAST8_TYPE__ unsigned char
#define __USER_LABEL_PREFIX__ _
#define __VERSION__ "4.2.1 Compatible Apple LLVM 7.0.0 (clang-700.1.76)"
#define __WCHAR_MAX__ 2147483647
#define __WCHAR_TYPE__ int
#define __WCHAR_WIDTH__ 32
#define __WINT_TYPE__ int
#define __WINT_WIDTH__ 32
#define __amd64 1
#define __amd64__ 1
#define __apple_build_version__ 7000176
#define __block __attribute__((__blocks__(byref)))
#define __clang__ 1
#define __clang_major__ 7
#define __clang_minor__ 0
#define __clang_patchlevel__ 0
#define __clang_version__ "7.0.0 (clang-700.1.76)"
#define __core2 1
#define __core2__ 1
#define __llvm__ 1
#define __nonnull _Nonnull
#define __null_unspecified _Null_unspecified
#define __nullable _Nullable
#define __pic__ 2
#define __strong
#define __tune_core2__ 1
#define __unsafe_unretained
#define __weak __attribute__((objc_gc(weak)))
#define __x86_64 1
#define __x86_64__ 1

Currently i commented actions in asBC_ClrVPtr and build is stable now.

The defines provided by AngelScript appears to be correct. The existence of AS_64BIT_PTR and AS_PTR_SIZE = 2 is what it should. Which makes me wonder what exactly is going wrong. The bug is in the C++ part (since the bytecode instruction is wrong), and if the macros are correct, it should be reproducible on any 64bit machine, but alas I'm not able to reproduce it, neither on Windows 64bit nor Linux 64bit.

As for the compiler pre-defines; it appears that you got the defines for the wrong target platform. The defines shows that you're compiling for a x86/64 CPU, and not an arm64 CPU.

Which version of AngelScript are you using?

Would you be able to debug into the compiler to check how exactly the compiler is emitting the wrong offset for the asBC_ClrVPtr? There are only a few places in the as_compiler.cpp code where this bytecode is emitted. The offset passed as the second argument to InstrSHORT() should be 8 byte aligned.

AngelCode.com - game development and more - Reference DB - game developer references
AngelScript - free scripting library - BMFont - free bitmap font generator - Tower - free puzzle game

It is defenetly compiled for arm64. Maybe such defins is for Mac Os compilator. I did not find flags for clag for iOS.

I using 2310 revision of AngelScript.

Ok i will try to debug compilation on iOS.

Hi!

I debugged compilation of script, so definitely problem in compilation.

In asCCompiler::CompileRefCast there are two calls ctx->bc.InstrSHORT(asBC_ClrVPtr, (asWORD)offset) at line 5506 and at line 5528. In first call offset equal 3. In second call offset equal 4.

So bytecode generated by asCCompiler::CompileRefCast not platform independent. Maybe on x64 compiler produce right code but not on Win32.

I modify sample with comes with sources of Angel Script. On Win 32 i see same problem as i saw in our IDE

There is link to source of sample with show problem - https://yadi.sk/d/bMkASSkJqvbYd

Thanks for this information. It greatly reduces the scope of the investigation.

Hopefully I should be able to find the cause with this.

AngelCode.com - game development and more - Reference DB - game developer references
AngelScript - free scripting library - BMFont - free bitmap font generator - Tower - free puzzle game

The only way for the compiler to get offset 3 and 4 respectively is if AngelScript isn't properly detecting that the pointers are 64bit when you're compiling for iOS 64bit. When AngelScript is properly detecting 64bit points the offsets will be 6 and 8 respectively.

Can you please check once more that AS_PTR_SIZE is correctly set to 2? Since you're apparently seeing the value as it would be for x86/64 in your IDE I recommend you add in your code something like this, so you can see the value at run time.

cout << "AS_PTR_SIZE = " << AS_PTR_SIZE << endl;

Also, while doing so, can you also tell me what the returned value from asGetLibraryOptions() is?

The following is the byte code that should be created on a 64bit platform:

void main()
 
Temps: 4, 6, 8, 9
 
Variables: 
 002: (heap) NGUIWidget@ wgt
 004: (heap) NGUISymbol {noname}
 006: null handle {noname}
 008: (heap) NGUIWidget {noname}
 
 
- 3,2 -
    0   9 *    SUSPEND
               VarDecl  0
    1   9 *    PshGPtr  0x53a470          (i:5481584, f:2.70826e-317)
    4  11 *    RefCpyV  v4, 0x5843e0          (type:NGUISymbol)
    7  11 *    PopPtr
    8   9 *    ClrVPtr  v6
    9   9 *    CmpPtr   v4, v6
   11   9 *    JZ       +9              (d:22)
   13   9 *    PshVPtr  v4
   14  11 *    CALLSYS  19           (NGUIWidget@ NGUISymbol::opImplCast())
   16   9 *    STOREOBJ v8
   17   9 *    FREE     v4, 0x5843e0          (type:NGUISymbol)
   20   9 *    JMP      +1              (d:23)
            1:
   22   9 *    ClrVPtr  v8
            2:
   23   9 *    PshVPtr  v8
   24  11 *    RefCpyV  v2, 0x583260          (type:NGUIWidget)
   27  11 *    FREE     v8, 0x583260          (type:NGUIWidget)
   30  11 *    PopPtr
- 4,2 -
   31   9 *    SUSPEND
   32   9 *    SetV4    v9, 0x3f147ae1          (i:1058306785, f:0.58)
   34   9 *    LoadRObjR v2, v0, 67108876
   37   9 *    WRTV4    v9
- 5,2 -
   38   9 *    SUSPEND
   39   9 *    FREE     v2, 0x583260          (type:NGUIWidget)
            0:
   42   9 *    RET      0
 

AngelCode.com - game development and more - Reference DB - game developer references
AngelScript - free scripting library - BMFont - free bitmap font generator - Tower - free puzzle game

This topic is closed to new replies.

Advertisement