13 ms·
The Shortest Crashing C Program
- qznc 13y ago"The shortest crashing C89 program" to be more precise. :)
- AlexanderDhoore 13y agoThis reminds me of "A Whirlwind Tutorial on Creating Really Teensy ELF Executables for Linux" [1]. The author tries to create the smallest possible elf executable possible. You would think it'd be easy... :) go read it. Very cool! [1] http://www.muppetlabs.com/~breadbox/software/tiny/teensy.html http://www.muppetlabs.com/~breadbox/software/tiny/teensy.htm...
- sublimit 13y agoThe way he just keeps pushing further and further pleases the hacker inside me. A recommended read for sure.
- alcuadrado 13y agoIt seems to be down, google cache: http://webcache.googleusercontent.com/search?q=cache:4FhUcns72Z4J:llbit.se/%3Fp%3D1744+&cd=1&hl=es-419&ct=clnk&gl=ar http://webcache.googleusercontent.com/search?q=cache:4FhUcns...
- lucb1e 13y agoWordpress strikes again; "error establishing database connection"
- rabino 13y agoA bad hosting strikes again.
- lucb1e 13y agoI have bad hosting with good software. Ran flawlessly with 8-15ms generation times on #3 of the HN homepage for a couple hours, only the network latency went up to at peak ~1.2 seconds (got less than 1mbps upload here). The page also executes multiple database queries for each pageload, just like Wordpress. No caching needed for me, it's all about optimization.
- sablezab 13y agoWhat software do you use?
- lucb1e 13y agoSelf written, no framework used. It's a simple blog with quite custom requirements so I figured whynot just build a custom one. It runs on an Intel Atom, 1GB RAM (and there's more to run than a wamp stack). and 832kbps uplink. As for software, I wrote it for PHP 5.3 (nowadays upgraded to 5.4 though) with MySQL and persistent database connections. The server is Windows 7 with apache 2.4.
- mortehu 13y agoWell, the mistake in this particular case is probably allowing more web application processes than database connections from those processes, which is an easy thing to get wrong.
- jstanley 13y agoI'm not convinced this is a C89 program. It is only an "accident" that the linker doesn't know about types. I find it hard to believe that the C89 spec states that an integer called "main" is to be considered the main function, and suspect this is undefined behaviour (though I've not checked).
- poizan42 13y agoIt can't be a valid C89 program. On many Harvard architecture based microprocessors data pointers and code pointers have differing size.
- dietrichepp 13y agoDifferent size maybe, but different busses^H^H^H^H^H^Haddress spaces definitely, and using an address on the wrong bus is a sure way to cause problems.
- poizan42 13y agoOf course that is the definition of a Harvard architecture. It doesn't says that it won't link, just that it won't work. If compiling to an architecture with smaller sized code pointers than data pointers then the linker will most likely refuse to link it at all - otherwise it will have to truncate the adresses.
- kmm 13y ago^W will delete the previous word.
- mikeash 13y agoIs any crashing C program valid? You can only crash by invoking undefined behavior, and I believe that any program which invokes undefined behavior is "invalid". It's a major pitfall of C that determining "validity" requires solving the halting problem.
- nitrogen 13y agoIt compiles and runs with gcc -std=c89 and gcc -std=c99, so even if it's not a true C89 program, it's a compilable GNUC89 program. $ gcc -std=c99 -pedantic /tmp/main.c -o /tmp/main /tmp/main.c:1:1: warning: data definition has no type or storage class [enabled by default] /tmp/main.c:1:1: warning: type defaults to ‘int’ in declaration of ‘main’ [enabled by default] /tmp/main.c:1:1: warning: ‘main’ is usually a function [-Wmain] $ /tmp/main Segmentation fault (core dumped)
- dysoco 13y agoSeems to work really well: It even crashed the website.
- femto 13y agoIt depends on the definition. You can do better than this if you define a valid C program as anything that passes though the C compiler and generates an executable. Behold the zero length program: $ touch a.c $ gcc -c a.c $ ld a.o ld: warning: cannot find entry symbol _start; defaulting to 0000000000400078 $ ./a.out Segmentation fault
- thristian 13y agoThat's a shame. At least in one point in history, that was the shortest-known quine: http://www.ioccc.org/years.html#1994_smr http://www.ioccc.org/years.html#1994_smr
- femto 13y agoIt still is, provided you follow the build procedure prescribed by the author of that quine (check the Makefile from the contest): $ rm -rf a $ cp a.c a $ chmod +x a $ ./a $
- mikeash 13y agoEven with the regular procedure, it's a quine if you ignore stderr and only look at stdout, which should definitely count.
- emillon 13y agoI find it interesting that displays the error from exec, but not bash: zsh: exec format error: ./a
- unwind 13y agoWhy? The file is marked as executable, so the shell very reasonably tries to execute it by calling some well-chosen member of the exec() family (http://linux.die.net/man/3/exec http://linux.die.net/man/3/exec). The exec() function then needs to open and parse the file according to the formats it supports, which of course fails since the file is empty. Do you simply mean that you expected the shell to validate this, and not try to execute empty files?
- sbanach 13y agoIt's also the shortest C program that you can link at all.
- efermat 13y ago$ echo "m;" > short.c $ gcc -O0 -c short.c short.c:1: warning: data definition has no type or storage class $ ld -e _m -o short short.o ld: warning: -macosx_version_min not specified, assuming 10.7 $ ./short [1] 2040 segmentation fault ./short
- danielsamuels 13y agoThe Shortest Crashing Wordpress Site
- bbanyc 13y agoThe first IOCCC winner declared main as a short[] of VAX machine code: http://www.ioccc.org/1984/mullender.c http://www.ioccc.org/1984/mullender.c You could probably do the same thing in x86 and it'd work on a modern compiler.
- ssp 13y agoIt won't work on modern Linux with modern CPUs because the array will not be in an executable mapping.
- _kushagra 13y agoThe site seems down, "Error establishing a database connection"
- to3m 13y agoThe explanation is not quite correct - execution starts at &main rather than the address given by the value of main. On VC++, at least - well, on my PC anyway - the process halts because the data segment doesn't have the execute bit set. It isn't trying to run code at address 0. (If execution of bytes in the data segment were possible, which I'm sure it used to be, then you'd still likely get a crash, but it's not guaranteed. (uint32_t)0 is a valid sequence of instructions - it's ADD BYTE PTR [EAX],AL - and so if EAX contained a valid value then it would execute without a problem. Then, if the following byte were 0xC3 (RET) then the program would execute. OK, so that's all rather unlikely, but you have to bear these things in mind. So I think 0xCC (INT 3) would be a better choice.)
- anarion 13y agoNo, a ret instruction would probably segfault, depending on the content of the stack. To terminate a program you have to use the corresponding system call. On linux : mov $1, %eax int $0x80
- lgeek 13y agoto3m is correct. On my GNU/Linux machine main() is called from __libc_start_main(). A ret instruction in main() returns to __libc_start_main(), which in turn calls exit().
- to3m 13y agoThat (or something like it) is true for the process as a whole, but not necessarily for main. It's usual to call main from a library-provided function, so it returns just like any other function. This removes the need to special-case main in any way, and provides a space for any system-specific startup and shutdown code. If you've got VS2012, you can see this code in the file at something like "c:\Program Files (x86)\Microsoft Visual Studio 11.0\VC\crt\src\crt0.c" (it should be easy to find for other versions - it's been in pretty much in that place, with that name, probably with those contents, since VC5 I think). For glibc, see http://sourceware.org/git/?p=glibc.git;a=blob;f=csu/libc-start.c;h=e5da3efd0699b37438841f3f048e5a84445de1ca;hb=HEAD#l300 http://sourceware.org/git/?p=glibc.git;a=blob;f=csu/libc-sta.... My post was a bit x86/VC++-specific but the principles have been common to all the C environments I've used. I don't think I've ever used one that by default called your startup function directly, bypassing C runtime initialisation. (Though it's very easy to set this up with Visual Studio.)
- marshray 13y agoHow about: main(){*(int*)0=0;} or: main(){*""=0;} or: main(){main();}
- pdw 13y agoThe last one is just as likely an infinite loop as a crash. Even C compilers occasionally manage to do tail-call optimization these days.
- mikeash 13y agoAll substantially longer than the example given.
- marshray 13y agoThe site was down when I made my suggestions. Still, I think mine may be a bit more language compliant than the shortest variants in the article.
- rwmj 13y agoEdit: deleted because I got to the Google cache and that's what the site was suggesting.
- marshray 13y agoThat's essentially where he's going with it, noting that you can even leave off the "=0". But as others here point out there's some question as to how many linkers will actually produce an executable image from that source.
- marshray 13y agoThat's essentially where he's going with it, noting that you can even leave off the "=0". But as others here point out there's some question as to how many linkers will actually produce an executable image from that source.
- stefap2 13y agoShortest crashing website: Error establishing a database connection
- kghose 13y agofor those who see the server crashing: The program is in C89 main;
- deweerdt 13y ago> Also, global variables in C are initialized to zero implicitly, so this is equivalent: EDIT: this is wrong, see below. That's wrong. 'static' variables are initialized to zero. Non-static variables are un-initialized, so they have a "random" value. See: $ valgrind ./a.out ==5118== Memcheck, a memory error detector ==5118== Copyright (C) 2002-2012, and GNU GPL'd, by Julian Seward et al. ==5118== Using Valgrind-3.8.1 and LibVEX; rerun with -h for copyright info ==5118== Command: ./a.out ==5118== ==5118== ==5118== Process terminating with default action of signal 11 (SIGSEGV) ==5118== Bad permissions for mapped region at address 0x600864 ==5118== at 0x600864: ??? (in /home/def/a.out) ==5118== by 0x4E54A14: (below main) (in /usr/lib/libc-2.17.so)
- bnegreve 13y agoBut global variables are static.
- deweerdt 13y agoNo, they're not. In fact, if the program used 'static main;' instead, it wouldn't even compile because the 'main' symbol wouldn't be visible by the linker.
- bnegreve 13y agoOk, well I agree. I mean global variables are not created dynamically. There is room reserved for them in the data segment which is initialized to 0. Can you give me an example where a global variable isn't initialized to 0? Your valgrind example doesn't say much about the value in the main variable .. Edit, @deweerdt: ok :)
- deweerdt 13y ago@bnegreve can't reply to your post, but i was mistaken. externally visible symbols are also initialized to 0
- anarion 13y agoYes they are ! Global variables have static storage duration and are therefore default initialized. Be careful with the word 'static' which does not always correspond to the the keyword static which has several meaning ! When used with a global variable the static keyword has not the same meaning as static storage duration". It only means no external linkage.
- sfvisser 13y agoInteresting. We tried to do the same for Haskell. The shortest we could come up with: import Unsafe.Coerce;main=unsafeCoerce()1
- themattrix 13y agoYou can go even shorter if you cheat: $ cat short.c M $ gcc -DM='main;' short.c -o short $ ./short Segmentation fault
- Trufa 13y agoAnd interesting question, what would be the shortest not crashing C program? main(){} ??
- lgeek 13y agoAn empty file would do: https://news.ycombinator.com/item?id=5762578 https://news.ycombinator.com/item?id=5762578
- joeyh 13y agoSeems appropriate that the default C program, as it were, segfaults.
- Jabbles 13y agoWho says it will crash? Could run very nicely, printing a list of prime numbers, or write poetry, or anything else that undefined behaviour encompasses.
- ghayes 13y ago"global variables in C are initialized to zero implicitly" NULL pointers will lead to a crash. It would be more interesting to have it as a random pointer, which could do quite anything.
- deleted 13y ago[deleted]
- subleq 13y ago> NULL pointers will lead to a crash. Not in C. Dereferencing a NULL pointer is undefined behavior, so any of the actions described by the parent would be correct.
- gizmo686 13y agoIs 0 really the same thing the sane thing as 'NULL' in the context of C? If you actually wanted a pointer to the begging of the memory, you would dereference 0, which has the well defined meaning of getting whatever is at memory address 0. When the programming attempts to get that, it is shut down by the system.
- asveikau 13y ago> Is 0 really the same thing the sane thing as 'NULL' in the context of C? Yes. I don't have chapter and verse handy but it is in the standard. The bit pattern of NULL is not required to be zero (so memset(&p, 0, sizeof(p)) is not guaranteed to yield null) but it must compare equally to 0 and assigning 0 must produce NULL. [Edit: OK, in C99 this is covered in 6.3.2.3: Pointers. "An integer constant expression with the value 0, or such an expression cast to type void * , is called a null pointer constant." Then 7.17.3 says that NULL expands to a null pointer constant.] > If you actually wanted a pointer to the begging of the memory, you would dereference 0, Yeah, it's really easy to set up an environment where that happens. At one point I was experimenting with writing a small/toy kernel for x86 and I mapped the virtual address 0 to a valid page, and boom, dereferencing NULL did stuff. Not a great idea to set up the page tables that way for obvious reasons, but I'm going to guess that lots of hardware out there will let you do it... In the old days of 16-bit x86, linear address 0 had the interrupt vector, so as I recall lots of DOS (maybe even Win9x) environments had dereferencing NULL do meaningful (surely confusing) things.
- hkmurakami 13y agoreminds me of the recent fad of TAS (tool assisted speed run) videos of "fastest crash" of video games.
- webreac 13y agoWith visual studio V6.0 (AFAIR), I made a short program that crashed the compiler: int a;::a::b();
- stinos 13y ago"address 0, which is not an address that we have access to" if I'm not mistaken, there are platforms like TI C600 dsps for which 0 is the start of the usable address space