String escaping fuzz bug with wasm-metadce
Los mantenedores suelen responder en 1 día
@kripken ya está trabajando en esto.
Desde el 20/3/2026.
Evaluación
Este issue todavía no se ha evaluado.
Descripción
This is a fuzz bug where the fuzzer runs the CtorEval handler with test/lit/basic/name-high-bytes.wast as its initial contents.
test.wast (reduced):
(module
(type $0 (func))
(export "test\\c3\\a9_invoker" (func $0))
(func $0 (type $0)
(unreachable)
)
)
graph.json produced by fuzz_opt.py's filter_exports (reduced):
[
{
"name": "outside",
"reaches": ["export-test\\\\c3\\\\a9_invoker"],
"root": true
},
{
"name": "export-test\\\\c3\\\\a9_invoker",
"export": "test\\\\c3\\\\a9_invoker"
}
]
Here we have an export name containing backslashes. Note that they are escaped in the Wasm text format, so the actual unescaped byte content of the export name is test\c3\a9_invoker. But fuzz_opt.py is not unescaping the string it reads from the disassembly, and then it is JSON-encoding the escaped name, so graph.json ends up with doubly escaped backslashes.
To make matters worse, wasm-metadce is parsing the input JSON in "ASCII" mode, which does not do any unescaping either. So wasm-metadce is rooting an export named test\\\\c3\\\\a9_invoker but in fact the export's name is test\c3\a9_invoker, so the export is removed and the filtered module is empty.
This causes the fuzzer to fail when it later runs wasm-ctor-eval and passes it --kept-exports=test\c3\a9_invoker (note that it has unescaped the string for this step). This errors out because that export no longer exists.
IIUC, the proper fix would be to 1) perform Wasm text format unescaping immediately when extracting export names in get_exports, and 2) perform JSON unescaping when parsing the JSON in wasm-metadce.
- Lenguaje dominante
- WebAssembly
- Estrellas
- 8.6k
- Forks
- 892
- Merge medio
- 1 d 18 h
- PR fusionados (30 d)
- 79
Preparar el entorno
- Sin Dockerfile ni archivo de Docker Compose
- Sin plantilla de pull request
- Leer la guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de WebAssembly/binaryen
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 76/100
WebAssembly/binaryen#9185 ·
Los mantenedores suelen responder en 1 día
-
Dificultad 1/5 Menos de una hora Aptitud para principiantes 88/100
WebAssembly/binaryen#9135 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 Medio día Aptitud para principiantes 76/100
WebAssembly/binaryen#9018 · 3 comentarios ·
Los mantenedores suelen responder en 1 día
-
Dificultad 4/5 3-5 días Aptitud para principiantes 52/100
WebAssembly/binaryen#9186 ·
Los mantenedores suelen responder en 1 día
-
LoopInvariantCodeMotion: `struct.new` is hoisted out of a loop, so all iterations share one objectAbierto
Dificultad 3/5 1-2 días Aptitud para principiantes 68/100
WebAssembly/binaryen#9184 ·
Los mantenedores suelen responder en 1 día