Hacktoberfest 2026: los issues que los mantenedores marcaron para octubre, abiertos y aptos para principiantes. Explorar issues de Hacktoberfest

Fuzzer: DAE generates invalid code

Cerrado
#9,233 1 comentario 0 reacciones 0 asignados Ver en GitHub

Los mantenedores suelen responder en 1 día

Nadie ha tomado este issue todavía.

Evaluación

Dificultad
4/5
Tiempo estimado
3-5 días
Aptitud para principiantes
47/100
Tipo de issue
Error
Claridad
Bastante claro
Estado de actividad
Activo
Stack tecnológico
cpp, wasm
Área
compilers

Línea de trabajo

Start with src/passes/DeadArgumentElimination.cpp and the dae-optimizing pass; reproduce the validator failure using the reduced WAT and command in the issue. Trace how callers are tracked when call_ref becomes a direct call, and check whether the enclosing expression is re-finalized after return-type refinement. Done means the reduced case validates after the pass and relevant tests pass.

Escrito por el modelo de indexación a partir del texto del issue.

Descripción

Run from the latest main bee0b57. Reduced WAT:

(module
 (rec
  (type $0 (sub (shared (func (result (ref null $1))))))
  (type $1 (sub (shared (array f32))))
  (type $2 (sub $0 (shared (func (result (ref null $1))))))
  (type $3 (sub (struct)))
  (type $4 (func (param (ref null $2)) (result f64)))
  (type $5 (func (result (ref $6))))
  (type $6 (shared (func (param (ref $3)) (result v128))))
  (type $7 (func))
 )
 (elem declare func $1 $2)
 (func $1 (type $6) (param $0 (ref $3)) (result v128)
  (unreachable)
 )
 (func $2 (type $5) (result (ref $6))
  (unreachable)
 )
 (func $3 (type $5) (result (ref $6))
  (local $10 i32)
  (select (result (ref $6))
   (call_ref $5
    (ref.func $2)
   )
   (ref.func $1)
   (stringview_wtf16.get_codeunit
    (string.const "\e2\82\ac")
    (block (result i32)
     (local.set $10
      (i32.const 1)
     )
     (local.get $10)
    )
   )
  )
 )
 (func $4 (type $7)
  (drop
   (call $3)
  )
 )
)

Command:

BINARYEN_PASS_DEBUG=1 bin/wasm-opt -all --closed-world --dae-optimizing fuzzed.wat

Output:

[wasm-validator error in function 3] stale type found in 3 on 0x561b46e160d8
(marked as (ref $func.0), should be (ref (exact $func.0)))
, on
(select (result (ref (exact $6)))
 (call $2)
 (ref.func $1)
 (stringview_wtf16.get_codeunit
  (string.const "\e2\82\ac")
  (i32.const 1)
 )
)
Fatal: Last pass (dae-optimizing) broke validation.

Replacing the call_ref with a direct call $2 makes the bug go away.

AI-generated hypothesis

In DeadArgumentElimination.cpp:

  1. callers is computed once, from direct Calls only. Initially $3 reaches $2 only via call_ref, so callers[$2] = {}.
  2. Iteration 1: $4 drops $3's result, so removeReturnValue($3) runs and $3 goes into worthOptimizing. optimizeAfterInlining then rewrites call_ref (ref.func $2) into call $2.
  3. Iteration 2: $2 now has a seen direct call, so refineReturnTypes($2) refines its result to (ref (shared nofunc)) and updates the Call's type. refinedCallers is populated from the stale callers[$2], which is empty, so $3 is never ReFinalized. The enclosing select keeps (ref $6) while its LUB is now (ref (exact $6)).

The comment above callers says over-approximating it is safe; this is an under-approximation, since new direct callers appear mid-pass via devirtualization.

Lenguaje dominante
WebAssembly
Estrellas
8.7k
Forks
895
Merge medio
1 d 22 h
PR fusionados (30 d)
97

Preparar el entorno

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Más de WebAssembly/binaryen

Todos los issues de WebAssembly/binaryen

Issues similares

Más issues de Compilers

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.