Fuzzer: DAE generates invalid code
Los mantenedores suelen responder en 1 día
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 4/5
- Tiempo estimado
- 3-5 días
- Aptitud para principiantes
- 47/100
Línea de trabajo
Start with src/passes/DeadArgumentElimination.cpp and the dae-optimizing pass; reproduce the validator failure using the reduced WAT and command in the issue. Trace how callers are tracked when call_ref becomes a direct call, and check whether the enclosing expression is re-finalized after return-type refinement. Done means the reduced case validates after the pass and relevant tests pass.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Run from the latest main bee0b57. Reduced WAT:
(module
(rec
(type $0 (sub (shared (func (result (ref null $1))))))
(type $1 (sub (shared (array f32))))
(type $2 (sub $0 (shared (func (result (ref null $1))))))
(type $3 (sub (struct)))
(type $4 (func (param (ref null $2)) (result f64)))
(type $5 (func (result (ref $6))))
(type $6 (shared (func (param (ref $3)) (result v128))))
(type $7 (func))
)
(elem declare func $1 $2)
(func $1 (type $6) (param $0 (ref $3)) (result v128)
(unreachable)
)
(func $2 (type $5) (result (ref $6))
(unreachable)
)
(func $3 (type $5) (result (ref $6))
(local $10 i32)
(select (result (ref $6))
(call_ref $5
(ref.func $2)
)
(ref.func $1)
(stringview_wtf16.get_codeunit
(string.const "\e2\82\ac")
(block (result i32)
(local.set $10
(i32.const 1)
)
(local.get $10)
)
)
)
)
(func $4 (type $7)
(drop
(call $3)
)
)
)
Command:
BINARYEN_PASS_DEBUG=1 bin/wasm-opt -all --closed-world --dae-optimizing fuzzed.wat
Output:
[wasm-validator error in function 3] stale type found in 3 on 0x561b46e160d8
(marked as (ref $func.0), should be (ref (exact $func.0)))
, on
(select (result (ref (exact $6)))
(call $2)
(ref.func $1)
(stringview_wtf16.get_codeunit
(string.const "\e2\82\ac")
(i32.const 1)
)
)
Fatal: Last pass (dae-optimizing) broke validation.
Replacing the call_ref with a direct call $2 makes the bug go away.
AI-generated hypothesis
In DeadArgumentElimination.cpp:
callersis computed once, from directCalls only. Initially$3reaches$2only viacall_ref, socallers[$2] = {}.- Iteration 1:
$4drops$3's result, soremoveReturnValue($3)runs and$3goes intoworthOptimizing.optimizeAfterInliningthen rewritescall_ref (ref.func $2)intocall $2. - Iteration 2:
$2now has a seen direct call, sorefineReturnTypes($2)refines its result to(ref (shared nofunc))and updates theCall's type.refinedCallersis populated from the stalecallers[$2], which is empty, so$3is neverReFinalized. The enclosingselectkeeps(ref $6)while its LUB is now(ref (exact $6)).
The comment above callers says over-approximating it is safe; this is an under-approximation, since new direct callers appear mid-pass via devirtualization.
- Lenguaje dominante
- WebAssembly
- Estrellas
- 8.7k
- Forks
- 895
- Merge medio
- 1 d 22 h
- PR fusionados (30 d)
- 97
Preparar el entorno
- Sin Dockerfile ni archivo de Docker Compose
- Sin plantilla de pull request
- Leer la guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de WebAssembly/binaryen
-
Dificultad 1/5 Menos de una hora Aptitud para principiantes 88/100
WebAssembly/binaryen#9135 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 Medio día Aptitud para principiantes 76/100
WebAssembly/binaryen#9018 · 3 comentarios ·
Los mantenedores suelen responder en 1 día
-
Dificultad 3/5 1-2 días Aptitud para principiantes 45/100
WebAssembly/binaryen#9249 ·
Los mantenedores suelen responder en 1 día
-
Dificultad 3/5 1-2 días Aptitud para principiantes 45/100
WebAssembly/binaryen#9246 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
Memory64Lowering: table.get/table.set keep i64 index on lowered table64, output fails validationAbierto
Dificultad 3/5 Medio día Aptitud para principiantes 66/100
WebAssembly/binaryen#9245 ·
Los mantenedores suelen responder en 1 día
Todos los issues de WebAssembly/binaryen
Issues similares
-
bug derived types format I/O medium priority semantics
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
Los mantenedores suelen responder en 1 día
-
lexer: a lone `"` at the end of a file panics instead of reporting an errorPosiblemente ocupada Un pull request vinculado a esta issue está abierto o ya se fusionó. Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 76/100
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 82/100
bytecodealliance/wasm-tools#2768 ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 76/100
antlr/grammars-v4#5035 ·
Los mantenedores suelen responder en 5 días
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
Los mantenedores suelen responder en 1 día