AlignmentLowering: an out-of-bounds unaligned store becomes a partial write
Les mainteneurs répondent en général sous 1 jour
Personne n'a encore pris cette issue.
Évaluation
- Difficulté
- 4/5
- Temps estimé
- 3-5 jours
- Accessibilité débutants
- 52/100
- Type d'issue
- Bug
- Clarté
- Clairement spécifiée
- Activité
- Active
- Stack technique
- wasm
- Domaine
- compilers
Piste de recherche
Start by locating the AlignmentLowering and i64-to-i32-lowering implementations, then run the provided wasm-opt reproducer with --alignment-lowering and --fuzz-exec. Check both affected passes for multi-byte stores near the memory boundary. Done means an out-of-bounds store traps without modifying memory in both passes, while valid stores retain their behavior.
Rédigé par le modèle d'indexation à partir du texte de l'issue.
Description
Summary
An unaligned i32.store align=1 is split into four i32.store8s. If the address is out of bounds, the first bytes are written and the later ones trap, so memory differs after the trap. In the spec, a store whose bytes do not all fit in the memory reduces to trap without changing the store (Step/store-num-oob), so a trapping store never writes anything.
Root cause
The byte stores are emitted in increasing address order. The last byte is the one that traps, and the earlier stores have already happened.
Affected passes
--alignment-lowering and --i64-to-i32-lowering. The latter writes the low word of an i64.store before the high word traps.
Reproducer
(module
(memory 1 1)
(func (export "store")
(i32.store align=1 (i32.const 65534) (i32.const 0x01020304)))
(func (export "peek") (result i32)
(i32.load (i32.const 65532))))
$ wasm-opt in.wat --alignment-lowering --print
(func $0
(local $0 i32)
(local $1 i32)
(local.set $0 (i32.const 65534))
(local.set $1 (i32.const 16909060))
(i32.store8 (local.get $0) (local.get $1))
(i32.store8 offset=1 (local.get $0) (i32.shr_u (local.get $1) (i32.const 8)))
(i32.store8 offset=2 (local.get $0) (i32.shr_u (local.get $1) (i32.const 16)))
(i32.store8 offset=3 (local.get $0) (i32.shr_u (local.get $1) (i32.const 24)))
)
The 4-byte store at 65534 in a 1-page memory is out of bounds, so it must trap without writing. peek reads the last word afterwards:
$ wasm-opt in.wat --alignment-lowering --fuzz-exec -o /dev/null
[fuzz-exec] export store
[trap highest > memory: 65534 > 65532]
[fuzz-exec] export peek
[fuzz-exec] note result: peek => 0
[fuzz-exec] export store
[trap highest > memory: 65536 > 65535]
[fuzz-exec] export peek
[fuzz-exec] note result: peek => 50593792
[fuzz-exec] comparing peek
values not identical! 50593792 != 0
[fuzz-exec] optimization passes changed results
Expected vs actual
The original traps with memory unchanged. After --alignment-lowering the first two byte stores succeed and the third traps; the last word becomes 50593792 (0x03040000).
Version
Reproduced on upstream main at 4d8ac549e2ab9b283246ea95e79ebe139ca579ac (wasm-opt version 133).
AI was used as part of the process of finding this issue. I have manually checked and reproduced it.
- Langage dominant
- WebAssembly
- Étoiles
- 8.7k
- Forks
- 893
- Merge moyen
- 1 j 15 h
- PR mergées (30 j)
- 79
Préparer son environnement
- Aucun Dockerfile ni fichier Docker Compose
- Aucun modèle de pull request
- Lire le guide de contribution
Par où commencer
- Lisez l'issue en entier, puis le guide de contribution du projet.
- Signalez en commentaire que vous la prenez — cela évite que deux personnes fassent le même travail.
- Forkez le dépôt et travaillez sur une branche.
- Ouvrez une pull request qui référence le numéro de l'issue.
Autres issues de WebAssembly/binaryen
-
AvoidReinterprets: `i32.atomic.load` under `f32.reinterpret_i32` loses its atomicityPeut-être pris Une pull request liée à cette issue est ouverte ou déjà fusionnée. Ouverte
Difficulté 2/5 1-3 heures Accessibilité débutants 76/100
WebAssembly/binaryen#9185 ·
Les mainteneurs répondent en général sous 1 jour
-
Difficulté 1/5 Moins d'une heure Accessibilité débutants 88/100
WebAssembly/binaryen#9135 · 1 commentaire ·
Les mainteneurs répondent en général sous 1 jour
-
Difficulté 2/5 Une demi-journée Accessibilité débutants 76/100
WebAssembly/binaryen#9018 · 3 commentaires ·
Les mainteneurs répondent en général sous 1 jour
-
TupleOptimization: tuple swap is miscompiledPeut-être pris @tlively l’a pris il y a 1 jour. Ouverte
Difficulté 3/5 1-2 jours Accessibilité débutants 58/100
WebAssembly/binaryen#9210 · 1 personne assignée ·
Les mainteneurs répondent en général sous 1 jour
-
LoopInvariantCodeMotion: `struct.new` is hoisted out of a loop, so all iterations share one objectPeut-être pris Une pull request liée à cette issue est ouverte ou déjà fusionnée. Ouverte
Difficulté 3/5 1-2 jours Accessibilité débutants 68/100
WebAssembly/binaryen#9184 ·
Les mainteneurs répondent en général sous 1 jour
Toutes les issues de WebAssembly/binaryen
Issues similaires
-
Difficulté 2/5 1-3 heures Accessibilité débutants 74/100
rubys/roundhouse#571 ·
Les mainteneurs répondent en général sous 1 jour
-
bug
Difficulté 2/5 1-3 heures Accessibilité débutants 88/100
anthropics/buffa#639 ·
Les mainteneurs répondent en général sous 3 jours
-
Module EQUIVALENCE into an array with a non-default lower bound ignores the bound (wrong element)Ouverte
Difficulté 2/5 1-3 heures Accessibilité débutants 84/100
Les mainteneurs répondent en général sous 1 jour
-
Discover carries headerEdges that nothing reads since #1914 moved E0507/E0517 to the compiler graphOuvertetech-debt
Difficulté 2/5 1-3 heures Accessibilité débutants 84/100
Les mainteneurs répondent en général sous 1 jour
-
VX_PRINT_DROPS prints each drop point twice on the default code generator, the second time at line 0Ouverte
Difficulté 2/5 1-3 heures Accessibilité débutants 82/100
Les mainteneurs répondent en général sous 1 jour