TupleOptimization: tuple swap is miscompiled
メンテナーはふだん 1 日以内に返信
まだ誰も着手していません。
評価
- 難易度
- 3/5
- 見積もり時間
- 1〜2日
- 初心者へのやさしさ
- 58/100
調査の方向性
Start by running the provided test.wat reproducer with and without --tuple-optimization, then locate the TupleOptimization pass in Binaryen. The issue suggests comparing its lowering with Heap2Local's handling of struct.new. Done means the optimized swap returns 16, matching the unoptimized module; add a regression test for the reproducer.
索引モデルが issue の本文から書いたものです。
説明
Summary
--tuple-optimization splits a tuple local into scalar locals and lowers local.set $t (tuple.make a0 a1) to $t0 = a0; $t1 = a1, in order. If an operand reads an element of $t that was already overwritten (a1 = tuple.extract 0 $t), it reads the new value:
t = (t.1, t.0) ==> $t0 = $t1; $t1 = $t0; // $t0 is already overwritten
The pass is in -O1 and above; a multivalue loop that swaps its parameters (plain wasm) is miscompiled by -O3, -Os, -Oz and -O4.
Evaluating the operands into temporaries first (as Heap2Local does for struct.new) would fix it.
Reproducer
test.wat:
(module
(func (export "f") (param $x i32) (param $y i32) (result i32)
(local $t (tuple i32 i32))
(local.set $t (tuple.make 2 (local.get $x) (local.get $y)))
(local.set $t (tuple.make 2 (tuple.extract 2 1 (local.get $t)) (tuple.extract 2 0 (local.get $t))))
(tuple.extract 2 1 (local.get $t))))
$ wasm-opt test.wat --enable-multivalue -o in.wasm
$ wasm-opt test.wat --enable-multivalue --tuple-optimization -o out.wasm
$ wasmtime run --invoke f in.wasm 16 1000
16
$ wasmtime run --invoke f out.wasm 16 1000
1000
f swaps the elements of t and returns t.1, which is the original x, so the correct result is 16. V8 gives the same results.
AI was used as part of the process of finding this issue. I have manually checked and reproduced it.
- 主要言語
- WebAssembly
- スター
- 8.7k
- フォーク
- 893
- 平均マージ
- 1日 14時間
- マージ済み PR(30日)
- 77
環境構築
- Dockerfile・Docker Compose ファイルなし
- プルリクエストのテンプレートなし
- コントリビューションガイドを読む
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
WebAssembly/binaryen のほかの issue
-
難易度 2/5 1〜3時間 初心者へのやさしさ 76/100
WebAssembly/binaryen#9185 ·
メンテナーはふだん 1 日以内に返信
-
難易度 1/5 1時間未満 初心者へのやさしさ 88/100
WebAssembly/binaryen#9135 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 半日 初心者へのやさしさ 76/100
WebAssembly/binaryen#9018 · コメント 3 件 ·
メンテナーはふだん 1 日以内に返信
-
難易度 4/5 3〜5日 初心者へのやさしさ 52/100
WebAssembly/binaryen#9186 ·
メンテナーはふだん 1 日以内に返信
-
LoopInvariantCodeMotion: `struct.new` is hoisted out of a loop, so all iterations share one objectオープン
難易度 3/5 1〜2日 初心者へのやさしさ 68/100
WebAssembly/binaryen#9184 ·
メンテナーはふだん 1 日以内に返信
WebAssembly/binaryen の issue をすべて見る
似ている issue
-
I-prioritize needs-triage regression-from-stable-to-beta T-lang
難易度 2/5 1〜3時間 初心者へのやさしさ 65/100
rust-lang/rust#163830 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 76/100
rubys/roundhouse#444 ·
メンテナーはふだん 1 日以内に返信
-
crash llvm:codegen
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
llvm/llvm-project#229064 ·
メンテナーはふだん 1 日以内に返信
-
vxc prints a debug line '[flat-codegen] emitted module via the flat path' on every compile対応中かも @YodHeVauHe が今日担当しました。 オープンdevex good first issue
難易度 2/5 1〜3時間 初心者へのやさしさ 82/100
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 70/100
メンテナーはふだん 1 日以内に返信