Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

Fuzzer: DAE generates invalid code

クローズ
#9,233 コメント 1 件 リアクション 0 件 担当者 0 名 GitHub で見る

メンテナーはふだん 1 日以内に返信

まだ誰も着手していません。

評価

難易度
4/5
見積もり時間
3〜5日
初心者へのやさしさ
47/100
issue の種類
バグ
明瞭さ
おおむね明確
活発さ
活発
技術スタック
cpp, wasm
領域
compilers

調査の方向性

Start with src/passes/DeadArgumentElimination.cpp and the dae-optimizing pass; reproduce the validator failure using the reduced WAT and command in the issue. Trace how callers are tracked when call_ref becomes a direct call, and check whether the enclosing expression is re-finalized after return-type refinement. Done means the reduced case validates after the pass and relevant tests pass.

索引モデルが issue の本文から書いたものです。

説明

Run from the latest main bee0b57. Reduced WAT:

(module
 (rec
  (type $0 (sub (shared (func (result (ref null $1))))))
  (type $1 (sub (shared (array f32))))
  (type $2 (sub $0 (shared (func (result (ref null $1))))))
  (type $3 (sub (struct)))
  (type $4 (func (param (ref null $2)) (result f64)))
  (type $5 (func (result (ref $6))))
  (type $6 (shared (func (param (ref $3)) (result v128))))
  (type $7 (func))
 )
 (elem declare func $1 $2)
 (func $1 (type $6) (param $0 (ref $3)) (result v128)
  (unreachable)
 )
 (func $2 (type $5) (result (ref $6))
  (unreachable)
 )
 (func $3 (type $5) (result (ref $6))
  (local $10 i32)
  (select (result (ref $6))
   (call_ref $5
    (ref.func $2)
   )
   (ref.func $1)
   (stringview_wtf16.get_codeunit
    (string.const "\e2\82\ac")
    (block (result i32)
     (local.set $10
      (i32.const 1)
     )
     (local.get $10)
    )
   )
  )
 )
 (func $4 (type $7)
  (drop
   (call $3)
  )
 )
)

Command:

BINARYEN_PASS_DEBUG=1 bin/wasm-opt -all --closed-world --dae-optimizing fuzzed.wat

Output:

[wasm-validator error in function 3] stale type found in 3 on 0x561b46e160d8
(marked as (ref $func.0), should be (ref (exact $func.0)))
, on
(select (result (ref (exact $6)))
 (call $2)
 (ref.func $1)
 (stringview_wtf16.get_codeunit
  (string.const "\e2\82\ac")
  (i32.const 1)
 )
)
Fatal: Last pass (dae-optimizing) broke validation.

Replacing the call_ref with a direct call $2 makes the bug go away.

AI-generated hypothesis

In DeadArgumentElimination.cpp:

  1. callers is computed once, from direct Calls only. Initially $3 reaches $2 only via call_ref, so callers[$2] = {}.
  2. Iteration 1: $4 drops $3's result, so removeReturnValue($3) runs and $3 goes into worthOptimizing. optimizeAfterInlining then rewrites call_ref (ref.func $2) into call $2.
  3. Iteration 2: $2 now has a seen direct call, so refineReturnTypes($2) refines its result to (ref (shared nofunc)) and updates the Call's type. refinedCallers is populated from the stale callers[$2], which is empty, so $3 is never ReFinalized. The enclosing select keeps (ref $6) while its LUB is now (ref (exact $6)).

The comment above callers says over-approximating it is safe; this is an under-approximation, since new direct callers appear mid-pass via devirtualization.

主要言語
WebAssembly
スター
8.7k
フォーク
893
平均マージ
1日 18時間
マージ済み PR(30日)
95

環境構築

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

WebAssembly/binaryen のほかの issue

WebAssembly/binaryen の issue をすべて見る

似ている issue

Compilers の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。