Fuzzer: DAE generates invalid code
メンテナーはふだん 1 日以内に返信
まだ誰も着手していません。
評価
調査の方向性
Start with src/passes/DeadArgumentElimination.cpp and the dae-optimizing pass; reproduce the validator failure using the reduced WAT and command in the issue. Trace how callers are tracked when call_ref becomes a direct call, and check whether the enclosing expression is re-finalized after return-type refinement. Done means the reduced case validates after the pass and relevant tests pass.
索引モデルが issue の本文から書いたものです。
説明
Run from the latest main bee0b57. Reduced WAT:
(module
(rec
(type $0 (sub (shared (func (result (ref null $1))))))
(type $1 (sub (shared (array f32))))
(type $2 (sub $0 (shared (func (result (ref null $1))))))
(type $3 (sub (struct)))
(type $4 (func (param (ref null $2)) (result f64)))
(type $5 (func (result (ref $6))))
(type $6 (shared (func (param (ref $3)) (result v128))))
(type $7 (func))
)
(elem declare func $1 $2)
(func $1 (type $6) (param $0 (ref $3)) (result v128)
(unreachable)
)
(func $2 (type $5) (result (ref $6))
(unreachable)
)
(func $3 (type $5) (result (ref $6))
(local $10 i32)
(select (result (ref $6))
(call_ref $5
(ref.func $2)
)
(ref.func $1)
(stringview_wtf16.get_codeunit
(string.const "\e2\82\ac")
(block (result i32)
(local.set $10
(i32.const 1)
)
(local.get $10)
)
)
)
)
(func $4 (type $7)
(drop
(call $3)
)
)
)
Command:
BINARYEN_PASS_DEBUG=1 bin/wasm-opt -all --closed-world --dae-optimizing fuzzed.wat
Output:
[wasm-validator error in function 3] stale type found in 3 on 0x561b46e160d8
(marked as (ref $func.0), should be (ref (exact $func.0)))
, on
(select (result (ref (exact $6)))
(call $2)
(ref.func $1)
(stringview_wtf16.get_codeunit
(string.const "\e2\82\ac")
(i32.const 1)
)
)
Fatal: Last pass (dae-optimizing) broke validation.
Replacing the call_ref with a direct call $2 makes the bug go away.
AI-generated hypothesis
In DeadArgumentElimination.cpp:
callersis computed once, from directCalls only. Initially$3reaches$2only viacall_ref, socallers[$2] = {}.- Iteration 1:
$4drops$3's result, soremoveReturnValue($3)runs and$3goes intoworthOptimizing.optimizeAfterInliningthen rewritescall_ref (ref.func $2)intocall $2. - Iteration 2:
$2now has a seen direct call, sorefineReturnTypes($2)refines its result to(ref (shared nofunc))and updates theCall's type.refinedCallersis populated from the stalecallers[$2], which is empty, so$3is neverReFinalized. The enclosingselectkeeps(ref $6)while its LUB is now(ref (exact $6)).
The comment above callers says over-approximating it is safe; this is an under-approximation, since new direct callers appear mid-pass via devirtualization.
- 主要言語
- WebAssembly
- スター
- 8.7k
- フォーク
- 893
- 平均マージ
- 1日 18時間
- マージ済み PR(30日)
- 95
環境構築
- Dockerfile・Docker Compose ファイルなし
- プルリクエストのテンプレートなし
- コントリビューションガイドを読む
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
WebAssembly/binaryen のほかの issue
-
難易度 1/5 1時間未満 初心者へのやさしさ 88/100
WebAssembly/binaryen#9135 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 半日 初心者へのやさしさ 76/100
WebAssembly/binaryen#9018 · コメント 3 件 ·
メンテナーはふだん 1 日以内に返信
-
Memory64Lowering: table.get/table.set keep i64 index on lowered table64, output fails validationオープン
難易度 3/5 半日 初心者へのやさしさ 66/100
WebAssembly/binaryen#9245 ·
メンテナーはふだん 1 日以内に返信
-
難易度 3/5 1〜2日 初心者へのやさしさ 65/100
WebAssembly/binaryen#9244 ·
メンテナーはふだん 1 日以内に返信
-
難易度 3/5 1〜2日 初心者へのやさしさ 62/100
WebAssembly/binaryen#9243 ·
メンテナーはふだん 1 日以内に返信
WebAssembly/binaryen の issue をすべて見る
似ている issue
-
難易度 2/5 1〜3時間 初心者へのやさしさ 82/100
-
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
メンテナーはふだん 1 日以内に返信
-
Default-import note suggests `import * as process` for velt:process, which does not name the builtinオープン
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
メンテナーはふだん 1 日以内に返信
-
diagnostics good first issue
難易度 2/5 1〜3時間 初心者へのやさしさ 82/100
メンテナーはふだん 1 日以内に返信
-
category:runtime
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
メンテナーはふだん 1 日以内に返信