String escaping fuzz bug with wasm-metadce
Maintainer thường phản hồi trong vòng 1 ngày
@kripken đang làm issue này rồi.
Từ ngày 20/3/2026.
Đánh giá
Issue này chưa được đánh giá.
Mô tả
This is a fuzz bug where the fuzzer runs the CtorEval handler with test/lit/basic/name-high-bytes.wast as its initial contents.
test.wast (reduced):
(module
(type $0 (func))
(export "test\\c3\\a9_invoker" (func $0))
(func $0 (type $0)
(unreachable)
)
)
graph.json produced by fuzz_opt.py's filter_exports (reduced):
[
{
"name": "outside",
"reaches": ["export-test\\\\c3\\\\a9_invoker"],
"root": true
},
{
"name": "export-test\\\\c3\\\\a9_invoker",
"export": "test\\\\c3\\\\a9_invoker"
}
]
Here we have an export name containing backslashes. Note that they are escaped in the Wasm text format, so the actual unescaped byte content of the export name is test\c3\a9_invoker. But fuzz_opt.py is not unescaping the string it reads from the disassembly, and then it is JSON-encoding the escaped name, so graph.json ends up with doubly escaped backslashes.
To make matters worse, wasm-metadce is parsing the input JSON in "ASCII" mode, which does not do any unescaping either. So wasm-metadce is rooting an export named test\\\\c3\\\\a9_invoker but in fact the export's name is test\c3\a9_invoker, so the export is removed and the filtered module is empty.
This causes the fuzzer to fail when it later runs wasm-ctor-eval and passes it --kept-exports=test\c3\a9_invoker (note that it has unescaped the string for this step). This errors out because that export no longer exists.
IIUC, the proper fix would be to 1) perform Wasm text format unescaping immediately when extracting export names in get_exports, and 2) perform JSON unescaping when parsing the JSON in wasm-metadce.
- Ngôn ngữ chính
- WebAssembly
- Star
- 8.7k
- Fork
- 893
- Merge trung bình
- 1 ngày 17 giờ
- Pull request đã merge (30 ngày)
- 76
Chuẩn bị môi trường
- Không có Dockerfile hay tệp Docker Compose
- Không có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của WebAssembly/binaryen
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 86/100
WebAssembly/binaryen#9207 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 76/100
WebAssembly/binaryen#9185 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 88/100
WebAssembly/binaryen#9135 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 Nửa ngày Mức phù hợp với người mới 76/100
WebAssembly/binaryen#9018 · 3 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 52/100
WebAssembly/binaryen#9186 ·
Maintainer thường phản hồi trong vòng 1 ngày