LegalizeJSInterface: heap-use-after-free in Fixer::visitCall when a function named $legalfunc$<import> already exists
Maintainer thường phản hồi trong vòng 1 ngày
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 3/5
- Thời gian dự kiến
- 1-2 ngày
- Mức phù hợp với người mới
- 62/100
Hướng nghiên cứu
The crash involves makeLegalStubForCalledImport and Fixer::visitCall in src/passes/LegalizeJSInterface.cpp. Read how the stub's unique_ptr is handled when a function with the same name already exists, and how illegalImportsToLegal keeps its pointer. Build with ASan and run the three-line reproducer from the issue with --legalize-js-interface. Done when that run is clean and the call is legalized correctly even when a user function named $legalfunc$imp exists.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
--legalize-js-interface reads freed memory, and the release build segfaults, when the module already has a function whose name is the one the pass picks for its stub ($legalfunc$imp here).
(module
(import "env" "imp" (func $imp (param i64) (result i32)))
(func $legalfunc$imp (param i64) (result i32) (i32.const 7))
(func $f (result i32) (call $imp (i64.const 1)))
)
wasm-opt input.wat --legalize-js-interface -o /dev/null
ASan build (with BINARYEN_PASS_DEBUG=1):
==192075==ERROR: AddressSanitizer: heap-use-after-free on address 0x516000000f80 at pc 0x557ea312a1f1 bp 0x7fa01da45390 sp 0x7fa01da45380
READ of size 8 at 0x516000000f80 thread T2
#0 0x557ea312a1f0 in visitCall src/passes/LegalizeJSInterface.cpp:138
#1 0x557ea312a1f0 in doVisitCall src/wasm-delegations.def:23
#2 0x557ea30b5738 in walk src/wasm-traversal.h:318
freed by thread T0 here:
#3 0x557ea311338d in std::unique_ptr<wasm::Function, std::default_delete<wasm::Function> >::~unique_ptr() /usr/include/c++/11/bits/unique_ptr.h:361
#4 0x557ea311338d in makeLegalStubForCalledImport src/passes/LegalizeJSInterface.cpp:319
I expected the pass to legalize the call normally. The module is valid (wasm-opt input.wat -o /dev/null exits 0) and function names are free-form, so a user function called $legalfunc$imp should not break the pass.
Found at commit 93d6e9de7e1d99be22a49b8952426906a65df397 and still reproduces at 207bbaec4b30 (ASan build). A normal release build crashes with SIGSEGV and prints nothing. -all is not needed.
Looks like makeLegalStubForCalledImport in src/passes/LegalizeJSInterface.cpp builds the stub in a unique_ptr, keeps stub.get(), and only adds the stub to the module if no function with that name exists. Here one exists, so the stub is freed on return, and the dangling pointer stored in illegalImportsToLegal is later read by Fixer::visitCall.
Found with an LLM-based testing tool; I used Claude to reduce it and look for the cause.
- Ngôn ngữ chính
- WebAssembly
- Star
- 8.7k
- Fork
- 893
- Merge trung bình
- 1 ngày 18 giờ
- Pull request đã merge (30 ngày)
- 95
Chuẩn bị môi trường
- Không có Dockerfile hay tệp Docker Compose
- Không có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của WebAssembly/binaryen
-
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 88/100
WebAssembly/binaryen#9135 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 Nửa ngày Mức phù hợp với người mới 76/100
WebAssembly/binaryen#9018 · 3 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Memory64Lowering: table.get/table.set keep i64 index on lowered table64, output fails validationĐang mở
Độ khó 3/5 Nửa ngày Mức phù hợp với người mới 66/100
WebAssembly/binaryen#9245 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 65/100
WebAssembly/binaryen#9244 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Closed world optimization of wasm modules that have function types in import/export boundaryĐang mở
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 18/100
WebAssembly/binaryen#9237 · 3 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
Tất cả issue của WebAssembly/binaryen
Issue tương tự
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 74/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
handsontable/hyperformula#1803 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
compile: jv_mem_calloc assertion abort after "too many function parameters" error in a nested functionCó thể đã có người làm Có pull request liên kết đang mở hoặc đã được merge. Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Default-import note suggests `import * as process` for velt:process, which does not name the builtinĐang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
Maintainer thường phản hồi trong vòng 1 ngày