store_probably_utf16_to_latin1_or_utf16 shrinks with alignment 1, so a stored latin1+utf16 string can fail to load
Maintainer thường phản hồi trong vòng 2 ngày
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 2/5
- Thời gian dự kiến
- 1-3 giờ
- Mức phù hợp với người mới
- 82/100
- Loại issue
- Lỗi
- Độ rõ ràng
- Đặc tả rõ ràng
- Mức độ hoạt động
- Sôi nổi
- Công nghệ
- python, wasm
- Lĩnh vực
- compilers, documentation
Hướng nghiên cứu
Bắt đầu tại definitions.py:1673 và so sánh store_probably_utf16_to_latin1_or_utf16 với đường dẫn thu nhỏ tương ứng trong store_string_to_latin1_or_utf16. Kiểm tra CanonicalABI.md:2751 và chạy bản tái hiện được cung cấp; hoàn tất có nghĩa là kết quả latin1+utf16 vẫn có thể được tải bằng một allocator di chuyển nó đến một địa chỉ lẻ.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
store_probably_utf16_to_latin1_or_utf16 requests alignment 1 when shrinking to Latin-1 and does not check the returned pointer’s alignment. But load_string_from_range requires 2-byte alignment for all latin1+utf16 strings. An allocator honoring the requested alignment can therefore return an odd pointer: storing succeeds, but loading the result traps.
This is at a25fc0b, in definitions.py:1673 and CanonicalABI.md:2751:
latin1_size = int(len(encoded) / 2)
for i in range(latin1_size):
cx.opts.memory[ptr + i] = cx.opts.memory[ptr + 2*i]
ptr = cx.reallocate(ptr, src_byte_length, 1, latin1_size) # alignment 1
trap_if(ptr + latin1_size > len(cx.opts.memory)) # no alignment check
return (ptr, latin1_size)
The other shrinking path, the final reallocate in store_string_to_latin1_or_utf16, passes alignment 2 and does trap_if(ptr != align_to(ptr, 2)). That matches #54 and #61, which made latin1+utf16 always 2-aligned. Wasmtime's FACT adapter for this case (crates/environ/src/fact/trampoline.rs, commented "Corresponds to store_probably_utf16_to_latin1_or_utf16") also passes alignment 2 to the downsizing realloc and validates the result.
Reproduction
Both the source and destination use latin1+utf16, and the source string is UTF-16-tagged even though every code point fits in latin1. The realloc below honors the requested alignment but moves the buffer to an odd address on the shrink:
import sys
sys.path.insert(0, sys.argv[1]) # .../design/mvp/canonical-abi
from definitions import *
def realloc(args):
old_ptr, old_size, align, new_size = args
if old_size == 0:
return [2] # initial allocation: 2-aligned
assert align == 1 # the shrink asks for alignment 1...
mem[1:1+new_size] = mem[old_ptr:old_ptr+new_size]
return [1] # ...so an odd pointer meets that alignment
mem = bytearray(64)
opts = CanonicalOptions()
opts.memory = MemInst(mem, 'i32'); opts.string_encoding = 'latin1+utf16'; opts.realloc = realloc
cx = LiftLowerContext(opts, ComponentInstance(Store()))
def run(f):
task = Task(FuncType([], []), CanonicalOptions(), cx.inst, lambda: [], lambda _: ())
out = {}
def body():
try: out['v'] = f()
except BaseException as e: out['exc'] = repr(e)
Thread(task, body).resume()
return out
stored = run(lambda: store_string_into_range(cx, ('hello', 'latin1+utf16', 5 | (1 << 31))))
print('store:', stored)
print('load :', run(lambda: load_string_from_range(cx, *stored['v'])))
Output:
store: {'v': (1, 5)}
load : {'exc': 'Trap()'}
Suggested fix
Match the other paths and Wasmtime:
- ptr = cx.reallocate(ptr, src_byte_length, 1, latin1_size)
+ ptr = cx.reallocate(ptr, src_byte_length, 2, latin1_size)
+ trap_if(ptr != align_to(ptr, 2))
trap_if(ptr + latin1_size > len(cx.opts.memory))
The same change is needed in CanonicalABI.md.
We found this while proving a canonical ABI string round trip in Lean.
- Ngôn ngữ chính
- WebAssembly
- Star
- 1.4k
- Fork
- 132
- Merge trung bình
- 3 ngày 9 giờ
- Pull request đã merge (30 ngày)
- 10
Chuẩn bị môi trường
Dự án này không cung cấp dev container, Dockerfile hay hướng dẫn đóng góp, nên bạn cần tự thiết lập môi trường: hãy bắt đầu từ README và xem hướng dẫn đóng góp lần đầu của chúng tôi để biết các bước chung.
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của WebAssembly/component-model
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
WebAssembly/component-model#609 · 2 bình luận · 1 reaction ·
Maintainer thường phản hồi trong vòng 2 ngày
-
Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 35/100
WebAssembly/component-model#732 ·
Maintainer thường phản hồi trong vòng 2 ngày
-
`bytes` as alias for `list<u8>`Đang mở
Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 35/100
WebAssembly/component-model#731 · 2 bình luận ·
Maintainer thường phản hồi trong vòng 2 ngày
-
Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 35/100
WebAssembly/component-model#724 · 10 bình luận ·
Maintainer thường phản hồi trong vòng 2 ngày
-
Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 25/100
WebAssembly/component-model#695 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 2 ngày
Tất cả issue của WebAssembly/component-model
Issue tương tự
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
tree-sitter/tree-sitter-cpp#374 ·
-
bug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 85/100
voidzero-dev/oxc-angular-compiler#511 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 86/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
tc39/proposal-deferred-reexports#98 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
bug good-title pdd
Độ khó 2/5 Dưới một giờ Mức phù hợp với người mới 82/100
objectionary/phino#1630 ·
Maintainer thường phản hồi trong vòng 1 ngày