TupleOptimization: tuple swap is miscompiled
维护者通常 1 天内回复
评估
调研方向
Start by running the provided test.wat reproducer with and without --tuple-optimization, then locate the TupleOptimization pass in Binaryen. The issue suggests comparing its lowering with Heap2Local's handling of struct.new. Done means the optimized swap returns 16, matching the unoptimized module; add a regression test for the reproducer.
由索引模型根据 Issue 内容生成。
描述
Summary
--tuple-optimization splits a tuple local into scalar locals and lowers local.set $t (tuple.make a0 a1) to $t0 = a0; $t1 = a1, in order. If an operand reads an element of $t that was already overwritten (a1 = tuple.extract 0 $t), it reads the new value:
t = (t.1, t.0) ==> $t0 = $t1; $t1 = $t0; // $t0 is already overwritten
The pass is in -O1 and above; a multivalue loop that swaps its parameters (plain wasm) is miscompiled by -O3, -Os, -Oz and -O4.
Evaluating the operands into temporaries first (as Heap2Local does for struct.new) would fix it.
Reproducer
test.wat:
(module
(func (export "f") (param $x i32) (param $y i32) (result i32)
(local $t (tuple i32 i32))
(local.set $t (tuple.make 2 (local.get $x) (local.get $y)))
(local.set $t (tuple.make 2 (tuple.extract 2 1 (local.get $t)) (tuple.extract 2 0 (local.get $t))))
(tuple.extract 2 1 (local.get $t))))
$ wasm-opt test.wat --enable-multivalue -o in.wasm
$ wasm-opt test.wat --enable-multivalue --tuple-optimization -o out.wasm
$ wasmtime run --invoke f in.wasm 16 1000
16
$ wasmtime run --invoke f out.wasm 16 1000
1000
f swaps the elements of t and returns t.1, which is the original x, so the correct result is 16. V8 gives the same results.
AI was used as part of the process of finding this issue. I have manually checked and reproduced it.
- 主要语言
- WebAssembly
- 星标
- 8.7k
- 派生
- 893
- 平均合并
- 1 天 14 小时
- 30 天内合并 PR
- 77
环境准备
- 没有 Dockerfile 或 Docker Compose 文件
- 没有 Pull Request 模板
- 阅读贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
WebAssembly/binaryen 的其他 Issue
-
难度 2/5 1-3 小时 新手友好度 76/100
WebAssembly/binaryen#9185 ·
维护者通常 1 天内回复
-
难度 1/5 1 小时以内 新手友好度 88/100
WebAssembly/binaryen#9135 · 1 条评论 ·
维护者通常 1 天内回复
-
难度 2/5 半天 新手友好度 76/100
WebAssembly/binaryen#9018 · 3 条评论 ·
维护者通常 1 天内回复
-
难度 4/5 3-5 天 新手友好度 52/100
WebAssembly/binaryen#9186 ·
维护者通常 1 天内回复
-
LoopInvariantCodeMotion: `struct.new` is hoisted out of a loop, so all iterations share one object未关闭
难度 3/5 1-2 天 新手友好度 68/100
WebAssembly/binaryen#9184 ·
维护者通常 1 天内回复
查看 WebAssembly/binaryen 的全部 Issue
相似的 Issue
-
I-prioritize needs-triage regression-from-stable-to-beta T-lang
难度 2/5 1-3 小时 新手友好度 65/100
rust-lang/rust#163830 · 1 条评论 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 76/100
rubys/roundhouse#444 ·
维护者通常 1 天内回复
-
crash llvm:codegen
难度 2/5 1-3 小时 新手友好度 72/100
llvm/llvm-project#229064 ·
维护者通常 1 天内回复
-
area:lowering kind:bug
难度 2/5 1-3 小时 新手友好度 68/100
维护者通常 1 天内回复
-
vxc prints a debug line '[flat-codegen] emitted module via the flat path' on every compile可能已有人在做 @YodHeVauHe 今天认领。 未关闭devex good first issue
难度 2/5 1-3 小时 新手友好度 82/100
维护者通常 1 天内回复