Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

Fuzzer: DAE generates invalid code

已关闭
#9,233 1 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

维护者通常 1 天内回复

还没有人认领这个 Issue。

评估

难度
4/5
预计耗时
3-5 天
新手友好度
47/100
Issue 类型
缺陷
描述清晰度
基本清楚
活跃度
活跃
技术栈
cpp, wasm
领域
compilers

调研方向

Start with src/passes/DeadArgumentElimination.cpp and the dae-optimizing pass; reproduce the validator failure using the reduced WAT and command in the issue. Trace how callers are tracked when call_ref becomes a direct call, and check whether the enclosing expression is re-finalized after return-type refinement. Done means the reduced case validates after the pass and relevant tests pass.

由索引模型根据 Issue 内容生成。

描述

Run from the latest main bee0b57. Reduced WAT:

(module
 (rec
  (type $0 (sub (shared (func (result (ref null $1))))))
  (type $1 (sub (shared (array f32))))
  (type $2 (sub $0 (shared (func (result (ref null $1))))))
  (type $3 (sub (struct)))
  (type $4 (func (param (ref null $2)) (result f64)))
  (type $5 (func (result (ref $6))))
  (type $6 (shared (func (param (ref $3)) (result v128))))
  (type $7 (func))
 )
 (elem declare func $1 $2)
 (func $1 (type $6) (param $0 (ref $3)) (result v128)
  (unreachable)
 )
 (func $2 (type $5) (result (ref $6))
  (unreachable)
 )
 (func $3 (type $5) (result (ref $6))
  (local $10 i32)
  (select (result (ref $6))
   (call_ref $5
    (ref.func $2)
   )
   (ref.func $1)
   (stringview_wtf16.get_codeunit
    (string.const "\e2\82\ac")
    (block (result i32)
     (local.set $10
      (i32.const 1)
     )
     (local.get $10)
    )
   )
  )
 )
 (func $4 (type $7)
  (drop
   (call $3)
  )
 )
)

Command:

BINARYEN_PASS_DEBUG=1 bin/wasm-opt -all --closed-world --dae-optimizing fuzzed.wat

Output:

[wasm-validator error in function 3] stale type found in 3 on 0x561b46e160d8
(marked as (ref $func.0), should be (ref (exact $func.0)))
, on
(select (result (ref (exact $6)))
 (call $2)
 (ref.func $1)
 (stringview_wtf16.get_codeunit
  (string.const "\e2\82\ac")
  (i32.const 1)
 )
)
Fatal: Last pass (dae-optimizing) broke validation.

Replacing the call_ref with a direct call $2 makes the bug go away.

AI-generated hypothesis

In DeadArgumentElimination.cpp:

  1. callers is computed once, from direct Calls only. Initially $3 reaches $2 only via call_ref, so callers[$2] = {}.
  2. Iteration 1: $4 drops $3's result, so removeReturnValue($3) runs and $3 goes into worthOptimizing. optimizeAfterInlining then rewrites call_ref (ref.func $2) into call $2.
  3. Iteration 2: $2 now has a seen direct call, so refineReturnTypes($2) refines its result to (ref (shared nofunc)) and updates the Call's type. refinedCallers is populated from the stale callers[$2], which is empty, so $3 is never ReFinalized. The enclosing select keeps (ref $6) while its LUB is now (ref (exact $6)).

The comment above callers says over-approximating it is safe; this is an under-approximation, since new direct callers appear mid-pass via devirtualization.

主要语言
WebAssembly
星标
8.7k
派生
893
平均合并
1 天 23 小时
30 天内合并 PR
105

环境准备

  • 没有 Dockerfile 或 Docker Compose 文件
  • 没有 Pull Request 模板
  • 阅读贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

WebAssembly/binaryen 的其他 Issue

查看 WebAssembly/binaryen 的全部 Issue

相似的 Issue

更多 Compilers Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。