Fuzzer: DAE generates invalid code
维护者通常 1 天内回复
还没有人认领这个 Issue。
评估
调研方向
Start with src/passes/DeadArgumentElimination.cpp and the dae-optimizing pass; reproduce the validator failure using the reduced WAT and command in the issue. Trace how callers are tracked when call_ref becomes a direct call, and check whether the enclosing expression is re-finalized after return-type refinement. Done means the reduced case validates after the pass and relevant tests pass.
由索引模型根据 Issue 内容生成。
描述
Run from the latest main bee0b57. Reduced WAT:
(module
(rec
(type $0 (sub (shared (func (result (ref null $1))))))
(type $1 (sub (shared (array f32))))
(type $2 (sub $0 (shared (func (result (ref null $1))))))
(type $3 (sub (struct)))
(type $4 (func (param (ref null $2)) (result f64)))
(type $5 (func (result (ref $6))))
(type $6 (shared (func (param (ref $3)) (result v128))))
(type $7 (func))
)
(elem declare func $1 $2)
(func $1 (type $6) (param $0 (ref $3)) (result v128)
(unreachable)
)
(func $2 (type $5) (result (ref $6))
(unreachable)
)
(func $3 (type $5) (result (ref $6))
(local $10 i32)
(select (result (ref $6))
(call_ref $5
(ref.func $2)
)
(ref.func $1)
(stringview_wtf16.get_codeunit
(string.const "\e2\82\ac")
(block (result i32)
(local.set $10
(i32.const 1)
)
(local.get $10)
)
)
)
)
(func $4 (type $7)
(drop
(call $3)
)
)
)
Command:
BINARYEN_PASS_DEBUG=1 bin/wasm-opt -all --closed-world --dae-optimizing fuzzed.wat
Output:
[wasm-validator error in function 3] stale type found in 3 on 0x561b46e160d8
(marked as (ref $func.0), should be (ref (exact $func.0)))
, on
(select (result (ref (exact $6)))
(call $2)
(ref.func $1)
(stringview_wtf16.get_codeunit
(string.const "\e2\82\ac")
(i32.const 1)
)
)
Fatal: Last pass (dae-optimizing) broke validation.
Replacing the call_ref with a direct call $2 makes the bug go away.
AI-generated hypothesis
In DeadArgumentElimination.cpp:
callersis computed once, from directCalls only. Initially$3reaches$2only viacall_ref, socallers[$2] = {}.- Iteration 1:
$4drops$3's result, soremoveReturnValue($3)runs and$3goes intoworthOptimizing.optimizeAfterInliningthen rewritescall_ref (ref.func $2)intocall $2. - Iteration 2:
$2now has a seen direct call, sorefineReturnTypes($2)refines its result to(ref (shared nofunc))and updates theCall's type.refinedCallersis populated from the stalecallers[$2], which is empty, so$3is neverReFinalized. The enclosingselectkeeps(ref $6)while its LUB is now(ref (exact $6)).
The comment above callers says over-approximating it is safe; this is an under-approximation, since new direct callers appear mid-pass via devirtualization.
- 主要语言
- WebAssembly
- 星标
- 8.7k
- 派生
- 893
- 平均合并
- 1 天 23 小时
- 30 天内合并 PR
- 105
环境准备
- 没有 Dockerfile 或 Docker Compose 文件
- 没有 Pull Request 模板
- 阅读贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
WebAssembly/binaryen 的其他 Issue
-
难度 1/5 1 小时以内 新手友好度 88/100
WebAssembly/binaryen#9135 · 1 条评论 ·
维护者通常 1 天内回复
-
难度 2/5 半天 新手友好度 76/100
WebAssembly/binaryen#9018 · 3 条评论 ·
维护者通常 1 天内回复
-
难度 3/5 1-2 天 新手友好度 45/100
WebAssembly/binaryen#9246 · 1 条评论 ·
维护者通常 1 天内回复
-
Memory64Lowering: table.get/table.set keep i64 index on lowered table64, output fails validation未关闭
难度 3/5 半天 新手友好度 66/100
WebAssembly/binaryen#9245 ·
维护者通常 1 天内回复
-
难度 3/5 1-2 天 新手友好度 65/100
WebAssembly/binaryen#9244 ·
维护者通常 1 天内回复
查看 WebAssembly/binaryen 的全部 Issue
相似的 Issue
-
难度 2/5 1-3 小时 新手友好度 78/100
rescript-lang/rescript#8763 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 72/100
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 66/100
维护者通常 5 天内回复
-
bug
难度 2/5 1-3 小时 新手友好度 66/100
partiql/partiql-lang-kotlin#1972 ·
-
area:protocol bug
难度 2/5 1-3 小时 新手友好度 72/100
维护者通常 1 天内回复