Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

LegalizeJSInterface: heap-use-after-free in Fixer::visitCall when a function named $legalfunc$<import> already exists

未关闭
#9,243 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

维护者通常 1 天内回复

还没有人认领这个 Issue。

评估

难度
3/5
预计耗时
1-2 天
新手友好度
62/100
Issue 类型
缺陷
描述清晰度
描述清楚
活跃度
活跃
技术栈
cpp, wasm
领域
compilers

调研方向

The crash involves makeLegalStubForCalledImport and Fixer::visitCall in src/passes/LegalizeJSInterface.cpp. Read how the stub's unique_ptr is handled when a function with the same name already exists, and how illegalImportsToLegal keeps its pointer. Build with ASan and run the three-line reproducer from the issue with --legalize-js-interface. Done when that run is clean and the call is legalized correctly even when a user function named $legalfunc$imp exists.

由索引模型根据 Issue 内容生成。

描述

--legalize-js-interface reads freed memory, and the release build segfaults, when the module already has a function whose name is the one the pass picks for its stub ($legalfunc$imp here).

(module
 (import "env" "imp" (func $imp (param i64) (result i32)))
 (func $legalfunc$imp (param i64) (result i32) (i32.const 7))
 (func $f (result i32) (call $imp (i64.const 1)))
)
wasm-opt input.wat --legalize-js-interface -o /dev/null

ASan build (with BINARYEN_PASS_DEBUG=1):

==192075==ERROR: AddressSanitizer: heap-use-after-free on address 0x516000000f80 at pc 0x557ea312a1f1 bp 0x7fa01da45390 sp 0x7fa01da45380
READ of size 8 at 0x516000000f80 thread T2
    #0 0x557ea312a1f0 in visitCall src/passes/LegalizeJSInterface.cpp:138
    #1 0x557ea312a1f0 in doVisitCall src/wasm-delegations.def:23
    #2 0x557ea30b5738 in walk src/wasm-traversal.h:318
freed by thread T0 here:
    #3 0x557ea311338d in std::unique_ptr<wasm::Function, std::default_delete<wasm::Function> >::~unique_ptr() /usr/include/c++/11/bits/unique_ptr.h:361
    #4 0x557ea311338d in makeLegalStubForCalledImport src/passes/LegalizeJSInterface.cpp:319

I expected the pass to legalize the call normally. The module is valid (wasm-opt input.wat -o /dev/null exits 0) and function names are free-form, so a user function called $legalfunc$imp should not break the pass.

Found at commit 93d6e9de7e1d99be22a49b8952426906a65df397 and still reproduces at 207bbaec4b30 (ASan build). A normal release build crashes with SIGSEGV and prints nothing. -all is not needed.

Looks like makeLegalStubForCalledImport in src/passes/LegalizeJSInterface.cpp builds the stub in a unique_ptr, keeps stub.get(), and only adds the stub to the module if no function with that name exists. Here one exists, so the stub is freed on return, and the dangling pointer stored in illegalImportsToLegal is later read by Fixer::visitCall.

Found with an LLM-based testing tool; I used Claude to reduce it and look for the cause.

主要语言
WebAssembly
星标
8.7k
派生
893
平均合并
1 天 18 小时
30 天内合并 PR
95

环境准备

  • 没有 Dockerfile 或 Docker Compose 文件
  • 没有 Pull Request 模板
  • 阅读贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

WebAssembly/binaryen 的其他 Issue

查看 WebAssembly/binaryen 的全部 Issue

相似的 Issue

更多 Compilers Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。