WebAssembly / WebAssembly/binaryen

Branch hint fuzz bug with --code-pushing

Open
#8,622 2 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
WebAssembly
Stars
8.6k
Forks
885
Avg merge
1d 19h
Merged PRs (30d)
69

Description

repro.zip

$ ./repro.sh
+ bin/wasm-opt -all b.wast -S -o b.inst.wast --randomize-branch-hints --instrument-branch-hints -g
+ bin/wasm-opt -all b.inst.wast --fuzz-exec-before
[fuzz-exec] export test
[LoggingExternalInterface log-branch 1 1 0]
[LoggingExternalInterface logging 0]
[LoggingExternalInterface log-branch 2 1 1]
warning: no passes specified, not doing any work
warning: no output file specified, not emitting output
+ bin/wasm-opt -all b.inst.wast -S -o b.de_inst.wast --delete-branch-hints=1 --deinstrument-branch-hints -g
+ bin/wasm-opt -all b.de_inst.wast -S -o b.opted.wast -g --code-pushing
+ bin/wasm-opt -all b.opted.wast -S -o b.final.wast --instrument-branch-hints -g
+ bin/wasm-opt -all b.final.wast --fuzz-exec-before
[fuzz-exec] export test
[LoggingExternalInterface logging 0]
[LoggingExternalInterface log-branch 1 1 1]
warning: no passes specified, not doing any work
warning: no output file specified, not emitting output

So it looks like branch hint number 1 changed results, but looking at the original instrumentation and the final instrumentation, it's maybe a completely different branch??? Not really sure what the correct next step is.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with repro.sh and the attached repro.zip, then run the shown bin/wasm-opt sequence to confirm the branch-hint change. Compare the original and final instrumentation around --code-pushing and inspect the relevant wasm-opt pass entry points. Done means the branch identity or expected behavior is explained and covered by a regression test.

Written by the indexing model from the issue text.

Assessment

Tech stack
wasm
Domain
compilers, tooling
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.