WebAssembly / WebAssembly/wabt

[wasm-interp] incorrect semantics in table.grow

Open
#2,734 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
C++
Stars
8.1k
Forks
827
Avg merge
4d 6h
Merged PRs (30d)
18

Description

Build

Build wasm-interp in debug mode

Command
./wasm-interp --enable-memory64 poc.wasm --run-all-exports
Observed result

test_grow_truncation() => i64:10 and get_table_size() => i64:15

Expected behavior

Should fail because the requested delta would exceed the table maximum

Environment
  • wabt 1.0.39
  • OS: Linux x86_64 Ubuntu

poc.wasm.zip

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Build wabt in debug mode and reproduce the issue with the provided poc.wasm using ./wasm-interp --enable-memory64 poc.wasm --run-all-exports. Start at the wasm-interp handling of table.grow and inspect how test_grow_truncation() and get_table_size() behave; done means the request fails when the delta exceeds the table maximum.

Written by the indexing model from the issue text.

Assessment

Tech stack
cpp, wasm
Domain
compilers
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
55/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.