Skip to content

Fuzzer: Emit memory.size and memory.grow - #9204

Open
tlively wants to merge 35 commits into
mainfrom
fuzzer-memory-size-grow
Open

tlively wants to merge 35 commits into
mainfrom
fuzzer-memory-size-grow

Conversation

@tlively

@tlively tlively commented Oct 3, 2026

Copy link
Copy Markdown
Member

Add makeMemorySize and makeMemoryGrow and include them in _makeConcrete when
generating an integer matching the memory address type.

…ructions

Previously, br_on_cast_desc_eq and br_on_cast_desc_eq_fail were rarely emitted
(~0.2 per module) because:
1. makeBrOn had low selection weight despite covering 6 instructions.
2. breakableStack searches stopped immediately on Type::none targets (forcing
   br_on_null) and often lacked reference targets.
3. Descriptor casts were only emitted when getSubType happened by chance to pick
   a struct with a descriptor.

Fix this by:
- Tracking described struct types by Shareability in describedTypes and adding
  hasDescribedSubType / getDescribedSubType helpers.
- Increasing makeBrOn weight to Important.
- Preferring reference targets (especially those with described subtypes) with
  randomness when searching breakableStack, and wrapping in a new target block
  when makeBrOn is called for a reference type without a suitable target.
- Selecting BrOnCastDescEq and BrOnCastDescEqFail directly when described
  subtypes are available instead of upgrading BrOnCast / BrOnCastFail.

Across 200 fuzzer modules, this increases br_on_cast_desc_eq from 0.20 to 2.69
per module (16.0% -> 48.0% of modules) and br_on_cast_desc_eq_fail from 0.18 to
2.88 per module (11.5% -> 50.0% of modules), while also increasing br_on_null
from 27.40 to 34.46 per module.
For i64 pair tuples in _makeConcrete, add makeWideIntExpression with
VeryImportant weight (requiring Multivalue as well as WideArithmetic)
alongside makeTupleMake instead of replacing it half the time with
default weight. This increases generation of unextracted (i64, i64)
wide arithmetic expressions by ~4.2x.
Add try-delegate generation to TranslateToFuzzReader::makeTry and update
fixAfterChanges to preserve DELEGATE_CALLER_TARGET on try-delegates.

Also fix three bugs uncovered by fuzzing delegate and add regression tests:
- Preserve concrete stack types on StackInst::Delegate in StackIRGenerator.
- Increment controlFlowDepth after printing the condition in
  PrintSExpression::visitIf and pop catchIndexStack on StackInst::Delegate in
  printStackIR.
- Use dynCast<Try>() instead of cast<Try>() when walking tryStack in
  CFGWalker.
Add makeElemDrop and call it from makeBulkMemory.
Generate extern.convert_any in makeBasicRef for HeapType::ext when GC is enabled.
Add makeMemorySize and makeMemoryGrow and include them in _makeConcrete when
generating an integer matching the memory address type.
@tlively
tlively requested a review from a team as a code owner October 3, 2026 18:43
@tlively
tlively requested review from stevenfontanella and removed request for a team October 3, 2026 18:43
@tlively
tlively requested review from kripken and removed request for stevenfontanella October 5, 2026 21:05
tlively added 17 commits October 6, 2026 00:03
# Conflicts:
#	src/tools/fuzzing/fuzzing.cpp
# Conflicts:
#	src/tools/fuzzing/fuzzing.cpp
#	test/passes/translate-to-fuzz_all-features_metrics_noprint.txt
# Conflicts:
#	test/passes/translate-to-fuzz_all-features_metrics_noprint.txt
# Conflicts:
#	test/passes/translate-to-fuzz_all-features_metrics_noprint.txt
# Conflicts:
#	test/passes/translate-to-fuzz_all-features_metrics_noprint.txt
# Conflicts:
#	test/passes/translate-to-fuzz_all-features_metrics_noprint.txt
# Conflicts:
#	test/passes/translate-to-fuzz_all-features_metrics_noprint.txt
# Conflicts:
#	test/passes/translate-to-fuzz_all-features_metrics_noprint.txt
# Conflicts:
#	test/passes/translate-to-fuzz_all-features_metrics_noprint.txt
# Conflicts:
#	test/passes/translate-to-fuzz_all-features_metrics_noprint.txt
# Conflicts:
#	test/passes/translate-to-fuzz_all-features_metrics_noprint.txt
# Conflicts:
#	test/passes/translate-to-fuzz_all-features_metrics_noprint.txt
# Conflicts:
#	test/passes/translate-to-fuzz_all-features_metrics_noprint.txt
Base automatically changed from fuzzer-wide-arithmetic to main October 9, 2026 22:36
@tlively
tlively enabled auto-merge (squash) October 9, 2026 22:39

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants