Skip to content

ASC crashes when builtin trace is used as a value in expressions #638

Description

@hungryzzz

Bug description

Hi, I found that asc / warpo crashes while compiling the following code snippet. I would expect this to report a normal compilation error rather than crashing.

// bad.ts
export function main(): void {
  trace++;
}
> node ~/fuzz_emerging_compilers/AssemblyScript/assemblyscript/bin/asc --optimizeLevel 2 --shrinkLevel 2 bad.ts -o bad.wasm

▌ Whoops, the AssemblyScript compiler has crashed during compile :-(
▌
▌ Here is the stack trace hinting at the problem, perhaps it's useful?
▌
▌ RangeError: Invalid array length
▌     at t.getNonParameterLocalTypes (.../assemblyscript/src/program.ts:3903:17)
▌     at t.ensureVarargsStub (.../assemblyscript/src/compiler.ts:6692:24)
▌     at t.compile (.../assemblyscript/src/compiler.ts:616:33)
▌     at Module.GS (.../assemblyscript/src/index-wasm.ts:360:32)
▌     at Module.De (.../assemblyscript/cli/index.js:732:31)
▌     at async file://.../assemblyscript/bin/asc.js:33:22

# ==========================================================

> ~/BMW-wasm/warpo/build/warpo/warpo_asc --optimizeLevel 2 --shrinkLevel 2 bad.ts -o bad.wasm

abort: Invalid length in ~lib/array.ts:70:60
Error: Unreachable instruction executed
    at ~lib/array/Array<assemblyscript/src/types/Type>#constructor (wasm-function[3446])
    at assemblyscript/src/program/Function#getNonParameterLocalTypes (wasm-function[3958])
    at assemblyscript/src/compiler/Compiler#ensureVarargsStub (wasm-function[3967])
    at assemblyscript/src/compiler/Compiler#compile (wasm-function[5490])
    at assemblyscript/src/index-wasm/compile (wasm-function[5491])
    at export:assemblyscript/src/index-wasm/compile (wasm-function[5896])
compilation failed
AS wasm execution failed
ERROR: compilation failed

Environment

  • AssemblyScript commit: b6bda05c29c9eb7d07d7f6cb2703508483b30493
  • Warpo commit: 0637147

Other Findings

  1. I found that the issue is not limited to trace. Applying postfix increment to abort also triggers the same crash, like abort++;. But the crash does not seem to affect all builtins. For example, the following cases report normal compilation errors instead of crashing: assert++;, sizeof++;, changetype++;, load++;.
  2. Besides, I also found that the issue is not limited to the postfix increment operator. Using trace as a value in other non-call expressions also triggers the same crash, for example: trace, trace--;, +trace;, trace + 1;, trace - 1;, trace == 1;, !trace;, trace as i32;, let a = trace. However, some invalid uses, such as trace[0]; and trace = 1; report normal compilation errors instead of crashing.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions