kevaundray opened PR #14526 from kevaundray:fix-shifts-ishl-shr-out-of-range to bytecodealliance:main:
Like the other PR, this PR description and commits was generated using AI. Feel free to take the test case and apply a different fix
Bug
In
cranelift/codegen/src/opts/shifts.isle, the two rules after;; (x << N) >> N == x as T_SMALL as T_LARGEcompute the narrow type asty_bits(ty) - Nfrom the raw shift constant. CLIF shift amounts are taken modulo the bit width of the shifted type, soiconst.i64 -8shifts ani8by 0, but8 - 0xffff_ffff_ffff_fff8wraps to16.shift_amt_to_typethen returnsi16, and the rule buildssextend.i8 (ireduce.i16 v0)withv0: i8, which is ill-typed. Withopt_level=speedcompilation aborts in the verifier, even though the original expression is justv0.function %sshr_ishl_neg8(i8) -> i8 { block0(v0: i8): v1 = iconst.i64 -8 v2 = ishl v0, v1 v3 = sshr v2, v1 return v3 }The bug affects every target because it's in the mid-end. Other affected amounts:
-24oni8(picksi32) and-16oni16(picksi32). Theushrrule builds the same ill-typeduextend (ireduce ..)node. In the tests here, elaboration happens to pickv0from the same e-class, so the bad node never reaches the verifier.Before (commit 1, without the fix)
$ clif-util test cranelift/filetests/filetests/egraph/shifts.clif cranelift/filetests/filetests/runtests/shift-left-right-same-amount.clif FAIL cranelift/filetests/filetests/egraph/shifts.clif: optimize Caused by: function %i8_shl_sshr_neg8(i8) -> i8 fast { block0(v0: i8): v7 = ireduce.i16 v0 ; ^~~~~~~~~~~~~~~~~~~ ; error: inst6 (v7 = ireduce.i16 v0): arg 0 (v0) with type i8 failed to satisfy type set ValueTypeSet { ... } v8 = sextend.i8 v7 ; ^~~~~~~~~~~~~~~~~~ ; error: inst7 (v8 = sextend.i8 v7): arg 0 (v7) with type i16 failed to satisfy type set ValueTypeSet { ... } return v8 } ; 2 verifier errors detected (see above). Compilation aborted. FAIL cranelift/filetests/filetests/runtests/shift-left-right-same-amount.clif: Compilation error: Verifier errors Caused by: 0: Verifier errors 1: - inst6 (v7 = ireduce.i16 v0): arg 0 (v0) with type i8 failed to satisfy type set ... - inst7 (v8 = sextend.i8 v7): arg 0 (v7) with type i16 failed to satisfy type set ... 2 tests Error: 2 failuresWhen each
sshrfunction is run on its own, they fail the same way:-24/i8buildsireduce.i32 v0/sextend.i8, and-16/i16buildsireduce.i32 v0/sextend.i16.After (commit 2)
$ cargo run -p cranelift-tools -- test cranelift/filetests/filetests/egraph/ cranelift/filetests/filetests/runtests/shift-left-right-same-amount.clif 78 tests $ clif-util test cranelift/filetests/filetests 1322 tests $ cargo test -p cranelift-codegen test result: ok. 201 passed; 0 failed; 0 ignored test result: ok. 22 passed; 0 failed; 4 ignoredAll of these pass on x86_64. The runtest runs natively on x86_64, on the pulley targets and in the interpreter. After the fix, the
ushrcases optimize toreturn v0. Thesshrcases leave the shifts by0in place: there is nosshr x, 0simplification, which is a separate issue.
github-actions[bot] added the label isle on PR #14526.
github-actions[bot] added the label cranelift on PR #14526.
github-actions[bot] commented on PR #14526:
Subscribe to Label Action
cc @avanhatt, @cfallin, @fitzgen, @mmcloughlin
<details>
This issue or pull request has been labeled: "cranelift", "isle"Thus the following users have been cc'd because of the following labels:
- avanhatt: isle
- cfallin: isle
- fitzgen: isle
- mmcloughlin: isle
To subscribe or unsubscribe from this label, edit the <code>.github/subscribe-to-label.json</code> configuration file.
Learn more.
</details>
kevaundray has marked PR #14526 as ready for review.
kevaundray requested alexcrichton for a review on PR #14526.
kevaundray requested wasmtime-compiler-reviewers for a review on PR #14526.
:thumbs_up: alexcrichton submitted PR review:
Thanks!
cc @avanhatt and @mmcloughlin for an ISLE opt bug which wasn't caught through verification
alexcrichton added PR #14526 cranelift: mask shift amount in (x << k) >> k mid-end rules to the merge queue.
:check: alexcrichton merged PR #14526.
alexcrichton removed PR #14526 cranelift: mask shift amount in (x << k) >> k mid-end rules from the merge queue.
Last updated: Oct 11 2026 at 04:10 UTC