fitzgen commented on issue #14570:
<details><summary>Full LLM report</summary>
Cranelift inliner does not remap user external names in
symbolglobal values
Date 2026-10-05 Wasmtime commit 73b04cff3317d1e308866eb24359483ac6116669(main)Host macOS 15.8.1 (Darwin 24.6.0), aarch64-apple-darwinModel Claude Opus 5.5 ( claude-opus-5-5)Component cranelift/codegen/src/inline.rs(create_global_values)Class Miscompile: an inlined symbol_valuerelocates against the wrong symbolSeverity Medium for Cranelift embedders using Context::inlinewithsymbolglobal values. Wasmtime does not emitsymbolglobal values.Summary
create_global_values(cranelift/codegen/src/inline.rs:1470-1474) copies
the callee'sGlobalValueData::Symbolverbatim:// These kinds of global values do not reference other global // values, so we can just clone them. ir::GlobalValueData::VMContext | ir::GlobalValueData::Symbol { .. } | ir::GlobalValueData::DynScaleTargetConst { .. } => gv.clone(),A
Symbolwhose name isExternalName::User(r)does reference another
per-function entity.ris aUserExternalNameRef, an index into the
callee'sparams.user_named_funcstable.create_func_refstranslates the
same kind of reference throughallocs.user_external_name_refs. The
global-value path does not translate it. It also could not:create_entities
callscreate_user_external_name_refs(inline.rs:1369) after
create_global_values(:1367).After inlining, the global value therefore names whichever user name the
caller has at the callee's index:
The index exists in the caller: the inlined
symbol_valuesilently
produces the address of an unrelated symbol. This is a wrong address at
link or relocation time, with no diagnostic.The index does not exist in the caller: the inlined code panics later
in compilation.Reproduction
repro.clifhas two functions:
- the callee:
gv0 = symbol colocated u7:7and returnssymbol_value gv0;- the caller: its own
gv0 = symbol colocated u1:1, plus a call to the
callee.$ target/debug/clif-util test reports/019-inline-symbol-user-name/repro.clif #0 check: gv1 = symbol colocated userextname1 Missed #0: ... > gv0 = symbol colocated userextname0 > gv1 = symbol colocated userextname0 <-- callee's u7:7 became the caller's u1:1 Error: 1 failureCompiling it end to end with report 018's harness shows the wrong relocation:
$ cargo run --manifest-path reports/018-inline-dynamic-type-offset/harness/Cargo.toml -- \ reports/019-inline-symbol-user-name/repro.clif compiled %callee reloc Aarch64AdrPrelPgHi21 at 0x0 -> u7:7 reloc Aarch64AddAbsLo12Nc at 0x4 -> u7:7 compiled %caller (with %callee inlined) reloc Aarch64AdrPrelPgHi21 at 0x0 -> u1:1 <-- expected u7:7 reloc Aarch64AddAbsLo12Nc at 0x4 -> u1:1Suggested fix
In
create_entities, callcreate_user_external_name_refsbefore
create_global_values.In
create_global_values, map
GlobalValueData::Symbol { name: ExternalName::User(r), .. }through
allocs.user_external_name_refs[r], the same waycreate_func_refs
does.Add a
test inlinefiletest whose caller and callee each declare
different user names.</details>
fitzgen opened issue #14570:
create_global_valuesincranelift/codegen/src/inline.rsclones
GlobalValueData::Symbol { name: ExternalName::User(r), .. }verbatim.r
is an index into the callee'suser_named_funcs, but it is never translated
into the caller's index space. (create_func_refsdoes translate these
indices.) The inlinedsymbol_valuetherefore relocates against whatever
user name the caller has at that index.
.clifTest Casetest inline target aarch64 function %callee() -> i64 { gv0 = symbol colocated u7:7 block0: v0 = symbol_value.i64 gv0 return v0 } function %caller() -> i64 { gv0 = symbol colocated u1:1 fn0 = %callee() -> i64 block0: v0 = call fn0() return v0 } ; check: gv1 = symbol colocated userextname1Steps to Reproduce
clif-util test test.clifExpected Results
The inlined global value refers to the callee's
u7:7, which is
userextname1in the caller.Actual Results
Missed #0: \bgv1 = symbol colocated userextname1\b > gv0 = symbol colocated userextname0 > gv1 = symbol colocated userextname0The inlined code relocates against
u1:1instead ofu7:7.Versions and Environment
Cranelift version or commit:
73b04cff33Operating system: macOS 15.8.1
Architecture: aarch64
fitzgen added the bug label to Issue #14570.
fitzgen added the cranelift label to Issue #14570.
Last updated: Oct 11 2026 at 04:10 UTC