Stream: git-wasmtime

Topic: wasmtime / issue #14570 Cranelift: inliner does not remap...


view this post on Zulip Wasmtime GitHub notifications bot (Oct 06 2026 at 15:06):

fitzgen commented on issue #14570:

<details><summary>Full LLM report</summary>

Cranelift inliner does not remap user external names in symbol global values

Date 2026-10-05
Wasmtime commit 73b04cff3317d1e308866eb24359483ac6116669 (main)
Host macOS 15.8.1 (Darwin 24.6.0), aarch64-apple-darwin
Model Claude Opus 5.5 (claude-opus-5-5)
Component cranelift/codegen/src/inline.rs (create_global_values)
Class Miscompile: an inlined symbol_value relocates against the wrong symbol
Severity Medium for Cranelift embedders using Context::inline with symbol global values. Wasmtime does not emit symbol global values.

Summary

create_global_values (cranelift/codegen/src/inline.rs:1470-1474) copies
the callee's GlobalValueData::Symbol verbatim:

// These kinds of global values do not reference other global
// values, so we can just clone them.
ir::GlobalValueData::VMContext
| ir::GlobalValueData::Symbol { .. }
| ir::GlobalValueData::DynScaleTargetConst { .. } => gv.clone(),

A Symbol whose name is ExternalName::User(r) does reference another
per-function entity. r is a UserExternalNameRef, an index into the
callee's params.user_named_funcs table. create_func_refs translates the
same kind of reference through allocs.user_external_name_refs. The
global-value path does not translate it. It also could not: create_entities
calls create_user_external_name_refs (inline.rs:1369) after
create_global_values (:1367).

After inlining, the global value therefore names whichever user name the
caller has at the callee's index:

Reproduction

repro.clif has two functions:

$ target/debug/clif-util test reports/019-inline-symbol-user-name/repro.clif
    #0 check: gv1 = symbol colocated userextname1
    Missed #0: ...
    >     gv0 = symbol colocated userextname0
    >     gv1 = symbol colocated userextname0      <-- callee's u7:7 became the caller's u1:1
Error: 1 failure

Compiling it end to end with report 018's harness shows the wrong relocation:

$ cargo run --manifest-path reports/018-inline-dynamic-type-offset/harness/Cargo.toml -- \
      reports/019-inline-symbol-user-name/repro.clif
compiled %callee
  reloc Aarch64AdrPrelPgHi21 at 0x0 -> u7:7
  reloc Aarch64AddAbsLo12Nc at 0x4 -> u7:7
compiled %caller            (with %callee inlined)
  reloc Aarch64AdrPrelPgHi21 at 0x0 -> u1:1      <-- expected u7:7
  reloc Aarch64AddAbsLo12Nc at 0x4 -> u1:1

Suggested fix

  1. In create_entities, call create_user_external_name_refs before
    create_global_values.

  2. In create_global_values, map
    GlobalValueData::Symbol { name: ExternalName::User(r), .. } through
    allocs.user_external_name_refs[r], the same way create_func_refs
    does.

  3. Add a test inline filetest whose caller and callee each declare
    different user names.

</details>

view this post on Zulip Wasmtime GitHub notifications bot (Oct 06 2026 at 15:12):

fitzgen opened issue #14570:

create_global_values in cranelift/codegen/src/inline.rs clones
GlobalValueData::Symbol { name: ExternalName::User(r), .. } verbatim. r
is an index into the callee's user_named_funcs, but it is never translated
into the caller's index space. (create_func_refs does translate these
indices.) The inlined symbol_value therefore relocates against whatever
user name the caller has at that index.

.clif Test Case

test inline
target aarch64

function %callee() -> i64 {
    gv0 = symbol colocated u7:7
block0:
    v0 = symbol_value.i64 gv0
    return v0
}

function %caller() -> i64 {
    gv0 = symbol colocated u1:1
    fn0 = %callee() -> i64
block0:
    v0 = call fn0()
    return v0
}
; check: gv1 = symbol colocated userextname1

Steps to Reproduce

clif-util test test.clif

Expected Results

The inlined global value refers to the callee's u7:7, which is
userextname1 in the caller.

Actual Results

    Missed #0: \bgv1 = symbol colocated userextname1\b
    >     gv0 = symbol colocated userextname0
    >     gv1 = symbol colocated userextname0

The inlined code relocates against u1:1 instead of u7:7.

Versions and Environment

Cranelift version or commit: 73b04cff33

Operating system: macOS 15.8.1

Architecture: aarch64

view this post on Zulip Wasmtime GitHub notifications bot (Oct 06 2026 at 15:12):

fitzgen added the bug label to Issue #14570.

view this post on Zulip Wasmtime GitHub notifications bot (Oct 06 2026 at 15:12):

fitzgen added the cranelift label to Issue #14570.


Last updated: Oct 11 2026 at 04:10 UTC