Stream: git-wasmtime

Topic: wasmtime / issue #14582 gc_ops fuzzbug: `Table::grow` pan...


view this post on Zulip Wasmtime GitHub notifications bot (Oct 06 2026 at 19:16):

khagankhan opened issue #14582:

Summary

Table::grow panics on an unrooted Rooted init value instead of returning Err. I submit here because I think it is not guest-caused panic.

Version: main at 73b04cff33 (2026-10-05), x86_64 Linux, rustc 1.99.0. Default features, wasm_gc and wasm_function_references on. Happens with both Collector::DeferredReferenceCounting and Collector::Copying.

Reproduce

use wasmtime::*;

fn engine(collector: Collector) -> Engine {
    let mut config = Config::new();
    config.wasm_gc(true);
    config.wasm_function_references(true);
    config.collector(collector);
    Engine::new(&config).unwrap()
}

/// A `Rooted<ExternRef>` whose `RootScope` has ended.
fn stale(store: &mut Store<()>) -> Rooted<ExternRef> {
    let mut scope = RootScope::new(&mut *store);
    ExternRef::new(&mut scope, 1u32).unwrap()
}

fn main() -> Result<()> {
    for collector in [Collector::DeferredReferenceCounting, Collector::Copying] {
        let engine = engine(collector);
        let mut store = Store::new(&engine, ());
        let ty = TableType::new(RefType::EXTERNREF, 2, None);
        let table = Table::new(&mut store, ty, Ref::Extern(None))?;
        let r = stale(&mut store);

        println!("set:  {:?}", table.set(&mut store, 0, Ref::Extern(Some(r))));
        println!("fill: {:?}", table.fill(&mut store, 0, Ref::Extern(Some(r)), 2));
        println!("grow: {:?}", table.grow(&mut store, 1, Ref::Extern(Some(r))));
    }
    Ok(())
}
set:  Err(attempted to use a garbage-collected object that has been unrooted)
fill: Err(attempted to use a garbage-collected object that has been unrooted)

thread 'main' panicked at crates/wasmtime/src/runtime/externals/table.rs:360:47:
called `Result::unwrap()` on an `Err` value: attempted to use a garbage-collected object that has been unrooted

view this post on Zulip Wasmtime GitHub notifications bot (Oct 06 2026 at 19:16):

khagankhan added the bug label to Issue #14582.

view this post on Zulip Wasmtime GitHub notifications bot (Oct 06 2026 at 19:16):

khagankhan added the fuzz-bug label to Issue #14582.

view this post on Zulip Wasmtime GitHub notifications bot (Oct 06 2026 at 19:17):

khagankhan commented on issue #14582:

I am not sure it is a quintessential GC bug but the oracle found it with new "GC actions" feature and I think it is worth submitting.

view this post on Zulip Wasmtime GitHub notifications bot (Oct 06 2026 at 19:23):

alexcrichton added the wasm-proposal:gc label to Issue #14582.

view this post on Zulip Wasmtime GitHub notifications bot (Oct 06 2026 at 23:17):

fitzgen assigned fitzgen to issue #14582.


Last updated: Oct 11 2026 at 04:10 UTC