Stream: git-wasmtime

Topic: wasmtime / issue #14587 Incorrect out-of-bounds traps wit...


view this post on Zulip Wasmtime GitHub notifications bot (Oct 06 2026 at 20:29):

alexcrichton opened issue #14587:

Wasmtime incorrectly deduces that a load/store is statically out of bounds in situations with an imported memory and -Omemory-may-move=n configuration.

For example

(module $a (memory (export "m") 4))
(register "a" $a)
(module $b
  (import "a" "m" (memory 1))
  (func (export "ld") (param i32) (result i32) (i32.load8_u (local.get 0)))
  (func (export "size") (result i32) (memory.size)))
(assert_return (invoke $b "size") (i32.const 4))
(assert_return (invoke $b "ld" (i32.const 0x20000)) (i32.const 0))

fails with:

$ wasmtime wast -Omemory-may-move=n,memory-reservation=65536 import32.wast
Error: failed to run script file 'import32.wast'

Caused by:
    0: failed directive on import32.wast:11
    1: error while executing at wasm backtrace:
    0:     0x39 - wasm-function[0]
                    at ./import32.wast:8:49
    2: wasm trap: out of bounds memory access

and

(module $a (memory (export "m") i64 0x10002))
(register "a" $a)
(module $b
  (import "a" "m" (memory i64 1))
  (func (export "ld") (param i64) (result i32) (i32.load8_u (local.get 0)))
  (func (export "size") (result i64) (memory.size)))
(assert_return (invoke $b "size") (i64.const 0x10002))
(assert_return (invoke $b "ld" (i64.const 0x100010000)) (i32.const 0))

fails with:

$ wasmtime wast import64.wast -Omemory-may-move=n
Error: failed to run script file 'import64.wast'

Caused by:
    0: failed directive on import64.wast:12
    1: error while executing at wasm backtrace:
    0:     0x39 - wasm-function[0]
                    at ./import64.wast:9:49
    2: wasm trap: out of bounds memory access

and

(module $exp
  (memory (export "mem") 100)
  (func (export "load") (param i32) (result i32)
    local.get 0
    i32.load))
(register "exp" $exp)
(module $imp
  (import "exp" "mem" (memory 1))
  (func (export "load") (param i32) (result i32)
    local.get 0
    i32.load))
;; 200000 is in-bounds of a 100-page (6553600 byte) memory
(assert_return (invoke $exp "load" (i32.const 200000)) (i32.const 0))
(assert_return (invoke $imp "load" (i32.const 200000)) (i32.const 0))

fails with:

$ wasmtime wast -O memory-reservation=131072 -O memory-may-move=n import_resv.wast
Error: failed to run script file 'import_resv.wast'

Caused by:
    0: failed directive on import_resv.wast:15
    1: error while executing at wasm backtrace:
    0:     0x33 - wasm-function[0]
                    at ./import_resv.wast:12:5
    2: wasm trap: out of bounds memory access

All of these tests pass when memory-may-move=n is dropped.

view this post on Zulip Wasmtime GitHub notifications bot (Oct 08 2026 at 16:49):

fitzgen added the bug label to Issue #14587.


Last updated: Oct 11 2026 at 04:10 UTC