Conversation
tlively
requested review from
aheejin and
kripken
and removed request for
a team and
kripken
October 3, 2026 00:19
…ructions Previously, br_on_cast_desc_eq and br_on_cast_desc_eq_fail were rarely emitted (~0.2 per module) because: 1. makeBrOn had low selection weight despite covering 6 instructions. 2. breakableStack searches stopped immediately on Type::none targets (forcing br_on_null) and often lacked reference targets. 3. Descriptor casts were only emitted when getSubType happened by chance to pick a struct with a descriptor. Fix this by: - Tracking described struct types by Shareability in describedTypes and adding hasDescribedSubType / getDescribedSubType helpers. - Increasing makeBrOn weight to Important. - Preferring reference targets (especially those with described subtypes) with randomness when searching breakableStack, and wrapping in a new target block when makeBrOn is called for a reference type without a suitable target. - Selecting BrOnCastDescEq and BrOnCastDescEqFail directly when described subtypes are available instead of upgrading BrOnCast / BrOnCastFail. Across 200 fuzzer modules, this increases br_on_cast_desc_eq from 0.20 to 2.69 per module (16.0% -> 48.0% of modules) and br_on_cast_desc_eq_fail from 0.18 to 2.88 per module (11.5% -> 50.0% of modules), while also increasing br_on_null from 27.40 to 34.46 per module.
tlively
force-pushed
the
fuzzer-more-br-on-desc
branch
from
October 3, 2026 00:20
9f94a49 to
9781802
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Previously, br_on_cast_desc_eq and br_on_cast_desc_eq_fail were rarely emitted
(~0.2 per module) because:
br_on_null) and often lacked reference targets.
a struct with a descriptor.
Fix this by:
hasDescribedSubType / getDescribedSubType helpers.
randomness when searching breakableStack, and wrapping in a new target block
when makeBrOn is called for a reference type without a suitable target.
subtypes are available instead of upgrading BrOnCast / BrOnCastFail.
Across 200 fuzzer modules, this increases br_on_cast_desc_eq from 0.20 to 2.69
per module (16.0% -> 48.0% of modules) and br_on_cast_desc_eq_fail from 0.18 to
2.88 per module (11.5% -> 50.0% of modules), while also increasing br_on_null
from 27.40 to 34.46 per module.