Skip to content

Fuzzer: Emit more br_on_cast_desc_eq{_fail} - #9198

Open
tlively wants to merge 1 commit into
mainfrom
fuzzer-more-br-on-desc
Open

tlively wants to merge 1 commit into
mainfrom
fuzzer-more-br-on-desc

Conversation

@tlively

@tlively tlively commented Oct 3, 2026 •

Copy link
Copy Markdown
Member

Previously, br_on_cast_desc_eq and br_on_cast_desc_eq_fail were rarely emitted
(~0.2 per module) because:

  1. makeBrOn had low selection weight despite covering 6 instructions.
  2. breakableStack searches stopped immediately on Type::none targets (forcing
    br_on_null) and often lacked reference targets.
  3. Descriptor casts were only emitted when getSubType happened by chance to pick
    a struct with a descriptor.

Fix this by:

  • Tracking described struct types by Shareability in describedTypes and adding
    hasDescribedSubType / getDescribedSubType helpers.
  • Increasing makeBrOn weight to Important.
  • Preferring reference targets (especially those with described subtypes) with
    randomness when searching breakableStack, and wrapping in a new target block
    when makeBrOn is called for a reference type without a suitable target.
  • Selecting BrOnCastDescEq and BrOnCastDescEqFail directly when described
    subtypes are available instead of upgrading BrOnCast / BrOnCastFail.

Across 200 fuzzer modules, this increases br_on_cast_desc_eq from 0.20 to 2.69
per module (16.0% -> 48.0% of modules) and br_on_cast_desc_eq_fail from 0.18 to
2.88 per module (11.5% -> 50.0% of modules), while also increasing br_on_null
from 27.40 to 34.46 per module.

@tlively
tlively requested a review from a team as a code owner October 3, 2026 00:19
@tlively
tlively requested review from aheejin and kripken and removed request for a team and kripken October 3, 2026 00:19
…ructions

Previously, br_on_cast_desc_eq and br_on_cast_desc_eq_fail were rarely emitted
(~0.2 per module) because:
1. makeBrOn had low selection weight despite covering 6 instructions.
2. breakableStack searches stopped immediately on Type::none targets (forcing
   br_on_null) and often lacked reference targets.
3. Descriptor casts were only emitted when getSubType happened by chance to pick
   a struct with a descriptor.

Fix this by:
- Tracking described struct types by Shareability in describedTypes and adding
  hasDescribedSubType / getDescribedSubType helpers.
- Increasing makeBrOn weight to Important.
- Preferring reference targets (especially those with described subtypes) with
  randomness when searching breakableStack, and wrapping in a new target block
  when makeBrOn is called for a reference type without a suitable target.
- Selecting BrOnCastDescEq and BrOnCastDescEqFail directly when described
  subtypes are available instead of upgrading BrOnCast / BrOnCastFail.

Across 200 fuzzer modules, this increases br_on_cast_desc_eq from 0.20 to 2.69
per module (16.0% -> 48.0% of modules) and br_on_cast_desc_eq_fail from 0.18 to
2.88 per module (11.5% -> 50.0% of modules), while also increasing br_on_null
from 27.40 to 34.46 per module.
@tlively
tlively force-pushed the fuzzer-more-br-on-desc branch from 9f94a49 to 9781802 Compare October 3, 2026 00:20
@tlively tlively changed the title Fixes in coverage-diff.py Fuzzer: Emit more br_on_cast_desc_eq{_fail} Oct 3, 2026
@tlively
tlively requested review from kripken and removed request for aheejin October 3, 2026 00:21

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant