1 use crate::generators::{DiffValue, DiffValueType, ModuleConfig}; 2 use crate::oracles::engine::{DiffEngine, DiffInstance}; 3 use anyhow::{bail, Error, Result}; 4 use std::cell::RefCell; 5 use std::rc::Rc; 6 use std::sync::Once; 7 use wasmtime::Trap; 8 use wasmtime::TrapCode; 9 10 pub struct V8Engine { 11 isolate: Rc<RefCell<v8::OwnedIsolate>>, 12 } 13 14 impl V8Engine { 15 pub fn new(config: &ModuleConfig) -> Result<V8Engine> { 16 static INIT: Once = Once::new(); 17 18 INIT.call_once(|| { 19 let platform = v8::new_default_platform(0, false).make_shared(); 20 v8::V8::initialize_platform(platform); 21 v8::V8::initialize(); 22 }); 23 24 // FIXME: reference types are disabled for now as we seemingly keep finding 25 // a segfault in v8. This is found relatively quickly locally and keeps 26 // getting found by oss-fuzz and currently we don't think that there's 27 // really much we can do about it. For the time being disable reference 28 // types entirely. An example bug is 29 // https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=45662 30 if config.config.reference_types_enabled { 31 bail!("reference types are buggy in v8"); 32 } 33 34 if config.config.memory64_enabled { 35 bail!("memory64 not enabled by default in v8"); 36 } 37 38 Ok(Self { 39 isolate: Rc::new(RefCell::new(v8::Isolate::new(Default::default()))), 40 }) 41 } 42 } 43 44 impl DiffEngine for V8Engine { 45 fn name(&self) -> &'static str { 46 "v8" 47 } 48 49 fn instantiate(&mut self, wasm: &[u8]) -> Result<Box<dyn DiffInstance>> { 50 // Setup a new `Context` in which we'll be creating this instance and 51 // executing code. 52 let mut isolate = self.isolate.borrow_mut(); 53 let isolate = &mut **isolate; 54 let mut scope = v8::HandleScope::new(isolate); 55 let context = v8::Context::new(&mut scope); 56 let global = context.global(&mut scope); 57 let mut scope = v8::ContextScope::new(&mut scope, context); 58 59 // Move the `wasm` into JS and then invoke `new WebAssembly.Module`. 60 let buf = v8::ArrayBuffer::new_backing_store_from_boxed_slice(wasm.into()); 61 let buf = v8::SharedRef::from(buf); 62 let name = v8::String::new(&mut scope, "WASM_BINARY").unwrap(); 63 let buf = v8::ArrayBuffer::with_backing_store(&mut scope, &buf); 64 global.set(&mut scope, name.into(), buf.into()); 65 let module = eval(&mut scope, "new WebAssembly.Module(WASM_BINARY)").unwrap(); 66 let name = v8::String::new(&mut scope, "WASM_MODULE").unwrap(); 67 global.set(&mut scope, name.into(), module); 68 69 // Using our `WASM_MODULE` run instantiation. Note that it's guaranteed 70 // that nothing is imported into differentially-executed modules so 71 // this is expected to only take the module argument. 72 let instance = eval(&mut scope, "new WebAssembly.Instance(WASM_MODULE)")?; 73 74 Ok(Box::new(V8Instance { 75 isolate: self.isolate.clone(), 76 context: v8::Global::new(&mut scope, context), 77 instance: v8::Global::new(&mut scope, instance), 78 })) 79 } 80 81 fn assert_error_match(&self, wasmtime: &Trap, err: Error) { 82 let v8 = err.to_string(); 83 let wasmtime_msg = wasmtime.to_string(); 84 let verify_wasmtime = |msg: &str| { 85 assert!(wasmtime_msg.contains(msg), "{}\n!=\n{}", wasmtime_msg, v8); 86 }; 87 let verify_v8 = |msg: &[&str]| { 88 assert!( 89 msg.iter().any(|msg| v8.contains(msg)), 90 "{:?}\n\t!=\n{}", 91 wasmtime_msg, 92 v8 93 ); 94 }; 95 match wasmtime.trap_code() { 96 Some(TrapCode::MemoryOutOfBounds) => { 97 return verify_v8(&[ 98 "memory access out of bounds", 99 "data segment is out of bounds", 100 ]) 101 } 102 Some(TrapCode::UnreachableCodeReached) => { 103 return verify_v8(&[ 104 "unreachable", 105 // All the wasms we test use wasm-smith's 106 // `ensure_termination` option which will `unreachable` when 107 // "fuel" runs out within the wasm module itself. This 108 // sometimes manifests as a call stack size exceeded in v8, 109 // however, since v8 sometimes has different limits on the 110 // call-stack especially when it's run multiple times. To 111 // get these error messages to line up allow v8 to say the 112 // call stack size exceeded when wasmtime says we hit 113 // unreachable. 114 "Maximum call stack size exceeded", 115 ]); 116 } 117 Some(TrapCode::IntegerDivisionByZero) => { 118 return verify_v8(&["divide by zero", "remainder by zero"]) 119 } 120 Some(TrapCode::StackOverflow) => { 121 return verify_v8(&[ 122 "call stack size exceeded", 123 // Similar to the above comment in `UnreachableCodeReached` 124 // if wasmtime hits a stack overflow but v8 ran all the way 125 // to when the `unreachable` instruction was hit then that's 126 // ok. This just means that wasmtime either has less optimal 127 // codegen or different limits on the stack than v8 does, 128 // which isn't an issue per-se. 129 "unreachable", 130 ]); 131 } 132 Some(TrapCode::IndirectCallToNull) => return verify_v8(&["null function"]), 133 Some(TrapCode::TableOutOfBounds) => { 134 return verify_v8(&[ 135 "table initializer is out of bounds", 136 "table index is out of bounds", 137 ]) 138 } 139 Some(TrapCode::BadSignature) => return verify_v8(&["function signature mismatch"]), 140 Some(TrapCode::IntegerOverflow) | Some(TrapCode::BadConversionToInteger) => { 141 return verify_v8(&[ 142 "float unrepresentable in integer range", 143 "divide result unrepresentable", 144 ]) 145 } 146 other => log::debug!("unknown code {:?}", other), 147 } 148 149 verify_wasmtime("not possibly present in an error, just panic please"); 150 } 151 } 152 153 struct V8Instance { 154 isolate: Rc<RefCell<v8::OwnedIsolate>>, 155 context: v8::Global<v8::Context>, 156 instance: v8::Global<v8::Value>, 157 } 158 159 impl DiffInstance for V8Instance { 160 fn name(&self) -> &'static str { 161 "v8" 162 } 163 164 fn evaluate( 165 &mut self, 166 function_name: &str, 167 arguments: &[DiffValue], 168 result_tys: &[DiffValueType], 169 ) -> Result<Option<Vec<DiffValue>>> { 170 let mut isolate = self.isolate.borrow_mut(); 171 let isolate = &mut **isolate; 172 let mut scope = v8::HandleScope::new(isolate); 173 let context = v8::Local::new(&mut scope, &self.context); 174 let global = context.global(&mut scope); 175 let mut scope = v8::ContextScope::new(&mut scope, context); 176 177 // See https://webassembly.github.io/spec/js-api/index.html#tojsvalue 178 // for how the Wasm-to-JS conversions are done. 179 let mut params = Vec::new(); 180 for arg in arguments { 181 params.push(match *arg { 182 DiffValue::I32(n) => v8::Number::new(&mut scope, n.into()).into(), 183 DiffValue::F32(n) => v8::Number::new(&mut scope, f32::from_bits(n).into()).into(), 184 DiffValue::F64(n) => v8::Number::new(&mut scope, f64::from_bits(n)).into(), 185 DiffValue::I64(n) => v8::BigInt::new_from_i64(&mut scope, n).into(), 186 DiffValue::FuncRef { null } | DiffValue::ExternRef { null } => { 187 assert!(null); 188 v8::null(&mut scope).into() 189 } 190 // JS doesn't support v128 parameters 191 DiffValue::V128(_) => return Ok(None), 192 }); 193 } 194 // JS doesn't support v128 return values 195 for ty in result_tys { 196 if let DiffValueType::V128 = ty { 197 return Ok(None); 198 } 199 } 200 201 let name = v8::String::new(&mut scope, "WASM_INSTANCE").unwrap(); 202 let instance = v8::Local::new(&mut scope, &self.instance); 203 global.set(&mut scope, name.into(), instance); 204 let name = v8::String::new(&mut scope, "EXPORT_NAME").unwrap(); 205 let func_name = v8::String::new(&mut scope, function_name).unwrap(); 206 global.set(&mut scope, name.into(), func_name.into()); 207 let name = v8::String::new(&mut scope, "ARGS").unwrap(); 208 let params = v8::Array::new_with_elements(&mut scope, ¶ms); 209 global.set(&mut scope, name.into(), params.into()); 210 let v8_vals = eval(&mut scope, "WASM_INSTANCE.exports[EXPORT_NAME](...ARGS)")?; 211 212 let mut results = Vec::new(); 213 match result_tys.len() { 214 0 => assert!(v8_vals.is_undefined()), 215 1 => results.push(get_diff_value(&v8_vals, result_tys[0], &mut scope)), 216 _ => { 217 let array = v8::Local::<'_, v8::Array>::try_from(v8_vals).unwrap(); 218 for (i, ty) in result_tys.iter().enumerate() { 219 let v8 = array.get_index(&mut scope, i as u32).unwrap(); 220 results.push(get_diff_value(&v8, *ty, &mut scope)); 221 } 222 } 223 } 224 Ok(Some(results)) 225 } 226 227 fn get_global(&mut self, global_name: &str, ty: DiffValueType) -> Option<DiffValue> { 228 if let DiffValueType::V128 = ty { 229 return None; 230 } 231 let mut isolate = self.isolate.borrow_mut(); 232 let mut scope = v8::HandleScope::new(&mut *isolate); 233 let context = v8::Local::new(&mut scope, &self.context); 234 let global = context.global(&mut scope); 235 let mut scope = v8::ContextScope::new(&mut scope, context); 236 237 let name = v8::String::new(&mut scope, "GLOBAL_NAME").unwrap(); 238 let memory_name = v8::String::new(&mut scope, global_name).unwrap(); 239 global.set(&mut scope, name.into(), memory_name.into()); 240 let val = eval(&mut scope, "WASM_INSTANCE.exports[GLOBAL_NAME].value").unwrap(); 241 Some(get_diff_value(&val, ty, &mut scope)) 242 } 243 244 fn get_memory(&mut self, memory_name: &str, shared: bool) -> Option<Vec<u8>> { 245 let mut isolate = self.isolate.borrow_mut(); 246 let mut scope = v8::HandleScope::new(&mut *isolate); 247 let context = v8::Local::new(&mut scope, &self.context); 248 let global = context.global(&mut scope); 249 let mut scope = v8::ContextScope::new(&mut scope, context); 250 251 let name = v8::String::new(&mut scope, "MEMORY_NAME").unwrap(); 252 let memory_name = v8::String::new(&mut scope, memory_name).unwrap(); 253 global.set(&mut scope, name.into(), memory_name.into()); 254 let v8 = eval(&mut scope, "WASM_INSTANCE.exports[MEMORY_NAME].buffer").unwrap(); 255 let v8_data = if shared { 256 v8::Local::<'_, v8::SharedArrayBuffer>::try_from(v8) 257 .unwrap() 258 .get_backing_store() 259 } else { 260 v8::Local::<'_, v8::ArrayBuffer>::try_from(v8) 261 .unwrap() 262 .get_backing_store() 263 }; 264 265 Some(v8_data.iter().map(|i| i.get()).collect()) 266 } 267 } 268 269 /// Evaluates the JS `code` within `scope`, returning either the result of the 270 /// computation or the stringified exception if one happened. 271 fn eval<'s>(scope: &mut v8::HandleScope<'s>, code: &str) -> Result<v8::Local<'s, v8::Value>> { 272 let mut tc = v8::TryCatch::new(scope); 273 let mut scope = v8::EscapableHandleScope::new(&mut tc); 274 let source = v8::String::new(&mut scope, code).unwrap(); 275 let script = v8::Script::compile(&mut scope, source, None).unwrap(); 276 match script.run(&mut scope) { 277 Some(val) => Ok(scope.escape(val)), 278 None => { 279 drop(scope); 280 assert!(tc.has_caught()); 281 bail!( 282 "{}", 283 tc.message() 284 .unwrap() 285 .get(&mut tc) 286 .to_rust_string_lossy(&mut tc) 287 ) 288 } 289 } 290 } 291 292 fn get_diff_value( 293 val: &v8::Local<'_, v8::Value>, 294 ty: DiffValueType, 295 scope: &mut v8::HandleScope<'_>, 296 ) -> DiffValue { 297 match ty { 298 DiffValueType::I32 => DiffValue::I32(val.to_int32(scope).unwrap().value() as i32), 299 DiffValueType::I64 => { 300 let (val, todo) = val.to_big_int(scope).unwrap().i64_value(); 301 assert!(todo); 302 DiffValue::I64(val) 303 } 304 DiffValueType::F32 => { 305 DiffValue::F32((val.to_number(scope).unwrap().value() as f32).to_bits()) 306 } 307 DiffValueType::F64 => DiffValue::F64(val.to_number(scope).unwrap().value().to_bits()), 308 DiffValueType::FuncRef => DiffValue::FuncRef { 309 null: val.is_null(), 310 }, 311 DiffValueType::ExternRef => DiffValue::ExternRef { 312 null: val.is_null(), 313 }, 314 DiffValueType::V128 => unreachable!(), 315 } 316 } 317 318 #[test] 319 fn smoke() { 320 crate::oracles::engine::smoke_test_engine(|config| V8Engine::new(&config.module_config)) 321 } 322