Skip to content

Use precise alias regions for statically-known entity imports - #14115

Open
fitzgen wants to merge 6 commits into
bytecodealliance:mainfrom
fitzgen:known-memories-tables-globals-alias-regions
Open

Use precise alias regions for statically-known entity imports#14115
fitzgen wants to merge 6 commits into
bytecodealliance:mainfrom
fitzgen:known-memories-tables-globals-alias-regions

Conversation

@fitzgen

@fitzgen fitzgen commented Aug 10, 2026

Copy link
Copy Markdown
Member

Accesses of statically-known globals, memories, and tables now use
AliasRegionKey::Defined{Global,Memory,Table} rather than the conservative
Public{Global,Memory,Table} region shared by every entity of that kind which
crosses a module boundary.

However, unlike known_imported_functions, this requires an extra condition:
every module that ever imports an entity must always import that same
entity. Otherwise a function that accesses, e.g., a memory via the conservative
region could be inlined into one that uses the precise region, and accessing the
same bytes through two different alias regions is invalid and leads to
miscompiles. That is, all of the importing modules and the defining module must
agree on the alias region.

Depends on #14114

Alias analysis's dead-store elimination removed the dead store's `mem_values`
entry, but left the region's last-store slot naming the instruction it had just
deleted. Leaving the removed-store meant that when we then reprocess the
overwriting store, we keyed its lookup on a removed instruction, found nothing,
and failed to notice that (for example) the overwriting store became idempotent
and could also be removed.

With this commit, each store now records the memory version it displaced, and
eliminating a dead store rolls that version back, so a chain like

    v1 = load.i32 region0 v0
    store region0 v2, v0  ;; dead
    store region0 v1, v0  ;; idempotent once the dead store is gone

collapses in the single pass we actually make, rather than removing only one
link in the chain and requiring that we do N passes to fully clean up a chain of
N dead/idempotent stores. This code pattern the shape fused sync adapters emit
around the `MAY_LEAVE` flag and the relevant disas tests each lose a store as a
result.
Before, we would emit a call to a host function, passing the trap code as a
constant argument. Now we emit a `trap <code>` instruction directly.

This is a large improvement for our sync adapter disas tests.
If a load is marked `notrap` then it is not side-effecting and we need not emit
it when its loaded value is unused.

Note that we *do* still have to increment the side effect color for these
instructions to prevent merging/sinking loads across stores that could change
the value they observe.

This drops two dead vmctx flag loads from our component-model fused adapter's
fast path.
Accesses of statically-known globals, memories, and tables now use
`AliasRegionKey::Defined{Global,Memory,Table}` rather than the conservative
`Public{Global,Memory,Table}` region shared by every entity of that kind which
crosses a module boundary.

However, unlike `known_imported_functions`, this requires an extra condition:
every module that ever imports an entity must always import that same
entity. Otherwise a function that accesses, e.g., a memory via the conservative
region could be inlined into one that uses the precise region, and accessing the
same bytes through two different alias regions is invalid and leads to
miscompiles. That is, all of the importing modules and the defining module must
agree on the alias region.
@fitzgen
fitzgen requested review from a team as code owners August 10, 2026 22:03
@fitzgen
fitzgen requested review from alexcrichton and removed request for a team August 10, 2026 22:03
@github-actions github-actions Bot added cranelift Issues related to the Cranelift code generator cranelift:area:machinst Issues related to instruction selection and the new MachInst backend. labels Aug 10, 2026

@alexcrichton alexcrichton left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thinking about this analysis done here I'm worried about the case where a module imports something and reexports it, although I can't quite place my finger on why so I wanted to ask about that. It seems like an import could be considered unambiguous but then an export could be considered ambiguous, but in that scenario we'd want the import to additionally be considered ambiguous. Does this handle that sort of case already?

// statically knows that its import is always this memory, so we can
// only use this memory's precise region when every module that may
// import it does know that. Memory accessed with two different alias
// regions must not actually alias, or else we will get miscompiles.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Could the comment here, or somewhere in this function, indicate that the global/table version of this function below is a copy/paste of this function and they should all stay in sync?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

cranelift:area:machinst Issues related to instruction selection and the new MachInst backend. cranelift Issues related to the Cranelift code generator

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants