[flags] Introduce --wasm-assume-ref-cast-desc-succeeds [v8/v8 : main]

0 views
Skip to first unread message

Matthias Liedtke (Gerrit)

unread,
Aug 11, 2026, 8:45:36 AM (4 days ago) Aug 11
to Jakob Kummerow, Leon Bettscheider, v8-s...@luci-project-accounts.iam.gserviceaccount.com, android-bu...@system.gserviceaccount.com, v8-flag...@chromium.org, v8-re...@googlegroups.com, was...@google.com
Attention needed from Jakob Kummerow

Matthias Liedtke voted and added 2 comments

Votes added by Matthias Liedtke

Auto-Submit+1

2 comments

Patchset-level comments
File-level comment, Patchset 1 (Latest):
Matthias Liedtke . resolved

@jkum...@chromium.org: PTAL.
@bettsc...@chromium.org: FYI. Once it landed, I'd add this flag to Fuzzilli to start this experiment.

File src/flags/flag-definitions.h
Line 2187, Patchset 1 (Latest):// This flag allows to bypass casts which is unsafe. Note that this flag is
// disabled in production and is disallowed for vulnerability reports. Creating
// a crash with this flag enabled is neither a vulnerability, nor a stability
// issue nor an issue at all.
Matthias Liedtke . resolved

I hope this reduces the wasted tokens by BigSleep and others. Not sure if that's possible to achieve or not. 😊

Open in Gerrit

Related details

Attention is currently required from:
  • Jakob Kummerow
Submit Requirements:
  • requirement satisfiedCode-Owners
  • requirement is not satisfiedCode-Review
  • requirement is not satisfiedReview-Enforcement
Inspect html for hidden footers to help with email filtering. To unsubscribe visit settings. DiffyGerrit
Gerrit-MessageType: comment
Gerrit-Project: v8/v8
Gerrit-Branch: main
Gerrit-Change-Id: I28813b86b57ecb2f1ac6ffcef6c7d0f25a35cd80
Gerrit-Change-Number: 8236732
Gerrit-PatchSet: 1
Gerrit-Owner: Matthias Liedtke <mlie...@chromium.org>
Gerrit-Reviewer: Jakob Kummerow <jkum...@chromium.org>
Gerrit-Reviewer: Matthias Liedtke <mlie...@chromium.org>
Gerrit-CC: Leon Bettscheider <bettsc...@chromium.org>
Gerrit-Attention: Jakob Kummerow <jkum...@chromium.org>
Gerrit-Comment-Date: Tue, 11 Aug 2026 12:45:29 +0000
Gerrit-HasComments: Yes
Gerrit-Has-Labels: Yes
satisfied_requirement
unsatisfied_requirement
open
diffy

Michael Lippautz (Gerrit)

unread,
Aug 11, 2026, 8:57:10 AM (4 days ago) Aug 11
to Matthias Liedtke, Jakob Kummerow, Leon Bettscheider, v8-s...@luci-project-accounts.iam.gserviceaccount.com, android-bu...@system.gserviceaccount.com, v8-flag...@chromium.org, v8-re...@googlegroups.com, was...@google.com
Attention needed from Jakob Kummerow and Matthias Liedtke

Michael Lippautz added 1 comment

File src/flags/flag-definitions.h
Line 2187, Patchset 1 (Latest):// This flag allows to bypass casts which is unsafe. Note that this flag is
// disabled in production and is disallowed for vulnerability reports. Creating
// a crash with this flag enabled is neither a vulnerability, nor a stability
// issue nor an issue at all.
Matthias Liedtke . unresolved

I hope this reduces the wasted tokens by BigSleep and others. Not sure if that's possible to achieve or not. 😊

Michael Lippautz

drive-by: Why not make it `DEFINE_TEST_ONY_FLAG()`? That automatically gets you the `disallow_unsafe_flags` implication that you defined below as well.

Open in Gerrit

Related details

Attention is currently required from:
  • Jakob Kummerow
  • Matthias Liedtke
Submit Requirements:
    • requirement satisfiedCode-Owners
    • requirement is not satisfiedCode-Review
    • requirement is not satisfiedNo-Unresolved-Comments
    • requirement is not satisfiedReview-Enforcement
    Inspect html for hidden footers to help with email filtering. To unsubscribe visit settings. DiffyGerrit
    Gerrit-MessageType: comment
    Gerrit-Project: v8/v8
    Gerrit-Branch: main
    Gerrit-Change-Id: I28813b86b57ecb2f1ac6ffcef6c7d0f25a35cd80
    Gerrit-Change-Number: 8236732
    Gerrit-PatchSet: 1
    Gerrit-Owner: Matthias Liedtke <mlie...@chromium.org>
    Gerrit-Reviewer: Jakob Kummerow <jkum...@chromium.org>
    Gerrit-Reviewer: Matthias Liedtke <mlie...@chromium.org>
    Gerrit-CC: Leon Bettscheider <bettsc...@chromium.org>
    Gerrit-CC: Michael Lippautz <mlip...@chromium.org>
    Gerrit-Attention: Matthias Liedtke <mlie...@chromium.org>
    Gerrit-Attention: Jakob Kummerow <jkum...@chromium.org>
    Gerrit-Comment-Date: Tue, 11 Aug 2026 12:57:06 +0000
    Gerrit-HasComments: Yes
    Gerrit-Has-Labels: No
    Comment-In-Reply-To: Matthias Liedtke <mlie...@chromium.org>
    satisfied_requirement
    unsatisfied_requirement
    open
    diffy

    Jakob Kummerow (Gerrit)

    unread,
    Aug 11, 2026, 8:58:18 AM (4 days ago) Aug 11
    to Matthias Liedtke, Jakob Kummerow, Michael Lippautz, Leon Bettscheider, v8-s...@luci-project-accounts.iam.gserviceaccount.com, android-bu...@system.gserviceaccount.com, v8-flag...@chromium.org, v8-re...@googlegroups.com, was...@google.com
    Attention needed from Matthias Liedtke

    Jakob Kummerow voted

    Code-Review+1
    Commit-Queue+2
    Open in Gerrit

    Related details

    Attention is currently required from:
    • Matthias Liedtke
    Submit Requirements:
    • requirement satisfiedCode-Owners
    • requirement satisfiedCode-Review
    • requirement is not satisfiedNo-Unresolved-Comments
    • requirement satisfiedReview-Enforcement
    Inspect html for hidden footers to help with email filtering. To unsubscribe visit settings. DiffyGerrit
    Gerrit-MessageType: comment
    Gerrit-Project: v8/v8
    Gerrit-Branch: main
    Gerrit-Change-Id: I28813b86b57ecb2f1ac6ffcef6c7d0f25a35cd80
    Gerrit-Change-Number: 8236732
    Gerrit-PatchSet: 1
    Gerrit-Owner: Matthias Liedtke <mlie...@chromium.org>
    Gerrit-Reviewer: Jakob Kummerow <jkum...@chromium.org>
    Gerrit-Reviewer: Matthias Liedtke <mlie...@chromium.org>
    Gerrit-CC: Leon Bettscheider <bettsc...@chromium.org>
    Gerrit-CC: Michael Lippautz <mlip...@chromium.org>
    Gerrit-Attention: Matthias Liedtke <mlie...@chromium.org>
    Gerrit-Comment-Date: Tue, 11 Aug 2026 12:58:12 +0000
    Gerrit-HasComments: No
    Gerrit-Has-Labels: Yes
    satisfied_requirement
    unsatisfied_requirement
    open
    diffy

    Matthias Liedtke (Gerrit)

    unread,
    Aug 11, 2026, 8:59:35 AM (4 days ago) Aug 11
    to Jakob Kummerow, Michael Lippautz, Leon Bettscheider, v8-s...@luci-project-accounts.iam.gserviceaccount.com, android-bu...@system.gserviceaccount.com, v8-flag...@chromium.org, v8-re...@googlegroups.com, was...@google.com
    Attention needed from Jakob Kummerow and Michael Lippautz

    Matthias Liedtke added 1 comment

    File src/flags/flag-definitions.h
    Line 2187, Patchset 1 (Latest):// This flag allows to bypass casts which is unsafe. Note that this flag is
    // disabled in production and is disallowed for vulnerability reports. Creating
    // a crash with this flag enabled is neither a vulnerability, nor a stability
    // issue nor an issue at all.
    Matthias Liedtke . unresolved

    I hope this reduces the wasted tokens by BigSleep and others. Not sure if that's possible to achieve or not. 😊

    Michael Lippautz

    drive-by: Why not make it `DEFINE_TEST_ONY_FLAG()`? That automatically gets you the `disallow_unsafe_flags` implication that you defined below as well.

    Matthias Liedtke

    ```
    // Note that it is a conscious decision not to use DEFINE_TEST_ONLY_FLAG as that
    // can't be used in combination with --fuzzing.
    ```
    And also discussed in chat. 😊
    I don't think, this is great but this is the current situation.

    Open in Gerrit

    Related details

    Attention is currently required from:
    • Jakob Kummerow
    • Michael Lippautz
    Submit Requirements:
    • requirement satisfiedCode-Owners
    • requirement satisfiedCode-Review
    • requirement is not satisfiedNo-Unresolved-Comments
    • requirement satisfiedReview-Enforcement
    Inspect html for hidden footers to help with email filtering. To unsubscribe visit settings. DiffyGerrit
    Gerrit-MessageType: comment
    Gerrit-Project: v8/v8
    Gerrit-Branch: main
    Gerrit-Change-Id: I28813b86b57ecb2f1ac6ffcef6c7d0f25a35cd80
    Gerrit-Change-Number: 8236732
    Gerrit-PatchSet: 1
    Gerrit-Owner: Matthias Liedtke <mlie...@chromium.org>
    Gerrit-Reviewer: Jakob Kummerow <jkum...@chromium.org>
    Gerrit-Reviewer: Matthias Liedtke <mlie...@chromium.org>
    Gerrit-CC: Leon Bettscheider <bettsc...@chromium.org>
    Gerrit-CC: Michael Lippautz <mlip...@chromium.org>
    Gerrit-Attention: Michael Lippautz <mlip...@chromium.org>
    Gerrit-Attention: Jakob Kummerow <jkum...@chromium.org>
    Gerrit-Comment-Date: Tue, 11 Aug 2026 12:59:30 +0000
    Gerrit-HasComments: Yes
    Gerrit-Has-Labels: No
    Comment-In-Reply-To: Michael Lippautz <mlip...@chromium.org>
    Comment-In-Reply-To: Matthias Liedtke <mlie...@chromium.org>
    satisfied_requirement
    unsatisfied_requirement
    open
    diffy

    Michael Lippautz (Gerrit)

    unread,
    Aug 11, 2026, 9:07:09 AM (4 days ago) Aug 11
    to Matthias Liedtke, Jakob Kummerow, Leon Bettscheider, v8-s...@luci-project-accounts.iam.gserviceaccount.com, android-bu...@system.gserviceaccount.com, v8-flag...@chromium.org, v8-re...@googlegroups.com, was...@google.com
    Attention needed from Jakob Kummerow and Matthias Liedtke

    Michael Lippautz added 1 comment

    File src/flags/flag-definitions.h
    Line 2187, Patchset 1 (Latest):// This flag allows to bypass casts which is unsafe. Note that this flag is
    // disabled in production and is disallowed for vulnerability reports. Creating
    // a crash with this flag enabled is neither a vulnerability, nor a stability
    // issue nor an issue at all.
    Matthias Liedtke . resolved

    I hope this reduces the wasted tokens by BigSleep and others. Not sure if that's possible to achieve or not. 😊

    Michael Lippautz

    drive-by: Why not make it `DEFINE_TEST_ONY_FLAG()`? That automatically gets you the `disallow_unsafe_flags` implication that you defined below as well.

    Matthias Liedtke

    ```
    // Note that it is a conscious decision not to use DEFINE_TEST_ONLY_FLAG as that
    // can't be used in combination with --fuzzing.
    ```
    And also discussed in chat. 😊
    I don't think, this is great but this is the current situation.

    Michael Lippautz

    Thanks, sorry for missing that :/

    Open in Gerrit

    Related details

    Attention is currently required from:
    • Jakob Kummerow
    • Matthias Liedtke
    Submit Requirements:
      • requirement satisfiedCode-Owners
      • requirement satisfiedCode-Review
      • requirement satisfiedReview-Enforcement
      Inspect html for hidden footers to help with email filtering. To unsubscribe visit settings. DiffyGerrit
      Gerrit-MessageType: comment
      Gerrit-Project: v8/v8
      Gerrit-Branch: main
      Gerrit-Change-Id: I28813b86b57ecb2f1ac6ffcef6c7d0f25a35cd80
      Gerrit-Change-Number: 8236732
      Gerrit-PatchSet: 1
      Gerrit-Owner: Matthias Liedtke <mlie...@chromium.org>
      Gerrit-Reviewer: Jakob Kummerow <jkum...@chromium.org>
      Gerrit-Reviewer: Matthias Liedtke <mlie...@chromium.org>
      Gerrit-CC: Leon Bettscheider <bettsc...@chromium.org>
      Gerrit-CC: Michael Lippautz <mlip...@chromium.org>
      Gerrit-Attention: Matthias Liedtke <mlie...@chromium.org>
      Gerrit-Attention: Jakob Kummerow <jkum...@chromium.org>
      Gerrit-Comment-Date: Tue, 11 Aug 2026 13:07:01 +0000
      satisfied_requirement
      open
      diffy

      Matthias Liedtke (Gerrit)

      unread,
      Aug 11, 2026, 9:45:18 AM (4 days ago) Aug 11
      to Jakob Kummerow, Michael Lippautz, Leon Bettscheider, v8-s...@luci-project-accounts.iam.gserviceaccount.com, android-bu...@system.gserviceaccount.com, v8-flag...@chromium.org, v8-re...@googlegroups.com, was...@google.com
      Attention needed from Jakob Kummerow and Michael Lippautz

      Matthias Liedtke voted and added 1 comment

      Votes added by Matthias Liedtke

      Commit-Queue+2

      1 comment

      File src/flags/flag-definitions.h
      Line 2187, Patchset 1 (Latest):// This flag allows to bypass casts which is unsafe. Note that this flag is
      // disabled in production and is disallowed for vulnerability reports. Creating
      // a crash with this flag enabled is neither a vulnerability, nor a stability
      // issue nor an issue at all.
      Matthias Liedtke . resolved

      I hope this reduces the wasted tokens by BigSleep and others. Not sure if that's possible to achieve or not. 😊

      Michael Lippautz

      drive-by: Why not make it `DEFINE_TEST_ONY_FLAG()`? That automatically gets you the `disallow_unsafe_flags` implication that you defined below as well.

      Matthias Liedtke

      ```
      // Note that it is a conscious decision not to use DEFINE_TEST_ONLY_FLAG as that
      // can't be used in combination with --fuzzing.
      ```
      And also discussed in chat. 😊
      I don't think, this is great but this is the current situation.

      Michael Lippautz

      Thanks, sorry for missing that :/

      Matthias Liedtke

      No worries!

      Open in Gerrit

      Related details

      Attention is currently required from:
      • Jakob Kummerow
      • Michael Lippautz
      Submit Requirements:
      • requirement satisfiedCode-Owners
      • requirement satisfiedCode-Review
      • requirement satisfiedReview-Enforcement
      Inspect html for hidden footers to help with email filtering. To unsubscribe visit settings. DiffyGerrit
      Gerrit-MessageType: comment
      Gerrit-Project: v8/v8
      Gerrit-Branch: main
      Gerrit-Change-Id: I28813b86b57ecb2f1ac6ffcef6c7d0f25a35cd80
      Gerrit-Change-Number: 8236732
      Gerrit-PatchSet: 1
      Gerrit-Owner: Matthias Liedtke <mlie...@chromium.org>
      Gerrit-Reviewer: Jakob Kummerow <jkum...@chromium.org>
      Gerrit-Reviewer: Matthias Liedtke <mlie...@chromium.org>
      Gerrit-CC: Leon Bettscheider <bettsc...@chromium.org>
      Gerrit-CC: Michael Lippautz <mlip...@chromium.org>
      Gerrit-Attention: Michael Lippautz <mlip...@chromium.org>
      Gerrit-Attention: Jakob Kummerow <jkum...@chromium.org>
      Gerrit-Comment-Date: Tue, 11 Aug 2026 13:45:11 +0000
      Gerrit-HasComments: Yes
      Gerrit-Has-Labels: Yes
      satisfied_requirement
      open
      diffy

      v8-scoped@luci-project-accounts.iam.gserviceaccount.com (Gerrit)

      unread,
      Aug 11, 2026, 9:48:37 AM (4 days ago) Aug 11
      to Matthias Liedtke, Jakob Kummerow, Michael Lippautz, Leon Bettscheider, android-bu...@system.gserviceaccount.com, v8-flag...@chromium.org, v8-re...@googlegroups.com, was...@google.com

      v8-s...@luci-project-accounts.iam.gserviceaccount.com submitted the change

      Change information

      Commit message:
      [flags] Introduce --wasm-assume-ref-cast-desc-succeeds

      This change adds an unsafe experimental flag that treats
      ref.cast_desc_eq as a no-op in both Liftoff and Turbofan.
      The flag is added for evaluating fuzzing capabilities and shall be
      removed again in the not-too-distant future.

      The flag is not enabled in production, is marked as experimental and is
      disallowed with --disallow-unsafe flags.
      Bug: 498924945
      Change-Id: I28813b86b57ecb2f1ac6ffcef6c7d0f25a35cd80
      Reviewed-by: Jakob Kummerow <jkum...@chromium.org>
      Commit-Queue: Matthias Liedtke <mlie...@chromium.org>
      Auto-Submit: Matthias Liedtke <mlie...@chromium.org>
      Cr-Commit-Position: refs/heads/main@{#109179}
      Files:
      • M src/flags/flag-definitions.h
      • M src/wasm/baseline/liftoff-compiler.cc
      • M src/wasm/turboshaft-graph-interface.cc
      Change size: S
      Delta: 3 files changed, 16 insertions(+), 2 deletions(-)
      Branch: refs/heads/main
      Submit Requirements:
      • requirement satisfiedCode-Review: +1 by Jakob Kummerow
      Open in Gerrit
      Inspect html for hidden footers to help with email filtering. To unsubscribe visit settings. DiffyGerrit
      Gerrit-MessageType: merged
      Gerrit-Project: v8/v8
      Gerrit-Branch: main
      Gerrit-Change-Id: I28813b86b57ecb2f1ac6ffcef6c7d0f25a35cd80
      Gerrit-Change-Number: 8236732
      Gerrit-PatchSet: 2
      Gerrit-Owner: Matthias Liedtke <mlie...@chromium.org>
      Gerrit-Reviewer: Jakob Kummerow <jkum...@chromium.org>
      Gerrit-Reviewer: Matthias Liedtke <mlie...@chromium.org>
      open
      diffy
      satisfied_requirement

      Matthias Liedtke (Gerrit)

      unread,
      1:07 PM (1 hour ago) 1:07 PM
      to v8-s...@luci-project-accounts.iam.gserviceaccount.com, Jakob Kummerow, Michael Lippautz, Leon Bettscheider, android-bu...@system.gserviceaccount.com, v8-flag...@chromium.org, v8-re...@googlegroups.com, was...@google.com

      Matthias Liedtke has created a revert of this change

      Related details

      Attention set is empty
      Submit Requirements:
      • requirement satisfiedCode-Owners
      • requirement satisfiedCode-Review
      • requirement satisfiedReview-Enforcement
      Inspect html for hidden footers to help with email filtering. To unsubscribe visit settings. DiffyGerrit
      Gerrit-MessageType: revert
      satisfied_requirement
      open
      diffy
      Reply all
      Reply to author
      Forward
      0 new messages