wasm: complete W4 (float execution + malformed-module robustness suite) - #162
Merged
Conversation
Finishes the W4 phase of scoot-wasm (#100): f32/f64 arithmetic, unary ops, min/max/copysign, ordered comparisons, int/float conversions, and trapping plus saturating truncation, with the static type validator extended to the float opcodes so float modules load and run end-to-end. NaN results are canonicalized for deterministic cross-host output while abs/neg/copysign preserve exact bit patterns; nearest rounds ties to even and preserves the zero sign. Adds a robustness suite that feeds truncated, byte-corrupted, and random/hostile module bytes through the loader and asserts every input yields a structured load error or trap instead of crashing, covering the issue's 'malformed/malicious .wasm must error, not crash' requirement. Docs updated bilingually (CHANGELOG, WASM_TOOLS, book). Refs #100
Merged
jamiesun
added a commit
that referenced
this pull request
Jun 27, 2026
- wasm host W0-W4: integer, WASI preview1, type validation, float execution (#145, #147, #148, #149, #162) - feat: wasm_tool action for compute-only packages (#154) - wasm: narrow plugin sandbox to stdin/stdout/stderr/argv as a new hard rule (#164) - feat: committed playground test environment with full action coverage (#161) - release: single ReleaseSafe flavor, ship scoot-wasm artifacts, Homebrew tap (#166) - fix(release): reference SCOOT_DOCKERHUB_* secrets so Docker Hub login is attempted - docs: README rewrite + infographic, English comment translation (#160, #165, #146, #153) Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Completes the W4 phase of
scoot-wasm(#100): floating point, bulk-memory (already landed), and a spec-style robustness/conformance suite for malformed input.What's in this PR
Floating-point execution (W4)
iNN.trunc_fMM_s/u) and saturating (iNN.trunc_sat_fMM_s/u) truncation.nearestrounds ties to even and preserves the sign of zero.Robustness suite (the issue's "诚实坎")
The issue requires that
malformed / malicious .wasm must return an error, not crash. New tests assert the host stays structured (load_error/trap, never a panic):Validation
zig fmt --check,zig build -Dwasm-host=true,zig build test— 604/604 tests pass.make cipasses (fmt / Debug / test / ReleaseSafe /--versionsmoke); pre-push local CI also green.Docs
Updated bilingually:
CHANGELOG.md/docs/CHANGELOG.zh.md,docs/WASM_TOOLS.md/docs/WASM_TOOLS.zh.md,book/en/book/zh.Scope note
Importing the official WebAssembly spec test suite (hand-written
.wat→.wasmfixtures) is intentionally out of scope here — the repo has no.wattoolchain and that is a separate, larger effort. This PR delivers the functional W4 behavior plus a structural-robustness conformance suite. Remaining full spec-conformance work can be tracked separately.Refs #100