Skip to content

fix(webgpu): reject non-Uint8Array byte arguments - #1832

Merged
ivokub merged 2 commits into
Consensys-Incorporated:masterfrom
colinaumaty:master
Sep 29, 2026
Merged

ivokub merged 2 commits into
Consensys-Incorporated:masterfrom
colinaumaty:master

Conversation

@colinaumaty

@colinaumaty colinaumaty commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

Description

Validate JavaScript byte arguments as Uint8Array values before accessing their byteLength property or passing them to js.CopyBytesToGo.

Previously, primitive values could panic in js.Value.Get, while arbitrary objects with a numeric byteLength could reach js.CopyBytesToGo and panic there. These panics could terminate the Go WASM runtime instead of rejecting the promise with the intended expected Uint8Array error.

Fixes #1831

Type of change

  • Bug fix (non-breaking change which fixes an issue)

How has this been tested?

  • Test A

  • Test B

  • GOOS=js GOARCH=wasm go test -exec="$(go env GOROOT)/lib/wasm/go_js_wasm_exec" ./backend/accelerated/webgpu/...

  • GOOS=js GOARCH=wasm go vet ./backend/accelerated/webgpu/internal/wasmruntime

  • GOOS=js GOARCH=wasm golangci-lint run --timeout=5m ./backend/accelerated/webgpu/internal/wasmruntime

A local go test -short ./... run was also attempted. Several unrelated cryptographic test packages reached their existing 10-minute per-package timeout; no failure involved the WebGPU/WASM packages changed here.

How has this been benchmarked?

  • Benchmark A, on Macbook pro M1, 32GB RAM
  • Benchmark B, on x86 Intel xxx, 16GB RAM

Not benchmarked. The change only adds boundary validation and regression tests.

Checklist:

  • I have performed a self-review of my code
  • I have commented my code, particularly in hard-to-understand areas
  • I have made corresponding changes to the documentation
  • I have added tests that prove my fix is effective or that my feature works
  • I did not modify files generated from templates
  • golangci-lint does not output errors locally
  • New and existing unit tests pass locally with my changes
  • Any dependent changes have been merged and published in downstream modules

Signed-off-by: colinaumaty <colinaumaty@outlook.com>
@colinaumaty
colinaumaty requested a review from a team as a code owner September 24, 2026 07:11

@ivokub ivokub left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for the PR. Indeed, your point is valid.

Though I don't think we need so many tests to cover this fix. Could you remove the changes from .github/workflows/webgpu.yml and remove backend/accelerated/webgpu/internal/wasmruntime/runtime_test.go alltogether? Even when the tests are correct, then it just adds bloat to source code and CI work.

Signed-off-by: colinaumaty <colinaumaty@outlook.com>
@colinaumaty

colinaumaty commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor Author

Thanks for the PR. Indeed, your point is valid.

Though I don't think we need so many tests to cover this fix. Could you remove the changes from .github/workflows/webgpu.yml and remove backend/accelerated/webgpu/internal/wasmruntime/runtime_test.go alltogether? Even when the tests are correct, then it just adds bloat to source code and CI work.

Thanks for the feedback. I removed the WebGPU workflow changes and the runtime test file. The PR now only contains the byte argument validation fix.

@ivokub Please review it again.

@ivokub ivokub left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for the follow-up! Looks good!

@ivokub
ivokub merged commit f0f4cff into Consensys-Incorporated:master Sep 29, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

bug: WebGPU/WASM byte arguments can panic on invalid input

2 participants