WITFuzz: Validity-Preserving Greybox Fuzzing for WebAssembly Interface Type Binding Generators
Hanqin Guan, Ningyu He, Shangtong Cao, Yifeng Cai, Yao Guo, Ding Li
Abstract
Modern build pipelines often rely on code generation to turn constraint-rich interface specifications into artifacts for target programming languages. In the WebAssembly component model, binding generators (bindgens) follow this pattern by translating WebAssembly Interface Types (WIT) packages into language-specific bindings that are later compiled with application code. This bindgen step already targets more than ten language ecosystems, and the Rust wit-bindgen crate alone has accumulated tens of millions of downloads. Yet a WIT package may pass WIT validation but still break this build pipeline: bindgens may crash or hang during generation (Phase I), or downstream toolchains may reject the generated bindings even when generation succeeds (Phase II). Testing bindgens at scale is challenging because WIT is strongly typed and constraint-rich, and Phase II failures require language-specific checking. We present WITFuzz, a validity-preserving greybox fuzzer for WIT bindgens. WITFuzz mutates resolved WIT abstract syntax trees via structure-aware rewrites expressed in a small domain-specific language, and propagates correlated updates to maintain WIT validity. When coverage plateaus, WITFuzz expands its strategy pool online using coverage-guided, LLM-assisted DSL synthesis, admitting only strategies that pass local validation. WITFuzz further uses a build-aware, multi-layer oracle that combines in-loop checks with selective asynchronous compilation/typechecking of generated bindings to capture non-crashing build breakers. Across 12 bindgens, WITFuzz improves average edge coverage by 8.3% over standalone wit-smith. It uncovers 40 previously unknown Phase I and Phase II build-breaking bugs, including 35 that are missed by all external baselines.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get cd1e13ad-7e1d-4316-aac4-1916c4d8ea8fRelated papers
- Finding Bugs in WebAssembly Interface Type Binding GeneratorsEthan Stanley, Eric EideASE 2025
- RULF: Rust Library Fuzzing via API Dependency Graph TraversalJianfeng Jiang, Hui Xu, Yangfan ZhouASE 2021 · 44 citations
- Waltzz: WebAssembly Runtime Fuzzing with Stack-Invariant TransformationLingming Zhang, Binbin Zhao, Jiacheng Xu, Peiyu Liu et al.USENIX Security 2025
- RGFuzz: Rule-Guided Fuzzer for WebAssembly RuntimesJunyoung Park, Yunho Kim, Insu YunS&P 2025
- WasmRef-Isabelle: A Verified Monadic Interpreter and Industrial Fuzzing Oracle for WebAssemblyConrad Watt, Maja Trela, Peter Lammich, Florian MärklPLDI 2023 · 13 citations
