Skip to content

mirth-lab gate-mutate: feature-gate mutation; findings 40-45 - #38

Merged
zmaril merged 2 commits into
mainfrom
mirth/check-gatemut
Oct 10, 2026
Merged

zmaril merged 2 commits into
mainfrom
mirth/check-gatemut

Conversation

@zmaril

@zmaril zmaril commented Oct 10, 2026

Copy link
Copy Markdown
Contributor

Feature-gate mutation (docs/checks.md Part 1, item 1): generated inputs that reach the ICEs unstable features cause. 144 of the 334 crash bugs in the survey needed a nightly feature.

mirth-lab gate-mutate

Draws from the 4,419 standalone UI tests that enable a feature (348 features). The 37 incomplete features, read from rustc_feature, are drawn three times as often. Each mutant uses one strategy:

  • splice: the items of a test that uses another feature, added flat (dropping names that collide) or inside a module, with both crates' gates;
  • move: an item copied (impls are moved) into a generic fn, an async fn, a closure, an anonymous const or a module; a free fn can also go into a trait as a default method or into an inherent impl; or the whole file through mirth-rewrite's generic-wrap;
  • gate: an extra incomplete feature enabled on the test;
  • edit: one to three of the fuzzers' mechanical edits.

Each mutant is compiled once, under one configuration: the test's own flags, -Znext-solver=globally, or -Zassumptions-on-binders.

A finding is an ICE, or a hang confirmed with three times the timeout, that the unmutated test does not give. Findings are grouped by signature (the panic location and the first query on the stack, or a delayed bug's message). For each signature:

  • the smallest mutant is kept and reduced greedily (top-level items, brace blocks, runs of lines). A reduction step may not introduce E0658, because an ICE after "feature not enabled" is a different bug;
  • --triage checks that the reduced file reproduces on its own (adding --test when the source test uses the test harness), records the exact command, and searches rust-lang/rust's issues for candidates. I then read the candidates by hand.

Runs are seeded and resumable, and support --pause-on-finding and --known. --rereduce redoes reduction after the reducer changes.

One-hour run on 4 cores (the machine was busy with the big run)

88,174 mutants gave 482 ICEs and 16 timeouts. 197 of those mutants gave a signature their unmutated test doesn't, in 19 signatures and 12 families.

  • Known: #153733, #156099, #151310 (fixed after the pin), #156410, #153735, and the async-drop assertion of closed #162756, still reached through the internal staged_api feature.
  • Looks new, findings 40–45 in docs/hunt.md, facts only, with repros in docs/hunt/tests/gate-mutate/:
    • 40: -Zassumptions-on-binders with generic_const_exprs asserts on any crate.
    • 41: generic_const_exprs with gca const items under -Znext-solver hits a delayed bug in the old solver's const normalization.
    • 42: a route around closed #162392, with gca_adts, gca_macroless_items and gca_min_const_items.
    • 43: a route around closed #162147, with generic_const_exprs.
    • 44: rustc --test with a #[test] #[unsafe(naked)] inner fn panics with "expected statement". Reachable on stable, 1.82.0 through 1.98.0.
    • 45: a hang under the new solver. It is the default on nightly, so a plain rustc hangs on nightly-2026-10-06.

🤖 Generated with Claude Code

https://claude.ai/code/session_01QXiEXbESemwqMLYKaWLDbT

zmaril and others added 2 commits October 10, 2026 09:16
…eatures (splices, moved items, extra incomplete gates, edits) under the solver configuration columns; ICEs and hangs grouped by signature, reduced, triaged against rust-lang/rust issues

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QXiEXbESemwqMLYKaWLDbT
… blocks, line runs, no new E0658), --rereduce, triage checks each reduced file alone (with --test when the source uses the harness); one-hour run: 88,174 mutants, 19 signatures, findings 40-45 with reduced repros

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QXiEXbESemwqMLYKaWLDbT
@zmaril
zmaril merged commit d6733a9 into main Oct 10, 2026
0 of 3 checks passed
@zmaril

zmaril commented Oct 10, 2026

Copy link
Copy Markdown
Contributor Author

Merged into main together with #33–#38; renumbered at merge so finding numbers are unique: findings 40–45 are now 50–55 (docs/hunt.md).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant