Skip to content

Fix sandboxing in read_link on Windows - #14512

Merged
alexcrichton merged 1 commit into
bytecodealliance:mainfrom
alexcrichton:fix-windows-read-link
Oct 5, 2026
Merged

alexcrichton merged 1 commit into
bytecodealliance:mainfrom
alexcrichton:fix-windows-read-link

Conversation

@alexcrichton

Copy link
Copy Markdown
Member

Refactoring in #14370 erroneously forgot to use open_parent to actually sandbox the read_link function, and additionally even had it used that function it would not have passed tests on Windows. This commit adds a test that read_link can't escape the sandbox and it additionally restores the old implementation, with the upstream winx code inline.

Refactoring in bytecodealliance#14370 erroneously forgot to use `open_parent` to
actually sandbox the `read_link` function, and additionally even had it
used that function it would not have passed tests on Windows. This
commit adds a test that `read_link` can't escape the sandbox and it
additionally restores the old implementation, with the upstream `winx`
code inline.
@alexcrichton
alexcrichton requested a review from a team as a code owner October 3, 2026 01:25
@alexcrichton
alexcrichton requested review from dicej and removed request for a team October 3, 2026 01:25
@github-actions github-actions Bot added the wasi Issues pertaining to WASI label Oct 3, 2026
@alexcrichton
alexcrichton added this pull request to the merge queue Oct 5, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Oct 5, 2026
@alexcrichton
alexcrichton added this pull request to the merge queue Oct 5, 2026
Merged via the queue into bytecodealliance:main with commit 47e6ba6 Oct 5, 2026
53 checks passed
@alexcrichton
alexcrichton deleted the fix-windows-read-link branch October 5, 2026 15:37
alexcrichton added a commit that referenced this pull request Oct 5, 2026
* Fix an adapter stdio impl for wasip3 (#14505)

This commit fixes a minor issue in a wasip3 adapter where a wasip2
stream is being viewed as a wasip3 stream. The wasip3 adapter didn't
consult `check_write` to see how much could be written, which is
adjusted here.

* cli: avoid overflow when deriving the async stack size (#14514)

* cli: avoid overflow when deriving the async stack size

`CommonOptions::to_config` derives `async_stack_size` from `max_wasm_stack` by
adding `DEFAULT_HOST_STACK` when the former isn't given explicitly. For a large
enough `-Wmax-wasm-stack` that sum overflows, which panics the CLI before it can
report anything.

A very large stack may still legitimately fail to be allocated, but the CLI
should not panic on the way there.

* Fix the test to look for the overflow, not for any panic

The merge queue's `Tests Linux i686` job failed on this test. On a 32-bit
target `usize::MAX` is 4294967295, so the CLI's derivation now saturates as
intended but the process then asks for a ~4 GiB stack and allocation fails:

    allocation failure during `Store::new` ... out of memory (failed to allocate 268435455 bytes)

That is documented `Store::new` behavior, not the overflow this PR fixes, so
the test must assert the absence of the overflow rather than the absence of any
failure. The previous assertion also could not have passed on i686.

* cranelift: avoid unsupported vector types in inline copies (#14524)

* Refactor Winch default features slightly (#14502)

* Refactor Winch default features slightly

I've realized locally that in addition to removing the
gc-types/exceptions defaults we should also be removing tail-call by
default. To handle that I've decided to refactor this slightly to
explicitly enable features for Winch instead of disabling them from
Cranelift's features. This should be a bit more robust over time because
if we add something to Cranelift's set we don't have to remember to
remove it from Winch's set.

* Fix CI

* Fix sandboxing in `read_link` on Windows (#14512)

Refactoring in #14370 erroneously forgot to use `open_parent` to
actually sandbox the `read_link` function, and additionally even had it
used that function it would not have passed tests on Windows. This
commit adds a test that `read_link` can't escape the sandbox and it
additionally restores the old implementation, with the upstream `winx`
code inline.

---------

Co-authored-by: Xia Chao <shapirolutts@gmail.com>
Co-authored-by: SUNG JE PARK <166581861+dotcom07@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

wasi Issues pertaining to WASI

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants