Skip to content

Saturate the epoch deadline below the unwinding sentinel - #14513

Merged
alexcrichton merged 1 commit into
bytecodealliance:mainfrom
xia-chao:epoch-deadline-saturating
Oct 4, 2026
Merged

alexcrichton merged 1 commit into
bytecodealliance:mainfrom
xia-chao:epoch-deadline-saturating

Conversation

@xia-chao

@xia-chao xia-chao commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

Passing u64::MAX to set_epoch_deadline should mean "never interrupt". The runtime already uses
that exact value for something else. In a debug build you get a crash. In a release build the
deadline lands in the past and interrupts right away.

`Store::set_epoch_deadline` computes `current_epoch + delta`. `delta` is a
caller-provided `u64` with no documented upper bound, and `u64::MAX` is not a
free value here: `new_epoch` returns the deadline to wasm as a `u64` and
reserves exactly that value as its unwinding sentinel.

So a caller passing `u64::MAX` after the epoch has advanced either overflows
(debug panics; release wraps the deadline into the past, which interrupts
immediately) or lands exactly on the sentinel, which trips
`assertion failed: abi != T::SENTINEL` in `traphandlers.rs`.

Saturate, then clamp below the sentinel, so a large `delta` keeps meaning
"effectively never".
@xia-chao
xia-chao requested a review from a team as a code owner October 3, 2026 09:52
@xia-chao
xia-chao requested review from cfallin and removed request for a team October 3, 2026 09:52
@github-actions github-actions Bot added the wasmtime:api Related to the API of the `wasmtime` crate itself label Oct 3, 2026
@alexcrichton
alexcrichton added this pull request to the merge queue Oct 4, 2026
Merged via the queue into bytecodealliance:main with commit 9ced314 Oct 4, 2026
53 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

wasmtime:api Related to the API of the `wasmtime` crate itself

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants