chore: update Wasmtime and resolve Clippy warnings - #404
Merged
Merged
Conversation
`cargo deny check advisories` fails on `main` with two RustSec advisories against `wasmtime` 48.0.1, both patched in the ranges `>= 48.0.3, < 49.0.0` and `>= 49.0.1`: - RUSTSEC-2026-0315 — `call_ref` and exception `catch` can drop some fuel accounting, leading to exponential fuel amplification. - RUSTSEC-2026-0316 — dynamic record lifting can allocate beyond the hostcall fuel limit. The advisory is not incidental to this codebase. The WASM UDF runtime meters every user-submitted module with `config.consume_fuel(true)` (`nodedb/src/control/planner/wasm/runtime.rs:33`) and sets a per-invocation budget with `store.set_fuel(fuel)` (`pool.rs:111`). Fuel is the bound that stops a submitted UDF from running away; an amplification bug lets a module exceed it. The modules import nothing (`Instance::new(&mut store, module, &[])`), so the impact is runaway CPU rather than reaching outside the sandbox, but the bound is one this runtime sets and relies on. Raise the workspace dependency to 49 and the lockfile to 49.0.1. `deny.toml` is untouched: the advisories have a fixed release, so they are cleared rather than ignored. 48.0.3 would also satisfy the patched range and is the smaller move, but 49.0.1 is the current release and was verified against the six `wasmtime` Api items this crate uses.
- Server counters use `try_update` with existing orderings and overflow handling. - Sorted-index bounds pass the framing closure without an unnecessary borrow. - Cargo.toml declares Rust 1.96, required by Wasmtime 49 and sufficient for `try_update`.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Changes
Cargo.tomlupdates Wasmtime from 48 to 49 and declares Rust 1.96, required by Wasmtime 49.Cargo.locklocks Wasmtime to 49.0.1 and updates its runtime, Cranelift, and WASM dependencies.nodedb/src/control/server/replaces four deprecatedfetch_updatecalls withtry_update, preserving atomic orderings and overflow handling.nodedb/src/engine/kv/sorted_index/key.rsremoves an unnecessary closure borrow when encoding range bounds.Reason
Cargo.lockclears RUSTSEC-2026-0315 and RUSTSEC-2026-0316, covering Wasmtime fuel accounting and allocation limits.nodedb/src/control/server/and sorted-index bounds address the five reported Rust 1.99 Clippy errors.deny.tomlretains its existing advisory policy without adding exceptions.Checks
cargo fmt --all -- --checkpasses.cargo deny --offline checkpasses, with duplicate-dependency warnings.cargo clippy --workspace --all-targets --all-features --profile ci --locked -- -D warningspasses.RUST_MIN_STACK=33554432 cargo nextest run -p nodedb --lib --all-features --cargo-profile ci --locked -E 'test(planner::wasm) | test(server::admission) | test(pgwire::connection_identity) | test(sync::listener::tests::accepted_) | test(sorted_index::key)'