Skip to content

chore: update Wasmtime and resolve Clippy warnings - #404

Merged
farhan-syah merged 2 commits into
NodeDB-Lab:mainfrom
EnRaiha:fix/wasmtime-49-advisories
Oct 1, 2026
Merged

farhan-syah merged 2 commits into
NodeDB-Lab:mainfrom
EnRaiha:fix/wasmtime-49-advisories

Conversation

@EnRaiha

@EnRaiha EnRaiha commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Changes

  • Cargo.toml updates Wasmtime from 48 to 49 and declares Rust 1.96, required by Wasmtime 49.
  • Cargo.lock locks Wasmtime to 49.0.1 and updates its runtime, Cranelift, and WASM dependencies.
  • nodedb/src/control/server/ replaces four deprecated fetch_update calls with try_update, preserving atomic orderings and overflow handling.
  • nodedb/src/engine/kv/sorted_index/key.rs removes an unnecessary closure borrow when encoding range bounds.

Reason

  • Cargo.lock clears RUSTSEC-2026-0315 and RUSTSEC-2026-0316, covering Wasmtime fuel accounting and allocation limits.
  • nodedb/src/control/server/ and sorted-index bounds address the five reported Rust 1.99 Clippy errors.
  • deny.toml retains its existing advisory policy without adding exceptions.

Checks

  • Formatting: cargo fmt --all -- --check passes.
  • Dependency audit: cargo deny --offline check passes, with duplicate-dependency warnings.
  • Clippy: cargo clippy --workspace --all-targets --all-features --profile ci --locked -- -D warnings passes.
  • Focused tests: 46 pass across WASM, admission accounting, connection identities, and sorted-index key bounds.
RUST_MIN_STACK=33554432 cargo nextest run -p nodedb --lib --all-features --cargo-profile ci --locked -E 'test(planner::wasm) | test(server::admission) | test(pgwire::connection_identity) | test(sync::listener::tests::accepted_) | test(sorted_index::key)'

`cargo deny check advisories` fails on `main` with two RustSec advisories
against `wasmtime` 48.0.1, both patched in the ranges `>= 48.0.3, < 49.0.0`
and `>= 49.0.1`:

- RUSTSEC-2026-0315 — `call_ref` and exception `catch` can drop some fuel
  accounting, leading to exponential fuel amplification.
- RUSTSEC-2026-0316 — dynamic record lifting can allocate beyond the hostcall
  fuel limit.

The advisory is not incidental to this codebase. The WASM UDF runtime meters
every user-submitted module with `config.consume_fuel(true)`
(`nodedb/src/control/planner/wasm/runtime.rs:33`) and sets a per-invocation
budget with `store.set_fuel(fuel)` (`pool.rs:111`). Fuel is the bound that stops
a submitted UDF from running away; an amplification bug lets a module exceed it.
The modules import nothing (`Instance::new(&mut store, module, &[])`), so the
impact is runaway CPU rather than reaching outside the sandbox, but the bound is
one this runtime sets and relies on.

Raise the workspace dependency to 49 and the lockfile to 49.0.1. `deny.toml` is
untouched: the advisories have a fixed release, so they are cleared rather than
ignored. 48.0.3 would also satisfy the patched range and is the smaller move,
but 49.0.1 is the current release and was verified against the six `wasmtime`
Api items this crate uses.
Copilot AI balanced review requested due to automatic review settings October 1, 2026 15:57

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@farhan-syah farhan-syah added the run-ci Opt this PR into the full test suite; re-add to force a re-run label Oct 1, 2026
- Server counters use `try_update` with existing orderings and overflow handling.
- Sorted-index bounds pass the framing closure without an unnecessary borrow.
- Cargo.toml declares Rust 1.96, required by Wasmtime 49 and sufficient for `try_update`.
@farhan-syah farhan-syah changed the title deps: raise wasmtime to 49.0.1 for two fuel-metering advisories chore: update Wasmtime and resolve Clippy warnings Oct 1, 2026
@farhan-syah
farhan-syah merged commit aa6e91b into NodeDB-Lab:main Oct 1, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

run-ci Opt this PR into the full test suite; re-add to force a re-run

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants