The Compponent Model async runtime in Wasmtime models guest tasks using the GuestTask struct, which has an associated ready_to_delete function to determine whether it can be safely removed from the table and dropped. However, that function does not currently take into account whether the guest has received and not yet dropped a handle to that task, which means it may be deleted before that handle is dropped, resulting in a resource not present trap when the guest handle is finally dropped. The following test case produces such an outcome:
(component
(component $C
(canon task.return (core func $task.return))
(core module $M
(import "" "task.return" (func $task.return))
(global $yield-count (mut i32) (i32.const 0))
(func (export "f") (result i32)
(i32.const 1 (; YIELD ;)))
(func (export "f-cb") (param i32 i32 i32) (result i32)
(if (i32.eq (global.get $yield-count) (i32.const 0))
(then (call $task.return)))
(global.set $yield-count (i32.add (global.get $yield-count) (i32.const 1)))
(if (result i32) (i32.ge_u (global.get $yield-count) (i32.const 5))
(then (i32.const 0 (; EXIT ;)))
(else (i32.const 1 (; YIELD ;)))))
)
(core instance $m (instantiate $M (with "" (instance
(export "task.return" (func $task.return))))))
(func $f (export "f") async (canon lift (core func $m "f") async (callback (core func $m "f-cb"))))
)
(component $D
(import "f" (func $f async))
(canon lower (func $f) async (core func $f))
(canon task.return (core func $task.return))
(canon subtask.drop (core func $subtask.drop))
(canon subtask.cancel (core func $subtask.cancel))
(core module $M
(import "" "task.return" (func $task.return))
(import "" "subtask.drop" (func $subtask.drop (param i32)))
(import "" "subtask.cancel" (func $subtask.cancel (param i32) (result i32)))
(import "" "f" (func $f (result i32)))
(global $subtask (mut i32) (i32.const 0))
(global $yield-count (mut i32) (i32.const 0))
(func (export "f") (result i32)
(local $result i32)
(local.set $result (call $f))
(if (i32.ne (i32.and (local.get $result) (i32.const 0xf)) (i32.const 1 (; STARTED ;)))
(then unreachable))
(global.set $subtask (i32.shr_u (local.get $result) (i32.const 4)))
(i32.const 1 (; YIELD ;)))
(func (export "f-cb") (param i32 i32 i32) (result i32)
(if (i32.eq (global.get $yield-count) (i32.const 0))
(then
(if (i32.ne (call $subtask.cancel (global.get $subtask)) (i32.const 2 (; RETURNED ;)))
(then unreachable))))
(global.set $yield-count (i32.add (global.get $yield-count) (i32.const 1)))
(if (result i32) (i32.ge_u (global.get $yield-count) (i32.const 10))
(then
(call $subtask.drop (global.get $subtask))
(call $task.return)
(i32.const 0 (; EXIT ;)))
(else (i32.const 1 (; YIELD ;)))))
)
(core instance $m (instantiate $M (with "" (instance
(export "f" (func $f))
(export "task.return" (func $task.return))
(export "subtask.drop" (func $subtask.drop))
(export "subtask.cancel" (func $subtask.cancel))))))
(func (export "f") async (canon lift (core func $m "f") async (callback (core func $m "f-cb"))))
)
(instance $c (instantiate $C))
(instance $d (instantiate $D
(with "f" (func $c "f"))
))
(func (export "run") (alias export $d "f"))
)
(assert_return (invoke "run"))
This is not a problem for HostTask, since the runtime is already careful to delay deleting those once the guest drops any handles to them.
At a minimum, we should add a boolean field to GuestTask indicating whether the guest has an open handle to it. However, a better option might be to use a reference count. That would eliminate the need for a ready_to_delete function altogether; instead, we'd increment the count for each thread, guest reference, etc., decrement it as appropriate, and only delete the task once the count goes to zero. That would also pave the way for WebAssembly/component-model#730, which will require reference counting anyway.
The Compponent Model async runtime in Wasmtime models guest tasks using the
GuestTaskstruct, which has an associatedready_to_deletefunction to determine whether it can be safely removed from the table and dropped. However, that function does not currently take into account whether the guest has received and not yet dropped a handle to that task, which means it may be deleted before that handle is dropped, resulting in aresource not presenttrap when the guest handle is finally dropped. The following test case produces such an outcome:This is not a problem for
HostTask, since the runtime is already careful to delay deleting those once the guest drops any handles to them.At a minimum, we should add a boolean field to
GuestTaskindicating whether the guest has an open handle to it. However, a better option might be to use a reference count. That would eliminate the need for aready_to_deletefunction altogether; instead, we'd increment the count for each thread, guest reference, etc., decrement it as appropriate, and only delete the task once the count goes to zero. That would also pave the way for WebAssembly/component-model#730, which will require reference counting anyway.