fix(wasm): bound blocking sleep by execution timeout - #2460
Conversation
Deploying with
|
| Status | Name | Latest Commit | Preview URL | Updated (UTC) |
|---|---|---|---|---|
| ✅ Deployment successful! View logs |
bashkit | cfdf325 | Commit Preview URL | Sep 25 2026, 10:32 AM |
The clamp only compiles for wasm32-unknown-unknown without wasm_js, so the wasmtime tier cannot reach it. Say what covers it today and what an e2e case would need, instead of leaving the gap implicit. Claude-Session: https://claude.ai/code/session_01MJBT5na4uL5yZZXwwH1FMy
a203fb2 to
cfdf325
Compare
|
Reviewed and rebased onto latest Blast radius is genuinely limited to non-JS wasmThe In that one world the precedence is necessary rather than merely defensible: the timer is a synchronous spin, so without it Coverage boundary, documented rather than left implicitThe clamp only compiles for this target, so the wasmtime tier in Not asking for that here: this target is an unpublished experiment, and 30 s of spin per CI run isn't a good trade for it. Validation
Generated by Claude Code |
Motivation
sleepthat could block the interpreter poll and let attacker-controlledsleepcalls bypass the configuredExecutionLimits::timeout, enabling bounded CPU DoS in the no-JS/no-WASI embedding.Description
sleepat the active execution deadline by readingExecutionDeadlinefrom execution extensions and passing a budget-bounded duration totime_compat::sleepincrates/bashkit/src/builtins/sleep.rs.time_compat::timeoutpath check the wall-clock deadline after every interpreter poll (including a poll that returnsReady) so an expired deadline takes precedence over a late Ready result incrates/bashkit/src/time_compat/mod.rs.effective_sleep_durationcovering boundary behavior for the cap, and update existingsleepunit tests to cover the change.`knowledge/runtimes/non-js-wasm.md,knowledge/security/threat-model.md, andcrates/bashkit/docs/threat-model.md).Testing
cargo fmt --all --checkandcargo clippy -p bashkit --lib -- -D warnings, both succeeded.cargo test -p bashkit builtins::sleep::tests --lib, all tests passed (6 passed).cargo test -p bashkit --test integration direct_sleep_respects_timeout -- --nocapture, which passed (1 passed).RUSTFLAGS='--cfg getrandom_backend="custom" -D warnings' cargo check --manifest-path examples/hyperlight/Cargo.toml --target wasm32-unknown-unknown, which completed successfully under the configured flags.just check-okfandjust check-doc-links, both succeeded.Codex Task