Repository navigation
Conversation
…c failures PluginInstance::init wrote the config through the guest's `alloc` before resetting fuel and the epoch deadline, so `alloc` ran on whatever the store had left after instantiation, which spends from the same budget from store creation on. A slow instantiation could leave too little, and the route answered 500 with "failed to get middleware". The per-request path already reset the budget before its write; init now does the same. `alloc` errors were wrapped as "alloc failed: <backtrace header>", which drops the trap reason. They now go through call_error like every other call, so running out of fuel, a timeout and other traps are named. Four tests, each failing without the change: init succeeds after instantiation spent all fuel and after the deadline passed, a runaway alloc reports "out of fuel", and an `unreachable` in alloc keeps its cause. Signed-off-by: Nicolas Dreno <nicolas.dreno@barbacane.dev>
|
Important Review skippedAuto reviews are limited based on label configuration. 🏷️ Required labels (at least one) (1)
Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Repository: barbacane-dev/barbacane/.coderabbit.yaml Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Summary
The full-coverage run on
main(ba339c7) failed once intest_jwt_auth_invalid_issuer: the request got500instead of401, and the gateway loggedThe same commit passed on the scheduled run. The log shows no cause for the trap, and reading the code turned up two defects:
initwrites the config on a leftover budget.PluginInstance::initcallswrite_to_memory, which runs the guest'salloc, before resetting fuel and the epoch deadline. The store's budget is set at creation and instantiation spends from it, soallocgets whatever is left. Under a slow, coverage-instrumented build, instantiation can come close to the deadline, andallocis then interrupted. The per-request path (call_with_body) already resets the budget before its write; onlyinitdidn't.allocerrors lose their cause. They were wrapped asalloc failed: {e}, which prints only wasmtime's backtrace header. Every other call goes throughcall_error, which names out of fuel, timeout or the trap.I can't prove (1) is what happened on CI, because (2) hid the cause. With this change, a recurrence would say which limit it hit.
Changes
crates/barbacane-wasm/src/instance.rs:reset_budget(), called before the config write and again before the guest'sinit.allocerrors go throughcall_error, with the fuel the call actually had.Testing
Four new tests, each failing without the change (4 of 20 in
instance::testsgo red):initsucceeds after instantiation spent all fuel (set_fuel(0)), and after the deadline passed (1 tick, then a 20 ms sleep).allocreports "out of fuel", and anallocthat hitsunreachablekeeps that cause.cargo test -p barbacane-wasm: 250 pass.cargo clippy -p barbacane-wasm --lib --binsis clean.