xia-chao opened PR #14397 from xia-chao:fix-wasi-datetime-overflow to bytecodealliance:main:
Fixes a guest-triggerable panic in the preview 2 filesystem host functions.
wall_clock.datetimecomes straight from the guest, andsystemtime_fromhands it toDuration::new. That constructor carries nanoseconds of 1e9 or more into the seconds field and panics when the addition overflows, so a guest passing seconds u64::MAX with nanoseconds 1000000000 takes down the whole host process (exit status 101) instead of gettingoverflowback. One nanosecond less, 999999999, returnsoverflowcorrectly, because it is the carry that pushes the value over.The
checked_add(...).ok_or(ErrorCode::Overflow)right below was meant to catch this, butDuration::newis evaluated first, so that line never runs.I applied the carry before building the
Duration, which sends every out-of-range datetime down the existing error path. Times that already worked, including the in-range carry, behave the same as before.Reproduced with a small wasm32-wasip2 component that calls
set_times_at.
xia-chao requested rvolosatovs for a review on PR #14397.
xia-chao requested wasmtime-wasi-reviewers for a review on PR #14397.
Last updated: Oct 11 2026 at 04:10 UTC