Stream: git-wasmtime

Topic: wasmtime / PR #14403 add tests and fixes for wasi filesys...


view this post on Zulip Wasmtime GitHub notifications bot (Sep 24 2026 at 17:46):

pchickey opened PR #14403 from pchickey:fix_ghsa_j2g9_main to bytecodealliance:main:

<!--
Please make sure you include the following information:

Our development process is documented in the Wasmtime book:
https://docs.wasmtime.dev/contributing-development-process.html

Please review the Bytecode Alliance's AI tool usage policy at
https://github.com/bytecodealliance/governance/blob/main/AI_TOOL_POLICY.md

Please ensure all communication follows the code of conduct:
https://github.com/bytecodealliance/wasmtime/blob/main/CODE_OF_CONDUCT.md
-->

view this post on Zulip Wasmtime GitHub notifications bot (Sep 24 2026 at 17:46):

pchickey requested rvolosatovs for a review on PR #14403.

view this post on Zulip Wasmtime GitHub notifications bot (Sep 24 2026 at 17:46):

pchickey requested wasmtime-wasi-reviewers for a review on PR #14403.

view this post on Zulip Wasmtime GitHub notifications bot (Sep 24 2026 at 17:46):

pchickey requested dicej for a review on PR #14403.

view this post on Zulip Wasmtime GitHub notifications bot (Sep 24 2026 at 17:46):

pchickey requested wasmtime-core-reviewers for a review on PR #14403.

view this post on Zulip Wasmtime GitHub notifications bot (Sep 24 2026 at 17:47):

pchickey requested alexcrichton for a review on PR #14403.

view this post on Zulip Wasmtime GitHub notifications bot (Sep 24 2026 at 17:47):

pchickey edited PR #14403:

Replaces #14397

<!--
Please make sure you include the following information:

Our development process is documented in the Wasmtime book:
https://docs.wasmtime.dev/contributing-development-process.html

Please review the Bytecode Alliance's AI tool usage policy at
https://github.com/bytecodealliance/governance/blob/main/AI_TOOL_POLICY.md

Please ensure all communication follows the code of conduct:
https://github.com/bytecodealliance/wasmtime/blob/main/CODE_OF_CONDUCT.md
-->

view this post on Zulip Wasmtime GitHub notifications bot (Sep 24 2026 at 17:47):

pchickey edited PR #14403:

Replaces #14397

<!--
Please make sure you include the following information:

Our development process is documented in the Wasmtime book:
https://docs.wasmtime.dev/contributing-development-process.html

Please review the Bytecode Alliance's AI tool usage policy at
https://github.com/bytecodealliance/governance/blob/main/AI_TOOL_POLICY.md

Please ensure all communication follows the code of conduct:
https://github.com/bytecodealliance/wasmtime/blob/main/CODE_OF_CONDUCT.md
-->

view this post on Zulip Wasmtime GitHub notifications bot (Sep 24 2026 at 17:54):

:thumbs_up: dicej submitted PR review.

view this post on Zulip Wasmtime GitHub notifications bot (Sep 24 2026 at 18:01):

pchickey edited PR #14403:

Replaces #14397

Tracking as security issue https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-j2g9-4prp-pf6h

The wasmtime-wasi crate allows guest WASI programs to trigger a host panic by specifying a filesystem timestamp value where the microseconds field overflows the seconds field. The root of the issue is that std::time::Duration::new panics in this case, rather than return an error.

This PR fixes the issues in the wasip2 and wasip3 host implementations by first adding the microseconds field to the seconds field with the appropriate overflow checks before calling Duration::new. Tests are added for the wasip2 and p3 paths. Since p1 is implemented straightforwardly in terms of p2, there are no additional tests added to exercise the p1 path.

wasip1

The path_filestat_set_times and fd_filestat_set_times functions take a timestamp typed arguments atim and mtim. A host panic is exposed if the microseconds can overflow the seconds field of this struct, e.g. Timestamp { seconds: u64::MAX, microseconds: 1_000_000_000 }, when passed in either argument position (atim or mtim) to these functions, as long as fst_flags does not obviate the atim or mtim argument with the ATIM_NOW/MTIM_NOW flag.

wasip2

The set-times and set-times-at methods on wasi:filesystem/types.descriptor take two new-timestamp typed arguments atim and mtim where the timestamp variant takes a datetime struct. A host panic is exposed if the microseconds can overflow the seconds field of this struct, e.g. NewTimestamp::Timestamp(Datetime { seconds: u64::MAX, microseconds: 1_000_000_000 }), when passed in either argument position (atim or mtim) to these functions.

wasip3

The set-times and set-times-at methods on wasi:filesystem/types.descriptor take two new-timestamp typed arguments atim and mtim where the timestamp variant takes a datetime struct. A host panic is exposed if the microseconds can overflow the seconds field of this struct, e.g. NewTimestamp::Timestamp(Datetime { seconds: i64::MAX, microseconds: 1_000_000_000 }), when passed in either argument position (atim or mtim) to these functions.

view this post on Zulip Wasmtime GitHub notifications bot (Sep 24 2026 at 18:03):

pchickey added PR #14403 add tests and fixes for wasi filesystem datetime overflow to the merge queue.

view this post on Zulip Wasmtime GitHub notifications bot (Sep 24 2026 at 18:30):

:check: pchickey merged PR #14403.

view this post on Zulip Wasmtime GitHub notifications bot (Sep 24 2026 at 18:30):

pchickey removed PR #14403 add tests and fixes for wasi filesystem datetime overflow from the merge queue.


Last updated: Oct 11 2026 at 04:10 UTC