xia-chao opened PR #14429 from xia-chao:fix-write-permit to bytecodealliance:main:
check-write gives the guest a number of bytes it may write next, and the interface says writing more than that traps. On stdout and on files it doesn't: I take a permit of 1048576, write 104857600 bytes in one call, get Ok back, and every byte arrives. TCP streams already trap and write-zeroes already checks in the same shared host function, so the check goes there and covers stdio, files and pipes at once - for TCP only the message text changes.
xia-chao requested dicej for a review on PR #14429.
xia-chao requested wasmtime-wasi-reviewers for a review on PR #14429.
xia-chao requested wasmtime-core-reviewers for a review on PR #14429.
xia-chao edited PR #14429:
The shared output-stream write host function doesn't check the permit that check-write returned. wasi:io says a write with more bytes than the permit has to trap, and today it returns Ok instead - after a permit of 1048576, a 104857600 byte write goes through on stdout and on files. The check isn't missing everywhere: TCP output streams enforce it, and write-zeroes checks in that same shared function, so I added it there and stdio, files and pipes are covered at once. TCP streams already trapped, and for them only the message text changes.
xia-chao edited PR #14429:
The shared output-stream write host function doesn't check the permit that check-write returned. wasi:io says a write with more bytes than the permit has to trap, and today it returns Ok instead - after a permit of 1048576, a 104857600 byte write goes through on stdout and on files.
The check isn't missing everywhere: TCP output streams enforce it, and write-zeroes checks in that same shared function, so I added it there and stdio, files and pipes are covered at once. TCP streams already trapped, and for them only the message text changes.
xia-chao edited PR #14429:
The shared output-stream write host function doesn't check the permit that check-write returned. wasi:io says a write with more bytes than the permit has to trap, and today it returns Ok instead.
after a permit of 1048576, a 104857600 byte write goes through on stdout and on files.
The check isn't missing everywhere: TCP output streams enforce it, and write-zeroes checks in that same shared function, so I added it there and stdio, files and pipes are covered at once. TCP streams already trapped, and for them only the message text changes.
xia-chao edited PR #14429:
The shared output-stream write host function doesn't check the permit that check-write returned. wasi:io says a write with more bytes than the permit has to trap, and today it returns Ok instead.
after a permit of 1048576, a 104857600 byte write goes through on stdout and on files.
The check isn't missing everywhere: TCP output streams enforce it, and write-zeroes checks in that same shared function.
so I added it there and stdio, files and pipes are covered at once. TCP streams already trapped, and for them only the message text changes.
xia-chao updated PR #14429.
xia-chao edited PR #14429:
The stdio and file output streams don't enforce the permit their own check_write reports. StdioOutputStream hands back 1 MiB and then writes any size it is given, so a 100 MiB write returns Ok; FileOutputStream checks that check-write came first, not the size. Every other output stream already traps on an over-permit write. I added the missing check to those two, so no existing trap message changes.
xia-chao edited PR #14429:
The stdio and file output streams don't enforce the permit their own check_write reports. StdioOutputStream hands back 1 MiB and then writes any size it is given, so a 100 MiB write returns Ok; FileOutputStream checks that check-write came first, not the size. Every other output stream already traps on an over-permit write.
I added the missing check to those two, so no existing trap message changes.
github-actions[bot] added the label wasi on PR #14429.
:thumbs_up: dicej submitted PR review:
Thanks, @xia-chao!
dicej added PR #14429 wasi:io: enforce the check-write permit in output-stream::write to the merge queue.
:check: dicej merged PR #14429.
dicej removed PR #14429 wasi:io: enforce the check-write permit in output-stream::write from the merge queue.
Last updated: Oct 11 2026 at 04:10 UTC