alexcrichton opened PR #14483 from alexcrichton:fix-zero-timeout to bytecodealliance:main:
This commit fixes an issue where tokio's
time::intervalAPI will panic with a zero-duration passed to it. This duration is controlled by the guest which means that a guest can use this as a vector by which to panic the host. The fix here in this commit is to clamp to a 1ns duration instead of 0 which effectively means the same thing for the purposes of a timeout.part of https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-w4qr-p94g-mjhv
<!--
Please make sure you include the following information:
If this work has been discussed elsewhere, please include a link to that
conversation. If it was discussed in an issue, just mention "issue #...".Explain why this change is needed. If the details are in an issue already,
this can be brief.Our development process is documented in the Wasmtime book:
https://docs.wasmtime.dev/contributing-development-process.htmlPlease review the Bytecode Alliance's AI tool usage policy at
https://github.com/bytecodealliance/governance/blob/main/AI_TOOL_POLICY.mdPlease ensure all communication follows the code of conduct:
https://github.com/bytecodealliance/wasmtime/blob/main/CODE_OF_CONDUCT.md
-->
alexcrichton requested dicej for a review on PR #14483.
alexcrichton requested wasmtime-wasi-reviewers for a review on PR #14483.
alexcrichton requested wasmtime-core-reviewers for a review on PR #14483.
alexcrichton has enabled auto merge for PR #14483.
:thumbs_up: adamrk submitted PR review.
alexcrichton added PR #14483 Fix a panic in wasi-http with a zero timeout to the merge queue.
:check: alexcrichton merged PR #14483.
alexcrichton removed PR #14483 Fix a panic in wasi-http with a zero timeout from the merge queue.
Last updated: Oct 11 2026 at 04:10 UTC