Skip to content

fix(runtime): consolidate patch correctness and retire unsafe shortcuts - #218

Open
f0rr0 wants to merge 8 commits into
mainfrom
f0rr0/patch-correctness-refresh
Open

f0rr0 wants to merge 8 commits into
mainfrom
f0rr0/patch-correctness-refresh

Conversation

@f0rr0

@f0rr0 f0rr0 commented Sep 27, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • Keep PostgreSQL recovery inside live guest calls; fix native startup/session cleanup and host process boundaries.
  • Apply configured-role login and startup policy without restoring bootstrap-superuser privileges on reset.
  • Remove unsafe or unproven patches and organize Wasmer/libc changes into documented, ordered series.
  • Preserve complete tool output without the introduced 64 MiB quota; use amortized allocation and report capture failures without truncated success.
  • Generate shared numeric protocol constants for their actual consumers and use one PostgreSQL source-fingerprint input recipe across build tools.
  • Retain the native caller directory without requiring listing permission; preserve rename-safe restoration and report directory-capture failures through the existing startup error API.
  • Allow browser extensions to import clock setters; an actual setter call switches all readers sharing the database memory to canonical WASIX clocks.

Native fsync defaults and LLVM memory policy remain unchanged; their separate proposals are #241 and #242. Destination output, async backpressure and native broker/mobile buffering are consolidated in #244.

Validation

Refreshed against main, preserving private initialization/publication and packaging fixes. Workflow/security checks, native unit/lint, Rust formatting, both doctest variants, eight public API tests, 176 WASIX unit tests and three browser clock tests pass locally. Rust unit checks use retained, version-matched AOT carriers; this is not new release qualification. Native npm facade packaging and source-fingerprint agreement were checked earlier.

The old browser host builds with the complete ordered patch series. Chromium integration passes PostGIS Worker loading, configured roles, SQL recovery, concurrent/direct databases, IndexedDB reopen and OPFS persistence/crash recovery. The TypeScript SDK's 357 tests, formatting, typecheck and package checks pass. Packed-consumer browser execution still needs the current seed-carrier tarballs absent from this local checkout; it remains covered by the hosted prerequisite graph.

The directory fix passes Linux native unit/lint and C ABI/integration smoke checks. The ordered PostgreSQL patch series applies cleanly. Search-only directories now permit startup/query/close; renamed directories restore by identity; deleted directories return the underlying capture error. The Android API 24 capture probe compiles. Installed Android and Apple runtime qualification remains pending. No new flags, public ABI changes, query-path checks, shutdown behavior or retry policy changes.

These are local checks, not complete installed-consumer or cross-platform qualification. Windows WASIX SQL recovery remains blocked by the unsupported MSVC exception runtime, tracked in #208; it is not repaired or skipped here. Buffered output remains limited by host memory; no query-performance improvement is claimed for collector cleanup. The independent Wasmer/browser SDK refresh remains #247.

@vercel

vercel Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
oliphaunt-docs Ready Ready Preview Oct 8, 2026 7:17pm UTC

@f0rr0

f0rr0 commented Oct 3, 2026

Copy link
Copy Markdown
Owner Author

Remaining regression review

Updated head: 7de2f6fd15d29a694b106f0a51ba696a7edc11e4. Recommendations 1–2 are now pushed; deferred destination/streaming/broker work is consolidated in #244. Native fsync and LLVM memory-policy changes remain separate in #241/#242.

The failures below are from CI at e3e6396c, before today's output/contract cleanup. They must not be presented as results for the new head. Comparison used current main (9899fa13); its changes since this PR's base are release-only. Recent green main runs skipped these consumer/mobile jobs, so that green badge is not a paired runtime control.

P1: Browser PostGIS is rejected by the new clock policy

Failing consumer job: loading /lib/postgresql/postgis-3.so fails because it imports wasix_32v1.clock_time_set.

The new clock installer rejects the module based on the import, even without a clock-setting call. This is a concrete compatibility regression in the broader PR, not the new collector work. Existing clock arithmetic tests do not exercise module instantiation.

Next: make the optional fast clock fall back coherently when setters are available, preserving shared clock state across the main guest and side modules. Simply removing the guard, or falling back only in the side module while the main guest retains stale fast-clock state, is insufficient. Prove extension load, clock-set/read consistency and browser non-regression performance; a canonical-clock instance is a useful correctness control.

P1: Native cwd preservation adds an unnecessary read-permission requirement

Android app job: startup fails before ReadyForQuery with status -1; the app's logcat also records an SELinux denial of reading /.

The new lifecycle capture requires open(".", O_RDONLY | O_CLOEXEC). A local unprivileged Linux probe in a searchable but unreadable directory reproduced getcwd success, O_RDONLY failure with EACCES, and successful restoration using O_PATH plus fchdir. The permission regression is reproducible; its attribution to the Android failure is strongly supported, but not yet confirmed by an Android rerun.

Next: retain the directory by search/path capability on platforms supporting it, preserving rename-safe restoration without requiring directory listing access. Retain appropriate platform handling elsewhere and surface the capture error instead of only status -1. Test execute-only cwd, rename/cleanup, and actual Android startup; do not solve this by weakening sandbox permissions or changing the application's cwd globally.

Windows: SQL error recovery remains unresolved

Windows job: the client compatibility recovery test fails and the process exits with 0xe06d7363. This is consistent with the already documented Windows exception/recovery problem in #208; this log alone does not provide a new engine-stack attribution. AOT production succeeding is not evidence of working SQL recovery. Keep #208's actual-Windows engine probe and product qualification as the next step, not a test skip.

Fixed in this update: stale native fsync assertion

The native consumer job expected fsync=on inside the login-identity test, although that policy was deliberately split into #241. Removed that unrelated assertion, preserving all role, login-trigger and session-setting checks. The targeted identity test passes against retained local native library/broker artifacts; fresh packaged CI remains required.

Validation and remaining limits

The 13 targeted Moon tasks have passing cached results for their current inputs, including 173 WASIX Rust unit tests, native tool tests, contract generation and shim checks. The modified browser host was built successfully; native npm facade packaging/import and fingerprint agreement were also checked. This is not a full installed-consumer or cross-platform pass.

Removing the 64 MiB quota restores complete-output semantics; buffered APIs can still exhaust host memory or encounter string/bridge representation limits. Actual large-dump/restore coverage and bounded destination APIs remain explicit acceptance work in #244. No new RTT/INSERT performance gain, nor full performance non-regression, is claimed from this update. The PR is not merge-ready while the browser/Android failures and Windows recovery qualification remain unresolved.

* build(wasix): upgrade embedded runtime to Wasmer 7.5

Refresh the coherent Wasmer/WASIX family, parser, Node-API bindings, and Rust build toolchain. Adapt upstream package metadata and regenerate affected dependency-license contracts.

Linux core execution is verified. Keep the browser and Postmaster pins unchanged pending adapter and patch ports; the existing Windows LLVM AOT producer is not supported by upstream 7.5.

* build: standardize on the minimum shared Rust toolchain

Use Rust 1.96.0 for the workspace and both baseline container builders, with a common 1.96 minimum in maintained and generated Cargo packages. Let private workspace tools inherit the shared minimum.

* feat(wasix): upgrade browser host to Wasmer SDK 0.19

* feat(wasix): integrate bundled Windows V8 engine and native caches (#255)

* feat(wasix): integrate bundled Windows V8 engine and native caches

* fix(release): plan embedded engine payloads before source acquisition

* fix(ci): qualify Windows engine contracts before cache production

* test(wasix): qualify the frozen Windows engine package closure

* fix(wasix): remove LLVM inputs from Windows runtime qualification

* fix(packaging): close transitive path dependency test sources

* test(wasix): run installed Windows SDK against frozen AOT carriers

* test(wasix): qualify the full extension lifecycle on Windows V8

* refactor(wasix): keep one Windows cache producer helper

* refactor(wasix): name native value ownership explicitly

* refactor(wasix): align engine qualification and producer conventions

* fix(ci): prepare WASIX engine toolchains and lifecycle sources

* fix(ci): execute selected WASIX engine tasks without base lookup

* fix(wasix): extract Windows engine archive with a local path

* fix(wasix): close installed engine qualification dependencies

* fix(packaging): normalize native Windows Cargo file listings

* fix(wasix): keep dependency resolution in native qualification

* fix(ci): serialize WASIX server executable consumers

* fix(wasix): split oversized Windows AOT Cargo payloads

* fix(wasix): align qualification and maintainer workflows

* perf(packaging): reuse validated Windows payload archives

* fix(wasix): align engine patches and qualification inputs
…riers (#268)

* fix(storage): separate embedded fsync defaults from publication barriers

Use PostgreSQL boot defaults instead of forced startup overrides. Route explicit WASIX file synchronization through the owned filesystem contract while keeping ordinary flush and close cheap. Preserve and repair initialization and restore publication barriers, and surface real native directory errors.

Ensure engine patches actually apply inside the enclosing checkout and cover configuration precedence and synchronization behavior with focused regression checks.

* fix(storage): correct Windows publication and restore diagnostics

* fix(test): create patch-replay fixture parent on clean checkouts

* fix(wasix): supervise Windows cache producer shutdown
* fix(wasix): reuse prepared sources without concurrent rewrites

* fix(wasix-ts): initialize seed-free browser workers (#271)
* fix(wasix): reuse prepared sources without concurrent rewrites

* fix(postgres): update PostgreSQL to 18.6

* fix(wasix): refresh the PostgreSQL 18.6 export closure

* fix(postgres): refresh fence and frozen carrier checks

This branch was successfully deployed

1 active deployment
Preview — 47c88b9a Deployed Oct 8, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant