Redline: concurrent calls on one Instance silently return wrong values
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 45/100
Research direction
The issue is in the Redline backend's machine state, specifically the argsBuffer, callDepth, TRAP_CODE, and pendingException fields which are shared across threads. Start by examining the machine class and the host-call argument passing mechanism. The goal is to implement a thread-owner check on the outermost call to turn silent corruption into an error, as suggested. Look for the compiled calling convention to understand the context pointer.
Written by the indexing model from the issue text.
Description
Calling one native Instance from several threads returns wrong results with no error. The other backends do not do this: bytecode is correct, and the interpreter throws. Redline is the only one that answers quietly and wrongly.
Eight threads, 2000 calls each, on a shared instance of host-import-roundtrip.wat.wasm, whose callTakeI32 must always return -1:
| Backend | Failed calls | Wrong results |
|---|---|---|
| Interpreter | 16000 / 16000 | 0 |
| Bytecode | 0 / 16000 | 0 |
| Redline (jffi) | 5318 / 16000 | 783 |
Every Redline failure is TrapException: call stack exhausted. The 783 wrong results carried no error at all.
Cause
Per-call state lives in the machine, shared by every thread that enters it, rather than per thread.
argsBufferis one buffer per machine, and host-call arguments pass through it, so one thread reads another's argument.takeI32returns what it was handed, which is where the wrong values come from.callDepthis an unsynchronisedint, sooutermostCallis missed,STACK_LIMITis never re-anchored, and the stack guard fires against a stale limit.TRAP_CODEandpendingExceptionare shared too, so one thread can see and clear another's trap.
Instances are not thread-safe in general and this may simply be unsupported usage. It is filed for the failure mode rather than the usage: silent wrong answers instead of an error.
Suggested fix
Cheap, and worth doing on its own: compare-and-set an owner thread on the outermost call and throw if another thread is already inside. One atomic operation per outermost call, and it turns silent corruption into an actionable error, which is what the interpreter already does in effect.
Real: per-thread context and argument buffers, and a per-thread call depth. Bigger, because the context pointer is part of the compiled calling convention.
Note on #201
The watchdog fix does not cause this, but it does make it visible. Before it, the same probe gave 0 to 3 wrong results rather than 783: starting a thread per call serialised callers enough that most trapped before they could race. The data race is older than the watchdog work; what went away is the throttle that was hiding it.
🤖 Generated with Claude Code
- Dominant language
- Java
- Stars
- 310
- Forks
- 23
- Avg merge
- 2d 8h
- Merged PRs (30d)
- 33
Getting set up
- No Dockerfile or Docker Compose file
- No pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from bytecodealliance/endive
-
Difficulty 5/5 Over a week Newbie friendliness 35/100
bytecodealliance/endive#225 · 1 comment ·
Maintainers usually reply within 1 day
-
Difficulty 3/5 1-2 days Newbie friendliness 55/100
bytecodealliance/endive#224 · 2 comments ·
Maintainers usually reply within 1 day
-
Difficulty 4/5 3-5 days Newbie friendliness 48/100
bytecodealliance/endive#203 · 1 comment ·
Maintainers usually reply within 1 day
-
Difficulty 5/5 Over a week Newbie friendliness 25/100
bytecodealliance/endive#202 · 2 comments ·
Maintainers usually reply within 1 day
-
Difficulty 5/5 Over a week Newbie friendliness 35/100
bytecodealliance/endive#181 · 3 comments · 1 reaction ·
Maintainers usually reply within 1 day
All issues in bytecodealliance/endive
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
typetools/checker-framework#8325 ·
Maintainers usually reply within 1 day
-
4Q-maintenance
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
OpenLiberty/liberty-tools-intellij#1790 ·
Maintainers usually reply within 2 days
-
fix(i18n): fix fr translationPossibly taken A pull request linked to this issue is open or already merged. Openbug needs triage
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
OpenAEV-Platform/openaev#8334 ·
Maintainers usually reply within 2 days
-
discussion welcome security waiting for feedback
Difficulty 2/5 1-3 hours Newbie friendliness 62/100
Maintainers usually reply within 1 day
-
🐞 bug
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
eclipse-rdf4j/rdf4j#6132 ·
Maintainers usually reply within 1 day