sync plugin OOMs ("memory allocation of N bytes failed") when the target canister already has assets
I maintainer di solito rispondono entro 1 giorno
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Idoneità per principianti
- 45/100
Direzione di ricerca
Riproduci il problema con l'icp.yaml fornito e i due comandi icp deploy o icp sync, confrontando un canister vuoto e uno popolato. Inizia tracciando il percorso del plugin sync e il plugin certified-assets migration-v2.2.1; determina se il problema si trova in icp-cli o nel plugin. Il lavoro è completo quando un canister popolato sincronizza gli asset modificati senza esaurire la memoria né rimanere silenzioso per minuti.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Summary
A plugin sync step against a canister that already holds assets exhausts the plugin sandbox's memory and aborts with memory allocation of 44 bytes failed, after ~7 minutes during which it produces no output. The same sync against an empty canister completes in 3–8 seconds.
The practical effect is that an asset canister can be deployed once and then never updated: every subsequent icp deploy / icp sync fails.
Environment
| icp-cli | 1.2.0 and 1.3.0 — identical behaviour |
| OS | macOS 26.5.2 (Darwin 25.5.0), arm64 |
| Network | mode: managed, launcher 15.0.0-2026-07-31-04-23. Also reproduces on mainnet |
| Recipe | @dfinity/[email protected] (sha256 ee41744b…) |
| Sync plugin | certified-assets migration-v2.2.1-6b48585 / sync_plugin.wasm (supplied by the recipe) |
| Canister wasm | dfx assetstorage 0.29.1 (sha256 4014793c…) |
| Asset set | 230 files, 4.4 MB total (a Docusaurus build/) |
Reproduction
icp.yaml:
canisters:
- name: docs
recipe:
type: "@dfinity/[email protected]"
sha256: ee41744bd1361593a041d830b06ce50598cae5b21b57209fc727e8f63ae7e906
configuration:
version: "0.29.1"
dir: docs/build # any static site; ours is ~230 files / 4.4 MB
build:
- npm run build-docs
networks:
- name: local
mode: managed
version: 15.0.0-2026-07-31-04-23
icp network start --background -e local
icp deploy docs -e local -y # 1st: creates the canister, syncs 230 assets — OK, ~8s
icp deploy docs -e local -y # 2nd: fails
icp sync docs -e local on its own reproduces it identically, so it is the sync step alone — no build, install or upgrade involved.
Actual
DEBUG icp::progress: sync plugin (legacy assetstorage / .ic-assets.json5): starting for canister <id> (environment: local)
DEBUG icp::progress: api_version: 2
DEBUG icp::progress: found 230 file(s) from ["docs/build"]
<~7 minutes, no output>
ERROR icp::operations::sync: ----- Failed to sync canister 'docs': <id> -----
ERROR icp::operations::sync: 'failed to run plugin'
ERROR icp::operations::sync: caused by: plugin returned error: memory allocation of 44 bytes failed
ERROR icp::operations::sync: note: run with `RUST_BACKTRACE=1` environment variable to display a backtrace
Error: Canister(s) ["docs"] failed to sync.
Expected
The sync completes, uploading only the changed assets — as it does when the canister is empty.
Notes
-
Empty vs populated is the trigger. First deploy (fresh canister,
listreturns nothing): 230 assets in 3–8s. Second: OOM. Clearing the canister restores the fast path —icp canister call docs clear '(record {})'followed byicp sync docs -e localuploads all 230 assets in 3 seconds. That is the only workaround we found, and it is not usable in production, since the canister serves nothing between the clear and the commit. -
Not an icp-cli version issue. 1.3.0 behaves identically; the plugin comes from the pinned recipe, not from the CLI.
-
Moving to the current plugin does not help.
certified-assetsv0.3.3(plugin-release.wasm) calls acan_syncquery, which the legacy dfxassetstoragecanister does not export, so it fails withIC0536 … has no query method 'can_sync'. Themigration-*plugin appears to be the only one supporting these canisters, and it is the one that OOMs. -
The memory limit is not configurable.
ICP_CLI_PLUGIN_COMPUTE_LIMIT_SECSexists (#669) but there is no memory equivalent, so the ceiling cannot be raised from the outside. If the allocation ceiling is a deliberate sandbox guard rather than a leak, the same argument as #669 applies — it cannot be calibrated for someone else's asset bundle. -
The silent ~7 minutes is its own problem. With no progress output, a hang and slow work are indistinguishable; in CI this consumed a 45-minute job timeout before failing.
-
Possibly related: dfinity/certified-assets#71, which tracks the legacy
assetstoragemigration plugin. If the fault is in the plugin rather than the sandbox, this may belong there instead.
Related, but separate
On a redeploy, icp deploy upgrades the canister (which stops it) and runs the sync step before restarting it, so the sync's first call is rejected with IC0508 … is stopped and therefore does not have a CallContextManager. A failed deploy also leaves the canister stopped — easy to miss on an asset canister, because http_request is a query and keeps serving normally while every update call is rejected. Happy to file that separately if you'd prefer it tracked on its own.
- Lingua principale
- Rust
- Stelle
- 115
- Fork
- 14
- Merge medio
- 2g 23h
- PR unite (30g)
- 40
Preparare l'ambiente
- Nessun Dockerfile né file Docker Compose
- Ha un modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di dfinity/icp-cli
-
Feature: `icp cycles buy` — buy cycles with a card for the current identity via an on-chain gatewayForse già presa @raymondk l’ha presa 2 giorni fa. Apertaenhancement
Difficoltà 5/5 Più di una settimana Idoneità per principianti 35/100
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 3/5 1-2 giorni Idoneità per principianti 68/100
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 3/5 1-2 giorni Idoneità per principianti 74/100
I maintainer di solito rispondono entro 1 giorno
-
question
Difficoltà 5/5 Più di una settimana Idoneità per principianti 35/100
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 3/5 1-2 giorni Idoneità per principianti 55/100
I maintainer di solito rispondono entro 1 giorno
Tutte le issue di dfinity/icp-cli
Issue simili
-
✨ enhancement needs-discussion
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 85/100
-
docs(openclaw): RTK_REWRITE_HOST relaxes every default ask, not only commands no rule matchedApertaarea:docs documentation good first issue priority:low
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
rtk-ai/rtk#4500 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
triage:accepted
Difficoltà 2/5 1-3 ore Idoneità per principianti 65/100
open-telemetry/otel-arrow#4343 ·
I maintainer di solito rispondono entro 2 giorni
-
bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
mishraprafful/multihull#150 ·
I maintainer di solito rispondono entro 1 giorno
-
area:tooling bug good first issue priority:P3
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
michaelnavazhylau/ngspice-rs#129 ·
I maintainer di solito rispondono entro 1 giorno