Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

Host function callbacks can deadlock when calling back into the sandbox

未关闭
#192 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

维护者通常 6 天内回复

还没有人认领这个 Issue。

评估

难度
5/5
预计耗时
一周以上
新手友好度
42/100
Issue 类型
缺陷
描述清晰度
基本清楚
活跃度
冷清
技术栈
javascript, rust
领域
backend

调研方向

首先跟踪 handle_event 中经由 call_handler 和 host-function dispatch 的 sandbox lock,然后将其与 src/hyperlight_host/src/sandbox/outb.rs 中的 separate-lock approach 进行比较。使用 registerHostFunction 和 callHandler 重现 callback,并检查 PR #55 的 executing_flag。完成的标准是 callback 可以调用 sandbox 操作而不会发生死锁,并且为报告的复现添加覆盖。

由索引模型根据 Issue 内容生成。

描述

bug lifecycle/needs-review

Problem

When a host function callback (registered via registerHostFunction or setHostPrintFn) tries to call back into the same sandbox (e.g. callHandler, snapshot, restore, unload), it deadlocks.

This happens because call_handler holds the LoadedJSSandbox mutex for the entire duration of guest execution. Host functions are dispatched via TSFN to the Node.js main thread while that lock is held. If the callback then calls any method that needs the same lock, it waits forever.

Why this doesn't happen in core hyperlight

In hyperlight-dev/hyperlight, the host function registry (Arc<Mutex<FunctionRegistry>>) uses a separate lock from the sandbox. Host functions are dispatched synchronously while the VM is paused — they don't need the sandbox lock at all. See src/hyperlight_host/src/sandbox/outb.rs.

In hyperlight-js, the QuickJS runtime invokes host function closures inside handle_event, which requires &mut self on the sandbox. The NAPI layer wraps this in a single tokio::sync::Mutex, so host function dispatch and sandbox lifecycle share the same lock.

Current workaround

PR #55 adds an executing_flag (AtomicBool) that detects reentrancy at runtime. If a callback tries to acquire the lock while guest code is executing, it returns ERR_REENTRANT instead of deadlocking. This prevents hangs but doesn't allow the operation to succeed.

Suggested fix

Separate host function dispatch from the sandbox lock, similar to how core hyperlight does it. Options:

  1. Move host function state out of the &mut self borrow so callbacks don't need the sandbox lock
  2. Temporarily release the sandbox lock before dispatching to host functions, reacquire after
  3. Provide a shared FFI/binding helper crate that handles this pattern correctly for any language binding

Reproduction

const loaded = await sandbox.getLoadedSandbox();

proto.registerHostModule('mymod', (mod) => {
  mod.registerHostFunction('callback', async () => {
    // This deadlocks (or returns ERR_REENTRANT with the fix)
    await loaded.callHandler('other_handler', {});
    return 'result';
  });
});
主要语言
Rust
星标
13
派生
5
平均合并
6 天 6 小时
30 天内合并 PR
17

环境准备

在 Codespaces 中打开

在浏览器里用你自己的 GitHub 账号启动这个项目的开发容器。

  • 没有 Dockerfile 或 Docker Compose 文件
  • 没有 Pull Request 模板
  • 阅读贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

hyperlight-dev/hyperlight-js 的其他 Issue

查看 hyperlight-dev/hyperlight-js 的全部 Issue

相似的 Issue

更多 Rust Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。