Repository navigation
Conversation
std::time::Instant::now and SystemTime::now panic with RuntimeError: unreachable on wasm32-unknown-unknown, which crashed the server-side auction (AuctionObservationContext) and would also crash the template cache and DataDome protection-scope cache on Cloudflare Workers. Switch those call sites to web_time (a std re-export on native and WASI). Add scripts/lint-wasm-clock.sh, run in CI, which uses a wasm32-unknown-unknown clippy pass to reject std clock calls in trusted-server-core.
erik-sv
force-pushed
the
wasm-safe-clock
branch
from
October 5, 2026 20:04
67225b6 to
a33d3ac
Compare
12 of 14 tasks
Collaborator
Collaborator
|
Closing since duplicate of #1226 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
std::time::Instant::now()andstd::time::SystemTime::now()panic onwasm32-unknown-unknown, the Cloudflare Workers target. A server-side auction on Cloudflare calls one of them for every dispatched auction, so the Worker crashes (Cloudflare Worker panics when a server-side auction runs (std::time::Instant::now()on wasm32-unknown-unknown) #1240). This PR moves the request-path call sites intrusted-server-coretoweb_time.scripts/lint-wasm-clock.sh, run in CI, so the std calls cannot come back.web_timere-exports the std types.Changes
crates/trusted-server-core/src/auction/telemetry.rsInstantfromweb_time. CoversAuctionObservationContext::from_parts(the reported panic) and theelapsed()call.crates/trusted-server-core/src/integrations/datadome/protection_scope.rsInstantfromweb_time;Durationstaysstd::time. Protection-scope cache expiry.crates/trusted-server-core/src/publisher.rsInstantfromweb_timefor template-cache expiry.origin_shared_ttlderives itsSystemTimefromweb_time::SystemTime::now();origin_shared_ttl_atstill takes a stdSystemTimebecausehttpdateparses into that type.scripts/lint-wasm-clock.sh,scripts/clippy-wasm-clock/clippy.tomlwasm32-unknown-unknownwith its own config that denies onlystd::time::Instant::nowandstd::time::SystemTime::now..github/workflows/format.ymlcargo clippy-cloudflare-wasm.AGENTS.mdWhy a separate lint config. A
disallowed-methodsrule in the workspaceclippy.tomlcannot work: on native andwasm32-wasip1,web_time::Instantandweb_time::SystemTimeare the std types, so the rule also flags every correctweb_timecall. In a trial it produced about 36 false positives incargo clippy-fastly. Onlywasm32-unknown-unknownhas distinct types, so the lint runs on that target alone. It coverstrusted-server-core; adapter crates are not linted.Left alone:
chrono::Utc::now()inauction/telemetry.rs,rotation.rsandintegrations/datadome/protection.rs. chrono's defaultwasmbindfeature reads the JS clock onwasm32-unknown-unknown. That is inferred from chrono's default features and was not run on Cloudflare.Closes
Closes #1240
Test plan
Run locally on this branch, based on
80483011:cargo fmt --all -- --checkcargo clippy-fastly,clippy-axum,clippy-cloudflare,clippy-cloudflare-wasm,clippy-spin-native,clippy-spin-wasm,clippy-cli,clippy-codegenscripts/lint-wasm-clock.shcargo test-fastly(3110 passed),cargo test-axum(43),cargo test-cloudflare(53),cargo test-spin(87); 0 failedcargo test --manifest-path crates/trusted-server-integration-tests/Cargo.toml --test parity(17 passed)cargo build --package trusted-server-adapter-fastly --release --target wasm32-wasip1AGENTS.md(covers theAGENTS.mdedit)Regression guard: the panic happens only inside a
wasm32-unknown-unknownruntime, which the native and Fastly test runners do not provide, so the lint is the regression test. On80483011without the core change,scripts/lint-wasm-clock.shfails on all six call sites (telemetry.rs:201,protection_scope.rs:405and:435,publisher.rs:2336,:5239and:6465). With the change it is clean.Real Cloudflare runtime: before the rebase, on
666953a0, the Cloudflare adapter underwrangler dev --local(worker-buildbundle) crashed withRuntimeError: unreachableinAuctionObservationContext::from_partson an auction page. With this change, the same setup served the page with bids, and the bidder received exactly one auction request.Not exercised:
Checklist
unwrap()in production codetracingmacros (notprintln!)