Skip to content

build(deps): bump rwasm to 0.7.2 - #570

Merged
dmitry123 merged 3 commits into
develfrom
build/bump-rwasm-0.7.1
Sep 28, 2026
Merged

dmitry123 merged 3 commits into
develfrom
build/bump-rwasm-0.7.1

Conversation

@dmitry123

@dmitry123 dmitry123 commented Sep 25, 2026 •

Copy link
Copy Markdown
Member

Summary

  • rwasm 0.6.0 → 0.7.1 in the workspace manifest and in all five lockfiles (root, contracts/, examples/, e2e/evm/, e2e/codec/); wasmtime-*-rwasm 45.0.0-rwasm.2 → rwasm.3 follows; the revm fork is relocked to v107-patched at build(deps): bump rwasm to 0.7.1 revm-rwasm#64, which pins the same rwasm.
  • StrategyDefinition::Rwasm gained entrypoint_type; the four state-routed constructions pass None (behaviour of 0.6.0).
  • docs/07-rwasm-integration.md: what 0.7.1 changes for existing bytecode, how the bump is verified, and the node-before-guest order for the wide-arithmetic opcodes.

What 0.7.1 means for the node

  • Existing bytecode, no fork gate: the interpreter's value-stack window is N_MAX_STACK_SIZE + 13 (was + 4, rwasm#212), and the Wasmtime backend now traps StackOverflow at the interpreter's recursion depth and window instead of its native 32 KiB stack (rwasm#213). Same class as the 0.5.0/0.6.0 bumps: fluent re-execute on both flavours before a release ships it.
  • Admission: wide arithmetic is accepted unconditionally by the 0.7.x compiler and nodes before 0.7.0 cannot decode opcodes 90-93. Rollout order: every node on this release first, then the WASM-runtime / runtime-upgrade guests rebuilt with an SDK on 0.7.x, and only then guests built with +wide-arithmetic. The published SDK must not enable the target feature by default before that.
  • Compiler output: 0.7.0 was byte-identical to 0.6.0 for every guest; 0.7.1 emits smaller StackCheck reservations for functions with dead code after end and different active-segment table entries (rwasm#220). Historical state is unaffected (user WASM is compiled by the on-chain WASM runtime guest, system runtimes by 0x…520010), but bins/runtime-upgrade artifact equality against an older on-chain compiler will differ, and the guest builds must stay on the same rwasm as the node, which is why the contracts/ lock moves in the same commit.
  • Known upstream issue, not reachable by anything on chain: in wasmtime-rwasm 45.0.0-rwasm.3 a return_call after a non-tail call in the same function reads stale stack counters and can trap StackOverflow on the Wasmtime backend only. No historical hint uses tail calls (rustc guests are built without +tail-call); it needs a fork fix before any tail-call payload lands.

Verification

  • Replay of every historical runtime-upgrade payload through RwasmModule::new_checked + validate_system_runtime: mainnet 138, testnet 188, devnet 226 → 552/552 decode and admit on both std and std,wasmtime.
  • Full CI-equivalent matrix locally on the final lockfiles: cargo fmt --check, cargo fetch --locked ×5, clippy root/contracts/examples with -D warnings, nextest root 985 tests ×2 flavours, contracts 138, examples 46, evm-e2e good_coverage_tests 34 ×2 and fixture 12 ×2, cargo check --all --locked.
  • Block gas limit scan on all three networks (for the 100 M cap from feat: cap transactions at 100 Mgas #569): mainnet and devnet max 100 M at genesis only, testnet max 50 M.

Owed before a release: fluent re-execute of mainnet, testnet and devnet on both flavours.

Summary by CodeRabbit

  • Documentation
    • Updated rWasm integration guidance for 0.7.x, covering entrypoint signature checks, stack behavior, wide-arithmetic compatibility, artifact comparison, and upgrade requirements.
  • Chores
    • Updated the workspace’s rWasm version to 0.7.2.

rwasm 0.7.1 keeps the wire format and fuel schedule of 0.6.0 and adds the
wide-arithmetic opcodes (90-93), emulates the rwasm recursion depth and
value-stack window on the Wasmtime backend (wasmtime-rwasm 45.0.0-rwasm.3),
widens the interpreter's trampoline headroom from 4 to 13 slots, and no
longer grows a function's StackCheck for dead code after end.

StrategyDefinition::Rwasm gained entrypoint_type, the Wasm signature a
named entrypoint is checked against; the four state-routed constructions
pass None, which keeps the executor behaviour of 0.6.0.

All five lockfiles move together (root, contracts, examples, e2e/evm,
e2e/codec) so the guest builds and the node compile with the same rwasm:
with the contracts lock left behind, the runtime-upgrade tests that compare
a host compile with what the guest installed fail on the smaller
StackCheck reservations. The revm fork is relocked to v107-patched at
revm-rwasm#64, which pins the same rwasm.

Verified: every historical runtime-upgrade payload of mainnet (138),
testnet (188) and devnet (226) still decodes and passes
validate_system_runtime on both flavours.
Record what 0.7.1 changes for existing bytecode (interpreter window,
Wasmtime stack-limit emulation), how the bump is verified (payload replay
and re-execution), the node-before-guest order for the wide-arithmetic
opcodes, and that node-compiled artifacts no longer match bodies produced
by an older on-chain compiler byte for byte.
@coderabbitai

coderabbitai Bot commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 0b74ffbc-7337-46ca-882e-2506e4466703

📥 Commits

Reviewing files that changed from the base of the PR and between bfd9409 and c2386a7.

⛔ Files ignored due to path filters (5)
  • Cargo.lock is excluded by !**/*.lock
  • contracts/Cargo.lock is excluded by !**/*.lock
  • e2e/codec/Cargo.lock is excluded by !**/*.lock
  • e2e/evm/Cargo.lock is excluded by !**/*.lock
  • examples/Cargo.lock is excluded by !**/*.lock
📒 Files selected for processing (2)
  • Cargo.toml
  • docs/07-rwasm-integration.md
🚧 Files skipped from review as they are similar to previous changes (2)
  • Cargo.toml
  • docs/07-rwasm-integration.md

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The workspace upgrades rWasm from 0.6.0 to 0.7.2. Runtime strategy configurations set entrypoint_type to None. The integration guide documents compilation behavior, upgrade constraints, artifact comparison, and verification details.

Changes

rWasm upgrade

Layer / File(s) Summary
Dependency and runtime strategy
Cargo.toml, crates/runtime/src/executor.rs, crates/runtime/src/runtime/contract_runtime.rs
The workspace dependency changes to rWasm 0.7.2. Contract runtime strategies and test helpers set entrypoint_type to None.
Compilation and verification contract
docs/07-rwasm-integration.md
The guide records rWasm 0.7.2 compilation behavior, upgrade constraints, artifact comparison guidance, and replay verification details.

Priority: ➖ Normal

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Other

Suggested reviewers: d1r1

Merge Risk: ⚪ Minimal · up to c2386

The dependency and runtime-strategy changes are consistent with the documented behavior; no actionable issue remains before normal merge checks.

Security Architecture Review

Security architecture risk: 🟡 Moderate · up to bfd94

The upgrade has a documented rollout order, but changes to execution limits can affect existing bytecode before every node is upgraded. Compatibility during a partial rollout needs confirmation.

Retained concerns

  • Medium · security · inferred: The documented stack-window and trap changes apply to existing bytecode without a fork gate. If old and new nodes execute a boundary-case call chain during a partial upgrade, differing outcomes could affect agreement on execution results; mixed-version equivalence is not established by the supplied checks.
  • Medium · security · inferred: Compatibility depends on all nodes upgrading before guests built with the newer compiler or wide arithmetic become executable. The documented sequence addresses this, but the supplied evidence does not establish how it is enforced or recovered if a guest is activated while older nodes remain.
Security review details

Security Blast Radius

  • inferred — The relevant exposure is network-wide agreement on runtime execution, not expanded authority at the changed entrypoint. An attacker-controlled contract reaching a changed execution limit, or newly compiled guest bytecode reaching an older node, could affect nodes running different versions.

Security Findings and Attack Paths

  • inferred — A partial node upgrade is the prerequisite for the identified compatibility paths. No supplied replay result or production rollout evidence demonstrates an exploitable disagreement, and no verified security finding is present.

Trust Boundaries and Controls

  • observed — State-derived contract entrypoints and system-runtime ABI validation remain visible controls. Neither establishes a fleet-wide version barrier.

Resilience and Maintainability Implications

  • inferred — The documented ordering supplies a safe intended sequence, but interruption, repetition, and rollback of a partially completed node-and-guest rollout remain unverified in the available evidence.

Hardening Proposals

  • proposed — Before release, establish mixed-version results for stack-boundary executions and record the prescribed historical replay on both backends. Make completion of the node upgrade a verifiable prerequisite to publishing or activating newly compiled guests, with an explicit recovery plan for partial activation.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 25.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 4 functions across 2 files. (2 skipped: 2… Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely identifies the main change: updating the rwasm dependency to version 0.7.2.
Full details: Docstring Coverage

Explanation

Docstring coverage is 25.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 4 functions across 2 files. (2 skipped: 2 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

Criterion results (vs baseline)


running 170 tests


Tokens Transfer Comparison/1_Original_EVM_ERC20
                        time:   [6.4893 µs 6.5776 µs 6.6793 µs]
Found 4 outliers among 1000 measurements (0.40%)
  4 (0.40%) high severe
Avg gas use: 35253
Tokens Transfer Comparison/2_Emulated_EVM_ERC20
                        time:   [23.408 µs 23.653 µs 23.941 µs]
Found 164 outliers among 1000 measurements (16.40%)
  41 (4.10%) high mild
  123 (12.30%) high severe
Avg gas use: 35253
deployment finished: initcode_size=96719, gas_used=4040188
Tokens Transfer Comparison/3_rWasm_Contract_ERC20
                        time:   [111.61 µs 112.86 µs 114.36 µs]
Found 101 outliers among 1000 measurements (10.10%)
  50 (5.00%) high mild
  51 (5.10%) high severe
Avg gas use: 35473
Tokens Transfer Comparison/4_Precompiled_Universal_token
                        time:   [9.1161 µs 9.2599 µs 9.4350 µs]
Found 89 outliers among 1000 measurements (8.90%)
  20 (2.00%) high mild
  69 (6.90%) high severe
Avg gas use: 29088

case                   gas/tx    native_us     rwasm_us  rwasm_reset   slowdown rwasm_Mgas/s
erc20_transfer          35253          5.7         24.9       5054.5       4.4x     1414.4
arith_loop_20k         541003        466.9       1755.7       6738.3       3.8x      308.1
keccak_loop_10k        721006       4230.8       6780.0      11731.4       1.6x      106.3
sload_loop_2k          285003        115.5       2586.4       7672.7      22.4x      110.2
sstore_loop_2k         287103        140.4       2464.5       7488.0      17.6x      116.5
Greeting Contract Comparison/Original_Greeting
                        time:   [3.4537 µs 3.4865 µs 3.5201 µs]
Found 5 outliers among 100 measurements (5.00%)
  3 (3.00%) high mild
  2 (2.00%) high severe
Greeting Contract Comparison/EVM_Greeting
                        time:   [8.0893 µs 8.1822 µs 8.2916 µs]
Found 5 outliers among 100 measurements (5.00%)
  5 (5.00%) high mild
deployment finished: initcode_size=190, gas_used=68151
Greeting Contract Comparison/WASM_Greeting
                        time:   [17.537 µs 17.901 µs 18.274 µs]
Found 5 outliers among 100 measurements (5.00%)
  5 (5.00%) high mild

Heads-up: runner perf is noisy; treat deltas as a smoke check.

0.7.2 is 0.7.1 plus wasmtime-rwasm 45.0.0-rwasm.4, where a tail call
made after a plain call publishes the caller's rwasm stack counters
again instead of reading the callee's. No opcode, bytecode or fuel
change; the five lockfiles follow the pin.
@dmitry123

Copy link
Copy Markdown
Member Author

Moved to rwasm 0.7.2 (c2386a7e5 build(deps): move rwasm to 0.7.2): 0.7.1 plus wasmtime-rwasm 45.0.0-rwasm.4, where a tail call made after a plain call publishes the caller's rwasm stack counters again (fluentlabs-xyz/wasmtime#15, rwasm#224). No opcode, bytecode or fuel change; the five lockfiles follow the pin and the published crate is built from the rwasm#225 merge commit.

Local verification on the final locks: fmt, cargo fetch --locked ×5, clippy root -D warnings, nextest root 985 ×2 flavours, contracts 138, evm-e2e fixture 12, historical upgrade payload replay 552/552 on both flavours.

@dmitry123 dmitry123 changed the title build(deps): bump rwasm to 0.7.1 build(deps): bump rwasm to 0.7.2 Sep 28, 2026
@dmitry123
dmitry123 merged commit dd95a29 into devel Sep 28, 2026
15 checks passed
@dmitry123
dmitry123 deleted the build/bump-rwasm-0.7.1 branch September 28, 2026 04:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants