Files
colbymchenry__codegraph/codegraph-kernel/Cargo.toml
Colby McHenry cbf84855e7 fix(kernel): guard the native walkers against stack overflow and defer deep files to wasm (#1581)
A C/C++ (or any other kernel-routed) file with extremely deep nesting —
clang's 16,384-brace `parser_overflow.c`, fuzzer corpora — parsed fine
(tree-sitter is iterative) and then overflowed the native stack of the
kernel's recursive walker. A native overflow is uncatchable: the parse
worker is a thread of the `codegraph` process, so the SIGSEGV took the
whole indexer down with no message, no partial index and no per-file
fallback. Worker threads get Node's 4 MiB default stack; the 8 MiB main
thread only moved the cliff (100k levels still died), so a bigger
`resourceLimits.stackSizeMb` was never a fix.

The walkers now guard their own recursion against the CALLING THREAD's
real stack bounds (`codegraph-kernel/src/stack.rs`: glibc/musl
`pthread_getattr_np`, macOS `pthread_get_stackaddr_np`, Win32
`GetCurrentThreadStackLimits`; one thread-local load + one compare per
recursive entry, inserted by the `stack_guard!` macro at all 150
self-recursive / on-cycle walker functions). Within 256 KiB of the limit
the walk stops descending and latches a flag; `stack::run_guarded` turns
a tripped walk into the kernel's existing `defer:` routing signal, so the
file takes the wasm path — whose walker catches its own JS `RangeError`
per file — and lands as a partial result with a recorded parse error
while the rest of the repository indexes normally. Platforms without a
bounds query fall back to a fixed descent budget that is safe on any
stack ≥ 2 MiB. No Worker stack bump; no new crates beyond `libc`
(already in the lock file transitively).

Validated: the reporter's `deep.c` inside a default 4 MiB worker goes
from rc=132/139 to a clean `deferred` exit; `codegraph init` on a repo
holding it exits 0 with the file recorded; 60k-deep expressions in every
default-routed language survive on the main thread and in a worker;
Rust unit tests drive the walkers on a 1 MiB thread; all 15 existing
kernel parity suites unchanged; index wall-clock on express and redis
within run-to-run noise with identical node/edge counts; Linux verified
in Docker (node:22-bookworm, glibc bounds path).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LxZj6W6Y1SHXwvpT3uwJpK
2026-08-22 11:01:26 -07:00

79 lines
3.3 KiB
TOML

[package]
name = "codegraph-kernel"
version = "0.1.0"
edition = "2021"
license = "MIT"
publish = false
description = "Native extraction kernel for CodeGraph — tree-sitter parse+extract with one JS boundary crossing per file"
[lib]
crate-type = ["cdylib"]
[dependencies]
napi = { version = "3", default-features = false, features = ["napi8"] }
napi-derive = "3"
tree-sitter = "0.25"
sha2 = "0.10"
regex = "1"
# Grammars — MUST stay revision-matched with the wasm grammars the fallback
# path loads (tree-sitter-wasms npm package / src/extraction/wasm/). The
# kernel-grammar-parity test asserts node-kind-table equality at test time;
# bump these together with the wasm side or that gate fails.
tree-sitter-typescript = "0.23"
tree-sitter-javascript = "0.25"
tree-sitter-java = "0.23"
tree-sitter-python = "0.23"
tree-sitter-go = "0.23"
# Pinned exact: the vendored wasm (src/extraction/wasm/) was built from these
# tags' checked-in parser.c, sha-matched against these registry tarballs
# (R7a prep, #1345). A patch bump here without re-vendoring breaks the match.
tree-sitter-c = "=0.24.2"
tree-sitter-cpp = "=0.23.4"
tree-sitter-rust = "=0.24.2"
# csharp: the vendored wasm (#717) predates the kernel and was verified
# table-identical to this crate's tarball (ABI 15, STATE_COUNT 8053, node-kind
# and field tables — csharp checklist header). Bump crate + wasm together.
tree-sitter-c-sharp = "=0.23.5"
# ruby: content bump, ABI stays 14 (the v0.23.1 tag predates the ABI-15
# generator) — kernel-grammar-parity asserts same-revision, not same-ABI.
tree-sitter-ruby = "=0.23.1"
# php: the walker calls LANGUAGE_PHP (the full HTML-interleaving variant the
# wasm ships) — NEVER LANGUAGE_PHP_ONLY, which errors on leading HTML.
tree-sitter-php = "=0.24.2"
# swift: the vendored wasm is built from THIS crate's tarball src/ (the tag's
# checked-in parser.c is an older ABI-14 generation that can never sha-match;
# grammar.json rules are JSON-equal — swift checklist header). parser.c is
# ~20MB generated — expect slow compiles.
tree-sitter-swift = "=0.7.3"
# r: the vendored wasm IS r-lib v1.2.0 and this crate's tarball ships both
# generated artifacts sha-identical to the tag (parser.c 6221657347…,
# scanner.c 1209d11076… — r checklist §Grammar prep). ABI 14 (the tag
# predates the ABI-15 generator) — parity asserts same-revision, not
# same-ABI (ruby precedent). Bump crate + wasm together.
tree-sitter-r = "=1.2.0"
# luau: the vendored wasm IS tree-sitter-grammars v1.2.0 and this crate's
# tarball ships parser.c/scanner.c sha-identical to the tag (8f25bc17… /
# a157bb52… — lua-luau checklist §Grammar prep). ABI 14. Lua itself is
# vendored C (build.rs) — its v0.4.1 revision is not on crates.io.
tree-sitter-luau = "=1.2.0"
# tree-sitter-language: the version-agnostic LanguageFn shim for the vendored
# kotlin grammar C (see build.rs — no kotlin crate dep is possible).
tree-sitter-language = "0.1"
# Stack-bounds queries for the walker stack guard (src/stack.rs, #1581):
# pthread_getattr_np / pthread_get_stackaddr_np. Already in the lock file
# transitively; Windows uses a hand-declared kernel32 extern instead.
[target.'cfg(unix)'.dependencies]
libc = "0.2"
[build-dependencies]
napi-build = "2"
cc = "1"
[profile.release]
lto = true
codegen-units = 1
strip = "symbols"