65 ms·
Standardizing WASI: A system interface to run WebAssembly outside the web
- justinmchase 8y agoLove it. This could be a huge innovation and really push the dream of cross platform development to the next level. I suppose this would have pretty big implications for Electron or a similar successor to aid in the UI portion of this endeavor.
- titanix2 8y agoYeap, so innovative it existed already for decades (virtual machine executing some fixed bytecode).
- superfist 8y agoBut lack of good and safe isolation was a serious problem
- rapsey 8y agoProperly sandboxed VM that you can compile practically any language into?
- AnIdiotOnTheNet 8y agoYes, it's called DOSBox. Or QEMU with dynamic syscall translation if you want to be real fancy.
- pjmlp 8y agoAS/400 TIMI comes to mind, and CLR as well.
- Rusky 8y agoThe CLR is not a great target for running unmodified C code. I suspect that was included in "practically any language."
- pjmlp 8y agoYeah, Managed C++ and C++/CLI don't exist.
- Rusky 8y agoI was careful to say "unmodified." C++/CLI is hardly that. It's also not at all sandboxed the way wasm is. Why the chip on the shoulder?
- pjmlp 8y agoC++/CLI is just ISO C++ plus a couple of language extensions, you know like the Linux kernel is ISO C plus GCC extensions. I hardly see the difference. No chip on the shoulder, just an old guy that has seen dozens of VMs since the mid-80s, delved into others from earlier decades, which doesn't buy into WASM marketing.
- int_19h 8y agoYou're conflating C++/CLI with the MSVC /clr compiler switch. They're distinct. With /clr:pure (which produces CIL only, although it is allowed to use memory-unsafe features like pointers), the entirety of ISO C90 is supported on CLR, with the sole exception of setjmp/longjmp. C++/CLI adds language extensions that allow one to interact with the CLR object model from C++ code. It is only needed if you need to call into the .NET standard library, or other managed libraries - i.e. if your C code is not portable to begin with.
- Rusky 8y agoI'm not conflating anything. And as I said, none of this is sandboxed like WebAssembly so it's hardly a comparison anyway.
- int_19h 8y agoCLR sandbox should not be considered a meaningful security boundary at this point. CAS and partial trust are both officially obsolete. The problem is always complexity. It can be difficult to reason about safety with so many features on bytecode level. There have been exploits using dynamically-generated methods, exception filters, and vararg handling - note the near-lack of any common patterns here other than they're all obscure features of the platform, the security impact of which wasn't fully analyzed. For example, a long time ago, I reported the vararg exploit, which boiled down to the fact that you can have ArgIterator over an argument list containing another ArgIterator, allowing the latter to be mutated via the former. Thus, you can stash away an ArgIterator to the arguments of a function call that has already returned. This is basically the same as having a managed reference to a managed reference, and it's exactly why CLR prohibits this - but they forgot that ArgIterator is also a kind of a managed reference.
- pjmlp 8y agoAnd WASM remains to be battle tested in the wild, as in the juicy target of millions of black hats out there. Forcing internal corruption of code produced from C compilers (like doing a stack out of bounds data overwrite due to incorrenct params size) is perfectly viable. Yeah the exploit doesn't leave the sandbox, so what. It can still be used to direct the sandboxed code to produce other outcome from the called functions.
- arcticbull 8y agoJVM and CLR.
- pjmlp 8y agoYep, just like....wait for it....UCSD Pascal.
- pcwalton 8y agoNobody is saying that the idea of a sandboxed VM is original. The interesting parts of wasm are the theoretically-uninteresting but important-in-practice features: JS interoperability, the LLVM backend, cross-browser support, etc.
- pjmlp 8y agoWell, many are behaving as such. Actually JVM got there first with JS-interoperabily.
- gwbas1c 8y agoWait a second... I thought Java was supposed to do this with the JVM... I thought .Net was supposed to do this with the CLR... What's different now?
- vardump 8y agoDifferent use cases. You don't necessarily want a 10 ton standard library for every use case, like on embedded devices or plugins for a software package. C/C++/Rust being 1st class citizens is also very useful.
- arcticbull 8y agoStandard libraries are what make languages useable. In my experience there's a solid case to be made for a 10-ton standard library (for targets with an operating system) or basically none whatsoever (for embedded). A thin standard library is always going to be too small to do useful things easily at the high level and too big to be deployed on an embedded system. Rust is good because it can play in both sandboxes.
- kllrnohj 8y agoFor embedded devices you'd always be better just compiling C/C++/Rust directly to the native code. You don't have any portability possibility there in the first place anyway, so why ship inferior code gen with arbitrary restrictions?
- SubiculumCode 8y agoThere is already a WASI and its a standardized IQ test. I did a double take.
- lachlan-sneff 8y agoThis is super cool! We're going to have to rush to implement this in the wasmer runtime!
- gbraad 8y agoThis is what I was thinking. How will this affect wasmer.
- kodablah 8y agoBeen hoping a stdlib for WASM would spring up. So if I wanted to implement a WASI backend (e.g. on the JVM), are the function definitions I should implement here: [0]? I assume string, array, struct, etc layout in WASM mem is as C expects? Also, is it a goal to provide a test suite to test conforming backend implementations (may already be there, didn't look)? Finally, pardon my lack of research before asking, does this mean that an LLVM-based WASM compilation can target this instead of emscripten/libc and the final WASM could reference all of these API pieces as a imports? Is there an expected posix/libc-to-wasi lib? 0 - https://github.com/CraneStation/wasmtime-wasi/blob/wasi/docs/WASI-api.md https://github.com/CraneStation/wasmtime-wasi/blob/wasi/docs...
- tschneidereit 8y ago(Member of the team at Mozilla here ) Yes, that's the list. And the layout of structs, strings, etc is up to the compiler, within the bounds of the restrictions WebAssembly imposes. We'll definitely have a test suite, but this is all early days, so a lot of all that isn't yet in place. And yes, this can be targeted by LLVM-based and other compilers. In fact, Emscripten could use this as the foundation for their POSIX-like libc and library packages. The syscalls are indeed exposed as Wasm function imports.
- echeese 8y agoWill WASI normalize differences between platforms? e.g. convert argv or paths to a consistent character encoding?
- tschneidereit 8y agoYes!
- azakai 8y agoWhat about platform differences like how file permissions work on windows vs posix? (i.e., stuff that Python does not fully normalize)
- pspeter3 8y agoHow much of the Fuscia model apply to Web Assembly? It seems like they could share similar security models
- tschneidereit 8y agoWe've mainly based the current design on CloudABI/Capsicum, but it's all early days, and Fuchsia is on our list of systems to at the very least take heavy inspiration from :)
- writepub 8y agoWill this be backwards compatible with existing libc?
- sunfish 8y agoThis tutorial gives an overview of how compatibility with existing portable C code works: https://github.com/CraneStation/wasmtime-wasi/blob/wasi/docs/WASI-tutorial.md https://github.com/CraneStation/wasmtime-wasi/blob/wasi/docs...
- steveklabnik 8y agoThis year is extremely interesting times for WebAssembly, there's a number of these different runtimes popping up. The effects of all of these decisions, including stuff like this, won't be felt until next year... I wonder how much adoption this will get, but the lineup looks extremely strong.
- maxgraey 8y agoWASI layer interface for AssemblyScript from Frank Denis: https://github.com/jedisct1/wasa https://github.com/jedisct1/wasa
- tschneidereit 8y agoOh, this is amazing!
- VikingCoder 8y agoWASI will have some interesting milestones ahead of it: * Self-hosting (WASI can run inside WASI) * GCC can run in it * Linux can run in it * Quake can run in it * Chrome can run in it
- londons_explore 8y agoHow can self-hosting be achieved considering SPECTRE etc? Surely, since WASI inside WASI couldn't be in different OS processes, there would be an opportunity to leak data between the inner and outer WASI?
- VikingCoder 8y agoThere's a difference between asking is self-hosting can be achieved, and if self-hosting can be secure. Second, I can run an emulator in WASI that implements WASI, including multiple processes. They might not be true OS processes. But as long as I have threads, I can do something. Also, maybe we get WASI without high precision clocks. /shrug
- dboreham 8y agoDoesn't Quake traditionally come first?
- TheAceOfHearts 8y agoIsn't Doom the standard go-to?
- ironchief 8y agoThese Mozilla blogs are some of the best edited, articulated and illustrated explanations I've seen on the web. I wish more people could put in the resources to help communicate their mission like this.
- humblebee 8y agoThe author, Lin Clark[0], is the person behind Code Cartoons[1]. She does absolutely amazing work. Unfortunately, there isn't really a single place to find everything she has done. She has done quite a few conference talks[2] as well. [0] https://twitter.com/linclark https://twitter.com/linclark [1] https://code-cartoons.com/ https://code-cartoons.com/ [1] https://hacks.mozilla.org/category/code-cartoons/ https://hacks.mozilla.org/category/code-cartoons/ [1] https://twitter.com/codecartoons https://twitter.com/codecartoons [2] https://www.youtube.com/playlist?list=PLIIHcC8epcPqhBrQ1dRmILg5e5okOVnER https://www.youtube.com/playlist?list=PLIIHcC8epcPqhBrQ1dRmI...
- hsndmoose 8y agoAdding a podcast Lin was on, detailed just how much work goes into creating Code Cartoons. It's pretty amazing and highly appreciated. https://changelog.com/podcast/294 https://changelog.com/podcast/294
- droobles 8y agoExcuse me if I come across as naive, I'm kind of a noob on these architectural topics, but how is this different/better than what the JVM is/accomplishes? When WASM first popped up I thought about the similarities with Java Web Applets and Flash.
- steveklabnik 8y agoI wrote a blog post about that a few months back, here's the HN discussion https://news.ycombinator.com/item?id=17616459 https://news.ycombinator.com/item?id=17616459
- droobles 8y agoThis is an excellent write up, thank you!
- jxcl 8y ago1. It's an open standard that the major browsers have agreed to, so it's not a plugin that you have to install. A WASM app will work seamlessly in your browser without any additional software. 2. WASM is designed from the ground up as a compile target, not a language. We already see many languages with support for building to WASM. C, C++, Rust, and eventually when WASM supports garbage collection we'll probably see Python, JS, Go, all with support for compiling to WASM.
- pjmlp 8y agoUNCOL and TIMI reborn.
- slimsag 8y agoGo already can be compiled to WASM, and it is likely that the Go GC will always perform better than the WASM one for Go applications (with some minor exceptions)
- the_duke 8y agoThe current Go implementation is pretty slow for a number of reasons though. GCs usually need low level system acces in a way that is not supported by WASM for obvious reasons (security, sandboxing, ...). Go also has problems with the way they implement Goroutines if I remember correctly. WASM will definitely need some kind of GC bridge to make things efficient for garbage collected languages. Potentially with certain primitives exposed that make shipping your own GC efficient. We'll see how it develops.
- dmitriid 8y agoShould they standardize to run WebAssembly on the Web first? There's like hundreds of things to do: https://webassembly.org/roadmap/ https://webassembly.org/roadmap/, https://webassembly.org/docs/future-features/ https://webassembly.org/docs/future-features/
- pjmlp 8y agoNo time, busy reinventing VMs.
- tschneidereit 8y agoWe're working on that, too :) See this post from last Fall where we laid out a way to think about where WebAssembly is going, which use cases to enable, and how: https://hacks.mozilla.org/2018/10/webassemblys-post-mvp-future/ https://hacks.mozilla.org/2018/10/webassemblys-post-mvp-futu...
- Touche 8y agoThis is nice and I'm excited about it, however there is a concern that people are going to start building code that targets WASI and then shim it to run in the browser. This happened to JavaScript when Node.js was released; people began using APIs intended for servers and then shimmed them to also run in the browser resulting in code bloat. I'm worried that the same is going to happen here; the video actually encourages doing just that. The browser is not a platform that should be treated as secondary.
- AnIdiotOnTheNet 8y agoI think the browser shouldn't be a platform at all, frankly, and WASI is one possible way we can finally stop trying to shoehorn it into being one. If everything runs a WASI runtime, which is designed to run applications from the ground up, there really isn't any need for the browser to run applications anymore, is there?
- Touche 8y agoYeah, sure, you go ahead and reinvent 30 years of cross-platform application APIs. I'll keep using the web until your new ones match maturity.
- AnIdiotOnTheNet 8y agoWe have had dozens of cross-platform application APIs running in VM sandboxes, yet the browser is intent on slowly reinventing them anyway.
- Touche 8y agoEh, I'm not trying to discourage you from building cool apps on top of WASI. I just hope you understand what you're up against. And most of it is not technical; you've got to convince Apple to include a WASI runtime on iOS (among others).
- 8y ago
- deleted 8y ago[deleted]
- naikrovek 8y agook, so I hate to be this guy and I'm going to do it anyway because it has to be said: Did they just invent Java again? Aren't they promising what Java promised? Won't they hit the same problems that Java hits during its write-one-run-anywhere promises? I'm asking honestly - why is WebAssembly outside of the browser needed?
- jzoch 8y agoThe idea of isolation that java espoused is not a bad one - it just wasnt executed well. Its not a java only idea either - see Native Client[0]. As with all things, execution and marketing matter. Java was lacking in both. [0] - https://static.googleusercontent.com/media/research.google.com/en//pubs/archive/34913.pdf https://static.googleusercontent.com/media/research.google.c...
- naikrovek 8y agoOK, that's all correct and valid. Java still exists and is a valid deployment platform. Why is WebAssembly outside of the browser needed?
- JeremyBanks 8y agoUsing Oracle's Java Programming Language is an immeasurable legal liability.
- deleted 8y ago[deleted]
- naikrovek 8y agoThere are open source and non-Oracle Java virtual machines you can buy support from if Oracle isn't your cup of tea. It's not really a legal liability either. Lawyers for companies who use Java go over those agreements with a fine tooth comb and approve them before they're signed. There are no surprises (if your attorneys aren't frauds.)
- writepub 8y agoI would love for WASI/WasmTime to emphasize on: 1. Backwards compatibility with existing libc. (Maybe pick musl) 2. Platform agnostic wasm generation: the same wasm file should run in the browser (with emscripten polyfills) and across ALL OS-es, mobile included. List: iOS, Android, Mac, Linux, Windows, FreeBSD #1 shall enable decades of legacy programs to work with minimal porting, while #2 shall enable true cross platform capabilities without multiple codebases. Specifically, don't repeat what node did: digress from browser js semantics, instead of polyfilling them
- jcranmer 8y ago> 1. Backwards compatibility with existing libc. (Maybe pick musl) Honestly, that ought to be a non-goal. We already know that POSIX often enforces models that we don't want--filesystem permissions and the fork model are two good examples of things that are broken. So why start with "implement POSIX"?
- writepub 8y agoThe backwards compatibility isn't a testament for POSIX's merit. Sure, please introduce better, safer paradigms whenever you set standards, but enabling legacy software to run immediately is a great value proposition. Also, goading legacy maintainers to adopt the newer, safer paradigms is likely more effective if you show them the traction the new platform is gaining
- Crinus 8y agoPOSIX != C and from what i understand from the official docs, they already have a (musl derived, even) C library.
- AnIdiotOnTheNet 8y agoThe C stdlib is so married to POSIX they may as well be the same thing.
- pjmlp 8y ago
- Others 8y agoThis is really interesting. As part of my undergrad research I've built `silverfish`, which is a tool that turns WASM binaries into LLVM bytecode. It's currently pretty chained to how I personally compile my C to WASM, but it'd be pretty cool to get it working with this standard! Here's a link: https://github.com/gwsystems/silverfish https://github.com/gwsystems/silverfish -- although the README is pretty sparse, so you'll have to look at the code.
- lyxsus1 8y agowow, thank you. that's amazing!
- Svoka 8y agoAfter reading about all the AMP and Google, Mozilla's blog is a welcome relief. Always a pleasure.
- gouh 8y agoThis sounds great. Basically the web created a cross platform & sandboxed API to access everything we need (Camera, Sensors, OpenGl through WebGl, etc.) but it was very opinionated (for historical reasons) as it imposes the slow JS, the DOM, CSS/HTML etc. Now this is the same idea but, this time, one layer lower so that we can have performance, the language we want, etc. This is kind what I always wished would happen. It will be interesting to see how the sandboxing will work with already existing sandboxing solutions. For e.g a WebAssembly app packaged as a Android/Flatpak/UWP/etc. , there will be the need to make mappings between the permissions of the two sandbox systems. Or even maybe one day we'll have the Webassembly sandbox as the only sandbox (like in https://github.com/nebulet/nebulet https://github.com/nebulet/nebulet)
- equalunique 8y agoI love cross-over episodes like this. Patiently waiting for when eBPF gets it's turn inside the browser.
- _jn 8y agoCan't help being reminded of that talk by Gary Bernhardt: “The Birth & Death of JavaScript”[0] — exploring a hypothetical future where JS takes over everything without (most) anyone using it of their own volition. 0: https://www.destroyallsoftware.com/talks/the-birth-and-death-of-javascript https://www.destroyallsoftware.com/talks/the-birth-and-death...
- tokyodude 8y agoExcept entirely irrelevant as WASM is not Javascript.
- _jn 8y agoSure, though it’s still a web technology taking over an otherwise unrelated space ¯\_(ツ)_/¯
- deleted 8y ago[deleted]
- int_19h 8y agoI don't think it's unrelated. Despite the name, WASM isn't really a "web technology" - it's a sandbox technology and a compile-once-run-everywhere technology, and there has always been demand for that outside the web, even before the web existed. It might be that the web is what created enough demand for it to happen in the end, but what do we care? The problem with JS was never that it's a web technology. It's that it's a bad technology that happened to be in the wrong place at the wrong time to get a first mover advantage.
- techntoke 8y agoCan you show me an example of a WebAssembly app that runs in the browser with JavaScript enabled?
- grungleshnorts 8y agoThere are probably newer examples, but from when WebAssembly was coming out: https://s3.amazonaws.com/mozilla-games/ZenGarden/EpicZenGarden.html https://s3.amazonaws.com/mozilla-games/ZenGarden/EpicZenGard... (from https://www.webassemblygames.com/ https://www.webassemblygames.com/ ) https://alpha.iodide.io/ https://alpha.iodide.io/ https://www.figma.com/blog/webassembly-cut-figmas-load-time-by-3x/ https://www.figma.com/blog/webassembly-cut-figmas-load-time-... https://github.com/mdn/webassembly-examples/ https://github.com/mdn/webassembly-examples/ https://github.com/emscripten-core/emscripten/wiki/Porting-Examples-and-Demos https://github.com/emscripten-core/emscripten/wiki/Porting-E...
- wolfspider 8y agoIf there are any WIP implementations utilizing CloudABI and Capsicum they would be interesting to look at.
- preordained 8y agostahp...
- jasonhansel 8y agoSince it's based on web tech, is this going to be focused on async, rather than synchronous, calls?
- throwaway66666 8y agoAnd here I am still writing asmjs by hand. Do we know if that's fully deprecated or are there any plans to keep it fast and loved like wasm?
- thosakwe 8y agoWhat does this mean for host bindings?
- hathawsh 8y agoSolomon Hykes, co-founder of Docker, believes WASM+WASI could take the place of Docker. https://twitter.com/solomonstre/status/1111004913222324225 https://twitter.com/solomonstre/status/1111004913222324225
- talkingtab 8y agoThis. I don't have a clear enough mental model for either docker or wasm+wasi, but I immediately thought of docker. What is docker except a bunch of purpose build operating system instances? And why do we need Linux installations (as much as I am a fan of Linux) when we could just run on WASI? And Electron, where each instance runs on an individual instance of a browser?
- simcop2387 8y agoThis is the same reason that things like unikernels have been built for. They haven't taken off because of how difficult it is to rebuild your application to also contain it's kernel, but this kind of sandboxing with WASM and WASI doesn't require that and could likely make things a lot simpler to deal with.
- pjmlp 8y agoYep, just like JEE servers deployed bare metal, oh wait.
- talkingtab 8y agoI'm not sure I get the reference? Could you explain a bit? I know what Java EE servers are, but don't recall anything about bare metal deployments. Comparing my experiences with using JEE and Docker was that they are nothing alike. Just unclear as to your point.
- simcop2387 8y agoJava was at one point going to have a bunch of CPUs[1] built around the JVM bytecode, that would have allowed J2EE and such to run on the bare metal hardware, but they largely didn't go anywhere. The most successful attempts that i'm aware of are Jazelle[2] and Java-card[3] plans to augment the software solutions [1] https://en.wikipedia.org/wiki/Java_processor https://en.wikipedia.org/wiki/Java_processor [2] https://en.wikipedia.org/wiki/Jazelle https://en.wikipedia.org/wiki/Jazelle [3] https://en.wikipedia.org/wiki/Java_Card https://en.wikipedia.org/wiki/Java_Card
- _bxg1 8y agoI've heard people predict that the future of the web is to replace userland, to make every program cross-platform and sandboxed close to the metal, and for JavaScript to fade into a family of "web"-targeted languages. Looks like it's happening.
- millstone 8y agoIn this scenario, what's the point of having more than one OS?
- Yoric 8y agoFor end-users, I'm not convinced that there is one. Well, besides keeping competition/innovation alive.
- Jach 8y agoDifferences of opinion in what/how to run code outside of whatever browser people decide the sandbox boundaries are.
- int_19h 8y agoSame as with POSIX - different implementations of the same standardized interface that target different hardware, and have different quality of implementation (possibly optimized for different use cases).
- skybrian 8y agoThis technology will become more compelling once there is a deployment target that runs WASM+WASI binaries but won't run native binaries. Nothing like that exists (it's too early) but it would be interesting to know if anyone is planning anything.
- naikrovek 8y agoThe amount of hatred in this thread for non-web technologies is insane.
- krapp 8y agoFunny, I see the exact opposite. People dismissing WASM as unecessary, or just another Java, or just another Flash, or just another Node.js, or something that shouldn't exist outside of the browser. If it didn't have "web" in the name, I think people would hate it a lot less.