Operate

Capabilities and resource limits

Make each host capability and execution budget an explicit choice.

Default-deny host access

Wasmd does not automatically inherit the host filesystem, environment, or network. Preview 1 offers 46 capability-based imports. A host that supplies directories, environment variables, network access, or host functions is extending the trust boundary.

Bound guest execution

Fuel, epoch deadlines, cancellation, and limits for memory, tables, stacks, and GC constrain guest execution. Memory-page limits are not a total process RSS limit. GC offers explicit bounded steps, but full collection, destruction, and allocation pressure are not hard-real-time operations.

Keep interface claims versioned

Component execution and WASI 0.2/0.3 development profiles are implemented, with distinct capability policies and acceptance reports. The published 1.0 security policy excludes Component Model and Preview 2 from its release claim. Do not equate a development feature with an expanded release security guarantee.

Verify releases and report issues

Verify checksums and release attestations against a trusted repository, workflow, tag, and source commit. Report vulnerabilities privately with the affected version, platform, minimal reproducer, and impact. Follow the repository security policy for current reporting instructions.

Keep the source in view

Based on the current repository documentation. Check your installed version and the linked acceptance records when adopting development features.

Read the Wasmd source document ↗
Explore all documentation →