Stream: git-wasmtime

Topic: wasmtime / PR #14628 Add required info for Anthropic's OS...


view this post on Zulip Wasmtime GitHub notifications bot (Oct 09 2026 at 16:41):

tschneidereit opened PR #14628 from tschneidereit:oss-scanner to bytecodealliance:main:

This adds a Dockerfile and a threat model description to be consumed by the OSS Scanner program, following the program's template.

The Dockerfile builds quite a bunch of stuff, which is by design: the image build process happens on much larger machines than where they're then run (16 instead of 2 cores, and something more than the 8GB it gets at runtime.)

The threat model largely describes our stability tiers and gives some information on what to focus on. The one place where I decided to deviate a bit is to say that issues with the aarch64 backend should be considered vulnerabilities and reported as such, even though that backend is tier 2. The reason is that a lack of continuous fuzzing is what's holding that backend back from tier 1, and I think with this initiative (plus other auditing we're doing right now) we should be able to reconsider this soon.

<!--
Please make sure you include the following information:

Our development process is documented in the Wasmtime book:
https://docs.wasmtime.dev/contributing-development-process.html

Please review the Bytecode Alliance's AI tool usage policy at
https://github.com/bytecodealliance/governance/blob/main/AI_TOOL_POLICY.md

Please ensure all communication follows the code of conduct:
https://github.com/bytecodealliance/wasmtime/blob/main/CODE_OF_CONDUCT.md
-->

view this post on Zulip Wasmtime GitHub notifications bot (Oct 09 2026 at 16:41):

tschneidereit requested alexcrichton for a review on PR #14628.

view this post on Zulip Wasmtime GitHub notifications bot (Oct 09 2026 at 16:41):

tschneidereit requested wasmtime-default-reviewers for a review on PR #14628.

view this post on Zulip Wasmtime GitHub notifications bot (Oct 09 2026 at 16:42):

tschneidereit commented on PR #14628:

Oh, and I tested the Dockerfile locally, and can confirm that it build successfully, and passes the smoke tests the build process runs. The resulting image is something like 65GB in size—well below the 120GB limit.

view this post on Zulip Wasmtime GitHub notifications bot (Oct 09 2026 at 16:44):

:thumbs_up: pchickey submitted PR review.

view this post on Zulip Wasmtime GitHub notifications bot (Oct 09 2026 at 16:46):

pchickey has enabled auto merge for PR #14628.

view this post on Zulip Wasmtime GitHub notifications bot (Oct 09 2026 at 16:51):

pchickey added PR #14628 Add required info for Anthropic's OSS Scanner program to the merge queue.

view this post on Zulip Wasmtime GitHub notifications bot (Oct 09 2026 at 16:54):

:memo: alexcrichton submitted PR review:

I'm fine with these being follow-ups, but I'm hesitant to duplicate so much of our documentation in these docs because it seems like it'll inevitable get pretty far out of sync and we'll forget to update it

view this post on Zulip Wasmtime GitHub notifications bot (Oct 09 2026 at 16:54):

:speech_balloon: alexcrichton created PR review comment:

You can drop --locked from all these commands, we test in CI it's not necessary

view this post on Zulip Wasmtime GitHub notifications bot (Oct 09 2026 at 16:54):

:speech_balloon: alexcrichton created PR review comment:

I'd probably say the tests here and cargo test above can be skipped

view this post on Zulip Wasmtime GitHub notifications bot (Oct 09 2026 at 16:54):

:speech_balloon: alexcrichton created PR review comment:

These seem like they can be dropped

view this post on Zulip Wasmtime GitHub notifications bot (Oct 09 2026 at 16:54):

:speech_balloon: alexcrichton created PR review comment:

I suspect nothing is going to read these warning messages, but also the fuzzers should always build, so perhaps just skip this?

view this post on Zulip Wasmtime GitHub notifications bot (Oct 09 2026 at 16:54):

:speech_balloon: alexcrichton created PR review comment:

Could this perhaps try to read https://github.com/bytecodealliance/wasmtime/blob/a8d33e523206646ca2850bac2744571b4827961b/.github/actions/install-rust/action.yml#L41 and use that version of rustc? That can be the default toolchain for this whole build, I don't think there's any need to switch between stable/nightly

view this post on Zulip Wasmtime GitHub notifications bot (Oct 09 2026 at 16:54):

:speech_balloon: alexcrichton created PR review comment:

This is probably better modeled as ./target/debug/wasmtime wast *.wast

view this post on Zulip Wasmtime GitHub notifications bot (Oct 09 2026 at 16:54):

:speech_balloon: alexcrichton created PR review comment:

Given the nature of how much this all changes over time, could this be omitted and deferred to our own docs/ folder?

view this post on Zulip Wasmtime GitHub notifications bot (Oct 09 2026 at 16:54):

:speech_balloon: alexcrichton created PR review comment:

This is mostly just a duplication of our other docs, right?

view this post on Zulip Wasmtime GitHub notifications bot (Oct 09 2026 at 16:54):

:speech_balloon: alexcrichton created PR review comment:

We've git a skill in-repo for reduction, could this point there?

view this post on Zulip Wasmtime GitHub notifications bot (Oct 09 2026 at 16:54):

:speech_balloon: alexcrichton created PR review comment:

Is this useful to include because all tests are always passing?

view this post on Zulip Wasmtime GitHub notifications bot (Oct 09 2026 at 16:54):

:speech_balloon: alexcrichton created PR review comment:

This is mostly a duplication of the wasmtime-auditor skill I think?

view this post on Zulip Wasmtime GitHub notifications bot (Oct 09 2026 at 17:08):

tschneidereit removed PR #14628 Add required info for Anthropic's OSS Scanner program from the merge queue.

view this post on Zulip Wasmtime GitHub notifications bot (Oct 09 2026 at 17:11):

:memo: tschneidereit submitted PR review.

view this post on Zulip Wasmtime GitHub notifications bot (Oct 09 2026 at 17:11):

:speech_balloon: tschneidereit created PR review comment:

it's useful to include because it primes the build cache, so modifications to individual files go more quickly. The machines building the image are much larger than the ones running it, so this kind of front-loading is apparently advisable.

view this post on Zulip Wasmtime GitHub notifications bot (Oct 09 2026 at 17:54):

:memo: tschneidereit submitted PR review.

view this post on Zulip Wasmtime GitHub notifications bot (Oct 09 2026 at 17:54):

:speech_balloon: tschneidereit created PR review comment:

See my other comments on these things: this is meant to prime the builds for running on the smaller machines after the image has been built.

view this post on Zulip Wasmtime GitHub notifications bot (Oct 09 2026 at 17:54):

:memo: tschneidereit submitted PR review.

view this post on Zulip Wasmtime GitHub notifications bot (Oct 09 2026 at 17:54):

:speech_balloon: tschneidereit created PR review comment:

(and note that it doesn't run the tests, just build them)

view this post on Zulip Wasmtime GitHub notifications bot (Oct 09 2026 at 17:57):

:memo: tschneidereit submitted PR review.

view this post on Zulip Wasmtime GitHub notifications bot (Oct 09 2026 at 17:57):

:speech_balloon: tschneidereit created PR review comment:

The template says "Run the cheap tests so you know the image works, but do not let a failing test abort the build", which is why it's done this way.

Also, apparently the primary contact will be emailed, so we'll have to see whether having that be a mailing list of all core maintainers will be the right call or not


Last updated: Oct 11 2026 at 04:10 UTC