Stream: git-wasmtime

Topic: wasmtime / issue #12713 Provide a way for a Wasmtime host...


view this post on Zulip Wasmtime GitHub notifications bot (Mar 03 2026 at 23:47):

itowlson opened issue #12713:

Feature

I would like to be able to customise the resolution of certain DNS names in the Wasmtime host. Specifically, the .alt TLD is defined as being for the host to resolve, and I'd like to be able to use hosts under that TLD as aliases, mapping them to IP addresses within the host.

Benefit

The issue at hand is enabling a component to make an outbound connection to a debug server. We want to restrict outbound access in configuration. But we do not know at configuration time where the debug server is running. So the idea is to have the debuggee connecting on a fixed .alt address, which we resolve at debug time to the debug server address.

Implementation

I'm not sufficiently au fait with the hosting APIs to have a view on implementation. I guess I am hoping for something similar to WasiCtxBuilder::socket_addr_check, i.e. I can set a resolver function on the context and have it invoked during resolution. Ideally such a function would not be required to encompass all resolution: in most cases, it should be able to hand off to normal DNS resolution (e.g. by returning a sentinel value such as None).

Alternatives

An alternative approach would be for a host to virtualise wasi:sockets by synthesising a shim implementation at runtime - to translate the .alt addresses, and pass everything else on - and composing that onto the main component. This would mean that each host that cared about this would need to build a shim generator.

view this post on Zulip Wasmtime GitHub notifications bot (Mar 26 2026 at 16:27):

fitzgen added the wasi label to Issue #12713.

view this post on Zulip Wasmtime GitHub notifications bot (Mar 26 2026 at 16:27):

fitzgen added the wasi-http label to Issue #12713.

view this post on Zulip Wasmtime GitHub notifications bot (Sep 25 2026 at 08:09):

Marlinski commented on issue #12713:

We'd like this too, but for filtering rather than aliasing. We run a multi-tenant host, and guests fetch URLs they're handed (webhooks, links in chat, tool arguments), so we have to refuse destinations that resolve to private, loopback or link-local space, plus some operator-defined CIDRs.

The only place that can check this is after resolution and before connecting. With default_send_request that's impossible, since the lookup happens inside TcpStream::connect(&authority). Checking up front and then calling it means resolving twice, which a DNS server can answer differently each time. So we ended up copying default_send_request, resolving once, checking the addresses, and connecting to those while keeping the hostname for SNI. It works, but it's a fork we have to re-sync on every bump.

A resolver hook like the one described here, as long as it's also used by default_send_request (not only wasi:sockets), would let us drop the copy. Ideally it would get the host name and return the addresses to connect to, or an error code. Related: #7694, #7681.

view this post on Zulip Wasmtime GitHub notifications bot (Sep 25 2026 at 08:10):

Marlinski edited a comment on issue #12713:

Bumping this issue, we'd like this too ! but for filtering rather than aliasing. We run a multi-tenant host, and guests fetch URLs they're handed (webhooks, links in chat, tool arguments), so we have to refuse destinations that resolve to private, loopback or link-local space, plus some operator-defined CIDRs.

The only place that can check this is after resolution and before connecting. With default_send_request that's impossible, since the lookup happens inside TcpStream::connect(&authority). Checking up front and then calling it means resolving twice, which a DNS server can answer differently each time. So we ended up copying default_send_request, resolving once, checking the addresses, and connecting to those while keeping the hostname for SNI. It works, but it's a fork we have to re-sync on every bump.

A resolver hook like the one described here, as long as it's also used by default_send_request (not only wasi:sockets), would let us drop the copy. Ideally it would get the host name and return the addresses to connect to, or an error code. Related: #7694, #7681.


Last updated: Oct 11 2026 at 04:10 UTC