iilyak opened issue #5648:
In cases where secure (or hermetic) execution environment is required it would be great to be able to disable such features as:
- networking
- time
- randomness
- host filesystem access
The capability model proposed by WASI is not sufficient in some cases. It would be great to be able to exclude code at compile time. So it is not even present in the final binary.
abrown commented on issue #5648:
If you're interested in tackling this, you may be able to plumb through a
wasifeature disabling, e.g., thewasi-commoncrate much like there are features forwasi-nnandwasi-crypto.
abrown edited a comment on issue #5648:
If you're interested in tackling this, you may be able to plumb through a
wasifeature enabling thewasi-commoncrate, e.g., much like there are features forwasi-nnandwasi-crypto.
abrown commented on issue #5648:
(I think the feature should make the
wasmtime-wasicrate optional, which pulls inwasi-common).
Last updated: Dec 13 2025 at 19:03 UTC