Visitar URL original
Releases · bytecodealliance/wasmtime · GitHub
Skip to content

Releases: bytecodealliance/wasmtime

dev: fix unmaintained dependency and improve redox support (#14561)

Choose a tag to compare

@github-actions github-actions released this 28 Sep 20:31
e4657a0
* fix unmaintained dependency and improve redox support

* Add vets

* update mio to fix freebsd build prtest:full

* update rustix to fix apple build prtest:full

* Add more vets

---------

Co-authored-by: Alex Crichton <alex@alexcrichton.com>

v50.0.0-rc.1: Release Wasmtime 50.0.0-rc.1 (#14530)

Choose a tag to compare

@github-actions github-actions released this 05 Oct 14:58
Immutable release. Only release title and notes can be modified.
f378efc

50.0.0

Unreleased.

Added

  • Add --listenfd option to wasmtime serve, which allows launching wasmtime
    with sockets inherited from a service manager (e.g. systemd socket units).

Changed

  • Remove non-functional listenfd WASI CLI option.

Fixed

  • Converting a borrowed Resource<T> or ResourceDynamic created with
    new_borrow into a ResourceAny outside of a component call no longer
    panics. The borrow is now lowered into the guest when the call happens, and
    ResourceAny::resource_drop is no longer required for such borrows.
    #7793

v49.0.2: Release Wasmtime 49.0.2 (#14474)

Choose a tag to compare

@github-actions github-actions released this 02 Oct 16:52
Immutable release. Only release title and notes can be modified.
3c8a3e7

49.0.2

Released 2026-10-02.

Fixed

  • WASI preview 0 implementation of poll_oneoff circumvents fuel consumption.
    GHSA-j366-h8gg-77pm

  • Excessive allocated memory on the host when guests don't have stdio.
    GHSA-gqmc-89g8-p25r

  • fd_readdir copies uninitialized struct padding into guest memory.
    GHSA-96f6-r43r-8c24

  • Guest can panic host through filesystem timestamp before the epoch on wasip3.
    GHSA-mr2v-56j5-cmfc

  • Wasmtime component async-lifted callback result count is unvalidated, causing a native stack buffer overflow.
    GHSA-32h6-97mm-8q3c

  • Mis-typed WebAssembly tag imports can lead to GC heap corruption.
    GHSA-cfhf-m2cr-62wj

  • Wasmtime wasi:http implementation panics with a zero timeout supplied.
    GHSA-w4qr-p94g-mjhv

  • Rooting for GC values live across try_call may be missing, causing GC heap corruption.
    GHSA-hw8m-q44c-ggrf

v48.0.5: Release Wasmtime 48.0.5 (#14495)

Choose a tag to compare

@github-actions github-actions released this 02 Oct 19:34
Immutable release. Only release title and notes can be modified.
563544c

48.0.5

Released 2026-10-02.

Fixed

  • Fixed an issue where artifacts for 48.0.4 didn't get correctly published from
    CI and a GitHub release for 48.0.4 wasn't made.
    #14494

48.0.4

Released 2026-10-02.

Fixed

  • WASI preview 0 implementation of poll_oneoff circumvents fuel consumption.
    GHSA-j366-h8gg-77pm

  • Excessive allocated memory on the host when guests don't have stdio.
    GHSA-gqmc-89g8-p25r

  • fd_readdir copies uninitialized struct padding into guest memory.
    GHSA-96f6-r43r-8c24

  • Guest can panic host through filesystem timestamp before the epoch on wasip3.
    GHSA-mr2v-56j5-cmfc

  • Wasmtime component async-lifted callback result count is unvalidated, causing a native stack buffer overflow.
    GHSA-32h6-97mm-8q3c

  • Mis-typed WebAssembly tag imports can lead to GC heap corruption.
    GHSA-cfhf-m2cr-62wj

  • Wasmtime wasi:http implementation panics with a zero timeout supplied.
    GHSA-w4qr-p94g-mjhv

  • Rooting for GC values live across try_call may be missing, causing GC heap corruption.
    GHSA-hw8m-q44c-ggrf

v36.0.17: Release Wasmtime 36.0.17 (#14472)

Choose a tag to compare

@github-actions github-actions released this 02 Oct 16:53
Immutable release. Only release title and notes can be modified.
5cbcb39

36.0.17

Released 2026-10-02.

Fixed

v49.0.1: Release Wasmtime 49.0.1 (#14401)

Choose a tag to compare

@github-actions github-actions released this 24 Sep 19:22
Immutable release. Only release title and notes can be modified.
46c23a8

49.0.1

Released 2026-09-24.

Fixed

v48.0.3: Release Wasmtime 48.0.3 (#14400)

Choose a tag to compare

@github-actions github-actions released this 24 Sep 19:02
Immutable release. Only release title and notes can be modified.
ebf20ab

48.0.3

Released 2026-09-24.

Fixed

v36.0.16: Release Wasmtime 36.0.16 (#14402)

Choose a tag to compare

@github-actions github-actions released this 24 Sep 19:14
Immutable release. Only release title and notes can be modified.
5cd4bf5

36.0.16

Released 2026-09-24.

Fixed

v49.0.0: Release Wasmtime 49.0.0 (#14363)

Choose a tag to compare

@github-actions github-actions released this 21 Sep 15:33
Immutable release. Only release title and notes can be modified.
17830bd

49.0.0

Released 2026-09-21.

Added

  • Winch now has initial experimental support for the WebAssembly
    exception-handling proposal.
    #14066
    #14081
    #14132
    #14149
    #14180
    #14209

  • Wasmtime's type reflection APIs for WebAssembly GC types now have dedicated
    enums for Heap{Top,Bottom}Types.
    #14208

  • Wasmtime now supports the use of environment variables to configure most CLI
    arguments in addition to the preexisting CLI flags.
    #14217

  • Cranelift will now fold u{add,mul}_overflow results combined with brif
    instructions for more optimal codegen.
    #14217
    #14254

  • Components can be tested for equality with a new Component::same API.
    #14257

  • The Wasmtime C/C++ API now supports the component-model-implements feature.
    #14264

  • Cranelift will now emit the {u,s}bfm instructions on AArch64.
    #14187

Changed

  • The wide-arithmetic WebAssembly proposal is now enabled by default.
    #14110

  • Config::operator_cost now applies to operators inside constant expressions
    (global initializers, element and data segment offsets, element segment
    expressions) and to the synthesized call to a module's start function.
    Previously each of those was charged 1 fuel unit regardless of the configured
    cost.
    #14215

  • Wasmtime's WASI implementation will no longer over-read stdin where possible.
    #14077

  • Wasmtime's WASIp2 implementation now maps host-level "broken pipe" errors to
    StreamError::Closed.
    #14107

  • Wasmtime's WASIp2 implementation of wasi:http now validates ports in the
    same manner as wasip3.
    #14123

  • Wasmtime's WASI implementation of wasi:filesystem now returns the
    is-directory error in some situations when a file is provided.
    #14135

  • The wasmtime-wasi-http crate now has the p3 feature enabled by default.
    #14137

  • Wasmtime's WASIp2 implementation of wasi:http now runs more hooks from the
    WasiHttpHooks trait in the same manner as wasip3.
    #14167

  • Wasmtime now requires Rust 1.96.0 to compile.
    #14184

  • Adjustments have been made to the scheduling of threads w.r.t. trapping
    behavior for cooperatively threaded components. These changes are made to
    align with the upstream component-model specification.
    #14146
    #14250

  • Fuel for bulk operations is now consumed after the bulk operation has
    completed instead of up-front, restoring previous behavior where a failed very
    large memory growth doesn't trap the original program.
    #14213

  • A number of future poll calls throughout the WASIp2 implementation now
    explicitly opt-out of Tokio's per-task cooperative budget to better uphold
    guarantees of WASIp2 APIs.
    #14265

  • The run_concurrent function is now allowed to run recursively for separate
    stores, but it still can only be used at most once recursively for any one
    store.
    #14302

  • The compile-time performance of the alias analysis in Cranelift has been
    greatly improved.
    #14306

v48.0.2: Release Wasmtime 48.0.2 (#14310)

Choose a tag to compare

@github-actions github-actions released this 10 Sep 19:20
Immutable release. Only release title and notes can be modified.
e9f1ea2

48.0.2

Released 2026-09-10.

Changed

  • Wasmtime's dependency on cap-primitives is now vendored within Wasmtime
    itself.
    #14225

Fixed

  • Code generated by bindgen! is now compatible with the latest Rust nightly by
    default.
    #14307