1 use crate::linker::{Definition, DefinitionType};
2 use crate::prelude::*;
3 use crate::runtime::vm::{
4     Imports, InstanceAllocationRequest, ModuleRuntimeInfo, StorePtr, VMFuncRef, VMFunctionImport,
5     VMGlobalImport, VMMemoryImport, VMOpaqueContext, VMTableImport,
6 };
7 use crate::store::{InstanceId, StoreOpaque, Stored};
8 use crate::types::matching;
9 use crate::{
10     AsContextMut, Engine, Export, Extern, Func, Global, Memory, Module, ModuleExport, SharedMemory,
11     StoreContext, StoreContextMut, Table, TypedFunc,
12 };
13 use alloc::sync::Arc;
14 use core::ptr::NonNull;
15 use wasmparser::WasmFeatures;
16 use wasmtime_environ::{
17     EntityIndex, EntityType, FuncIndex, GlobalIndex, MemoryIndex, PrimaryMap, TableIndex, TypeTrace,
18 };
19 
20 /// An instantiated WebAssembly module.
21 ///
22 /// This type represents the instantiation of a [`Module`]. Once instantiated
23 /// you can access the [`exports`](Instance::exports) which are of type
24 /// [`Extern`] and provide the ability to call functions, set globals, read
25 /// memory, etc. When interacting with any wasm code you'll want to make an
26 /// [`Instance`] to call any code or execute anything.
27 ///
28 /// Instances are owned by a [`Store`](crate::Store) which is passed in at
29 /// creation time. It's recommended to create instances with
30 /// [`Linker::instantiate`](crate::Linker::instantiate) or similar
31 /// [`Linker`](crate::Linker) methods, but a more low-level constructor is also
32 /// available as [`Instance::new`].
33 #[derive(Copy, Clone, Debug)]
34 #[repr(transparent)]
35 pub struct Instance(Stored<InstanceData>);
36 
37 pub(crate) struct InstanceData {
38     /// The id of the instance within the store, used to find the original
39     /// `InstanceHandle`.
40     id: InstanceId,
41     /// A lazily-populated list of exports of this instance. The order of
42     /// exports here matches the order of the exports in the original
43     /// module.
44     exports: Vec<Option<Extern>>,
45 }
46 
47 impl InstanceData {
48     pub fn from_id(id: InstanceId) -> InstanceData {
49         InstanceData {
50             id,
51             exports: vec![],
52         }
53     }
54 }
55 
56 impl Instance {
57     /// Creates a new [`Instance`] from the previously compiled [`Module`] and
58     /// list of `imports` specified.
59     ///
60     /// This method instantiates the `module` provided with the `imports`,
61     /// following the procedure in the [core specification][inst] to
62     /// instantiate. Instantiation can fail for a number of reasons (many
63     /// specified below), but if successful the `start` function will be
64     /// automatically run (if specified in the `module`) and then the
65     /// [`Instance`] will be returned.
66     ///
67     /// Per the WebAssembly spec, instantiation includes running the module's
68     /// start function, if it has one (not to be confused with the `_start`
69     /// function, which is not run).
70     ///
71     /// Note that this is a low-level function that just performs an
72     /// instantiation. See the [`Linker`](crate::Linker) struct for an API which
73     /// provides a convenient way to link imports and provides automatic Command
74     /// and Reactor behavior.
75     ///
76     /// ## Providing Imports
77     ///
78     /// The entries in the list of `imports` are intended to correspond 1:1
79     /// with the list of imports returned by [`Module::imports`]. Before
80     /// calling [`Instance::new`] you'll want to inspect the return value of
81     /// [`Module::imports`] and, for each import type, create an [`Extern`]
82     /// which corresponds to that type.  These [`Extern`] values are all then
83     /// collected into a list and passed to this function.
84     ///
85     /// Note that this function is intentionally relatively low level. For an
86     /// easier time passing imports by doing name-based resolution it's
87     /// recommended to instead use the [`Linker`](crate::Linker) type.
88     ///
89     /// ## Errors
90     ///
91     /// This function can fail for a number of reasons, including, but not
92     /// limited to:
93     ///
94     /// * The number of `imports` provided doesn't match the number of imports
95     ///   returned by the `module`'s [`Module::imports`] method.
96     /// * The type of any [`Extern`] doesn't match the corresponding
97     ///   [`ExternType`] entry that it maps to.
98     /// * The `start` function in the instance, if present, traps.
99     /// * Module/instance resource limits are exceeded.
100     ///
101     /// When instantiation fails it's recommended to inspect the return value to
102     /// see why it failed, or bubble it upwards. If you'd like to specifically
103     /// check for trap errors, you can use `error.downcast::<Trap>()`. For more
104     /// about error handling see the [`Trap`] documentation.
105     ///
106     /// [`Trap`]: crate::Trap
107     ///
108     /// # Panics
109     ///
110     /// This function will panic if called with a store associated with a
111     /// [`asynchronous config`](crate::Config::async_support). This function
112     /// will also panic if any [`Extern`] supplied is not owned by `store`.
113     ///
114     /// [inst]: https://webassembly.github.io/spec/core/exec/modules.html#exec-instantiation
115     /// [`ExternType`]: crate::ExternType
116     pub fn new(
117         mut store: impl AsContextMut,
118         module: &Module,
119         imports: &[Extern],
120     ) -> Result<Instance> {
121         let mut store = store.as_context_mut();
122         let imports = Instance::typecheck_externs(store.0, module, imports)?;
123         // Note that the unsafety here should be satisfied by the call to
124         // `typecheck_externs` above which satisfies the condition that all
125         // the imports are valid for this module.
126         unsafe { Instance::new_started(&mut store, module, imports.as_ref()) }
127     }
128 
129     /// Same as [`Instance::new`], except for usage in [asynchronous stores].
130     ///
131     /// For more details about this function see the documentation on
132     /// [`Instance::new`]. The only difference between these two methods is that
133     /// this one will asynchronously invoke the wasm start function in case it
134     /// calls any imported function which is an asynchronous host function (e.g.
135     /// created with [`Func::new_async`](crate::Func::new_async).
136     ///
137     /// # Panics
138     ///
139     /// This function will panic if called with a store associated with a
140     /// [`synchronous config`](crate::Config::new). This is only compatible with
141     /// stores associated with an [`asynchronous
142     /// config`](crate::Config::async_support).
143     ///
144     /// This function will also panic, like [`Instance::new`], if any [`Extern`]
145     /// specified does not belong to `store`.
146     #[cfg(feature = "async")]
147     pub async fn new_async<T>(
148         mut store: impl AsContextMut<Data = T>,
149         module: &Module,
150         imports: &[Extern],
151     ) -> Result<Instance>
152     where
153         T: Send,
154     {
155         let mut store = store.as_context_mut();
156         let imports = Instance::typecheck_externs(store.0, module, imports)?;
157         // See `new` for notes on this unsafety
158         unsafe { Instance::new_started_async(&mut store, module, imports.as_ref()).await }
159     }
160 
161     fn typecheck_externs(
162         store: &mut StoreOpaque,
163         module: &Module,
164         imports: &[Extern],
165     ) -> Result<OwnedImports> {
166         for import in imports {
167             if !import.comes_from_same_store(store) {
168                 bail!("cross-`Store` instantiation is not currently supported");
169             }
170         }
171         typecheck(module, imports, |cx, ty, item| {
172             let item = DefinitionType::from(store, item);
173             cx.definition(ty, &item)
174         })?;
175         let mut owned_imports = OwnedImports::new(module);
176         for import in imports {
177             owned_imports.push(import, store, module);
178         }
179         Ok(owned_imports)
180     }
181 
182     /// Internal function to create an instance and run the start function.
183     ///
184     /// This function's unsafety is the same as `Instance::new_raw`.
185     pub(crate) unsafe fn new_started<T>(
186         store: &mut StoreContextMut<'_, T>,
187         module: &Module,
188         imports: Imports<'_>,
189     ) -> Result<Instance> {
190         assert!(
191             !store.0.async_support(),
192             "must use async instantiation when async support is enabled",
193         );
194         Self::new_started_impl(store, module, imports)
195     }
196 
197     /// Internal function to create an instance and run the start function.
198     ///
199     /// ONLY CALL THIS IF YOU HAVE ALREADY CHECKED FOR ASYNCNESS AND HANDLED
200     /// THE FIBER NONSENSE
201     pub(crate) unsafe fn new_started_impl<T>(
202         store: &mut StoreContextMut<'_, T>,
203         module: &Module,
204         imports: Imports<'_>,
205     ) -> Result<Instance> {
206         let (instance, start) = Instance::new_raw(store.0, module, imports)?;
207         if let Some(start) = start {
208             instance.start_raw(store, start)?;
209         }
210         Ok(instance)
211     }
212 
213     /// Internal function to create an instance and run the start function.
214     ///
215     /// This function's unsafety is the same as `Instance::new_raw`.
216     #[cfg(feature = "async")]
217     async unsafe fn new_started_async<T>(
218         store: &mut StoreContextMut<'_, T>,
219         module: &Module,
220         imports: Imports<'_>,
221     ) -> Result<Instance>
222     where
223         T: Send,
224     {
225         assert!(
226             store.0.async_support(),
227             "must use sync instantiation when async support is disabled",
228         );
229 
230         store
231             .on_fiber(|store| Self::new_started_impl(store, module, imports))
232             .await?
233     }
234 
235     /// Internal function to create an instance which doesn't have its `start`
236     /// function run yet.
237     ///
238     /// This is not intended to be exposed from Wasmtime, it's intended to
239     /// refactor out common code from `new_started` and `new_started_async`.
240     ///
241     /// Note that this step needs to be run on a fiber in async mode even
242     /// though it doesn't do any blocking work because an async resource
243     /// limiter may need to yield.
244     ///
245     /// # Unsafety
246     ///
247     /// This method is unsafe because it does not type-check the `imports`
248     /// provided. The `imports` provided must be suitable for the module
249     /// provided as well.
250     unsafe fn new_raw(
251         store: &mut StoreOpaque,
252         module: &Module,
253         imports: Imports<'_>,
254     ) -> Result<(Instance, Option<FuncIndex>)> {
255         if !Engine::same(store.engine(), module.engine()) {
256             bail!("cross-`Engine` instantiation is not currently supported");
257         }
258         store.bump_resource_counts(module)?;
259 
260         // Allocate the GC heap, if necessary.
261         if store.engine().features().gc_types() {
262             let _ = store.gc_store_mut()?;
263         }
264 
265         let compiled_module = module.compiled_module();
266 
267         // Register the module just before instantiation to ensure we keep the module
268         // properly referenced while in use by the store.
269         let module_id = store.modules_mut().register_module(module);
270         store.fill_func_refs();
271 
272         // The first thing we do is issue an instance allocation request
273         // to the instance allocator. This, on success, will give us an
274         // instance handle.
275         //
276         // Note that the `host_state` here is a pointer back to the
277         // `Instance` we'll be returning from this function. This is a
278         // circular reference so we can't construct it before we construct
279         // this instance, so we determine what the ID is and then assert
280         // it's the same later when we do actually insert it.
281         let instance_to_be = store.store_data().next_id::<InstanceData>();
282 
283         let mut instance_handle =
284             store
285                 .engine()
286                 .allocator()
287                 .allocate_module(InstanceAllocationRequest {
288                     runtime_info: &ModuleRuntimeInfo::Module(module.clone()),
289                     imports,
290                     host_state: Box::new(Instance(instance_to_be)),
291                     store: StorePtr::new(store.traitobj()),
292                     wmemcheck: store.engine().config().wmemcheck,
293                     pkey: store.get_pkey(),
294                     tunables: store.engine().tunables(),
295                 })?;
296 
297         // The instance still has lots of setup, for example
298         // data/elements/start/etc. This can all fail, but even on failure
299         // the instance may persist some state via previous successful
300         // initialization. For this reason once we have an instance handle
301         // we immediately insert it into the store to keep it alive.
302         //
303         // Note that we `clone` the instance handle just to make easier
304         // working the borrow checker here easier. Technically the `&mut
305         // instance` has somewhat of a borrow on `store` (which
306         // conflicts with the borrow on `store.engine`) but this doesn't
307         // matter in practice since initialization isn't even running any
308         // code here anyway.
309         let id = store.add_instance(instance_handle.clone(), module_id);
310 
311         // Additionally, before we start doing fallible instantiation, we
312         // do one more step which is to insert an `InstanceData`
313         // corresponding to this instance. This `InstanceData` can be used
314         // via `Caller::get_export` if our instance's state "leaks" into
315         // other instances, even if we don't return successfully from this
316         // function.
317         //
318         // We don't actually load all exports from the instance at this
319         // time, instead preferring to lazily load them as they're demanded.
320         // For module/instance exports, though, those aren't actually
321         // stored in the instance handle so we need to immediately handle
322         // those here.
323         let instance = {
324             let exports = vec![None; compiled_module.module().exports.len()];
325             let data = InstanceData { id, exports };
326             Instance::from_wasmtime(data, store)
327         };
328 
329         // double-check our guess of what the new instance's ID would be
330         // was actually correct.
331         assert_eq!(instance.0, instance_to_be);
332 
333         // Now that we've recorded all information we need to about this
334         // instance within a `Store` we can start performing fallible
335         // initialization. Note that we still defer the `start` function to
336         // later since that may need to run asynchronously.
337         //
338         // If this returns an error (or if the start function traps) then
339         // any other initialization which may have succeeded which placed
340         // items from this instance into other instances should be ok when
341         // those items are loaded and run we'll have all the metadata to
342         // look at them.
343         let bulk_memory = store
344             .engine()
345             .features()
346             .contains(WasmFeatures::BULK_MEMORY);
347         instance_handle.initialize(store, compiled_module.module(), bulk_memory)?;
348 
349         Ok((instance, compiled_module.module().start_func))
350     }
351 
352     pub(crate) fn from_wasmtime(handle: InstanceData, store: &mut StoreOpaque) -> Instance {
353         Instance(store.store_data_mut().insert(handle))
354     }
355 
356     fn start_raw<T>(&self, store: &mut StoreContextMut<'_, T>, start: FuncIndex) -> Result<()> {
357         let id = store.0.store_data()[self.0].id;
358         // If a start function is present, invoke it. Make sure we use all the
359         // trap-handling configuration in `store` as well.
360         let instance = store.0.instance_mut(id);
361         let f = instance.get_exported_func(start);
362         let caller_vmctx = instance.vmctx();
363         unsafe {
364             super::func::invoke_wasm_and_catch_traps(store, |_default_caller| {
365                 f.func_ref
366                     .as_ref()
367                     .array_call(VMOpaqueContext::from_vmcontext(caller_vmctx), &mut [])
368             })?;
369         }
370         Ok(())
371     }
372 
373     /// Get this instance's module.
374     pub fn module<'a, T: 'a>(&self, store: impl Into<StoreContext<'a, T>>) -> &'a Module {
375         self._module(store.into().0)
376     }
377 
378     fn _module<'a>(&self, store: &'a StoreOpaque) -> &'a Module {
379         let InstanceData { id, .. } = store[self.0];
380         store.module_for_instance(id).unwrap()
381     }
382 
383     /// Returns the list of exported items from this [`Instance`].
384     ///
385     /// # Panics
386     ///
387     /// Panics if `store` does not own this instance.
388     pub fn exports<'a, T: 'a>(
389         &'a self,
390         store: impl Into<StoreContextMut<'a, T>>,
391     ) -> impl ExactSizeIterator<Item = Export<'a>> + 'a {
392         self._exports(store.into().0)
393     }
394 
395     fn _exports<'a>(
396         &'a self,
397         store: &'a mut StoreOpaque,
398     ) -> impl ExactSizeIterator<Item = Export<'a>> + 'a {
399         // If this is an `Instantiated` instance then all the `exports` may not
400         // be filled in. Fill them all in now if that's the case.
401         let InstanceData { exports, id, .. } = &store[self.0];
402         if exports.iter().any(|e| e.is_none()) {
403             let module = Arc::clone(store.instance(*id).module());
404             let data = &store[self.0];
405             let id = data.id;
406 
407             for name in module.exports.keys() {
408                 let instance = store.instance(id);
409                 if let Some((export_name_index, _, &entity)) =
410                     instance.module().exports.get_full(name)
411                 {
412                     self._get_export(store, entity, export_name_index);
413                 }
414             }
415         }
416 
417         let data = &store.store_data()[self.0];
418         let module = store.instance(data.id).module();
419         module
420             .exports
421             .iter()
422             .zip(&data.exports)
423             .map(|((name, _), export)| Export::new(name, export.clone().unwrap()))
424     }
425 
426     /// Looks up an exported [`Extern`] value by name.
427     ///
428     /// This method will search the module for an export named `name` and return
429     /// the value, if found.
430     ///
431     /// Returns `None` if there was no export named `name`.
432     ///
433     /// # Panics
434     ///
435     /// Panics if `store` does not own this instance.
436     ///
437     /// # Why does `get_export` take a mutable context?
438     ///
439     /// This method requires a mutable context because an instance's exports are
440     /// lazily populated, and we cache them as they are accessed. This makes
441     /// instantiating a module faster, but also means this method requires a
442     /// mutable context.
443     pub fn get_export(&self, mut store: impl AsContextMut, name: &str) -> Option<Extern> {
444         let store = store.as_context_mut().0;
445         let data = &store[self.0];
446         let instance = store.instance(data.id);
447         let (export_name_index, _, &entity) = instance.module().exports.get_full(name)?;
448         self._get_export(store, entity, export_name_index)
449     }
450 
451     /// Looks up an exported [`Extern`] value by a [`ModuleExport`] value.
452     ///
453     /// This is similar to [`Instance::get_export`] but uses a [`ModuleExport`] value to avoid
454     /// string lookups where possible. [`ModuleExport`]s can be obtained by calling
455     /// [`Module::get_export_index`] on the [`Module`] that this instance was instantiated with.
456     ///
457     /// This method will search the module for an export with a matching entity index and return
458     /// the value, if found.
459     ///
460     /// Returns `None` if there was no export with a matching entity index.
461     /// # Panics
462     ///
463     /// Panics if `store` does not own this instance.
464     pub fn get_module_export(
465         &self,
466         mut store: impl AsContextMut,
467         export: &ModuleExport,
468     ) -> Option<Extern> {
469         let store = store.as_context_mut().0;
470 
471         // Verify the `ModuleExport` matches the module used in this instance.
472         if self._module(store).id() != export.module {
473             return None;
474         }
475 
476         self._get_export(store, export.entity, export.export_name_index)
477     }
478 
479     fn _get_export(
480         &self,
481         store: &mut StoreOpaque,
482         entity: EntityIndex,
483         export_name_index: usize,
484     ) -> Option<Extern> {
485         // Instantiated instances will lazily fill in exports, so we process
486         // all that lazy logic here.
487         let data = &store[self.0];
488 
489         if let Some(export) = &data.exports[export_name_index] {
490             return Some(export.clone());
491         }
492 
493         let instance = store.instance_mut(data.id); // Reborrow the &mut InstanceHandle
494         let item =
495             unsafe { Extern::from_wasmtime_export(instance.get_export_by_index(entity), store) };
496         let data = &mut store[self.0];
497         data.exports[export_name_index] = Some(item.clone());
498         Some(item)
499     }
500 
501     /// Looks up an exported [`Func`] value by name.
502     ///
503     /// Returns `None` if there was no export named `name`, or if there was but
504     /// it wasn't a function.
505     ///
506     /// # Panics
507     ///
508     /// Panics if `store` does not own this instance.
509     pub fn get_func(&self, store: impl AsContextMut, name: &str) -> Option<Func> {
510         self.get_export(store, name)?.into_func()
511     }
512 
513     /// Looks up an exported [`Func`] value by name and with its type.
514     ///
515     /// This function is a convenience wrapper over [`Instance::get_func`] and
516     /// [`Func::typed`]. For more information see the linked documentation.
517     ///
518     /// Returns an error if `name` isn't a function export or if the export's
519     /// type did not match `Params` or `Results`
520     ///
521     /// # Panics
522     ///
523     /// Panics if `store` does not own this instance.
524     pub fn get_typed_func<Params, Results>(
525         &self,
526         mut store: impl AsContextMut,
527         name: &str,
528     ) -> Result<TypedFunc<Params, Results>>
529     where
530         Params: crate::WasmParams,
531         Results: crate::WasmResults,
532     {
533         let f = self
534             .get_export(store.as_context_mut(), name)
535             .and_then(|f| f.into_func())
536             .ok_or_else(|| anyhow!("failed to find function export `{}`", name))?;
537         Ok(f.typed::<Params, Results>(store)
538             .with_context(|| format!("failed to convert function `{name}` to given type"))?)
539     }
540 
541     /// Looks up an exported [`Table`] value by name.
542     ///
543     /// Returns `None` if there was no export named `name`, or if there was but
544     /// it wasn't a table.
545     ///
546     /// # Panics
547     ///
548     /// Panics if `store` does not own this instance.
549     pub fn get_table(&self, store: impl AsContextMut, name: &str) -> Option<Table> {
550         self.get_export(store, name)?.into_table()
551     }
552 
553     /// Looks up an exported [`Memory`] value by name.
554     ///
555     /// Returns `None` if there was no export named `name`, or if there was but
556     /// it wasn't a memory.
557     ///
558     /// # Panics
559     ///
560     /// Panics if `store` does not own this instance.
561     pub fn get_memory(&self, store: impl AsContextMut, name: &str) -> Option<Memory> {
562         self.get_export(store, name)?.into_memory()
563     }
564 
565     /// Looks up an exported [`SharedMemory`] value by name.
566     ///
567     /// Returns `None` if there was no export named `name`, or if there was but
568     /// it wasn't a shared memory.
569     ///
570     /// # Panics
571     ///
572     /// Panics if `store` does not own this instance.
573     pub fn get_shared_memory(
574         &self,
575         mut store: impl AsContextMut,
576         name: &str,
577     ) -> Option<SharedMemory> {
578         let mut store = store.as_context_mut();
579         self.get_export(&mut store, name)?.into_shared_memory()
580     }
581 
582     /// Looks up an exported [`Global`] value by name.
583     ///
584     /// Returns `None` if there was no export named `name`, or if there was but
585     /// it wasn't a global.
586     ///
587     /// # Panics
588     ///
589     /// Panics if `store` does not own this instance.
590     pub fn get_global(&self, store: impl AsContextMut, name: &str) -> Option<Global> {
591         self.get_export(store, name)?.into_global()
592     }
593 
594     #[cfg(feature = "component-model")]
595     pub(crate) fn id(&self, store: &StoreOpaque) -> InstanceId {
596         store[self.0].id
597     }
598 
599     /// Get all globals within this instance.
600     ///
601     /// Returns both import and defined globals.
602     ///
603     /// Returns both exported and non-exported globals.
604     ///
605     /// Gives access to the full globals space.
606     pub(crate) fn all_globals<'a>(
607         &'a self,
608         store: &'a mut StoreOpaque,
609     ) -> impl ExactSizeIterator<Item = (GlobalIndex, Global)> + 'a {
610         let data = &store[self.0];
611         let instance = store.instance_mut(data.id);
612         instance
613             .all_globals()
614             .collect::<Vec<_>>()
615             .into_iter()
616             .map(|(i, g)| (i, unsafe { Global::from_wasmtime_global(g, store) }))
617     }
618 
619     /// Get all memories within this instance.
620     ///
621     /// Returns both import and defined memories.
622     ///
623     /// Returns both exported and non-exported memories.
624     ///
625     /// Gives access to the full memories space.
626     pub(crate) fn all_memories<'a>(
627         &'a self,
628         store: &'a mut StoreOpaque,
629     ) -> impl ExactSizeIterator<Item = (MemoryIndex, Memory)> + 'a {
630         let data = &store[self.0];
631         let instance = store.instance_mut(data.id);
632         instance
633             .all_memories()
634             .collect::<Vec<_>>()
635             .into_iter()
636             .map(|(i, m)| (i, unsafe { Memory::from_wasmtime_memory(m, store) }))
637     }
638 }
639 
640 pub(crate) struct OwnedImports {
641     functions: PrimaryMap<FuncIndex, VMFunctionImport>,
642     tables: PrimaryMap<TableIndex, VMTableImport>,
643     memories: PrimaryMap<MemoryIndex, VMMemoryImport>,
644     globals: PrimaryMap<GlobalIndex, VMGlobalImport>,
645 }
646 
647 impl OwnedImports {
648     fn new(module: &Module) -> OwnedImports {
649         let mut ret = OwnedImports::empty();
650         ret.reserve(module);
651         return ret;
652     }
653 
654     pub(crate) fn empty() -> OwnedImports {
655         OwnedImports {
656             functions: PrimaryMap::new(),
657             tables: PrimaryMap::new(),
658             memories: PrimaryMap::new(),
659             globals: PrimaryMap::new(),
660         }
661     }
662 
663     pub(crate) fn reserve(&mut self, module: &Module) {
664         let raw = module.compiled_module().module();
665         self.functions.reserve(raw.num_imported_funcs);
666         self.tables.reserve(raw.num_imported_tables);
667         self.memories.reserve(raw.num_imported_memories);
668         self.globals.reserve(raw.num_imported_globals);
669     }
670 
671     #[cfg(feature = "component-model")]
672     pub(crate) fn clear(&mut self) {
673         self.functions.clear();
674         self.tables.clear();
675         self.memories.clear();
676         self.globals.clear();
677     }
678 
679     fn push(&mut self, item: &Extern, store: &mut StoreOpaque, module: &Module) {
680         match item {
681             Extern::Func(i) => {
682                 self.functions.push(i.vmimport(store, module));
683             }
684             Extern::Global(i) => {
685                 self.globals.push(i.vmimport(store));
686             }
687             Extern::Table(i) => {
688                 self.tables.push(i.vmimport(store));
689             }
690             Extern::Memory(i) => {
691                 self.memories.push(i.vmimport(store));
692             }
693             Extern::SharedMemory(i) => {
694                 self.memories.push(i.vmimport(store));
695             }
696         }
697     }
698 
699     /// Note that this is unsafe as the validity of `item` is not verified and
700     /// it contains a bunch of raw pointers.
701     #[cfg(feature = "component-model")]
702     pub(crate) unsafe fn push_export(&mut self, item: &crate::runtime::vm::Export) {
703         match item {
704             crate::runtime::vm::Export::Function(f) => {
705                 let f = f.func_ref.as_ref();
706                 self.functions.push(VMFunctionImport {
707                     wasm_call: f.wasm_call.unwrap(),
708                     array_call: f.array_call,
709                     vmctx: f.vmctx,
710                 });
711             }
712             crate::runtime::vm::Export::Global(g) => {
713                 self.globals.push(VMGlobalImport { from: g.definition });
714             }
715             crate::runtime::vm::Export::Table(t) => {
716                 self.tables.push(VMTableImport {
717                     from: t.definition,
718                     vmctx: t.vmctx,
719                 });
720             }
721             crate::runtime::vm::Export::Memory(m) => {
722                 self.memories.push(VMMemoryImport {
723                     from: m.definition,
724                     vmctx: m.vmctx,
725                     index: m.index,
726                 });
727             }
728         }
729     }
730 
731     pub(crate) fn as_ref(&self) -> Imports<'_> {
732         Imports {
733             tables: self.tables.values().as_slice(),
734             globals: self.globals.values().as_slice(),
735             memories: self.memories.values().as_slice(),
736             functions: self.functions.values().as_slice(),
737         }
738     }
739 }
740 
741 /// An instance, pre-instantiation, that is ready to be instantiated.
742 ///
743 /// This structure represents an instance *just before* it was instantiated,
744 /// after all type-checking and imports have been resolved. The only thing left
745 /// to do for this instance is to actually run the process of instantiation.
746 ///
747 /// Note that an `InstancePre` may not be tied to any particular [`Store`] if
748 /// none of the imports it closed over are tied to any particular [`Store`].
749 ///
750 /// This structure is created through the [`Linker::instantiate_pre`] method,
751 /// which also has some more information and examples.
752 ///
753 /// [`Store`]: crate::Store
754 /// [`Linker::instantiate_pre`]: crate::Linker::instantiate_pre
755 pub struct InstancePre<T> {
756     module: Module,
757 
758     /// The items which this `InstancePre` use to instantiate the `module`
759     /// provided, passed to `Instance::new_started` after inserting them into a
760     /// `Store`.
761     ///
762     /// Note that this is stored as an `Arc<[T]>` to quickly move a strong
763     /// reference to everything internally into a `Store<T>` without having to
764     /// clone each individual item.
765     items: Arc<[Definition]>,
766 
767     /// A count of `Definition::HostFunc` entries in `items` above to
768     /// preallocate space in a `Store` up front for all entries to be inserted.
769     host_funcs: usize,
770 
771     /// The `VMFuncRef`s for the functions in `items` that do not
772     /// have a `wasm_call` trampoline. We pre-allocate and pre-patch these
773     /// `VMFuncRef`s so that we don't have to do it at
774     /// instantiation time.
775     ///
776     /// This is an `Arc<[T]>` for the same reason as `items`.
777     func_refs: Arc<[VMFuncRef]>,
778 
779     _marker: core::marker::PhantomData<fn() -> T>,
780 }
781 
782 /// InstancePre's clone does not require T: Clone
783 impl<T> Clone for InstancePre<T> {
784     fn clone(&self) -> Self {
785         Self {
786             module: self.module.clone(),
787             items: self.items.clone(),
788             host_funcs: self.host_funcs,
789             func_refs: self.func_refs.clone(),
790             _marker: self._marker,
791         }
792     }
793 }
794 
795 impl<T> InstancePre<T> {
796     /// Creates a new `InstancePre` which type-checks the `items` provided and
797     /// on success is ready to instantiate a new instance.
798     ///
799     /// # Unsafety
800     ///
801     /// This method is unsafe as the `T` of the `InstancePre<T>` is not
802     /// guaranteed to be the same as the `T` within the `Store`, the caller must
803     /// verify that.
804     pub(crate) unsafe fn new(module: &Module, items: Vec<Definition>) -> Result<InstancePre<T>> {
805         typecheck(module, &items, |cx, ty, item| cx.definition(ty, &item.ty()))?;
806 
807         let mut func_refs = vec![];
808         let mut host_funcs = 0;
809         for item in &items {
810             match item {
811                 Definition::Extern(_, _) => {}
812                 Definition::HostFunc(f) => {
813                     host_funcs += 1;
814                     if f.func_ref().wasm_call.is_none() {
815                         // `f` needs its `VMFuncRef::wasm_call` patched with a
816                         // Wasm-to-native trampoline.
817                         debug_assert!(matches!(f.host_ctx(), crate::HostContext::Array(_)));
818                         func_refs.push(VMFuncRef {
819                             wasm_call: module.wasm_to_array_trampoline(f.sig_index()),
820                             ..*f.func_ref()
821                         });
822                     }
823                 }
824             }
825         }
826 
827         Ok(InstancePre {
828             module: module.clone(),
829             items: items.into(),
830             host_funcs,
831             func_refs: func_refs.into(),
832             _marker: core::marker::PhantomData,
833         })
834     }
835 
836     /// Returns a reference to the module that this [`InstancePre`] will be
837     /// instantiating.
838     pub fn module(&self) -> &Module {
839         &self.module
840     }
841 
842     /// Instantiates this instance, creating a new instance within the provided
843     /// `store`.
844     ///
845     /// This function will run the actual process of instantiation to
846     /// completion. This will use all of the previously-closed-over items as
847     /// imports to instantiate the module that this was originally created with.
848     ///
849     /// For more information about instantiation see [`Instance::new`].
850     ///
851     /// # Panics
852     ///
853     /// Panics if any import closed over by this [`InstancePre`] isn't owned by
854     /// `store`, or if `store` has async support enabled. Additionally this
855     /// function will panic if the `store` provided comes from a different
856     /// [`Engine`] than the [`InstancePre`] originally came from.
857     pub fn instantiate(&self, mut store: impl AsContextMut<Data = T>) -> Result<Instance> {
858         let mut store = store.as_context_mut();
859         let imports = pre_instantiate_raw(
860             &mut store.0,
861             &self.module,
862             &self.items,
863             self.host_funcs,
864             &self.func_refs,
865         )?;
866 
867         // This unsafety should be handled by the type-checking performed by the
868         // constructor of `InstancePre` to assert that all the imports we're passing
869         // in match the module we're instantiating.
870         unsafe { Instance::new_started(&mut store, &self.module, imports.as_ref()) }
871     }
872 
873     /// Creates a new instance, running the start function asynchronously
874     /// instead of inline.
875     ///
876     /// For more information about asynchronous instantiation see the
877     /// documentation on [`Instance::new_async`].
878     ///
879     /// # Panics
880     ///
881     /// Panics if any import closed over by this [`InstancePre`] isn't owned by
882     /// `store`, or if `store` does not have async support enabled.
883     #[cfg(feature = "async")]
884     pub async fn instantiate_async(
885         &self,
886         mut store: impl AsContextMut<Data = T>,
887     ) -> Result<Instance>
888     where
889         T: Send,
890     {
891         let mut store = store.as_context_mut();
892         let imports = pre_instantiate_raw(
893             &mut store.0,
894             &self.module,
895             &self.items,
896             self.host_funcs,
897             &self.func_refs,
898         )?;
899 
900         // This unsafety should be handled by the type-checking performed by the
901         // constructor of `InstancePre` to assert that all the imports we're passing
902         // in match the module we're instantiating.
903         unsafe { Instance::new_started_async(&mut store, &self.module, imports.as_ref()).await }
904     }
905 }
906 
907 /// Helper function shared between
908 /// `InstancePre::{instantiate,instantiate_async}`
909 ///
910 /// This is an out-of-line function to avoid the generic on `InstancePre` and
911 /// get this compiled into the `wasmtime` crate to avoid having it monomorphized
912 /// elsewhere.
913 fn pre_instantiate_raw(
914     store: &mut StoreOpaque,
915     module: &Module,
916     items: &Arc<[Definition]>,
917     host_funcs: usize,
918     func_refs: &Arc<[VMFuncRef]>,
919 ) -> Result<OwnedImports> {
920     if host_funcs > 0 {
921         // Any linker-defined function of the `Definition::HostFunc` variant
922         // will insert a function into the store automatically as part of
923         // instantiation, so reserve space here to make insertion more efficient
924         // as it won't have to realloc during the instantiation.
925         store.store_data_mut().reserve_funcs(host_funcs);
926 
927         // The usage of `to_extern_store_rooted` requires that the items are
928         // rooted via another means, which happens here by cloning the list of
929         // items into the store once. This avoids cloning each individual item
930         // below.
931         store.push_rooted_funcs(items.clone());
932         store.push_instance_pre_func_refs(func_refs.clone());
933     }
934 
935     let mut func_refs = func_refs.iter().map(|f| NonNull::from(f));
936     let mut imports = OwnedImports::new(module);
937     for import in items.iter() {
938         if !import.comes_from_same_store(store) {
939             bail!("cross-`Store` instantiation is not currently supported");
940         }
941         // This unsafety should be encapsulated in the constructor of
942         // `InstancePre` where the `T` of the original item should match the
943         // `T` of the store. Additionally the rooting necessary has happened
944         // above.
945         let item = match import {
946             Definition::Extern(e, _) => e.clone(),
947             Definition::HostFunc(func) => unsafe {
948                 func.to_func_store_rooted(
949                     store,
950                     if func.func_ref().wasm_call.is_none() {
951                         Some(func_refs.next().unwrap())
952                     } else {
953                         None
954                     },
955                 )
956                 .into()
957             },
958         };
959         imports.push(&item, store, module);
960     }
961 
962     Ok(imports)
963 }
964 
965 fn typecheck<I>(
966     module: &Module,
967     import_args: &[I],
968     check: impl Fn(&matching::MatchCx<'_>, &EntityType, &I) -> Result<()>,
969 ) -> Result<()> {
970     let env_module = module.compiled_module().module();
971     let expected_len = env_module.imports().count();
972     let actual_len = import_args.len();
973     if expected_len != actual_len {
974         bail!("expected {expected_len} imports, found {actual_len}");
975     }
976     let cx = matching::MatchCx::new(module.engine());
977     for ((name, field, mut expected_ty), actual) in env_module.imports().zip(import_args) {
978         expected_ty.canonicalize_for_runtime_usage(&mut |module_index| {
979             module.signatures().shared_type(module_index).unwrap()
980         });
981 
982         check(&cx, &expected_ty, actual)
983             .with_context(|| format!("incompatible import type for `{name}::{field}`"))?;
984     }
985     Ok(())
986 }
987