1 use crate::prelude::*;
2 #[cfg(feature = "std")]
3 use crate::runtime::vm::open_file_for_mmap;
4 use crate::runtime::vm::{CompiledModuleId, MmapVec, ModuleMemoryImages, VMWasmCallFunction};
5 use crate::sync::OnceLock;
6 use crate::{
7     code::CodeObject,
8     code_memory::CodeMemory,
9     instantiate::CompiledModule,
10     resources::ResourcesRequired,
11     type_registry::TypeCollection,
12     types::{ExportType, ExternType, ImportType},
13     Engine,
14 };
15 use alloc::sync::Arc;
16 use core::fmt;
17 use core::ops::Range;
18 use core::ptr::NonNull;
19 #[cfg(feature = "std")]
20 use std::{fs::File, path::Path};
21 use wasmparser::{Parser, ValidPayload, Validator};
22 use wasmtime_environ::{
23     CompiledModuleInfo, EntityIndex, HostPtr, ModuleTypes, ObjectKind, TypeTrace, VMOffsets,
24     VMSharedTypeIndex,
25 };
26 mod registry;
27 
28 pub use registry::*;
29 
30 /// A compiled WebAssembly module, ready to be instantiated.
31 ///
32 /// A `Module` is a compiled in-memory representation of an input WebAssembly
33 /// binary. A `Module` is then used to create an [`Instance`](crate::Instance)
34 /// through an instantiation process. You cannot call functions or fetch
35 /// globals, for example, on a `Module` because it's purely a code
36 /// representation. Instead you'll need to create an
37 /// [`Instance`](crate::Instance) to interact with the wasm module.
38 ///
39 /// A `Module` can be created by compiling WebAssembly code through APIs such as
40 /// [`Module::new`]. This would be a JIT-style use case where code is compiled
41 /// just before it's used. Alternatively a `Module` can be compiled in one
42 /// process and [`Module::serialize`] can be used to save it to storage. A later
43 /// call to [`Module::deserialize`] will quickly load the module to execute and
44 /// does not need to compile any code, representing a more AOT-style use case.
45 ///
46 /// Currently a `Module` does not implement any form of tiering or dynamic
47 /// optimization of compiled code. Creation of a `Module` via [`Module::new`] or
48 /// related APIs will perform the entire compilation step synchronously. When
49 /// finished no further compilation will happen at runtime or later during
50 /// execution of WebAssembly instances for example.
51 ///
52 /// Compilation of WebAssembly by default goes through Cranelift and is
53 /// recommended to be done once-per-module. The same WebAssembly binary need not
54 /// be compiled multiple times and can instead used an embedder-cached result of
55 /// the first call.
56 ///
57 /// `Module` is thread-safe and safe to share across threads.
58 ///
59 /// ## Modules and `Clone`
60 ///
61 /// Using `clone` on a `Module` is a cheap operation. It will not create an
62 /// entirely new module, but rather just a new reference to the existing module.
63 /// In other words it's a shallow copy, not a deep copy.
64 ///
65 /// ## Examples
66 ///
67 /// There are a number of ways you can create a `Module`, for example pulling
68 /// the bytes from a number of locations. One example is loading a module from
69 /// the filesystem:
70 ///
71 /// ```no_run
72 /// # use wasmtime::*;
73 /// # fn main() -> anyhow::Result<()> {
74 /// let engine = Engine::default();
75 /// let module = Module::from_file(&engine, "path/to/foo.wasm")?;
76 /// # Ok(())
77 /// # }
78 /// ```
79 ///
80 /// You can also load the wasm text format if more convenient too:
81 ///
82 /// ```no_run
83 /// # use wasmtime::*;
84 /// # fn main() -> anyhow::Result<()> {
85 /// let engine = Engine::default();
86 /// // Now we're using the WebAssembly text extension: `.wat`!
87 /// let module = Module::from_file(&engine, "path/to/foo.wat")?;
88 /// # Ok(())
89 /// # }
90 /// ```
91 ///
92 /// And if you've already got the bytes in-memory you can use the
93 /// [`Module::new`] constructor:
94 ///
95 /// ```no_run
96 /// # use wasmtime::*;
97 /// # fn main() -> anyhow::Result<()> {
98 /// let engine = Engine::default();
99 /// # let wasm_bytes: Vec<u8> = Vec::new();
100 /// let module = Module::new(&engine, &wasm_bytes)?;
101 ///
102 /// // It also works with the text format!
103 /// let module = Module::new(&engine, "(module (func))")?;
104 /// # Ok(())
105 /// # }
106 /// ```
107 ///
108 /// Serializing and deserializing a module looks like:
109 ///
110 /// ```no_run
111 /// # use wasmtime::*;
112 /// # fn main() -> anyhow::Result<()> {
113 /// let engine = Engine::default();
114 /// # let wasm_bytes: Vec<u8> = Vec::new();
115 /// let module = Module::new(&engine, &wasm_bytes)?;
116 /// let module_bytes = module.serialize()?;
117 ///
118 /// // ... can save `module_bytes` to disk or other storage ...
119 ///
120 /// // recreate the module from the serialized bytes. For the `unsafe` bits
121 /// // see the documentation of `deserialize`.
122 /// let module = unsafe { Module::deserialize(&engine, &module_bytes)? };
123 /// # Ok(())
124 /// # }
125 /// ```
126 ///
127 /// [`Config`]: crate::Config
128 #[derive(Clone)]
129 pub struct Module {
130     inner: Arc<ModuleInner>,
131 }
132 
133 struct ModuleInner {
134     engine: Engine,
135     /// The compiled artifacts for this module that will be instantiated and
136     /// executed.
137     module: CompiledModule,
138 
139     /// Runtime information such as the underlying mmap, type information, etc.
140     ///
141     /// Note that this `Arc` is used to share information between compiled
142     /// modules within a component. For bare core wasm modules created with
143     /// `Module::new`, for example, this is a uniquely owned `Arc`.
144     code: Arc<CodeObject>,
145 
146     /// A set of initialization images for memories, if any.
147     ///
148     /// Note that this is behind a `OnceCell` to lazily create this image. On
149     /// Linux where `memfd_create` may be used to create the backing memory
150     /// image this is a pretty expensive operation, so by deferring it this
151     /// improves memory usage for modules that are created but may not ever be
152     /// instantiated.
153     memory_images: OnceLock<Option<ModuleMemoryImages>>,
154 
155     /// Flag indicating whether this module can be serialized or not.
156     serializable: bool,
157 
158     /// Runtime offset information for `VMContext`.
159     offsets: VMOffsets<HostPtr>,
160 }
161 
162 impl fmt::Debug for Module {
163     fn fmt(&self, f: &mut fmt::Formatter<'_>) -> fmt::Result {
164         f.debug_struct("Module")
165             .field("name", &self.name())
166             .finish_non_exhaustive()
167     }
168 }
169 
170 impl fmt::Debug for ModuleInner {
171     fn fmt(&self, f: &mut fmt::Formatter<'_>) -> fmt::Result {
172         f.debug_struct("ModuleInner")
173             .field("name", &self.module.module().name.as_ref())
174             .finish_non_exhaustive()
175     }
176 }
177 
178 impl Module {
179     /// Creates a new WebAssembly `Module` from the given in-memory `bytes`.
180     ///
181     /// The `bytes` provided must be in one of the following formats:
182     ///
183     /// * A [binary-encoded][binary] WebAssembly module. This is always supported.
184     /// * A [text-encoded][text] instance of the WebAssembly text format.
185     ///   This is only supported when the `wat` feature of this crate is enabled.
186     ///   If this is supplied then the text format will be parsed before validation.
187     ///   Note that the `wat` feature is enabled by default.
188     ///
189     /// The data for the wasm module must be loaded in-memory if it's present
190     /// elsewhere, for example on disk. This requires that the entire binary is
191     /// loaded into memory all at once, this API does not support streaming
192     /// compilation of a module.
193     ///
194     /// The WebAssembly binary will be decoded and validated. It will also be
195     /// compiled according to the configuration of the provided `engine`.
196     ///
197     /// # Errors
198     ///
199     /// This function may fail and return an error. Errors may include
200     /// situations such as:
201     ///
202     /// * The binary provided could not be decoded because it's not a valid
203     ///   WebAssembly binary
204     /// * The WebAssembly binary may not validate (e.g. contains type errors)
205     /// * Implementation-specific limits were exceeded with a valid binary (for
206     ///   example too many locals)
207     /// * The wasm binary may use features that are not enabled in the
208     ///   configuration of `engine`
209     /// * If the `wat` feature is enabled and the input is text, then it may be
210     ///   rejected if it fails to parse.
211     ///
212     /// The error returned should contain full information about why module
213     /// creation failed if one is returned.
214     ///
215     /// [binary]: https://webassembly.github.io/spec/core/binary/index.html
216     /// [text]: https://webassembly.github.io/spec/core/text/index.html
217     ///
218     /// # Examples
219     ///
220     /// The `new` function can be invoked with a in-memory array of bytes:
221     ///
222     /// ```no_run
223     /// # use wasmtime::*;
224     /// # fn main() -> anyhow::Result<()> {
225     /// # let engine = Engine::default();
226     /// # let wasm_bytes: Vec<u8> = Vec::new();
227     /// let module = Module::new(&engine, &wasm_bytes)?;
228     /// # Ok(())
229     /// # }
230     /// ```
231     ///
232     /// Or you can also pass in a string to be parsed as the wasm text
233     /// format:
234     ///
235     /// ```
236     /// # use wasmtime::*;
237     /// # fn main() -> anyhow::Result<()> {
238     /// # let engine = Engine::default();
239     /// let module = Module::new(&engine, "(module (func))")?;
240     /// # Ok(())
241     /// # }
242     /// ```
243     #[cfg(any(feature = "cranelift", feature = "winch"))]
244     pub fn new(engine: &Engine, bytes: impl AsRef<[u8]>) -> Result<Module> {
245         crate::CodeBuilder::new(engine)
246             .wasm_binary_or_text(bytes.as_ref(), None)?
247             .compile_module()
248     }
249 
250     /// Creates a new WebAssembly `Module` from the contents of the given
251     /// `file` on disk.
252     ///
253     /// This is a convenience function that will read the `file` provided and
254     /// pass the bytes to the [`Module::new`] function. For more information
255     /// see [`Module::new`]
256     ///
257     /// # Examples
258     ///
259     /// ```no_run
260     /// # use wasmtime::*;
261     /// # fn main() -> anyhow::Result<()> {
262     /// let engine = Engine::default();
263     /// let module = Module::from_file(&engine, "./path/to/foo.wasm")?;
264     /// # Ok(())
265     /// # }
266     /// ```
267     ///
268     /// The `.wat` text format is also supported:
269     ///
270     /// ```no_run
271     /// # use wasmtime::*;
272     /// # fn main() -> anyhow::Result<()> {
273     /// # let engine = Engine::default();
274     /// let module = Module::from_file(&engine, "./path/to/foo.wat")?;
275     /// # Ok(())
276     /// # }
277     /// ```
278     #[cfg(all(feature = "std", any(feature = "cranelift", feature = "winch")))]
279     pub fn from_file(engine: &Engine, file: impl AsRef<Path>) -> Result<Module> {
280         crate::CodeBuilder::new(engine)
281             .wasm_binary_or_text_file(file.as_ref())?
282             .compile_module()
283     }
284 
285     /// Creates a new WebAssembly `Module` from the given in-memory `binary`
286     /// data.
287     ///
288     /// This is similar to [`Module::new`] except that it requires that the
289     /// `binary` input is a WebAssembly binary, the text format is not supported
290     /// by this function. It's generally recommended to use [`Module::new`], but
291     /// if it's required to not support the text format this function can be
292     /// used instead.
293     ///
294     /// # Examples
295     ///
296     /// ```
297     /// # use wasmtime::*;
298     /// # fn main() -> anyhow::Result<()> {
299     /// # let engine = Engine::default();
300     /// let wasm = b"\0asm\x01\0\0\0";
301     /// let module = Module::from_binary(&engine, wasm)?;
302     /// # Ok(())
303     /// # }
304     /// ```
305     ///
306     /// Note that the text format is **not** accepted by this function:
307     ///
308     /// ```
309     /// # use wasmtime::*;
310     /// # fn main() -> anyhow::Result<()> {
311     /// # let engine = Engine::default();
312     /// assert!(Module::from_binary(&engine, b"(module)").is_err());
313     /// # Ok(())
314     /// # }
315     /// ```
316     #[cfg(any(feature = "cranelift", feature = "winch"))]
317     pub fn from_binary(engine: &Engine, binary: &[u8]) -> Result<Module> {
318         crate::CodeBuilder::new(engine)
319             .wasm_binary(binary, None)?
320             .compile_module()
321     }
322 
323     /// Creates a new WebAssembly `Module` from the contents of the given `file`
324     /// on disk, but with assumptions that the file is from a trusted source.
325     /// The file should be a binary- or text-format WebAssembly module, or a
326     /// precompiled artifact generated by the same version of Wasmtime.
327     ///
328     /// # Unsafety
329     ///
330     /// All of the reasons that [`deserialize`] is `unsafe` apply to this
331     /// function as well. Arbitrary data loaded from a file may trick Wasmtime
332     /// into arbitrary code execution since the contents of the file are not
333     /// validated to be a valid precompiled module.
334     ///
335     /// [`deserialize`]: Module::deserialize
336     ///
337     /// Additionally though this function is also `unsafe` because the file
338     /// referenced must remain unchanged and a valid precompiled module for the
339     /// entire lifetime of the [`Module`] returned. Any changes to the file on
340     /// disk may change future instantiations of the module to be incorrect.
341     /// This is because the file is mapped into memory and lazily loaded pages
342     /// reflect the current state of the file, not necessarily the original
343     /// state of the file.
344     #[cfg(all(feature = "std", any(feature = "cranelift", feature = "winch")))]
345     pub unsafe fn from_trusted_file(engine: &Engine, file: impl AsRef<Path>) -> Result<Module> {
346         let open_file = open_file_for_mmap(file.as_ref())?;
347         let mmap = MmapVec::from_file(open_file)?;
348         if &mmap[0..4] == b"\x7fELF" {
349             let code = engine.load_code(mmap, ObjectKind::Module)?;
350             return Module::from_parts(engine, code, None);
351         }
352 
353         crate::CodeBuilder::new(engine)
354             .wasm_binary_or_text(&mmap[..], Some(file.as_ref()))?
355             .compile_module()
356     }
357 
358     /// Deserializes an in-memory compiled module previously created with
359     /// [`Module::serialize`] or [`Engine::precompile_module`].
360     ///
361     /// This function will deserialize the binary blobs emitted by
362     /// [`Module::serialize`] and [`Engine::precompile_module`] back into an
363     /// in-memory [`Module`] that's ready to be instantiated.
364     ///
365     /// Note that the [`Module::deserialize_file`] method is more optimized than
366     /// this function, so if the serialized module is already present in a file
367     /// it's recommended to use that method instead.
368     ///
369     /// # Unsafety
370     ///
371     /// This function is marked as `unsafe` because if fed invalid input or used
372     /// improperly this could lead to memory safety vulnerabilities. This method
373     /// should not, for example, be exposed to arbitrary user input.
374     ///
375     /// The structure of the binary blob read here is only lightly validated
376     /// internally in `wasmtime`. This is intended to be an efficient
377     /// "rehydration" for a [`Module`] which has very few runtime checks beyond
378     /// deserialization. Arbitrary input could, for example, replace valid
379     /// compiled code with any other valid compiled code, meaning that this can
380     /// trivially be used to execute arbitrary code otherwise.
381     ///
382     /// For these reasons this function is `unsafe`. This function is only
383     /// designed to receive the previous input from [`Module::serialize`] and
384     /// [`Engine::precompile_module`]. If the exact output of those functions
385     /// (unmodified) is passed to this function then calls to this function can
386     /// be considered safe. It is the caller's responsibility to provide the
387     /// guarantee that only previously-serialized bytes are being passed in
388     /// here.
389     ///
390     /// Note that this function is designed to be safe receiving output from
391     /// *any* compiled version of `wasmtime` itself. This means that it is safe
392     /// to feed output from older versions of Wasmtime into this function, in
393     /// addition to newer versions of wasmtime (from the future!). These inputs
394     /// will deterministically and safely produce an `Err`. This function only
395     /// successfully accepts inputs from the same version of `wasmtime`, but the
396     /// safety guarantee only applies to externally-defined blobs of bytes, not
397     /// those defined by any version of wasmtime. (this means that if you cache
398     /// blobs across versions of wasmtime you can be safely guaranteed that
399     /// future versions of wasmtime will reject old cache entries).
400     pub unsafe fn deserialize(engine: &Engine, bytes: impl AsRef<[u8]>) -> Result<Module> {
401         let code = engine.load_code_bytes(bytes.as_ref(), ObjectKind::Module)?;
402         Module::from_parts(engine, code, None)
403     }
404 
405     /// Same as [`deserialize`], except that the contents of `path` are read to
406     /// deserialize into a [`Module`].
407     ///
408     /// This method is provided because it can be faster than [`deserialize`]
409     /// since the data doesn't need to be copied around, but rather the module
410     /// can be used directly from an mmap'd view of the file provided.
411     ///
412     /// [`deserialize`]: Module::deserialize
413     ///
414     /// # Unsafety
415     ///
416     /// All of the reasons that [`deserialize`] is `unsafe` applies to this
417     /// function as well. Arbitrary data loaded from a file may trick Wasmtime
418     /// into arbitrary code execution since the contents of the file are not
419     /// validated to be a valid precompiled module.
420     ///
421     /// Additionally though this function is also `unsafe` because the file
422     /// referenced must remain unchanged and a valid precompiled module for the
423     /// entire lifetime of the [`Module`] returned. Any changes to the file on
424     /// disk may change future instantiations of the module to be incorrect.
425     /// This is because the file is mapped into memory and lazily loaded pages
426     /// reflect the current state of the file, not necessarily the original
427     /// state of the file.
428     #[cfg(feature = "std")]
429     pub unsafe fn deserialize_file(engine: &Engine, path: impl AsRef<Path>) -> Result<Module> {
430         let file = open_file_for_mmap(path.as_ref())?;
431         Self::deserialize_open_file(engine, file)
432             .with_context(|| format!("failed deserialization for: {}", path.as_ref().display()))
433     }
434 
435     /// Same as [`deserialize_file`], except that it takes an open `File`
436     /// instead of a path.
437     ///
438     /// This method is provided because it can be used instead of
439     /// [`deserialize_file`] in situations where `wasmtime` is running with
440     /// limited file system permissions. In that case a process
441     /// with file system access can pass already opened files to `wasmtime`.
442     ///
443     /// [`deserialize_file`]: Module::deserialize_file
444     ///
445     /// Note that the corresponding will be mapped as private writeable
446     /// (copy-on-write) and executable. For `windows` this means the file needs
447     /// to be opened with at least `FILE_GENERIC_READ | FILE_GENERIC_EXECUTE`
448     /// [`access_mode`].
449     ///
450     /// [`access_mode`]: https://doc.rust-lang.org/std/os/windows/fs/trait.OpenOptionsExt.html#tymethod.access_mode
451     ///
452     /// # Unsafety
453     ///
454     /// All of the reasons that [`deserialize_file`] is `unsafe` applies to this
455     /// function as well.
456     #[cfg(feature = "std")]
457     pub unsafe fn deserialize_open_file(engine: &Engine, file: File) -> Result<Module> {
458         let code = engine.load_code_file(file, ObjectKind::Module)?;
459         Module::from_parts(engine, code, None)
460     }
461 
462     /// Entrypoint for creating a `Module` for all above functions, both
463     /// of the AOT and jit-compiled categories.
464     ///
465     /// In all cases the compilation artifact, `code_memory`, is provided here.
466     /// The `info_and_types` argument is `None` when a module is being
467     /// deserialized from a precompiled artifact or it's `Some` if it was just
468     /// compiled and the values are already available.
469     pub(crate) fn from_parts(
470         engine: &Engine,
471         code_memory: Arc<CodeMemory>,
472         info_and_types: Option<(CompiledModuleInfo, ModuleTypes)>,
473     ) -> Result<Self> {
474         // Acquire this module's metadata and type information, deserializing
475         // it from the provided artifact if it wasn't otherwise provided
476         // already.
477         let (info, types) = match info_and_types {
478             Some((info, types)) => (info, types),
479             None => postcard::from_bytes(code_memory.wasmtime_info()).err2anyhow()?,
480         };
481 
482         // Register function type signatures into the engine for the lifetime
483         // of the `Module` that will be returned. This notably also builds up
484         // maps for trampolines to be used for this module when inserted into
485         // stores.
486         //
487         // Note that the unsafety here should be ok since the `trampolines`
488         // field should only point to valid trampoline function pointers
489         // within the text section.
490         let signatures = TypeCollection::new_for_module(engine, &types);
491 
492         // Package up all our data into a `CodeObject` and delegate to the final
493         // step of module compilation.
494         let code = Arc::new(CodeObject::new(code_memory, signatures, types.into()));
495         Module::from_parts_raw(engine, code, info, true)
496     }
497 
498     pub(crate) fn from_parts_raw(
499         engine: &Engine,
500         code: Arc<CodeObject>,
501         info: CompiledModuleInfo,
502         serializable: bool,
503     ) -> Result<Self> {
504         let module =
505             CompiledModule::from_artifacts(code.code_memory().clone(), info, engine.profiler())?;
506 
507         // Validate the module can be used with the current instance allocator.
508         let offsets = VMOffsets::new(HostPtr, module.module());
509         engine
510             .allocator()
511             .validate_module(module.module(), &offsets)?;
512 
513         Ok(Self {
514             inner: Arc::new(ModuleInner {
515                 engine: engine.clone(),
516                 code,
517                 memory_images: OnceLock::new(),
518                 module,
519                 serializable,
520                 offsets,
521             }),
522         })
523     }
524 
525     /// Validates `binary` input data as a WebAssembly binary given the
526     /// configuration in `engine`.
527     ///
528     /// This function will perform a speedy validation of the `binary` input
529     /// WebAssembly module (which is in [binary form][binary], the text format
530     /// is not accepted by this function) and return either `Ok` or `Err`
531     /// depending on the results of validation. The `engine` argument indicates
532     /// configuration for WebAssembly features, for example, which are used to
533     /// indicate what should be valid and what shouldn't be.
534     ///
535     /// Validation automatically happens as part of [`Module::new`].
536     ///
537     /// # Errors
538     ///
539     /// If validation fails for any reason (type check error, usage of a feature
540     /// that wasn't enabled, etc) then an error with a description of the
541     /// validation issue will be returned.
542     ///
543     /// [binary]: https://webassembly.github.io/spec/core/binary/index.html
544     pub fn validate(engine: &Engine, binary: &[u8]) -> Result<()> {
545         let mut validator = Validator::new_with_features(engine.features());
546 
547         let mut functions = Vec::new();
548         for payload in Parser::new(0).parse_all(binary) {
549             let payload = payload.err2anyhow()?;
550             if let ValidPayload::Func(a, b) = validator.payload(&payload).err2anyhow()? {
551                 functions.push((a, b));
552             }
553             if let wasmparser::Payload::Version { encoding, .. } = &payload {
554                 if let wasmparser::Encoding::Component = encoding {
555                     bail!("component passed to module validation");
556                 }
557             }
558         }
559 
560         engine
561             .run_maybe_parallel(functions, |(validator, body)| {
562                 // FIXME: it would be best here to use a rayon-specific parallel
563                 // iterator that maintains state-per-thread to share the function
564                 // validator allocations (`Default::default` here) across multiple
565                 // functions.
566                 validator.into_validator(Default::default()).validate(&body)
567             })
568             .err2anyhow()?;
569         Ok(())
570     }
571 
572     /// Serializes this module to a vector of bytes.
573     ///
574     /// This function is similar to the [`Engine::precompile_module`] method
575     /// where it produces an artifact of Wasmtime which is suitable to later
576     /// pass into [`Module::deserialize`]. If a module is never instantiated
577     /// then it's recommended to use [`Engine::precompile_module`] instead of
578     /// this method, but if a module is both instantiated and serialized then
579     /// this method can be useful to get the serialized version without
580     /// compiling twice.
581     #[cfg(any(feature = "cranelift", feature = "winch"))]
582     pub fn serialize(&self) -> Result<Vec<u8>> {
583         // The current representation of compiled modules within a compiled
584         // component means that it cannot be serialized. The mmap returned here
585         // is the mmap for the entire component and while it contains all
586         // necessary data to deserialize this particular module it's all
587         // embedded within component-specific information.
588         //
589         // It's not the hardest thing in the world to support this but it's
590         // expected that there's not much of a use case at this time. In theory
591         // all that needs to be done is to edit the `.wasmtime.info` section
592         // to contains this module's metadata instead of the metadata for the
593         // whole component. The metadata itself is fairly trivially
594         // recreateable here it's more that there's no easy one-off API for
595         // editing the sections of an ELF object to use here.
596         //
597         // Overall for now this simply always returns an error in this
598         // situation. If you're reading this and feel that the situation should
599         // be different please feel free to open an issue.
600         if !self.inner.serializable {
601             bail!("cannot serialize a module exported from a component");
602         }
603         Ok(self.compiled_module().mmap().to_vec())
604     }
605 
606     pub(crate) fn compiled_module(&self) -> &CompiledModule {
607         &self.inner.module
608     }
609 
610     pub(crate) fn code_object(&self) -> &Arc<CodeObject> {
611         &self.inner.code
612     }
613 
614     pub(crate) fn env_module(&self) -> &Arc<wasmtime_environ::Module> {
615         self.compiled_module().module()
616     }
617 
618     pub(crate) fn types(&self) -> &ModuleTypes {
619         self.inner.code.module_types()
620     }
621 
622     pub(crate) fn signatures(&self) -> &TypeCollection {
623         self.inner.code.signatures()
624     }
625 
626     /// Returns identifier/name that this [`Module`] has. This name
627     /// is used in traps/backtrace details.
628     ///
629     /// Note that most LLVM/clang/Rust-produced modules do not have a name
630     /// associated with them, but other wasm tooling can be used to inject or
631     /// add a name.
632     ///
633     /// # Examples
634     ///
635     /// ```
636     /// # use wasmtime::*;
637     /// # fn main() -> anyhow::Result<()> {
638     /// # let engine = Engine::default();
639     /// let module = Module::new(&engine, "(module $foo)")?;
640     /// assert_eq!(module.name(), Some("foo"));
641     ///
642     /// let module = Module::new(&engine, "(module)")?;
643     /// assert_eq!(module.name(), None);
644     ///
645     /// # Ok(())
646     /// # }
647     /// ```
648     pub fn name(&self) -> Option<&str> {
649         self.compiled_module().module().name.as_deref()
650     }
651 
652     /// Returns the list of imports that this [`Module`] has and must be
653     /// satisfied.
654     ///
655     /// This function returns the list of imports that the wasm module has, but
656     /// only the types of each import. The type of each import is used to
657     /// typecheck the [`Instance::new`](crate::Instance::new) method's `imports`
658     /// argument. The arguments to that function must match up 1-to-1 with the
659     /// entries in the array returned here.
660     ///
661     /// The imports returned reflect the order of the imports in the wasm module
662     /// itself, and note that no form of deduplication happens.
663     ///
664     /// # Examples
665     ///
666     /// Modules with no imports return an empty list here:
667     ///
668     /// ```
669     /// # use wasmtime::*;
670     /// # fn main() -> anyhow::Result<()> {
671     /// # let engine = Engine::default();
672     /// let module = Module::new(&engine, "(module)")?;
673     /// assert_eq!(module.imports().len(), 0);
674     /// # Ok(())
675     /// # }
676     /// ```
677     ///
678     /// and modules with imports will have a non-empty list:
679     ///
680     /// ```
681     /// # use wasmtime::*;
682     /// # fn main() -> anyhow::Result<()> {
683     /// # let engine = Engine::default();
684     /// let wat = r#"
685     ///     (module
686     ///         (import "host" "foo" (func))
687     ///     )
688     /// "#;
689     /// let module = Module::new(&engine, wat)?;
690     /// assert_eq!(module.imports().len(), 1);
691     /// let import = module.imports().next().unwrap();
692     /// assert_eq!(import.module(), "host");
693     /// assert_eq!(import.name(), "foo");
694     /// match import.ty() {
695     ///     ExternType::Func(_) => { /* ... */ }
696     ///     _ => panic!("unexpected import type!"),
697     /// }
698     /// # Ok(())
699     /// # }
700     /// ```
701     pub fn imports<'module>(
702         &'module self,
703     ) -> impl ExactSizeIterator<Item = ImportType<'module>> + 'module {
704         let module = self.compiled_module().module();
705         let types = self.types();
706         let engine = self.engine();
707         module
708             .imports()
709             .map(move |(imp_mod, imp_field, mut ty)| {
710                 ty.canonicalize_for_runtime_usage(&mut |i| {
711                     self.signatures().shared_type(i).unwrap()
712                 });
713                 ImportType::new(imp_mod, imp_field, ty, types, engine)
714             })
715             .collect::<Vec<_>>()
716             .into_iter()
717     }
718 
719     /// Returns the list of exports that this [`Module`] has and will be
720     /// available after instantiation.
721     ///
722     /// This function will return the type of each item that will be returned
723     /// from [`Instance::exports`](crate::Instance::exports). Each entry in this
724     /// list corresponds 1-to-1 with that list, and the entries here will
725     /// indicate the name of the export along with the type of the export.
726     ///
727     /// # Examples
728     ///
729     /// Modules might not have any exports:
730     ///
731     /// ```
732     /// # use wasmtime::*;
733     /// # fn main() -> anyhow::Result<()> {
734     /// # let engine = Engine::default();
735     /// let module = Module::new(&engine, "(module)")?;
736     /// assert!(module.exports().next().is_none());
737     /// # Ok(())
738     /// # }
739     /// ```
740     ///
741     /// When the exports are not empty, you can inspect each export:
742     ///
743     /// ```
744     /// # use wasmtime::*;
745     /// # fn main() -> anyhow::Result<()> {
746     /// # let engine = Engine::default();
747     /// let wat = r#"
748     ///     (module
749     ///         (func (export "foo"))
750     ///         (memory (export "memory") 1)
751     ///     )
752     /// "#;
753     /// let module = Module::new(&engine, wat)?;
754     /// assert_eq!(module.exports().len(), 2);
755     ///
756     /// let mut exports = module.exports();
757     /// let foo = exports.next().unwrap();
758     /// assert_eq!(foo.name(), "foo");
759     /// match foo.ty() {
760     ///     ExternType::Func(_) => { /* ... */ }
761     ///     _ => panic!("unexpected export type!"),
762     /// }
763     ///
764     /// let memory = exports.next().unwrap();
765     /// assert_eq!(memory.name(), "memory");
766     /// match memory.ty() {
767     ///     ExternType::Memory(_) => { /* ... */ }
768     ///     _ => panic!("unexpected export type!"),
769     /// }
770     /// # Ok(())
771     /// # }
772     /// ```
773     pub fn exports<'module>(
774         &'module self,
775     ) -> impl ExactSizeIterator<Item = ExportType<'module>> + 'module {
776         let module = self.compiled_module().module();
777         let types = self.types();
778         let engine = self.engine();
779         module.exports.iter().map(move |(name, entity_index)| {
780             ExportType::new(name, module.type_of(*entity_index), types, engine)
781         })
782     }
783 
784     /// Looks up an export in this [`Module`] by name.
785     ///
786     /// This function will return the type of an export with the given name.
787     ///
788     /// # Examples
789     ///
790     /// There may be no export with that name:
791     ///
792     /// ```
793     /// # use wasmtime::*;
794     /// # fn main() -> anyhow::Result<()> {
795     /// # let engine = Engine::default();
796     /// let module = Module::new(&engine, "(module)")?;
797     /// assert!(module.get_export("foo").is_none());
798     /// # Ok(())
799     /// # }
800     /// ```
801     ///
802     /// When there is an export with that name, it is returned:
803     ///
804     /// ```
805     /// # use wasmtime::*;
806     /// # fn main() -> anyhow::Result<()> {
807     /// # let engine = Engine::default();
808     /// let wat = r#"
809     ///     (module
810     ///         (func (export "foo"))
811     ///         (memory (export "memory") 1)
812     ///     )
813     /// "#;
814     /// let module = Module::new(&engine, wat)?;
815     /// let foo = module.get_export("foo");
816     /// assert!(foo.is_some());
817     ///
818     /// let foo = foo.unwrap();
819     /// match foo {
820     ///     ExternType::Func(_) => { /* ... */ }
821     ///     _ => panic!("unexpected export type!"),
822     /// }
823     ///
824     /// # Ok(())
825     /// # }
826     /// ```
827     pub fn get_export(&self, name: &str) -> Option<ExternType> {
828         let module = self.compiled_module().module();
829         let entity_index = module.exports.get(name)?;
830         Some(ExternType::from_wasmtime(
831             self.engine(),
832             self.types(),
833             &module.type_of(*entity_index),
834         ))
835     }
836 
837     /// Looks up an export in this [`Module`] by name to get its index.
838     ///
839     /// This function will return the index of an export with the given name. This can be useful
840     /// to avoid the cost of looking up the export by name multiple times. Instead the
841     /// [`ModuleExport`] can be stored and used to look up the export on the
842     /// [`Instance`](crate::Instance) later.
843     pub fn get_export_index(&self, name: &str) -> Option<ModuleExport> {
844         let compiled_module = self.compiled_module();
845         let module = compiled_module.module();
846         module
847             .exports
848             .get_full(name)
849             .map(|(export_name_index, _, &entity)| ModuleExport {
850                 module: self.id(),
851                 entity,
852                 export_name_index,
853             })
854     }
855 
856     /// Returns the [`Engine`] that this [`Module`] was compiled by.
857     pub fn engine(&self) -> &Engine {
858         &self.inner.engine
859     }
860 
861     /// Returns a summary of the resources required to instantiate this
862     /// [`Module`].
863     ///
864     /// Potential uses of the returned information:
865     ///
866     /// * Determining whether your pooling allocator configuration supports
867     ///   instantiating this module.
868     ///
869     /// * Deciding how many of which `Module` you want to instantiate within a
870     ///   fixed amount of resources, e.g. determining whether to create 5
871     ///   instances of module X or 10 instances of module Y.
872     ///
873     /// # Example
874     ///
875     /// ```
876     /// # fn main() -> wasmtime::Result<()> {
877     /// use wasmtime::{Config, Engine, Module};
878     ///
879     /// let mut config = Config::new();
880     /// config.wasm_multi_memory(true);
881     /// let engine = Engine::new(&config)?;
882     ///
883     /// let module = Module::new(&engine, r#"
884     ///     (module
885     ///         ;; Import a memory. Doesn't count towards required resources.
886     ///         (import "a" "b" (memory 10))
887     ///         ;; Define two local memories. These count towards the required
888     ///         ;; resources.
889     ///         (memory 1)
890     ///         (memory 6)
891     ///     )
892     /// "#)?;
893     ///
894     /// let resources = module.resources_required();
895     ///
896     /// // Instantiating the module will require allocating two memories, and
897     /// // the maximum initial memory size is six Wasm pages.
898     /// assert_eq!(resources.num_memories, 2);
899     /// assert_eq!(resources.max_initial_memory_size, Some(6));
900     ///
901     /// // The module doesn't need any tables.
902     /// assert_eq!(resources.num_tables, 0);
903     /// assert_eq!(resources.max_initial_table_size, None);
904     /// # Ok(()) }
905     /// ```
906     pub fn resources_required(&self) -> ResourcesRequired {
907         let em = self.env_module();
908         let num_memories = u32::try_from(em.num_defined_memories()).unwrap();
909         let max_initial_memory_size = em
910             .memories
911             .values()
912             .skip(em.num_imported_memories)
913             .map(|memory| memory.limits.min)
914             .max();
915         let num_tables = u32::try_from(em.num_defined_tables()).unwrap();
916         let max_initial_table_size = em
917             .tables
918             .values()
919             .skip(em.num_imported_tables)
920             .map(|table| table.limits.min)
921             .max();
922         ResourcesRequired {
923             num_memories,
924             max_initial_memory_size,
925             num_tables,
926             max_initial_table_size,
927         }
928     }
929 
930     /// Returns the range of bytes in memory where this module's compilation
931     /// image resides.
932     ///
933     /// The compilation image for a module contains executable code, data, debug
934     /// information, etc. This is roughly the same as the `Module::serialize`
935     /// but not the exact same.
936     ///
937     /// The range of memory reported here is exposed to allow low-level
938     /// manipulation of the memory in platform-specific manners such as using
939     /// `mlock` to force the contents to be paged in immediately or keep them
940     /// paged in after they're loaded.
941     ///
942     /// It is not safe to modify the memory in this range, nor is it safe to
943     /// modify the protections of memory in this range.
944     pub fn image_range(&self) -> Range<*const u8> {
945         self.compiled_module().mmap().image_range()
946     }
947 
948     /// Force initialization of copy-on-write images to happen here-and-now
949     /// instead of when they're requested during first instantiation.
950     ///
951     /// When [copy-on-write memory
952     /// initialization](crate::Config::memory_init_cow) is enabled then Wasmtime
953     /// will lazily create the initialization image for a module. This method
954     /// can be used to explicitly dictate when this initialization happens.
955     ///
956     /// Note that this largely only matters on Linux when memfd is used.
957     /// Otherwise the copy-on-write image typically comes from disk and in that
958     /// situation the creation of the image is trivial as the image is always
959     /// sourced from disk. On Linux, though, when memfd is used a memfd is
960     /// created and the initialization image is written to it.
961     ///
962     /// Also note that this method is not required to be called, it's available
963     /// as a performance optimization if required but is otherwise handled
964     /// automatically.
965     pub fn initialize_copy_on_write_image(&self) -> Result<()> {
966         self.memory_images()?;
967         Ok(())
968     }
969 
970     /// Get the map from `.text` section offsets to Wasm binary offsets for this
971     /// module.
972     ///
973     /// Each entry is a (`.text` section offset, Wasm binary offset) pair.
974     ///
975     /// Entries are yielded in order of `.text` section offset.
976     ///
977     /// Some entries are missing a Wasm binary offset. This is for code that is
978     /// not associated with any single location in the Wasm binary, or for when
979     /// source information was optimized away.
980     ///
981     /// Not every module has an address map, since address map generation can be
982     /// turned off on `Config`.
983     ///
984     /// There is not an entry for every `.text` section offset. Every offset
985     /// after an entry's offset, but before the next entry's offset, is
986     /// considered to map to the same Wasm binary offset as the original
987     /// entry. For example, the address map will not contain the following
988     /// sequence of entries:
989     ///
990     /// ```ignore
991     /// [
992     ///     // ...
993     ///     (10, Some(42)),
994     ///     (11, Some(42)),
995     ///     (12, Some(42)),
996     ///     (13, Some(43)),
997     ///     // ...
998     /// ]
999     /// ```
1000     ///
1001     /// Instead, it will drop the entries for offsets `11` and `12` since they
1002     /// are the same as the entry for offset `10`:
1003     ///
1004     /// ```ignore
1005     /// [
1006     ///     // ...
1007     ///     (10, Some(42)),
1008     ///     (13, Some(43)),
1009     ///     // ...
1010     /// ]
1011     /// ```
1012     pub fn address_map<'a>(&'a self) -> Option<impl Iterator<Item = (usize, Option<u32>)> + 'a> {
1013         Some(
1014             wasmtime_environ::iterate_address_map(
1015                 self.code_object().code_memory().address_map_data(),
1016             )?
1017             .map(|(offset, file_pos)| (offset as usize, file_pos.file_offset())),
1018         )
1019     }
1020 
1021     /// Get this module's code object's `.text` section, containing its compiled
1022     /// executable code.
1023     pub fn text(&self) -> &[u8] {
1024         self.code_object().code_memory().text()
1025     }
1026 
1027     /// Get information about functions in this module's `.text` section: their
1028     /// index, name, and offset+length.
1029     ///
1030     /// Results are yielded in a ModuleFunction struct.
1031     pub fn functions<'a>(&'a self) -> impl ExactSizeIterator<Item = ModuleFunction> + 'a {
1032         let module = self.compiled_module();
1033         module.finished_functions().map(|(idx, _)| {
1034             let loc = module.func_loc(idx);
1035             let idx = module.module().func_index(idx);
1036             ModuleFunction {
1037                 index: idx,
1038                 name: module.func_name(idx).map(|n| n.to_string()),
1039                 offset: loc.start as usize,
1040                 len: loc.length as usize,
1041             }
1042         })
1043     }
1044 
1045     pub(crate) fn id(&self) -> CompiledModuleId {
1046         self.inner.module.unique_id()
1047     }
1048 
1049     pub(crate) fn offsets(&self) -> &VMOffsets<HostPtr> {
1050         &self.inner.offsets
1051     }
1052 
1053     /// Return the address, in memory, of the trampoline that allows Wasm to
1054     /// call a array function of the given signature.
1055     pub(crate) fn wasm_to_array_trampoline(
1056         &self,
1057         signature: VMSharedTypeIndex,
1058     ) -> Option<NonNull<VMWasmCallFunction>> {
1059         log::trace!("Looking up trampoline for {signature:?}");
1060         let trampoline_shared_ty = self.inner.engine.signatures().trampoline_type(signature);
1061         let trampoline_module_ty = self
1062             .inner
1063             .code
1064             .signatures()
1065             .trampoline_type(trampoline_shared_ty)?;
1066         debug_assert!(self
1067             .inner
1068             .engine
1069             .signatures()
1070             .borrow(
1071                 self.inner
1072                     .code
1073                     .signatures()
1074                     .shared_type(trampoline_module_ty)
1075                     .unwrap()
1076             )
1077             .unwrap()
1078             .unwrap_func()
1079             .is_trampoline_type());
1080 
1081         let ptr = self
1082             .compiled_module()
1083             .wasm_to_array_trampoline(trampoline_module_ty)
1084             .as_ptr()
1085             .cast::<VMWasmCallFunction>()
1086             .cast_mut();
1087         Some(NonNull::new(ptr).unwrap())
1088     }
1089 
1090     pub(crate) fn memory_images(&self) -> Result<Option<&ModuleMemoryImages>> {
1091         let images = self
1092             .inner
1093             .memory_images
1094             .get_or_try_init(|| memory_images(&self.inner.engine, &self.inner.module))?
1095             .as_ref();
1096         Ok(images)
1097     }
1098 
1099     /// Lookup the stack map at a program counter value.
1100     pub(crate) fn lookup_stack_map(&self, pc: usize) -> Option<&wasmtime_environ::StackMap> {
1101         let text_offset = pc - self.inner.module.text().as_ptr() as usize;
1102         let (index, func_offset) = self.inner.module.func_by_text_offset(text_offset)?;
1103         let info = self.inner.module.wasm_func_info(index);
1104 
1105         // Do a binary search to find the stack map for the given offset.
1106         let index = match info
1107             .stack_maps
1108             .binary_search_by_key(&func_offset, |i| i.code_offset)
1109         {
1110             // Found it.
1111             Ok(i) => i,
1112 
1113             // No stack map associated with this PC.
1114             //
1115             // Because we know we are in Wasm code, and we must be at some kind
1116             // of call/safepoint, then the Cranelift backend must have avoided
1117             // emitting a stack map for this location because no refs were live.
1118             Err(_) => return None,
1119         };
1120 
1121         Some(&info.stack_maps[index].stack_map)
1122     }
1123 }
1124 
1125 /// Describes a function for a given module.
1126 pub struct ModuleFunction {
1127     pub index: wasmtime_environ::FuncIndex,
1128     pub name: Option<String>,
1129     pub offset: usize,
1130     pub len: usize,
1131 }
1132 
1133 impl Drop for ModuleInner {
1134     fn drop(&mut self) {
1135         // When a `Module` is being dropped that means that it's no longer
1136         // present in any `Store` and it's additionally not longer held by any
1137         // embedder. Take this opportunity to purge any lingering instantiations
1138         // within a pooling instance allocator, if applicable.
1139         self.engine
1140             .allocator()
1141             .purge_module(self.module.unique_id());
1142     }
1143 }
1144 
1145 /// Describes the location of an export in a module.
1146 #[derive(Copy, Clone)]
1147 pub struct ModuleExport {
1148     /// The module that this export is defined in.
1149     pub(crate) module: CompiledModuleId,
1150     /// A raw index into the wasm module.
1151     pub(crate) entity: EntityIndex,
1152     /// The index of the export name.
1153     pub(crate) export_name_index: usize,
1154 }
1155 
1156 fn _assert_send_sync() {
1157     fn _assert<T: Send + Sync>() {}
1158     _assert::<Module>();
1159 }
1160 
1161 /// Helper method to construct a `ModuleMemoryImages` for an associated
1162 /// `CompiledModule`.
1163 fn memory_images(engine: &Engine, module: &CompiledModule) -> Result<Option<ModuleMemoryImages>> {
1164     // If initialization via copy-on-write is explicitly disabled in
1165     // configuration then this path is skipped entirely.
1166     if !engine.tunables().memory_init_cow {
1167         return Ok(None);
1168     }
1169 
1170     // ... otherwise logic is delegated to the `ModuleMemoryImages::new`
1171     // constructor.
1172     let mmap = if engine.config().force_memory_init_memfd {
1173         None
1174     } else {
1175         Some(module.mmap())
1176     };
1177     ModuleMemoryImages::new(module.module(), module.code_memory().wasm_data(), mmap)
1178 }
1179 
1180 #[cfg(test)]
1181 mod tests {
1182     use crate::{Engine, Module};
1183     use wasmtime_environ::MemoryInitialization;
1184 
1185     #[test]
1186     fn cow_on_by_default() {
1187         let engine = Engine::default();
1188         let module = Module::new(
1189             &engine,
1190             r#"
1191                 (module
1192                     (memory 1)
1193                     (data (i32.const 100) "abcd")
1194                 )
1195             "#,
1196         )
1197         .unwrap();
1198 
1199         let init = &module.env_module().memory_initialization;
1200         assert!(matches!(init, MemoryInitialization::Static { .. }));
1201     }
1202 }
1203