Expand description
§Wasmtime’s wasi-tls (Transport Layer Security) Implementation
This crate provides the Wasmtime host implementation for the wasi-tls API. The wasi-tls world allows WebAssembly modules to perform SSL/TLS operations, such as establishing secure connections to servers. TLS often relies on other wasi networking systems to provide the stream so it will be common to enable the wasi:cli world as well with the networking features enabled.
§An example of how to configure wasi-tls is the following:
use wasmtime_wasi::{WasiCtx, WasiCtxView, WasiView};
use wasmtime::{
component::{Linker, ResourceTable},
Store, Engine, Result,
};
use wasmtime_wasi_tls::{WasiTlsCtx, WasiTlsCtxBuilder, WasiTlsView, WasiTlsCtxView};
use wasmtime_wasi_tls::p2::LinkOptions;
struct Ctx {
table: ResourceTable,
wasi_ctx: WasiCtx,
wasi_tls_ctx: WasiTlsCtx,
}
impl WasiView for Ctx {
fn ctx(&mut self) -> WasiCtxView<'_> {
WasiCtxView { ctx: &mut self.wasi_ctx, table: &mut self.table }
}
}
impl WasiTlsView for Ctx {
fn tls(&mut self) -> WasiTlsCtxView<'_> {
WasiTlsCtxView { ctx: &mut self.wasi_tls_ctx, table: &mut self.table }
}
}
#[tokio::main]
async fn main() -> Result<()> {
let ctx = Ctx {
table: ResourceTable::new(),
wasi_ctx: WasiCtx::builder()
.inherit_stderr()
.inherit_network()
.allow_ip_name_lookup(true)
.build(),
wasi_tls_ctx: WasiTlsCtxBuilder::new()
// Optionally, configure a specific TLS provider:
// .provider(Box::new(wasmtime_wasi_tls::RustlsProvider::default()))
// .provider(Box::new(wasmtime_wasi_tls::NativeTlsProvider::default()))
// .provider(Box::new(wasmtime_wasi_tls::OpenSslProvider::default()))
.build(),
};
let engine = Engine::default();
// Set up wasi-cli
let mut store = Store::new(&engine, ctx);
let mut linker: Linker<Ctx> = Linker::new(&engine);
wasmtime_wasi::p2::add_to_linker_async(&mut linker)?;
// Add wasi-tls types and turn on the feature in linker
let mut opts = LinkOptions::default();
opts.tls(true);
wasmtime_wasi_tls::p2::add_to_linker(&mut linker, &opts)?;
// ... use `linker` to instantiate within `store` ...
Ok(())
}
Modules§
- p2
- WASIp2 (
wasi:tls@0.2.0-draft) host implementation. - p3
- WASIp3 (
wasi:tls@0.3.0-draft) host implementation. Experimental, unstable and incomplete implementation of wasip3 version ofwasi:tls.
Structs§
- Default
Provider - The
rustlsprovider. - Error
- TLS error
- Native
TlsProvider - The
native_tlsprovider. - Open
SslProvider - The
opensslprovider. - Rustls
Provider - The
rustlsprovider. - Unsupported
Provider - A pseudo TLS provider that returns an error for all operations. This is the default provider when no real TLS providers were enabled at compile time.
- Wasi
TlsCtx - Wasi TLS context needed for internal
wasi-tlsstate. - Wasi
TlsCtx Builder - Builder-style structure used to create a
WasiTlsCtx. - Wasi
TlsCtx View - View into
WasiTlsCtximplementation andResourceTable.
Traits§
- TlsProvider
- A TLS implementation.
- TlsStream
- A TLS connection.
- TlsTransport
- The data stream that carries the encrypted TLS data. Typically this is a TCP stream.
- Wasi
TlsView - A trait which provides internal WASI TLS state.