WasiFs

Struct WasiFs 

Source
pub struct WasiFs {
    pub preopen_fds: RwLock<Vec<u32>>,
    pub fd_map: RwLock<FdList>,
    pub current_dir: Mutex<String>,
    pub root_fs: WasiFsRoot,
    pub root_inode: InodeGuard,
    pub has_unioned: Mutex<HashSet<PackageId>>,
    ephemeral_symlinks: Arc<RwLock<HashMap<PathBuf, EphemeralSymlinkEntry>>>,
    is_wasix: AtomicBool,
    pub(crate) init_preopens: Vec<PreopenedDir>,
    pub(crate) init_vfs_preopens: Vec<String>,
}
Expand description

Warning, modifying these fields directly may cause invariants to break and should be considered unsafe. These fields may be made private in a future release

Lock order when touching both the fd map and an inode: fd_map first, then inode. Prefer the *_locked helpers on WasiFs (insert_fd_locked, clone_fd_locked, close_fd_locked, dup2_at) so handle counts and map slots stay consistent under concurrency.

Fields§

§preopen_fds: RwLock<Vec<u32>>§fd_map: RwLock<FdList>§current_dir: Mutex<String>§root_fs: WasiFsRoot§root_inode: InodeGuard§has_unioned: Mutex<HashSet<PackageId>>§ephemeral_symlinks: Arc<RwLock<HashMap<PathBuf, EphemeralSymlinkEntry>>>§is_wasix: AtomicBool§init_preopens: Vec<PreopenedDir>§init_vfs_preopens: Vec<String>

Implementations§

Source§

impl WasiFs

Source

fn writable_package_mount( fs: Arc<dyn FileSystem + Send + Sync>, limiter: Option<&DynFsMemoryLimiter>, ) -> Arc<dyn FileSystem + Send + Sync>

Source

pub fn is_wasix(&self) -> bool

Source

pub fn set_is_wasix(&self, is_wasix: bool)

Source

pub fn fork(&self) -> Self

Forking the WasiState is used when either fork or vfork is called

Source

pub async fn close_cloexec_fds(&self)

Closes all file descriptors marked CLOEXEC (except stdio and preopens).

Source

pub async fn close_all(&self)

Closes all file descriptors, flushing captured handles after dropping the map lock.

Source

pub async fn conditional_union( &self, binary: &BinaryPackage, ) -> Result<(), FsError>

Will conditionally union the binary file system with this one if it has not already been unioned

Source

pub(crate) fn new_with_preopen( inodes: &WasiInodes, preopens: &[PreopenedDir], vfs_preopens: &[String], fs_backing: WasiFsRoot, ) -> Result<Self, String>

Created for the builder API. like new but with more information

Source

pub(crate) fn relative_path_to_absolute(&self, path: String) -> String

Converts a relative path into an absolute path

Source

fn new_init( fs_backing: WasiFsRoot, inodes: &WasiInodes, st_ino: Inode, ) -> Result<Self, String>

Private helper function to init the filesystem, called in new and new_with_preopen

Source

pub unsafe fn open_dir_all( &mut self, inodes: &WasiInodes, base: WasiFd, name: String, rights: Rights, rights_inheriting: Rights, flags: Fdflags, fd_flags: Fdflagsext, ) -> Result<WasiFd, FsError>

This function is like create dir all, but it also opens it. Function is unsafe because it may break invariants and hasn’t been tested. This is an experimental function and may be removed

§Safety
  • Virtual directories created with this function must not conflict with the standard operation of the WASI filesystem. This is vague and unlikely in practice. Join the discussion for what the newer, safer WASI FS APIs should look like.
Source

pub fn open_file_at( &mut self, inodes: &WasiInodes, base: WasiFd, file: Box<dyn VirtualFile + Send + Sync + 'static>, open_flags: u16, name: String, rights: Rights, rights_inheriting: Rights, flags: Fdflags, fd_flags: Fdflagsext, ) -> Result<WasiFd, FsError>

Opens a user-supplied file in the directory specified with the name and flags given

Source

pub fn swap_file( &self, fd: WasiFd, file: Box<dyn VirtualFile + Send + Sync + 'static>, ) -> Result<Option<Box<dyn VirtualFile + Send + Sync + 'static>>, FsError>

Change the backing of a given file descriptor Returns the old backing TODO: add examples

Source

pub fn filestat_resync_size(&self, fd: WasiFd) -> Result<Filesize, Errno>

refresh size from filesystem

Source

pub fn set_current_dir(&self, path: &str)

Changes the current directory

Source

pub fn get_current_dir( &self, inodes: &WasiInodes, base: WasiFd, ) -> Result<(InodeGuard, String), Errno>

Gets the current directory

Source

pub(crate) fn get_current_dir_inner( &self, inodes: &WasiInodes, base: WasiFd, symlink_count: u32, ) -> Result<(InodeGuard, String), Errno>

Source

fn get_inode_at_path_inner( &self, inodes: &WasiInodes, cur_inode: InodeGuard, path_str: &str, symlink_count: &mut u32, follow_symlinks: bool, ) -> Result<InodeGuard, Errno>

Resolve a path in the POSIX namespace visible to the WASIX guest.

This function intentionally resolves guest paths, not host-native paths. A Windows host path may contain \, drive prefixes, or UNC prefixes, but those belong to mount setup and backing filesystem access. Once a host directory is mounted into WASIX, the guest observes a POSIX path tree where / is the only separator. Raw syscall paths must therefore be parsed with POSIX rules even when the runtime itself is running on Windows.

POSIX path resolution is stricter than Rust’s Path::components(): explicit ., explicit .., an empty pathname, and a trailing slash are all observable. In particular, file/ and file/. must fail with Errno::Notdir, lstat("symlink_to_dir/") must follow the symlink to prove the result is a directory, and lstat("symlink_to_file/") must fail with Errno::Notdir. For that reason this function uses a small POSIX component parser instead of Path::components().

Symlink following follows the POSIX rule used by openat-style APIs: intermediate symlinks are always followed, while the final component is followed only when follow_symlinks is true. Recursive symlink resolution increments symlink_count, and symlink depth exhaustion maps to Errno::Loop.

There are two loops here with different jobs. The outer loop walks the parsed path components. The inner component_lookup loop normally runs once, but has one virtual-root overlay case: when the current inode is Kind::Root and a component is not found directly, it can jump through the mounted entries["/"] inode and retry the same component. That is WASIX virtual-root behavior, not plain POSIX filesystem traversal.

Keep these edge cases intact when editing this function:

  • Empty pathnames are Errno::Noent; they do not resolve to the base inode unless a separate AT_EMPTY_PATH-style extension is introduced.
  • Absolute paths resolve from VIRTUAL_ROOT_FD, independent of the caller-provided starting inode.
  • A literal root pathname (/, //, and so on) preserves historical WASIX behavior: if the virtual root contains a mounted entries["/"] directory, the literal root path resolves to that mounted directory. This special case is intentionally limited to an all-slashes pathname.
  • Parent traversal is semantic, not a string rewrite. The virtual root’s parent is itself, but a mounted directory whose guest name is / still has the virtual root as its parent. Therefore /.. may resolve to Kind::Root after walking from the mounted / directory upward, and traversal that genuinely reaches Kind::Root must not be remapped back to entries["/"] at the end. That distinction lets WASI guests see the virtual root with all preopens via .. without changing the behavior of opening literal /.
  • . and .. are semantic components: they require the current inode to be a directory or virtual root, otherwise they fail with Errno::Notdir.
  • Special files may be returned only as the final component. As path prefixes, they fail with Errno::Notdir.

The returned InodeGuard is the inode for the resolved final object in the WASIX inode graph. It is not necessarily an already-open host file: file inodes discovered here are normally created with handle: None, and path_open or a similar caller opens the backing file later. If the final object is a symlink and follow_symlinks is false, the returned inode is the symlink itself; otherwise symlink targets are resolved recursively and the returned inode is the target.

Directory entries are a lazy cache over the backing filesystem. When a child name is already present in the current Kind::Dir or Kind::Root, that cached inode wins. When a child is missing from a Kind::Dir, this resolver builds the backing path for that one component, checks the ephemeral symlink table, then calls root_fs.symlink_metadata() without following symlinks. Based on that metadata it materializes a Kind::Dir, Kind::File, Kind::Symlink, or supported special-file inode. Persistent backing entries are inserted into the parent directory cache; ephemeral symlink inodes are transient and are not cached as directory entries.

Cached directory entries are part of the guest-visible directory model, not merely an implementation detail. A later fd_readdir over a backing directory must merge these cached children with host children instead of hiding non-preopen cache entries; otherwise cleanup and tree-walking code can miss inodes that this resolver can still reach.

This function is therefore not a full synchronization pass. It observes the backing filesystem on cache misses, but cached entries are reused without re-statting. Syscalls that mutate the filesystem are responsible for keeping the inode cache and ephemeral symlink map coherent with their changes.

Source

pub(crate) fn get_inode_at_path( &self, inodes: &WasiInodes, base: WasiFd, path: &str, follow_symlinks: bool, ) -> Result<InodeGuard, Errno>

gets a host file from a base directory and a path this function ensures the fs remains sandboxed

Source

pub(crate) fn get_inode_at_path_from_inode( &self, inodes: &WasiInodes, base_inode: InodeGuard, path: &str, follow_symlinks: bool, ) -> Result<InodeGuard, Errno>

Source

pub(crate) fn get_parent_inode_at_path( &self, inodes: &WasiInodes, base: WasiFd, path: &Path, follow_symlinks: bool, ) -> Result<(InodeGuard, String), Errno>

Returns the parent Dir or Root that the file at a given path is in and the file name stripped off

Source

pub fn get_fd(&self, fd: WasiFd) -> Result<Fd, Errno>

Source

pub fn get_fd_inode(&self, fd: WasiFd) -> Result<InodeGuard, Errno>

Source

pub fn filestat_fd(&self, fd: WasiFd) -> Result<Filestat, Errno>

Source

pub fn fdstat(&self, fd: WasiFd) -> Result<Fdstat, Errno>

Source

pub fn prestat_fd(&self, fd: WasiFd) -> Result<Prestat, Errno>

Source

pub(crate) fn prestat_fd_inner(&self, inode_val: &InodeVal) -> Prestat

Source

pub(crate) fn create_inode( &self, inodes: &WasiInodes, kind: Kind, is_preopened: bool, name: String, ) -> Result<InodeGuard, Errno>

Creates an inode and inserts it given a Kind and some extra data

Source

pub(crate) fn create_inode_with_default_stat( &self, inodes: &WasiInodes, kind: Kind, is_preopened: bool, name: Cow<'static, str>, ) -> InodeGuard

Creates an inode and inserts it given a Kind, does not assume the file exists.

Source

pub(crate) fn create_inode_with_stat( &self, inodes: &WasiInodes, kind: Kind, is_preopened: bool, name: Cow<'static, str>, stat: Filestat, ) -> InodeGuard

Creates an inode with the given filestat and inserts it.

Source

fn make_fd( rights: Rights, rights_inheriting: Rights, fs_flags: Fdflags, fd_flags: Fdflagsext, open_flags: u16, inode: InodeGuard, idx: Option<WasiFd>, ) -> Fd

Source

pub(crate) fn insert_fd_locked( fd_map: &mut FdList, rights: Rights, rights_inheriting: Rights, fs_flags: Fdflags, fd_flags: Fdflagsext, open_flags: u16, inode: InodeGuard, idx: Option<WasiFd>, exclusive: bool, ) -> Result<WasiFd, Errno>

Insert a new fd into an already write-locked fd map.

Lock order: callers must hold fd_map.write() and must not hold any inode lock while acquiring the fd map lock.

Source

pub(crate) fn clone_fd_locked( fs: &WasiFs, fd_map: &mut FdList, fd: WasiFd, min_result_fd: WasiFd, cloexec: Option<bool>, ) -> Result<WasiFd, Errno>

Duplicate an fd into an already write-locked fd map.

Source

pub(crate) fn get_fd_from_locked_map( fs: &WasiFs, fd_map: &FdList, fd: WasiFd, ) -> Result<Fd, Errno>

Resolve an fd from a write-locked map (includes VIRTUAL_ROOT_FD fallback).

Source

fn virtual_root_fd(root_inode: InodeGuard) -> Fd

Source

fn ensure_file_handle_present(fd: &Fd) -> Result<(), Errno>

Source

pub(crate) fn dup2_at( &self, src: WasiFd, dst: WasiFd, ) -> Result<Option<Arc<RwLock<Box<dyn VirtualFile + Send + Sync + 'static>>>>, Errno>

POSIX dup2: copy src onto exact slot dst, replacing any existing entry.

Holds fd_map.write() for the full remove+insert. Returns a flush target for the replaced dst entry (if any), captured while the lock is held and before remove calls drop_one_handle, which may clear the inode’s file handle.

Source

pub fn create_fd( &self, rights: Rights, rights_inheriting: Rights, fs_flags: Fdflags, fd_flags: Fdflagsext, open_flags: u16, inode: InodeGuard, ) -> Result<WasiFd, Errno>

Source

pub fn with_fd( &self, rights: Rights, rights_inheriting: Rights, fs_flags: Fdflags, fd_flags: Fdflagsext, open_flags: u16, inode: InodeGuard, idx: WasiFd, ) -> Result<(), Errno>

Source

pub fn create_fd_ext( &self, rights: Rights, rights_inheriting: Rights, fs_flags: Fdflags, fd_flags: Fdflagsext, open_flags: u16, inode: InodeGuard, idx: Option<WasiFd>, exclusive: bool, ) -> Result<WasiFd, Errno>

Source

pub fn clone_fd(&self, fd: WasiFd) -> Result<WasiFd, Errno>

Source

pub fn clone_fd_ext( &self, fd: WasiFd, min_result_fd: WasiFd, cloexec: Option<bool>, ) -> Result<WasiFd, Errno>

Source

pub unsafe fn remove_inode( &self, inodes: &WasiInodes, ino: Inode, ) -> Option<Arc<InodeVal>>

Low level function to remove an inode, that is it deletes the WASI FS’s knowledge of a file.

This function returns the inode if it existed and was removed.

§Safety
  • The caller must ensure that all references to the specified inode have been removed from the filesystem.
Source

pub(crate) fn create_stdout(&self, inodes: &WasiInodes)

Source

pub(crate) fn create_stdin(&self, inodes: &WasiInodes)

Source

pub(crate) fn create_stderr(&self, inodes: &WasiInodes)

Source

pub(crate) fn create_rootfd(&self) -> Result<(), String>

Source

pub(crate) fn create_preopens( &self, inodes: &WasiInodes, ignore_duplicates: bool, ) -> Result<(), String>

Source

pub(crate) fn create_std_dev_inner( &self, inodes: &WasiInodes, handle: Box<dyn VirtualFile + Send + Sync + 'static>, name: &'static str, raw_fd: WasiFd, rights: Rights, fd_flags: Fdflags, st_ino: Inode, )

Source

pub fn get_stat_for_kind(&self, kind: &Kind) -> Result<Filestat, Errno>

Source

pub(crate) fn close_fd_and_capture_flush(&self, fd: WasiFd) -> CloseFdOutcome

Closes an open FD under fd_map.write(), capturing a file handle for post-close flush while the map lock is held.

Lock order: fd_map write, then inode read (never the reverse).

Source

fn close_fd_locked(fd_map: &mut FdList, fd: WasiFd) -> CloseFdOutcome

Closes an open FD in an already write-locked fd map.

Source

pub(crate) async fn flush_file_best_effort( file: Arc<RwLock<Box<dyn VirtualFile + Send + Sync + 'static>>>, )

Source

fn file_flush_target( inode: &InodeGuard, ) -> Option<Arc<RwLock<Box<dyn VirtualFile + Send + Sync + 'static>>>>

Source

pub(crate) fn close_fd(&self, fd: WasiFd) -> Result<(), Errno>

Closes an open FD, handling all details such as FD being preopen

Trait Implementations§

Source§

impl Debug for WasiFs

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more

Auto Trait Implementations§

§

impl !Freeze for WasiFs

§

impl !RefUnwindSafe for WasiFs

§

impl Send for WasiFs

§

impl Sync for WasiFs

§

impl Unpin for WasiFs

§

impl !UnwindSafe for WasiFs

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
§

impl<T> ArchivePointee for T

§

type ArchivedMetadata = ()

The archived version of the pointer metadata for this type.
§

fn pointer_metadata( _: &<T as ArchivePointee>::ArchivedMetadata, ) -> <T as Pointee>::Metadata

Converts some archived metadata to the pointer metadata for itself.
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

§

impl<T> Instrument for T

§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided [Span], returning an Instrumented wrapper. Read more
§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoEither for T

Source§

fn into_either(self, into_left: bool) -> Either<Self, Self>

Converts self into a Left variant of Either<Self, Self> if into_left is true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
where F: FnOnce(&Self) -> bool,

Converts self into a Left variant of Either<Self, Self> if into_left(&self) returns true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
§

impl<T> LayoutRaw for T

§

fn layout_raw(_: <T as Pointee>::Metadata) -> Result<Layout, LayoutError>

Returns the layout of the type.
§

impl<T, N1, N2> Niching<NichedOption<T, N1>> for N2
where T: SharedNiching<N1, N2>, N1: Niching<T>, N2: Niching<T>,

§

unsafe fn is_niched(niched: *const NichedOption<T, N1>) -> bool

Returns whether the given value has been niched. Read more
§

fn resolve_niched(out: Place<NichedOption<T, N1>>)

Writes data to out indicating that a T is niched.
§

impl<T> Pointable for T

§

const ALIGN: usize

The alignment of pointer.
§

type Init = T

The type for initializers.
§

unsafe fn init(init: <T as Pointable>::Init) -> usize

Initializes a with the given initializer. Read more
§

unsafe fn deref<'a>(ptr: usize) -> &'a T

Dereferences the given pointer. Read more
§

unsafe fn deref_mut<'a>(ptr: usize) -> &'a mut T

Mutably dereferences the given pointer. Read more
§

unsafe fn drop(ptr: usize)

Drops the object pointed to by the given pointer. Read more
§

impl<T> Pointee for T

§

type Metadata = ()

The metadata type for pointers and references to this type.
§

impl<T> PolicyExt for T
where T: ?Sized,

§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns [Action::Follow] only if self and other return Action::Follow. Read more
§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns [Action::Follow] if either self or other returns Action::Follow. Read more
Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<T> Upcastable for T
where T: Any + Debug + 'static,

Source§

fn upcast_any_ref(&self) -> &(dyn Any + 'static)

Source§

fn upcast_any_mut(&mut self) -> &mut (dyn Any + 'static)

Source§

fn upcast_any_box(self: Box<T>) -> Box<dyn Any>

§

impl<T> Upcastable for T
where T: Any + Send + Sync + 'static,

§

fn upcast_any_ref(&self) -> &(dyn Any + 'static)

upcast ref
§

fn upcast_any_mut(&mut self) -> &mut (dyn Any + 'static)

upcast mut ref
§

fn upcast_any_box(self: Box<T>) -> Box<dyn Any>

upcast boxed dyn
§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

§

fn vzip(self) -> V

§

impl<T> WithSubscriber for T

§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a [WithDispatch] wrapper. Read more
§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a [WithDispatch] wrapper. Read more
§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

§

impl<A, B, T> HttpServerConnExec<A, B> for T
where B: Body,

§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,