0.18.0 (2026-10-05)
Breaking changes:
- [CAPI]
- The
WasmEdge_ModuleInstanceAddFunction(),WasmEdge_ModuleInstanceAddTable(),WasmEdge_ModuleInstanceAddMemory(), andWasmEdge_ModuleInstanceAddGlobal()APIs returnWasmEdge_Resultinstead ofvoid.- They fail with the
WrongVMWorkflowerror after the module instance is first used in execution, and do NOT take the ownership of the added instance on failure.
- They fail with the
- The
libwasmedgeshared library exports the versioned symbols with the backward-compatible shims, so that the applications linked against the previous versions keep working. (#4951) - Deprecated the
WasmEdge_VMForceDeleteRegisteredModule()API in favor ofWasmEdge_VMDeleteRegisteredModule(), and movedWasmEdge_ModuleInstanceInitWasmEdgeProcess()intowasmedge_deprecated.h.
- The
- [AOT]
- Bumped the AOT binary version from
2to3. The artifacts compiled by the older versions should be recompiled.
- Bumped the AOT binary version from
- [Runtime]
- The execution traps with the new
CallStackExhaustederror when the call stack exceeds the limit, which defaults to 8 MiB in the interpreter and 512 KiB in the AOT and JIT modes. (#5040)
- The execution traps with the new
- [Plugin]
- [Tools]
- Removed the
--enable-tail-call,--enable-extended-const,--enable-function-reference,--enable-gc,--enable-multi-memory,--enable-relaxed-simd, and--enable-exception-handlingoptions, since the WASM 3.0 standard includes these proposals.
- Removed the
- [Installer]
- Dropped the support of installing WasmEdge
0.12.xand the older versions. (#5165)
- Dropped the support of installing WasmEdge
- [Build]
- Deprecated the
WASMEDGE_USE_CXX11_ABICMake option, since WasmEdge is always built with the cxx11 ABI now.
- Deprecated the
Features:
- [WASM C API]
- Implemented the WebAssembly C API proposal (
wasm.h) inlibwasmedge, providing the C (wasm_*) and the C++ (wasm::) APIs in parallel with the existingWasmEdge_*C API.
- Implemented the WebAssembly C API proposal (
- [Exception Handling]
- Supported the exception-handling proposal in the AOT, JIT, and lazy JIT modes. (#5168)
- [Lazy JIT]
- Added the lazy JIT mode, which compiles each function on its first call, selected by the
--run-mode lazyjitCLI option.
- Added the lazy JIT mode, which compiles each function on its first call, selected by the
- [Stack Size Limit]
- Limited the call stack size to trap the deep recursion instead of crashing, configured by the
WasmEdge_ConfigureSetMaxStackSize()API or the--stack-size-limitCLI option. (#5040)
- Limited the call stack size to trap the deep recursion instead of crashing, configured by the
- [Component Model]
- Completed the loading and the validation of the component model MVP and the async features, following the latest specification. (#4863, #4878, #4915, #4967, #4987, #4990, #5014, #5068, #5132, #5276, #5376)
- Implemented the synchronous canonical ABI of
canon liftandcanon lower. (#4893) - Supported exporting and aliasing the core tags and the components on instantiation. (#5122, #5137)
- [Runtime]
- Finalized the module instances after their first use in execution, which removes the getter locks from the hot path. (#5052)
- Added the module dependency tree, so that unregistering a module destroys it only when no other module depends on it.
- [Tools]
- Added the
parse,validate, andinstantiatesubcommands into thewasmedgeCLI. (#4957)
- Added the
- [Installer]
- Added the
--no-modify-shell-profileflag to skip modifying the shell login profiles. (#4956)
- Added the
- [Build]
- Used the system blake3 library when it is available. (#5339)
- [WASI-NN]
- [Plugin]
- [Misc]
Performance:
- [AOT]
- [Executor]
- Force-inlined the interpreter instruction dispatch. (#5051)
- [Validator]
- Memoized the subtype depth computation of the GC type validation. (#5058)
Fixed issues:
- [Loader]
- Bounded the recursion depth of the nested components, and checked the size bound before allocating the read buffer. (#5325)
- Rejected the reserved flags of
br_on_castandbr_on_cast_fail, the out-of-bounds symbol offsets of the AOT custom sections, and the non-regular file paths. (#5255, #5264) - Loaded the native shared-library WASM only in the AOT run mode (#5292), and initialized the memory lane immediate of the instructions.
- [Serializer]
- [Validator]
- Rejected the non-funcref tables and references in
call_indirectandcall_ref(#4920), the subtypes of the forward-declared supertypes (#5087), andref.funcon the undeclared imported functions (#5314). - Reported the subtypes with multiple supertypes by the new
MultipleSuperTypeserror (#5374), and checked the whole recursive type group before matching the subtypes (#5389).
- Rejected the non-funcref tables and references in
- [Executor]
- Erased the exception payload on
catch_all(#5202), and dropped the staletry_tablehandlers at branch time (#5252). - Corrected the
return_callinto the host functions (#5286), andref.testandref.caston the null locals of the abstract reference types (#5347). - Corrected the alignment, the bounds check, and the operand widths of
memory.atomic.notifyandmemory.atomic.wait. (#5304, #5318) - Attributed the recorded stack frames and the cross-module traps to their own modules.
- Erased the exception payload on
- [AOT]
- Ran the compiled cross-module calls with the module context of the callee.
- Bound-checked the memory64 accesses (#5282, #5294, #5304), widened the
call_indirecttable index for table64, and applied the memmove semantics to the same-memorymemory.copy(#5010). - Kept the temporary values of the runtime calls in the entry block, which used to overflow the native stack in loops. (#5379)
- Corrected the tail calls of the mismatched prototypes, the AArch64 NEON intrinsic names, and the lazy JIT state lifetime.
- Failed the compilation on the LLVM module verification errors, and mapped the
OsandOzlevels toO2with the size attributes on LLVM 23. (#5328)
- [Runtime]
- [Component Model]
- [CAPI]
- [WASI]
- Rejected the symlink targets outside the preopened root (#4938), and enforced the read-only preopen rights (#5340).
- Trapped on the misaligned guest pointers (#5089, #5229, #5263, #5301, #5316), and validated the output buffer bounds of
sock_getaddrinfo(#5344). - Corrected the IPv6 address size of the Windows
connect(#4860),F_SETFLon the accepted sockets (#4670), theaddrlenof theAF_UNIXsockets (#5124), and the error codes of the Windows sockets andgetaddrinfo(#5373, #5392). - Corrected
poll_oneoffwith no subscribed events on Linux (#5364), and its timeouts andselecterrors on Windows (#5365). - Split the
fcntlcalls to prevent the FORTIFY crash on Android. (#4807)
- [WASI-NN]
- Prevented the shell injection through the whisper audio input (#4902) and the load-by-name races of the MLX backend.
- Bounds-checked the
get_outputbuffers, and sized the RPC output by the guest buffer instead of a hardcoded size. (#5031) - Validated the
load_by_nameextents, the MLX tensor fields (#4949), and the RPCset_inputtensor data (#4942). - Corrected the lifetime of the graphs and the contexts across the backends.
- Validated the metadata of the GGML and BitNet backends, rolled back the whole metadata on a rejected option, and applied the options which were ignored before. (#4916, #5356)
- Rejected the prompts which the tokenizer cannot decode instead of terminating the process. (#4916)
- Pinned the OpenVINO CPU inference precision to f32. (#5348)
- [Plugin]
- Hardened the guest input handling of the
wasmedge_zlib,wasmedge_opencvmini(#4923),wasmedge_image(#4914, #5177), andwasi_logging(#5008) plug-ins. - Kept the
wasi_loggingdefault logger alive across the module instances, and made the plug-in loading robust against the repeated libraries, the duplicate descriptors, and the concurrent accesses.
- Hardened the guest input handling of the
- [Common]
- Avoided the undefined behaviors in the
DenseEnumMapiterator (#5004), the rapidhash tail read (#5225), andclz()(#5240). - Restored the build against fmt 6 to 12.2 and the older spdlog, and corrected the
uint128formatting and subtraction. (#4936) - Corrected the strings in
enum.inc(#5241), and added the missingsvsuffix to the format strings (#5055, #5098, #5372).
- Avoided the undefined behaviors in the
- [Tools]
- Registered the
--run-modeCLI option with a warning on the unknown values, rejected the emptyinstantiateinput, and corrected the coredump generation. (#5284) - Corrected the extra newline and the indentation of the options in the help message. (#5398)
- Rejected the negative values of the
--memory-page-limitoption, which wrapped around to the maximum limit. (#5363)
- Registered the
- [Installer]
- Corrected the
uninstall.shcrash on the duplicate environment entries in the shell profiles. (#5345)
- Corrected the
- [Misc]
Tests:
- Updated the spec test suite to the 2026/09/22 version. (#5279, #5276, #5374)
- Enabled the
assert_exhaustionspec tests (#5040), and the loading and validation of all the component model spec tests (#4967, #4981, #4987, #5276). - Added the tests of the WASM C API, the new driver subcommands, the lazy JIT mode (#5093), the cross-module AOT calls, the module dependency tree, and the component canonical ABI (#4893).
- Rebuilt the serializer test suite (#5006, #5223, #5285), and covered the ULEB32 decoding of the miscellaneous opcodes (#5350).
- Added the unit tests of the common utilities (#5029) and the spdlog logging API (#4874).
- Pinned the WASI-NN graph lifetime behaviors, and added the FFmpeg (#5233) and opencvmini plug-in tests.
- Removed the concrete types from the plug-in tests to keep the host function bindings observable. (#4910, #4913, #4940)
- Corrected the test builds (#4922, #5277), the random abort of the WASI-NN BitNet test (#4916), and the memory leak in
APICoreTest.ModuleDeletion(#5359). - Cleaned up the stale test registrations and the misspelled test suite names. (#5396)
- Shrank the CI test models, and downloaded them through a retrying helper.
Refactored:
- [AOT]
- Split the compiled execution context into the per-module
ModuleContextand the per-executorExecutorContext, and resolved the module fields against the executing module. - Split
lib/llvm/compiler.cppinto the focused compilation units (#5101), and moved the lazy JIT orchestration into a dedicated engine.
- Split the compiled execution context into the per-module
- [Executor]
- Made the recorded stack traces module-qualified, and extracted the SIMD superinstruction primitives into a header. (#4802)
- [VM]
- Deduplicated the WASM unit dispatch and the module container cleanup.
- [Runtime]
- Added the
RefLifetimeprimitive for the reference-counted runtime instances, and handled the overlapping copies ofsetBytes()andsetRefs()with memmove. (#5111)
- Added the
- [Serializer]
- Removed the proposal guards from the serializer, and filled the encoding gaps which they used to hide.
- [Component Model]
- [WASI-NN]
- Redesigned the graph and context lifetime around a shared-ownership
ResourceTable, and split the dependency setup into the per-backend CMake modules. (#5141)
- Redesigned the graph and context lifetime around a shared-ownership
- [Misc]
- Moved the fmt compatibility macros into a dedicated header, and removed the legacy proposal enabling flags from the driver. (#5261)
Misc:
- [Dependencies]
- [Documentation]
- Updated the roadmap for Q3/2026 (#5099), the security policy (#5320),
AGENTS.md(#5354), and the owner list (#5138). - Documented the WASI-NN lifetime design, the CI workflows (#5027), and the AI assistance disclosure (#5013, #5025).
- Merged the 0.15.1 and 0.16.4 changelogs (#4502, #4970), synchronized the translated READMEs, and corrected the stale links and comments (#4664, #4929, #5053, #5200, #5211, #5266).
- Updated the roadmap for Q3/2026 (#5099), the security policy (#5320),
- [Chore]
CI:
- [Cache]
- Cached the compilation with sccache, and the LLVM, Android NDK, CMake, and model downloads.
- Saved the heavy caches only on
master, and deleted the caches of the closed pull requests.
- [Runner]
- Added the macOS arm64 static library build (#4948), the fuzzer build (#5036), the wasm-c-api symbol check, and the issue assignment command (#5244, #5253).
- Enabled the CI for the backward supporting branches (#4976, #4980), and gated the extension and WASI-NN jobs on the path filters per backend (#5104, #5141, #5147).
- Skipped the macOS test step of the release builds (#5353), upgraded the Debian static build to Bookworm (#5333), and covered the system blake3 in the Debian Testing job (#5339).
- Pinned the clang-format linter to version 22, moved the IWYU scan to IWYU 0.26 with LLVM 22 (#5335), and bumped lineguard to 0.2.0 (#5336).
- Corrected the RISC-V64 cross-compilation, the macOS lld installation, the Fedora Rawhide packages, the ChatTTS installation, the libtorch download, and the clang-format version selection. (#4892, #5069, #5114, #5119, #5134)
- Ignored the gcov negative-hit errors (#5062), limited the Codecov uploads to the filtered report (#5394), trimmed the obsolete apt packages (#4646), corrected the Homebrew tap trust of
wasmedge/llvm(#5079), relaxed the commitlint footer length to a warning (#5163), and disabled the automatic triage of s390x and OpenWrt (#5107).
- [dependabot]
- ci(dependabot): bump github/codeql-action from 4.35.4 to 4.38.2 (#4889, #4924, #4944, #5127, #5130, #5155, #5156, #5190, #5193, #5219, #5220, #5249, #5251, #5273, #5274, #5289, #5291, #5307, #5308, #5321, #5322, #5351, #5352, #5367, #5369, #5384, #5385)
- ci(dependabot): bump step-security/harden-runner from 2.19.1 to 2.21.1 (#4890, #4899, #5157, #5275, #5290, #5334)
- ci(dependabot): bump cachix/install-nix-action from 31.10.6 to 31.11.1 (#5158, #5191, #5288)
- ci(dependabot): bump actions/cache from 5.0.5 to 6.1.0 (#5083, #5084, #5085)
- ci(dependabot): bump actions/checkout from 6.0.2 to 7.0.1 (#4925, #5042, #5218)
- ci(dependabot): bump actions/labeler from 6.1.0 to 7.0.0 (#5154, #5221)
- ci(dependabot): bump actions/setup-python from 6.2.0 to 7.0.0 (#5082, #5192)
- ci(dependabot): bump codecov/codecov-action from 6.0.0 to 7.1.1 (#4888, #4943, #5370)
- ci(dependabot): bump dorny/paths-filter from 4.0.1 to 4.0.3 (#5129, #5272)
- ci(dependabot): bump mozilla-actions/sccache-action to 0.0.11 (#5128, #5250)
- ci(dependabot): bump docker/login-action from 4.4.0 to 4.6.0 (#5217, #5247)
- ci(dependabot): bump docker/setup-buildx-action from 4.2.0 to 4.3.0 (#5306)
- ci(dependabot): bump crazy-max/ghaction-chocolatey from 4.0.0 to 4.1.0 (#5081)
- ci(dependabot): bump vedantmgoyal9/winget-releaser from 7bd472b to a8fff44 (#5248, #5368)
- ci(dependabot): bump the docker group with 3 updates (#4898, #5126, #5366)
Thank all the contributors who made this release possible!
Aaron Chen, Abdelrahman Emad, Abhijit Das, ADITYA SWAROOP, aizu-m, Ankit Kumar Tiwari, Anusha Murthy, Arthur Chan, Byte-Naut, David laid, Divyansh Khatri, dm4, Drona Raj Gyawali, Faisal Mehmood, Gauarv Chaudhary, Han-Wen Tsao, Harsh, Harsh-6291, Harshita Yadav, hydai, Lia, Manar Elhabbal, Matt Hargett, Mohit Agarwal, nGimotty, Nico Braun, Panda, Parth Dagia, Pramila Kumari, Pranjal Kole, Prerak Tanwar, Priyanshu Bharti, ravindra-RKB, Shen-Ta Hsieh(BestSteve), SHIGRAF SALIK, SHIVA SHARMA, Shivam Kumar, shivansh023023, sleepingeight, SohamBalwant, Sriram-B-Srivatsa, Suhrid Marwah, Taanvi Khevaria, uda18, utsav, Vishal Malyan, Wang-Yang Li, William-Mou, Yan-Hao Wang, Yashika, Yi, Yi Liu, Yi-Ying He
If you want to build from source, please use WasmEdge-0.18.0-src.tar.gz instead of the zip or tarball provided by GitHub directly.