github WasmEdge/WasmEdge 0.18.0
WasmEdge 0.18.0

4 hours ago

0.18.0 (2026-10-05)

Breaking changes:

  • [CAPI]
    • The WasmEdge_ModuleInstanceAddFunction(), WasmEdge_ModuleInstanceAddTable(), WasmEdge_ModuleInstanceAddMemory(), and WasmEdge_ModuleInstanceAddGlobal() APIs return WasmEdge_Result instead of void.
      • They fail with the WrongVMWorkflow error after the module instance is first used in execution, and do NOT take the ownership of the added instance on failure.
    • The libwasmedge shared library exports the versioned symbols with the backward-compatible shims, so that the applications linked against the previous versions keep working. (#4951)
    • Deprecated the WasmEdge_VMForceDeleteRegisteredModule() API in favor of WasmEdge_VMDeleteRegisteredModule(), and moved WasmEdge_ModuleInstanceInitWasmEdgeProcess() into wasmedge_deprecated.h.
  • [AOT]
    • Bumped the AOT binary version from 2 to 3. The artifacts compiled by the older versions should be recompiled.
  • [Runtime]
    • The execution traps with the new CallStackExhausted error when the call stack exceeds the limit, which defaults to 8 MiB in the interpreter and 512 KiB in the AOT and JIT modes. (#5040)
  • [Plugin]
    • Removed the wasmedge_process plug-in (#5295), deprecated the wasmedge-llmc plug-in (#4964), and disabled gzdopen in the wasmedge_zlib plug-in.
    • The wasmedge_opencvmini plug-in requires OpenCV 5, and drops the imshow and waitkey exports. (#5280)
  • [Tools]
    • Removed the --enable-tail-call, --enable-extended-const, --enable-function-reference, --enable-gc, --enable-multi-memory, --enable-relaxed-simd, and --enable-exception-handling options, since the WASM 3.0 standard includes these proposals.
  • [Installer]
    • Dropped the support of installing WasmEdge 0.12.x and the older versions. (#5165)
  • [Build]
    • Deprecated the WASMEDGE_USE_CXX11_ABI CMake option, since WasmEdge is always built with the cxx11 ABI now.

Features:

  • [WASM C API]
    • Implemented the WebAssembly C API proposal (wasm.h) in libwasmedge, providing the C (wasm_*) and the C++ (wasm::) APIs in parallel with the existing WasmEdge_* C API.
  • [Exception Handling]
    • Supported the exception-handling proposal in the AOT, JIT, and lazy JIT modes. (#5168)
  • [Lazy JIT]
    • Added the lazy JIT mode, which compiles each function on its first call, selected by the --run-mode lazyjit CLI option.
  • [Stack Size Limit]
    • Limited the call stack size to trap the deep recursion instead of crashing, configured by the WasmEdge_ConfigureSetMaxStackSize() API or the --stack-size-limit CLI option. (#5040)
  • [Component Model]
    • Completed the loading and the validation of the component model MVP and the async features, following the latest specification. (#4863, #4878, #4915, #4967, #4987, #4990, #5014, #5068, #5132, #5276, #5376)
    • Implemented the synchronous canonical ABI of canon lift and canon lower. (#4893)
    • Supported exporting and aliasing the core tags and the components on instantiation. (#5122, #5137)
  • [Runtime]
    • Finalized the module instances after their first use in execution, which removes the getter locks from the hot path. (#5052)
    • Added the module dependency tree, so that unregistering a module destroys it only when no other module depends on it.
  • [Tools]
    • Added the parse, validate, and instantiate subcommands into the wasmedge CLI. (#4957)
  • [Installer]
    • Added the --no-modify-shell-profile flag to skip modifying the shell login profiles. (#4956)
  • [Build]
    • Used the system blake3 library when it is available. (#5339)
  • [WASI-NN]
    • Upgraded the GGML backend to llama.cpp v0.5.0, and added the load-mode metadata. (#5188, #5356, #5395)
  • [Plugin]
    • The wasi_crypto plug-in supports the managed EdDSA keypair generation (#4776), the EdDSA and ECDSA public key verification (#4927, #4932), and the ML-KEM key encapsulation with OpenSSL 3.5 or later (#5167).
    • The wasmedge_zlib plug-in resolves the gzopen paths through the WASI preopens.
  • [Misc]
    • Enabled the -Wshadow and -Wshadow-field warnings, and added the component model fuzzer targets for OSS-Fuzz. (#5044, #5090)

Performance:

  • [AOT]
    • Inlined memory.size, table.size, table.get, table.set, and the call_indirect dispatch into the compiled code. (#4613)
    • Lowered the SIMD min, max, and abs operations onto the LLVM intrinsics (#4847), and v128.store onto a single vector store (#5329).
  • [Executor]
    • Force-inlined the interpreter instruction dispatch. (#5051)
  • [Validator]
    • Memoized the subtype depth computation of the GC type validation. (#5058)

Fixed issues:

  • [Loader]
    • Bounded the recursion depth of the nested components, and checked the size bound before allocating the read buffer. (#5325)
    • Rejected the reserved flags of br_on_cast and br_on_cast_fail, the out-of-bounds symbol offsets of the AOT custom sections, and the non-regular file paths. (#5255, #5264)
    • Loaded the native shared-library WASM only in the AOT run mode (#5292), and initialized the memory lane immediate of the instructions.
  • [Serializer]
    • Corrected the encodings of table.copy, memory.init, memory.copy, v128.const, and i8x16.shuffle (#4983), the non-final GC subtypes (#5001), the memory64 limits (#5178), the passive element segments (#5269), and the tag exports (#4965).
  • [Validator]
    • Rejected the non-funcref tables and references in call_indirect and call_ref (#4920), the subtypes of the forward-declared supertypes (#5087), and ref.func on the undeclared imported functions (#5314).
    • Reported the subtypes with multiple supertypes by the new MultipleSuperTypes error (#5374), and checked the whole recursive type group before matching the subtypes (#5389).
  • [Executor]
    • Erased the exception payload on catch_all (#5202), and dropped the stale try_table handlers at branch time (#5252).
    • Corrected the return_call into the host functions (#5286), and ref.test and ref.cast on the null locals of the abstract reference types (#5347).
    • Corrected the alignment, the bounds check, and the operand widths of memory.atomic.notify and memory.atomic.wait. (#5304, #5318)
    • Attributed the recorded stack frames and the cross-module traps to their own modules.
  • [AOT]
    • Ran the compiled cross-module calls with the module context of the callee.
    • Bound-checked the memory64 accesses (#5282, #5294, #5304), widened the call_indirect table index for table64, and applied the memmove semantics to the same-memory memory.copy (#5010).
    • Kept the temporary values of the runtime calls in the entry block, which used to overflow the native stack in loops. (#5379)
    • Corrected the tail calls of the mismatched prototypes, the AArch64 NEON intrinsic names, and the lazy JIT state lifetime.
    • Failed the compilation on the LLVM module verification errors, and mapped the Os and Oz levels to O2 with the size attributes on LLVM 23. (#5328)
  • [Runtime]
    • Corrected the module lookup after unregistering a module (#4905), and cleared the named components in StoreManager::reset() (#4897).
    • Corrected the data races and the deep recursion during the store teardown.
  • [Component Model]
    • Trapped on the out-of-bounds and the invalid UTF-8 string lifting, and checked the realloc result of the string lowering. (#4883, #4893, #4991)
    • Grew the component index space on the exports to match the validator. (#5256, #5276)
  • [CAPI]
    • Corrected WasmEdge_FunctionInstanceGetData() for the function instances not created by the C API (#5313), and WasmEdge_ExportTypeGetTagType() for the re-exported imported tags (#5309).
    • Corrected the wasm::Module member functions and the documentation of the WASM C API.
  • [WASI]
    • Rejected the symlink targets outside the preopened root (#4938), and enforced the read-only preopen rights (#5340).
    • Trapped on the misaligned guest pointers (#5089, #5229, #5263, #5301, #5316), and validated the output buffer bounds of sock_getaddrinfo (#5344).
    • Corrected the IPv6 address size of the Windows connect (#4860), F_SETFL on the accepted sockets (#4670), the addrlen of the AF_UNIX sockets (#5124), and the error codes of the Windows sockets and getaddrinfo (#5373, #5392).
    • Corrected poll_oneoff with no subscribed events on Linux (#5364), and its timeouts and select errors on Windows (#5365).
    • Split the fcntl calls to prevent the FORTIFY crash on Android. (#4807)
  • [WASI-NN]
    • Prevented the shell injection through the whisper audio input (#4902) and the load-by-name races of the MLX backend.
    • Bounds-checked the get_output buffers, and sized the RPC output by the guest buffer instead of a hardcoded size. (#5031)
    • Validated the load_by_name extents, the MLX tensor fields (#4949), and the RPC set_input tensor data (#4942).
    • Corrected the lifetime of the graphs and the contexts across the backends.
    • Validated the metadata of the GGML and BitNet backends, rolled back the whole metadata on a rejected option, and applied the options which were ignored before. (#4916, #5356)
    • Rejected the prompts which the tokenizer cannot decode instead of terminating the process. (#4916)
    • Pinned the OpenVINO CPU inference precision to f32. (#5348)
  • [Plugin]
    • Hardened the guest input handling of the wasmedge_zlib, wasmedge_opencvmini (#4923), wasmedge_image (#4914, #5177), and wasi_logging (#5008) plug-ins.
    • Kept the wasi_logging default logger alive across the module instances, and made the plug-in loading robust against the repeated libraries, the duplicate descriptors, and the concurrent accesses.
  • [Common]
    • Avoided the undefined behaviors in the DenseEnumMap iterator (#5004), the rapidhash tail read (#5225), and clz() (#5240).
    • Restored the build against fmt 6 to 12.2 and the older spdlog, and corrected the uint128 formatting and subtraction. (#4936)
    • Corrected the strings in enum.inc (#5241), and added the missing sv suffix to the format strings (#5055, #5098, #5372).
  • [Tools]
    • Registered the --run-mode CLI option with a warning on the unknown values, rejected the empty instantiate input, and corrected the coredump generation. (#5284)
    • Corrected the extra newline and the indentation of the options in the help message. (#5398)
    • Rejected the negative values of the --memory-page-limit option, which wrapped around to the maximum limit. (#5363)
  • [Installer]
    • Corrected the uninstall.sh crash on the duplicate environment entries in the shell profiles. (#5345)
  • [Misc]
    • Made the sources compile as C++20 (#5338), kept the pinned and the system fmt from mixing (#5270), and corrected the missing includes and the shadowed identifiers.
    • Added the missing PropComponent in the driver fuzzer (#5035), and corrected the bug report issue template (#5047).

Tests:

  • Updated the spec test suite to the 2026/09/22 version. (#5279, #5276, #5374)
  • Enabled the assert_exhaustion spec tests (#5040), and the loading and validation of all the component model spec tests (#4967, #4981, #4987, #5276).
  • Added the tests of the WASM C API, the new driver subcommands, the lazy JIT mode (#5093), the cross-module AOT calls, the module dependency tree, and the component canonical ABI (#4893).
  • Rebuilt the serializer test suite (#5006, #5223, #5285), and covered the ULEB32 decoding of the miscellaneous opcodes (#5350).
  • Added the unit tests of the common utilities (#5029) and the spdlog logging API (#4874).
  • Pinned the WASI-NN graph lifetime behaviors, and added the FFmpeg (#5233) and opencvmini plug-in tests.
  • Removed the concrete types from the plug-in tests to keep the host function bindings observable. (#4910, #4913, #4940)
  • Corrected the test builds (#4922, #5277), the random abort of the WASI-NN BitNet test (#4916), and the memory leak in APICoreTest.ModuleDeletion (#5359).
  • Cleaned up the stale test registrations and the misspelled test suite names. (#5396)
  • Shrank the CI test models, and downloaded them through a retrying helper.

Refactored:

  • [AOT]
    • Split the compiled execution context into the per-module ModuleContext and the per-executor ExecutorContext, and resolved the module fields against the executing module.
    • Split lib/llvm/compiler.cpp into the focused compilation units (#5101), and moved the lazy JIT orchestration into a dedicated engine.
  • [Executor]
    • Made the recorded stack traces module-qualified, and extracted the SIMD superinstruction primitives into a header. (#4802)
  • [VM]
    • Deduplicated the WASM unit dispatch and the module container cleanup.
  • [Runtime]
    • Added the RefLifetime primitive for the reference-counted runtime instances, and handled the overlapping copies of setBytes() and setRefs() with memmove. (#5111)
  • [Serializer]
    • Removed the proposal guards from the serializer, and filled the encoding gaps which they used to hide.
  • [Component Model]
    • Simplified the component loader and validator. (#5326, #5332)
  • [WASI-NN]
    • Redesigned the graph and context lifetime around a shared-ownership ResourceTable, and split the dependency setup into the per-backend CMake modules. (#5141)
  • [Misc]
    • Moved the fmt compatibility macros into a dedicated header, and removed the legacy proposal enabling flags from the driver. (#5261)

Misc:

  • [Dependencies]
    • Upgraded fmt to 12.1.0, spdlog to v1.17.0, googletest to v1.17.0, simdjson to v4.6.4 (#5131), stb_image (#5175), TensorFlow to TF-2.21.0-CC, and libtorch to 2.12.1 (#5166).
    • Pinned the FetchContent dependencies to the commit hashes, and included the third-party headers as the system headers. (#5145)
  • [Documentation]
    • Updated the roadmap for Q3/2026 (#5099), the security policy (#5320), AGENTS.md (#5354), and the owner list (#5138).
    • Documented the WASI-NN lifetime design, the CI workflows (#5027), and the AI assistance disclosure (#5013, #5025).
    • Merged the 0.15.1 and 0.16.4 changelogs (#4502, #4970), synchronized the translated READMEs, and corrected the stale links and comments (#4664, #4929, #5053, #5200, #5211, #5266).
  • [Chore]
    • Updated the copyright to The WasmEdge Authors, the contact emails, and the issue and pull request templates (#4911, #5050, #5102, #5159, #5184), and applied the clang-format 20 and 22 results.

CI:

  • [Cache]
    • Cached the compilation with sccache, and the LLVM, Android NDK, CMake, and model downloads.
    • Saved the heavy caches only on master, and deleted the caches of the closed pull requests.
  • [Runner]
    • Added the macOS arm64 static library build (#4948), the fuzzer build (#5036), the wasm-c-api symbol check, and the issue assignment command (#5244, #5253).
    • Enabled the CI for the backward supporting branches (#4976, #4980), and gated the extension and WASI-NN jobs on the path filters per backend (#5104, #5141, #5147).
    • Skipped the macOS test step of the release builds (#5353), upgraded the Debian static build to Bookworm (#5333), and covered the system blake3 in the Debian Testing job (#5339).
    • Pinned the clang-format linter to version 22, moved the IWYU scan to IWYU 0.26 with LLVM 22 (#5335), and bumped lineguard to 0.2.0 (#5336).
    • Corrected the RISC-V64 cross-compilation, the macOS lld installation, the Fedora Rawhide packages, the ChatTTS installation, the libtorch download, and the clang-format version selection. (#4892, #5069, #5114, #5119, #5134)
    • Ignored the gcov negative-hit errors (#5062), limited the Codecov uploads to the filtered report (#5394), trimmed the obsolete apt packages (#4646), corrected the Homebrew tap trust of wasmedge/llvm (#5079), relaxed the commitlint footer length to a warning (#5163), and disabled the automatic triage of s390x and OpenWrt (#5107).
  • [dependabot]

Thank all the contributors who made this release possible!

Aaron Chen, Abdelrahman Emad, Abhijit Das, ADITYA SWAROOP, aizu-m, Ankit Kumar Tiwari, Anusha Murthy, Arthur Chan, Byte-Naut, David laid, Divyansh Khatri, dm4, Drona Raj Gyawali, Faisal Mehmood, Gauarv Chaudhary, Han-Wen Tsao, Harsh, Harsh-6291, Harshita Yadav, hydai, Lia, Manar Elhabbal, Matt Hargett, Mohit Agarwal, nGimotty, Nico Braun, Panda, Parth Dagia, Pramila Kumari, Pranjal Kole, Prerak Tanwar, Priyanshu Bharti, ravindra-RKB, Shen-Ta Hsieh(BestSteve), SHIGRAF SALIK, SHIVA SHARMA, Shivam Kumar, shivansh023023, sleepingeight, SohamBalwant, Sriram-B-Srivatsa, Suhrid Marwah, Taanvi Khevaria, uda18, utsav, Vishal Malyan, Wang-Yang Li, William-Mou, Yan-Hao Wang, Yashika, Yi, Yi Liu, Yi-Ying He

If you want to build from source, please use WasmEdge-0.18.0-src.tar.gz instead of the zip or tarball provided by GitHub directly.

Don't miss a new WasmEdge release

NewReleases is sending notifications on new releases.