A collection of utility components that remix wasi:sockets types and interfaces.
Access control for wasi:sockets is split between gates and latches. A gate wraps the sockets interfaces and consults a latch before each operation, a latch decides whether the operation may proceed. Latches are small and single purpose, combine them to build a policy. Tracing components log socket activity without changing it.
Put wasi:sockets behind a latch. Each operation is authorized before it reaches the underlying socket, denied operations fail, and denied inbound traffic is dropped before it reaches the guest.
gate: gates both tcp/udp sockets and ip-name-lookupgate-types: gates tcp and udp socketsgate-ip-name-lookup: gates ip-name-lookup
Caution
Interfering with network sockets can have dramatic, unintended consequences. A denied operation surfaces to the guest as a network failure, and dropped inbound traffic looks like a peer that never answers, which can trigger retries, timeouts and fallbacks far from the operation that was denied. A policy that looks correct can still cut off traffic a component depends on, for example name lookups or return traffic. Install new latches, and new configurations of existing latches, cautiously and monitor the result: roll out with latch-dry-run, watch decisions with latch-trace, and review the denials the gate logs.
Decide which socket operations are allowed. A latch defers or denies, an operation proceeds unless a latch denies it.
Deny a whole category of operations, without configuration.
latch-defer-all: defers everything, allowing all operationslatch-deny-all: denies every operationlatch-deny-tcp/latch-deny-udp: denies all tcp or all udp operationslatch-deny-ipv4/latch-deny-ipv6: denies all IPv4 or all IPv6 operationslatch-deny-bind: denies explicitly binding tcp and udp sockets to a local addresslatch-deny-connect: denies outbound connectionslatch-deny-ip-name-lookup: denies all ip-name lookups, uses the internallatch-deny-ip-name-lookup-config
Control which host names can be resolved, and tie connections to names that were resolved.
latch-ip-name-lookup-glob: grants or denies lookups by host name glob patternslatch-deny-connect-unless-lookup-address: denies connecting to addresses that were not returned by an allowed lookup
Restrict which remote addresses traffic can originate from or be sent to, by CIDR range and optionally port range, while allowing return traffic.
latch-cidr: restricts traffic originating in either directionlatch-cidr-bind: restricts which local addresses and ports sockets are bound tolatch-cidr-egress: restricts outbound traffic the guest originateslatch-cidr-ingress: restricts inbound traffic remote peers originatelatch-deny-private-networks-cidr-config: config forlatch-cidr-egressdenying outbound traffic to private, loopback, link local and other addresses that are not globally reachable, a baseline against server side request forgery that can be refined before use
Build a policy from several latches, apply a latch to only part of the traffic, for example to configure tcp and udp differently, or try a policy before enforcing it.
latch-n2,latch-n3,latch-n4,latch-n5: aggregate two to five latches, any latch can deny an operationlatch-delegate-tcp/latch-delegate-udp: apply a wrapped latch to only tcp or only udp operationslatch-dry-run: log what a wrapped latch would deny without enforcing it, to roll out a policy
Deny operations on purpose, to prove a component is resilient to failures in a hostile environment.
latch-deny-random: randomly denies a configurable fraction of operations, reproducible with a seed
Log wasi:sockets calls and latch decisions, for debugging or auditing, without affecting them.
trace: traces both tcp/udp sockets and ip-name-lookuptrace-types: traces tcp and udp socketstrace-ip-name-lookup: traces ip-name-lookuplatch-trace: traces the decisions of a wrapped latch
Prereqs:
- a rust toolchain
cargo-binstall, optional, to download prebuilt tools instead of building them
make componentsThe cli tools the build uses, static-config, wasm-tools, wac and wkg, are pinned in tools/Cargo.toml and installed into target/tools as needed, or ahead of time with make tools. Dependabot bumps the pinned versions.
The Componentized project follow the Contributor Covenant Code of Conduct. In short, be kind and treat others with respect.
General discussion and questions about the project can occur in the project's GitHub discussions.
The Componentized project team welcomes contributions from the community. A contributor license agreement (CLA) is not required. You own full rights to your contribution and agree to license the work to the community under the Apache License v2.0, via a Developer Certificate of Origin (DCO). For more detailed information, refer to CONTRIBUTING.md.
This project was conceived in discussion between Mark Fisher and Scott Andrews.
Apache License v2.0: see LICENSE for details.