← PortfolioCompute and infrastructure

Dylibso

WebAssembly infrastructure and developer tools for plugin systems

Team
Steve ManuelCEO
Benjamin EckelCTO
Founded
2022
Invested
2022
Links
The problem

How do you let strangers run code inside your app without getting burned?

Click a line of the manifest to grant or revoke it. The plug-in gets through only where the host has opened the way; everything else stops at the sandbox wall.A plug-in runs sandboxed inside the program that loaded it, and a manifest says what it may reach. Its calls to web hosts and folders stop at the wall unless the manifest lists them, and an empty list means none at all. The one way back into the host is a function the host chose to hand over, and memory and running time are capped too.An illustration, not real data.
How WebAssembly works

, or Wasm, is a portable binary format for executable programs. It was built to run fast code in web pages, but it works outside the browser too, and it is meant to support any language on any operating system. You write in Rust, C, Go or Python, and the compiler hands you a .wasm file.

Each module runs in a , walled off from the program hosting it, and can't get out except through the doors the host provides. It has to declare every function it can reach when it loads. Touch memory outside its bounds, or call a function with the wrong signature, and it stops dead with a .

A Wasm runtime can be embedded into any host application, much like a Java virtual machine, and plug-in interfaces are one of the main uses for it outside the browser.

Further reading WebAssembly (Wikipedia)Why the Component Model? (Bytecode Alliance)Security (WebAssembly)

Why it is hard
  1. i.

    A plugin is a stranger

    A plug-in system lets users or customers add their own logic at chosen points in your application. Running that code is, at bottom, running someone else's program inside yours. The naive way is JavaScript's eval, which one engineering team called "the quintessential definition of insecure."

  2. ii.

    Slow, broken, or both

    Software history is full of third-party extensions that hurt their platform. Some slowed the tool to a crawl. Others broke whenever the platform shipped a new version. Figma tried an iframe sandbox first, and ended up running plugins in a JavaScript engine written in C and compiled to WebAssembly.

  3. iii.

    Only numbers cross

    Plain Wasm functions can only pass integers and floating-point numbers. A string travels as two integers, an offset into memory and a length, and nothing in the type system stops you mixing them up. Every language lays out strings differently in memory too, so getting a Go host to talk to a Rust plugin takes careful plumbing.

Further reading Overview (Extism)How to build a plugin system on the web and also sleep well at night (Figma)Why the Component Model? (Bytecode Alliance)

What Dylibso is after

Engineering teams face more feature requests than they can build, often several times over. Letting customers extend the product themselves moves some of that work outside the core, but only if the product's owners aren't afraid of what the extensions might do.

Dylibso builds WebAssembly tools to make plug-in systems something any team can add. Its open-source framework, Extism, has a plain goal: "to make all software programmable."

Further reading Overview (Extism)Extism (Dylibso)

How they go at it
  1. Step 1: A library import away

    Extism is a lightweight framework that a host program imports like any other library, with SDKs for Python, Node, Ruby, Rust, Go, PHP, C/C++, OCaml and more. Plug-ins can be written in any language and embedded in any language, and all plug-in code runs fully sandboxed.

  2. Step 2: The host holds the keys

    A describes each plugin and the limits on it: how much memory it may take, which web hosts it may call and which files it may see. Leave the host list empty and no hosts are allowed. Leave the paths empty and it gets no file access. Extism adds runtime limiters and timers so a plugin can't run forever.

  3. Step 3: Doors in both directions

    Usually a host calls the plugin. With , the host can also hand the plugin a few of its own functions, say one that queries the host's database, so the plugin can call back in through a door the host chose.

  4. Step 4: Wasm on the JVM

    Chicory, another Dylibso project, is a WebAssembly runtime written in pure Java on top of the standard library, so Java applications can run Wasm plugins without relying on native system resources.

Further reading extism/extism (GitHub)Extism (Dylibso)Plug-in System (Extism)The Manifest (Extism)Host Functions (Extism)Chicory (Dylibso)Dylibso (GitHub)

Still open
  • Will the component model fix the plumbing?

    It wraps Wasm modules in components that talk through interfaces written in a language called WIT, with real strings and records. A component written in Go can call one in C or Rust, and components can't export memory, which tightens the sandbox further.

  • How much speed does the sandbox cost?

    Early benchmarks put Wasm about 10% slower than comparable native code. In one study of cryptography, the fastest runtime was about 2.32 times slower than native code tuned for the chip. It depends heavily on the task.

  • Is the tooling ready?

    In one developer survey, fewer than half of participants were satisfied with the state of WebAssembly, and most wanted better support, debugging and build tools.

Further reading Why the Component Model? (Bytecode Alliance)WebAssembly (Wikipedia)

About Dylibso

Dylibso builds WebAssembly infrastructure and developer tools that enable plugin systems and user-defined code execution in platforms.

Key products include XTP (platform for building plugin systems), Extism (open-source universal plugin system), Chicory (Java-native WebAssembly runtime), and mcp.run (registry of AI tools for the Model Context Protocol).

Dylibso's tools are used in production by developer-facing platforms across the industry.

Words used here
WebAssembly
A compact, portable format for programs that runs at close to native speed inside a sandbox.
sandbox
A walled-off environment where code can run without touching anything the host hasn't allowed.
trap
An immediate halt when a Wasm program does something illegal, such as reading outside its memory.
host functions
Functions an application deliberately exposes to a plugin, so the plugin can ask the host to do things.
manifest
A description of a plugin's code and the limits it runs under.
component model
A layer on top of WebAssembly that lets modules written in different languages exchange rich data types safely.
WASI
The WebAssembly System Interface: a standard set of capabilities, like files and clocks, for Wasm outside the browser.
Sources