
WASI là gì?
WASI (WebAssembly System Interface) là chuẩn giao diện hệ thống cho WebAssembly (WASM) chạy ngoài trình duyệt, cho phép module WASM truy cập file system, network, clocks, random — mà không cần runtime đầy đủ như OS. Ra mắt bởi nhóm đặc tả WASI, WASI giải quyết bài toán “WASM tồn tại ở đâu ngoài Chrome”.
WASM vốn sinh ra trong browser: sandbox, an toàn, near-native speed. Nhưng bài toán lớn hơn là: tại sao không dùng khả năng này cho server, IoT, plugin systems? WASI chính là bridge giữa WASM và thế giới bên ngoài browser.
Tại sao WASI quan trọng?
WASM vốn được thiết kế sandbox: an toàn, portable, fast. Nhưng thiếu system interface — không gọi file, không bind socket. WASI lấp khoảng trống đó, biến WASM thành container thay thế nhẹ: khởi chạy measured trong milliseconds, footprint measured trong megabytes thay vì gigabytes, isolated mặc định.
So với Docker container truyền thống (100MB-1GB image), WASM binary thường nhỏ hơn 100 lần. Cold start từ 500ms của Docker xuống chưa đến 1ms với WASM runtime. Điều này mở khóa serverless functions responds trong microseconds, thay vì milliseconds.

Thiết kế: Capability-based Security
WASI không dùng permission flags kiểu Unix (read/write/exec bitmask). Thay vào đó, dùng capability: reference mở (handle) phải được cấp tường minh từ host sang guest module. Module không thể mở file trừ khi host explicitly cấp file descriptor.
Model này có 3 ưu điểm: (1) Không privilege escalation — cấp ít nhất có thể (principle of least privilege), (2) Explicit và auditable — không ambient authority, mọi access đều visible, (3) Composable — chain capabilities cho multi-module pipeline.
Các phiên bản WASI
- WASI Preview 1: Thư mục file system, POSIX-compatible subset. API ổn định nhưng limited — chỉ cover basic I/O. Được hỗ trợ rộng rãi bởi Wasmtime và Wasmer.
- WASI Preview 2: Async I/O, streams, non-blocking operations. Phản hồi feedback từ implementers về performance bottleneck. Component Model tích hợp.
- WASI Core (2024+): Spec chuẩn hóa cuối cùng, ghidra cho interoperability đa runtime. Mục tiêu: WASM module chạy trên bất kỳ WASI-compliant runtime nào.
Runtime hỗ trợ WASI
| Runtime | Ngôn ngữ | Đặc điểm chính |
|---|---|---|
| Wasmtime | Rust | Cranelift JIT compiler, component model support, wasm32-wasi target chuẩn |
| Wasmer | Rust | 3 compiler backends (Singlepass/Cranelift/LLVM), WASI packages marketplace |
| Wasm3 | C | Interpreter-based, ultra-portable (runs on Arduino, embedded devices) |
| WasmEdge | Rust | Focused trên serverless computing và edge AI inference |
| V8 / SpiderMonkey | C++ | Built-in WASI trong browser engine, nhưng WASI outside browser cần standalone runtime |
WASM Component Model — Architecture mới
Component Model (CM) là binary format mới thay thế truyền thống wasm32-wasi. CM cho phép: cross-runtime interoperability (module từ language A gọi language B), dynamic linking, và module reuse không cần host adapter.
WIT (WebAssembly Interface Types) định nghĩa interface giữa host và guest bằng ngôn ngữ interface-level. Ví dụ: host expose filesystem.open(path), guest gọi trực tiếp — không cần FFI bindings.

Ứng dụng thực tế
Serverless Functions thế hệ mới
WASM cold start approximately 1ms so với container approximately 500ms. Framework: Fermyon Spin, Cloudflare Workers WASM. Deploy trên Kubernetes qua runwasi shim.
Cloudflare Workers dùng WASM để isolate user code: mỗi request chạy trong WASM sandbox riêng, zero shared state, natural security boundary. Speed: global cold start under 5ms.
Plugin System an toàn
WASM sandbox lý tưởng cho third-party plugins: crash isolation, predictable resource usage, zero side effects trên host. Docker dùng WASM cho plugins intern. Figma dùng WASM plugin runtime từ 2021 — cho phép designers chạy custom code an toàn. Shopify Extensions dùng WASM cho merchant apps.
Edge Computing lightweight
WASM footprint nhỏ (approximately 100KB binary) phù hợp IoT và edge. Fermyon Spin deploy ở edge, giữ state cục bộ, sync lên cloud khi kết nối available. Dữ liệu nhạy cảm giữ tại device — compliance requirement cho healthcare, finance.
Microservices composition
WASM modules composing thành microservices pipeline: module A xử lý input → module B gọi database → module C format output. Mỗi module independent, sandboxed, composable. Resources sharing controlled bởi host runtime.
So sánh WASM vs Docker
| Khía cạnh | Docker Container | WASM (WASI) |
|---|---|---|
| Khởi động (cold start) | approximately 500ms | approximately 1ms |
| Kích thước image | 100MB-1GB | 1-10MB |
| Isolation model | Namespaces + cgroups | Capability-based sandbox |
| Security | Linux capabilities, seccomp | Explicit capability grant, zero ambient authority |
| Language support | Bất kỳ (packaged trong image) | Compiles to WASM (Rust, C, Go, AssemblyScript) |
| Orchestration | Kubernetes mature ecosystem | SpinKube, containerd shim (emerging) |
Bắt đầu với WASI
Cài đặt toolchain (Rust + wasm-pack + WASI target), tạo project và chạy:
rustup target add wasm32-wasicargo new --lib my_wasi_app- Thêm
wasi = "0.11"vào Cargo.toml dependencies cargo build --target wasm32-wasiwasmtime run target/wasm32-wasi/debug/my_wasi_app.wasm
Hoặc dùng Wasmer với wasmer run --dir=. my_wasi_app.wasm — directory mount trực tiếp.
Thách thức hiện tại
- Ecosystem non-standard: WASI Preview 1 chưa hoàn thiện — code cần recompile khi spec thay đổi. Component Model hứa hẹn nhưng chưa stable.
- Tooling chưa trưởng thành: Debugging WASM ngoài trình duyệt phức tạp — không gdb truyền thống, cần dedicated debugging tools.
- Language support unequal: Rust, AssemblyScript, C support tốt nhất. Python và Go trên WASM vẫn experimental (GC overhead lớn).
- Adoption: Thiếu killer app mainstream — serverless vẫn niche so với AWS Lambda và Cloudflare Workers truyền thống. Docker ecosystem quá mature.
- State management: WASM module stateless — persistent storage cần external solution (Redis, SQLite).
Kết luận
WASI là mảnh ghép quan trọng cho WASM outside browser — mở khóa serverless thế hệ mới, plugin secure, và edge computing lightweight. Không thay thế container ngay hôm nay, nhưng với cold start measured trong milliseconds và footprint measured trong kilobytes, WASM đang chiếm mảng compute short-lived workloads. Developer Rust và C nên bắt đầu dùng WASI now; ngôn ngữ khác chờ Component Model ổn định để ecosystem mature hơn.
Nguồn: WASI Spec, Bytecode Alliance, W3C WASM, Docker, Fermyon Spin, Wasmer
