And wasm could run in ring 0 if you want, the runtime is that hardened.
On the other hand, wasm is low-level enough to handle C.
.NET / CLR was the previous attempt to do something like this, and it did have compilers for many different languages targeting it. But the downside there was that the runtime itself wasn't meaningfully portable for a very long time. If it were open and cross-platform from the get go, who knows, perhaps wasm would have been a CIL subset.
Stay tuned, the next article in this series on Wasmtime security will run next Tuesday.
The security of this looks very very fragile. Practically any vulnerability may leave the requests of all customers unprotected.
Compare with the common practice of isolating each customer on its own address space or, better yet, on their own VM, requiring a privilege escalation vulnerability (which is much rarer) to eveasdrop on other processes or VMs running on the same computer
edit: now, if you're running each wasm module on a separate process, sandboxed with seccomp-bpf, now that's another thing entirely, and might be more secure AND more performant than traditional VMs