WebVM: WASM virtual machine in browser with networking via Tailscale
leaningtech.com
leaningtech.com
Support/Discussion: https://discord.leaningtech.com
Lead dev of CheerpX/WebVM here. Happy to answer questions.
In terms of use cases: education, testing, documentation, distribution of applications, safe execution of legacy applications... and there are surely many others
“ so preoccupied with whether they could, they didn't stop to think if they should”
https://github.com/tailscale/tailscale/commit/6f5096fa61f36e...
its unfortunate one has to result to this, but unfettered access is a lot more palatable on a private network
My latest talk on the topic is available here: https://www.youtube.com/watch?v=rI7opIKW_z4
But what I really want is a capability-based WASM sandbox runtime (like wasmtime or workerd from Cloudflare) that provides an API that lists people that it can send messages to (through Tailscale.)
I configure the runtime with my contacts, and say which apps can communicate with which people.
And then a Dynamic DNS-like system for me to have an identity key, and look up the servers to find them. In case my contacts need to migrate to a new server. Maybe Tailscale already does this?
The runtime keeps the apps updated (like Sandstorm.io).
What I'm describing, I think could be the basis for federated services.
I imagine implementing RSS feeds and RSS Aggregators on top of a system like this.
And lots of other services, too.
I like the idea of it being capability based and sandboxed, because then I can feel safe running a service you wrote on my machine.
And I like the idea of all of the networking being in the framework, rather than being implemented in each app. Just like Sandstorm.io takes a lot of the problems of sharing out of each app.
The way this article ended up with WASM + Tailscale in the browser seems like a great way for a client to talk to a server based on WASM + Tailscale, like I want. So then my phone can connect to my home PC, running these federated services. I can picture implementing Google Photos on top of that. With sharing, too.
Edit: oh it's already a thing now? https://tailscale.com/kb/1084/sharing/
For example, I bet NixOS would alleviate a lot of pain with development and deployment, but the learning curve is steep, poorly documented, and still in need of work, and the community is just not very big yet.
Why is it written in GO when it could have been written in C? Lazy programmers.
This used to be a serious argument once, by the way.
What problem is this, or any WASM, solving? Why do we need a VM in the browser?
This turns a lock-down old Chromebook into a box you can learn to develop on.
Even chromebooks have real linux underneath, the scenario you're describing is so niche it's hard to imagine. IMO it makes much more sense to use free tier on a cloud provider
Think about education Chromebooks that get locked down, too.
for example, these guys link to a discord channel to chat about their work, but i can’t join it easily because even though Discord ships a Linux client, they only ship it for x86 and not arm. further down the road, i’d like to try some RISC-V devices: that’ll be that same experience times ten. a portable assembly format has the chance to overcome this.
https://en.wikipedia.org/wiki/UNCOL
https://en.wikipedia.org/wiki/Architecture_Neutral_Distribut...
https://en.wikipedia.org/wiki/P-code_machine
https://en.wikipedia.org/wiki/IBM_i#TIMI
Not bothering to list all of them since 1958, WebAssembly is only the latest go at it.
but also, look at its neighbors. Vulkan/SPIR-V has made it standard to ship bytecode-level shaders (graphical or compute) which are device agnostic but still performant. even if we’re cursed to try this “architecture agnostic” stuff a hundred times, i don’t think we can say there hasn’t been any progress. that progress only comes from people trying, even if 9 out of 10 serious attempts are flops.
So Wasm has a few legs up on what came before.
As for how sound the type system is in the face of attacks at the Flash, ActiveX and Java applets scale, it remains to be seen, although there are already some USENIX papers slowly coming up regarding WebAssembly actual security.
Other than JavaScript, what other way can you send arbitrary code to a device and expect it to run there? WASM is the only other option.
This is just really inefficient: VM in WASM in javascript in a sandbox in a browser, is insane and will forever be slow due to complexity.
Fun for the lulz, but for the planet's sake I hope this doesn't get adopted.
The networking capabilities are implemented via a JS API (itself, compiled from Go to WebAssembly/JavaScript). This Go library connects to Tailscale DERPs via WebSockets to provide network access to the Tailscale network of each user. The broader internet can then be also accessed if an exit node is configured.