New QuickJS Release
github.com
github.com
If you want to safely evaluate untrusted Javascript in the browser or Node with control over CPU time and memory use, a custom module system, or call async code synchronously, check it out: https://github.com/justjake/quickjs-emscripten
It's used by a few projects like Hoppscotch, a Postman-like visual API client (https://hoppscotch.io/). They use it for request scripting: https://docs.hoppscotch.io/documentation/getting-started/res...
I put together a proof of concept for this about a year ago, in case this is a use case you currently have: https://github.com/ijustlovemath/jescx
I wanted to try Bun, but it had some blocking bugs at the time (which have since been resolved—or so I’ve read).
[1] https://nitter.net/kebsworld/status/1648488613351657474#m
If I wanted to make a HTTPS request in quickjs I'd probably need to pull in openssl, write a http parser, etc, etc.
I might be wrong, but comparing quickjs to node/deno seems like comparing a aquarium pump to an electric car. They both contain engines that are driven by electricity, but the similarities stop there. They are both good at what they do, but I would never replace one with the other.
> I might be wrong, but comparing quickjs to node/deno seems like comparing a aquarium pump to an electric car.
My intention was not to compare QuickJS to Node/Deno, only their ability to create small binaries.
The only time I'd prefer another runtime is if I had really high performance expectations, but if that was the case, I'd probably write a new implementation of the JS library in a performance focused language versus try to shoehorn JS into doing something it wasn't designed to do
The newsworthy bit here is that the activity seemed to have stalled for year or two and now Fabrice pushed a few fixes and made a new release.
Event loops, a dynamic pixel canvas, very little and basic audio/video/network/vector drawing interfaces.
Something along that line. I know that the hard parts would be to decide when this framework is "done" and keep it immune to non critical change/feature creeps etc.
LuaJIT is pretty good as far as performance goes. In these benchmarks, sometimes slower than Node/Bun but uses consistently less memory too:
https://programming-language-benchmarks.vercel.app/lua-vs-ja...
For a long running orlarge JS code something like Spidermonkey or V8 with their JITs might be faster. But they are not as embedding friendly and their code bases are much larger.
Just need adding some new "pertinent" standard stuff, once in while.
Pros of quickjs-emscripten over ShadowRealm:
- You can use quickjs today in any browser with WASM. ShadowRealm isn't available yet, and polyfills have had security issues in the past. See https://www.figma.com/blog/an-update-on-plugin-security/
- In ShadowRealm eval, untrusted code can consume arbitrary CPU cycles. With QuickJS, you can control the CPU time used during an `eval` using an [interrupt handler] that's called periodically during the eval.
- In ShadowRealm eval, untrusted code can allocate arbitrary amounts of memory. With QuickJS, you can control both the [stack size] and the [heap size] available inside the runtime.
- quickjs-emscripten can do interesting things with custom module loaders and facades that allow synchronous code inside the runtime to call async code on the host.
Pros of ShadowRealm over QuickJS:
- ShadowRealm will (presumably?) execute code using your native runtime, probably v8, JavaScriptCore, or SpiderMonkey. Quickjs is orders of magnitude slower than JIT'd javascript performance of v8 etc. It's also slower than v8/JSC's interpreters, although not by a huge amount. See [benchmarks] from 2019.
- You can easily call and pass values to ShadowRealm imported functions. Talking to quickjs-emscripten guest code requires a lot of fiddly and manual object building.
- Overall the quickjs(-emscripten) API is verbose, and requires manual memory management of references to values inside the quickjs runtime.
[interrupt handler]: https://github.com/justjake/quickjs-emscripten/blob/main/doc...
[stack size]: https://github.com/justjake/quickjs-emscripten/blob/main/doc...
[heap size]: https://github.com/justjake/quickjs-emscripten/blob/main/doc...
[benchmarks]: https://bellard.org/quickjs/bench.html