findutils for WASIX
uutils findutils 0.10.0, based on
42143b5260bc60f4b643fe58dd7b8c5fe476f8c8. The package provides find, xargs,
locate, and updatedb as native WASIX commands. It includes no Bash wrappers.
Build
Install Rustup, Python 3.9+, patch, a native C compiler, Wasmer 7.4.2,
and wasm-tools 1.251.0. Install the pinned build dependencies once:
rustup toolchain install 1.96.1 --profile minimal
cargo +1.96.1 install cargo-wasix --version 0.1.33 --locked
cargo wasix download-toolchain v2026-07-07.3+rust-1.96
# This WASIX distribution omits Cargo; avoid a host-dependent rustup fallback.
ln -s "$(rustup which --toolchain 1.96.1 cargo)" "$(rustc +wasix --print sysroot)/bin/cargo"
cargo +1.96.1 install wasixcc --version 0.4.4 --locked
wasixccenv install-executables "$HOME/.cargo/bin"
wasixccenv download-llvm 21.1.204
WASIXCC_SYSROOT_PREFIX="$HOME/.wasixcc/sysroot-v2026-05-12.1" wasixccenv download-sysroot v2026-05-12.1
On Linux, restore executable bits missing from the pinned native linker shims:
chmod +x "$(rustc +wasix --print sysroot)"/lib/rustlib/*-unknown-linux-gnu/bin/gcc-ld/*
Build from the fork:
git clone --branch codex/wasix https://github.com/wasix-org/findutils.git
cd findutils
bash wasix/build.sh
python3 wasix/test.py
The build uses cargo wasix build --release --locked --bin find --bin xargs --bin locate --bin updatedb. Cargo-wasix handles the Rust toolchain and
Binaryen 130 exception conversion. Wasixcc compiles the Oniguruma dependency.
The small script prepares checksum-verified dependency patches, supplies
browser-compatible flags, validates the modules, collects license notices,
and builds .wasix/findutils-0.10.1.webc using wasmer package build.
The lockfile, overlay registry, compiler versions and dependency archive hashes
are pinned. wasix/prepare.py never changes Cargo's shared registry sources.
Artifacts and dependency sources are under ignored .wasix/ and target/.
.wasix/provenance.json records the source revision, dirty state, tools and
lockfile hash. Release builds should use a clean checkout.
Reproducibility and validation
CI builds and runs the real WebC on Linux, then builds in a fresh target directory and compares all four modules and the WebC byte for byte. The same check can be run locally:
cp -R .wasix/dist .wasix/first-dist
cp .wasix/findutils-0.10.1.webc .wasix/first.webc
CARGO_TARGET_DIR=.wasix/repro-target bash wasix/build.sh
for command in find xargs locate updatedb; do
cmp ".wasix/first-dist/$command.wasm" ".wasix/dist/$command.wasm"
done
cmp .wasix/first.webc .wasix/findutils-0.10.1.webc
This verifies repeat builds with the same host toolchain. Cross-host compiler distributions are not assumed to produce identical bytes. Package filesystem timestamps and embedded source paths are normalized.
Tests cover matching, Unicode/spaces, file identity, inode/link counts,
symlink following and loops, -xdev, deletion, exit status, child execution,
NUL-delimited xargs input, and creating/querying a locate database.
Port changes and limits
WASIX metadata enables -inum, -links, and the %i/%n printf fields.
These reflect the sandbox filesystem: mounted host hardlinks may have distinct
virtual inodes and link counts, rather than their host metadata. Three dependency patches add WASIX
file handling: same-file uses real device/inode identity; walkdir supports
filesystem boundaries; uucore compiles for WASIX, uses real file identity
instead of comparing sizes, and recognizes directory stdin.
Upstream Unix-only ownership, permission and filesystem-type predicates retain
upstream's non-Unix limitations. WASIX access checks follow the upstream
best-effort fallback. updatedb retains its default path pruning; filesystem-type pruning is
unavailable on this target. Commands launched
by find -exec or xargs must be supplied by the surrounding sandbox. Upstream
uutils compatibility limitations still apply; this is not GNU findutils.
Run and publish
wasmer run wasmer/findutils@0.10.1 --volume "$PWD:/workspace" -- /workspace -name '*.rs'
wasmer run wasmer/findutils@0.10.1 --entrypoint xargs -- --help
wasmer run wasmer/findutils@0.10.1 --registry wasmer.wtf -- --version
Consume the commands without embedding modules:
[dependencies]
"wasmer/findutils" = "=0.10.1"
[[command]]
name = "find"
module = "wasmer/findutils:find"
runner = "wasi"
After building and testing a committed checkout, publish the same staged
package with credentials authorized for the wasmer namespace:
wasmer publish . --registry wasmer.io --wait=container --non-interactive
wasmer publish . --registry wasmer.wtf --wait=container --non-interactive
Packages: wasmer.io and wasmer.wtf. CI uploads artifacts and checksums; it does not publish or require registry credentials.
Package 0.10.1 stores dependency notices at /opt/findutils/licenses. This keeps
license mounts out of /usr, where they interfere with Wasmer command installation.
The compiled utility versions are unchanged.