Skip to content

About

Rust runtime for signed, encrypted WebAssembly bundles on Android: Ed25519 verification, capability-based sandbox, private-range socket filter, and a JNI bridge with Kotlin wrapper

Resources

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Repository files navigation

WASM Engine in Rust

A Rust runtime that executes signed .fuel bundles (WASM programs such as CPython, QuickJS, yt-dlp and small tools) inside a sandbox. Android (aarch64 + armv7) is the main target, and Linux desktop is supported too. The engine uses the wasmi interpreter, so it needs no JIT, mmap or signal handlers.

Documentation

Document What it covers
SPEC.md The full implementation spec: .fuel bundle format (Ed25519 signing, optional AES-256-GCM), capabilities and limits, engine dispatch, custom WASI host functions (sockets, process, poll_oneoff), the virtual filesystem, environment variables, network policy / SSRF protection, and the test plan.
ANDROID-GETTING-STARTED.md How to add the engine to an Android app: getting the libfuel_jni.so files, the Kotlin FuelEngine wrapper, the ExecSpec/ExecResult API, threading, performance, yt-dlp URL extraction, production vs. dev builds, and troubleshooting.
SECURITY.md How to report a vulnerability (support@uprock.com), what is in scope, and known issues such as browser traffic not being private-range filtered.

New to the project? Read the Android guide first to see how the engine is used, then the spec for how it works inside.

Workspace layout

Crate Purpose
fuel-engine/ Core crate: bundle parser and verification, wasmi runtime, WASI extensions, virtual filesystem. See SPEC.md, Parts 1–7.
fuel-jni/ JNI bridge for Android, the browser bridge (browser_bridge.rs, implemented on the Kotlin side by a class like examples/kotlin-demo/) and the Kotlin wrapper (fuel-jni/kotlin/). See SPEC.md, Part 9 and the Android guide.
fuel-network/ Optional HTTP client for media downloads. Not used in production (SPEC.md, Part 8).
examples/kotlin-demo/ Desktop JVM demo that runs the same JNI code path as Android.

BrowserProvider skeleton: every method browser_bridge.rs calls over JNI, with its contract documented and the body left to implement. Pass an instance as the fourth argument of nativeLoadBundle to enable browser:* capabilities.
scripts/build-android.sh Cross-compiles libfuel_jni.so for the Android ABIs.

Quick start

# Build and test on the host
cargo build --release
cargo test

# Android build (production + dev variants); needs the NDK and FUEL_PUBLIC_KEY
export ANDROID_NDK_HOME=/path/to/android-ndk
export FUEL_PUBLIC_KEY="kid:base64-encoded-ed25519-public-key"
./scripts/build-android.sh --ndk $ANDROID_NDK_HOME

# Dev-only build (no signing key needed)
./scripts/build-android.sh --ndk $ANDROID_NDK_HOME --dev-only

# Desktop JNI demo
cargo build --release -p fuel-jni --features dev-mode
./examples/kotlin-demo/run.sh

Never ship libfuel_jni_dev.so in a release build. See Production vs. Dev Builds.

Prerequisites, output paths and troubleshooting are in ANDROID-GETTING-STARTED.md → Building from Source.

License

Copyright 2026 UpRock. Licensed under the Apache License, Version 2.0.

About

Rust runtime for signed, encrypted WebAssembly bundles on Android: Ed25519 verification, capability-based sandbox, private-range socket filter, and a JNI bridge with Kotlin wrapper

Resources

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages