SYSTEM Cited by 2 sources
workers-rs¶
workers-rs is
Cloudflare's Rust SDK for writing
Cloudflare Workers. Rust source is
compiled to WebAssembly (wasm32-unknown-unknown
target), marshalled across the Rust↔JS boundary by
wasm-bindgen, and executed inside a
V8 isolate on
workerd.
Role on this wiki¶
Canonical system for Rust-on-Workers reliability work disclosed in Cloudflare's 2026-04-22 post. Two inflection points:
- workers-rs 0.6 — first fix: a platform-side custom wrapper combining a Rust panic handler that tracks failure state per Worker, JS Proxy encapsulation of every Rust↔JS call, and targeted patches to wasm-bindgen's generated bindings to reinitialize the Wasm module after failure. Solved the sandbox-poisoning symptom for workers-rs users but lived outside wasm-bindgen.
- workers-rs 0.8.0 — second fix: the upstreamed
panic=unwind+ abort-recovery machinery, gated behind a--panic-unwindbuild flag. "Highly recommend upgrading and trying it out for a more stable Rust Workers experience, and plan to makepanic=unwindthe default in a subsequent release." Users staying onpanic=abortstill get the 0.6.0 wrapper.
Failure-mode substrate¶
Rust on wasm32-unknown-unknown defaults to
panic=abort: a panic traps with
unreachable, exits Wasm back to JS with
WebAssembly.RuntimeError, and — in stock wasm-bindgen —
leaves the instance in an undefined state. Before workers-rs
0.6, "panics were historically fatal, poisoning the instance
and possibly even bricking the Worker for a period of time."
Workers holding in-memory state (e.g.
Durable Objects) were particularly exposed because
reinitialisation would destroy that state.
Emscripten-target examples: native Rust + Tokio (2026-09-28)¶
workers-rs today compiles to the wasm32-unknown-unknown target. The
2026-09-28 experimental preview adds a second path via the
Emscripten wasm32-unknown-emscripten target in
wasm-bindgen, enabling native Rust — including
Tokio-based apps — on Workers, with "significantly improved
library compatibility." The Rust Workers
Emscripten examples
require the Tokio patchsets directly (JSPI + LocalEventLoop; socket support via
-sNODERAWSOCKETS) pending further upstream integration into Tokio. This is a
distinct target/experience from the panic-recovery-hardened wasm32-unknown-unknown
path above — a preview of the second Rust-on-Workers sub-tier rather than a change
to the existing one. (Source:
sources/2026-09-28-cloudflare-supporting-native-rust-in-workers-with-the-new-emscripten-target)
Seen in¶
- sources/2026-09-28-cloudflare-supporting-native-rust-in-workers-with-the-new-emscripten-target
— the experimental
wasm32-unknown-emscriptenexamples for running native Rust + Tokio on Workers, shipped in the workers-rsexamples/emscriptentree. - sources/2026-04-22-cloudflare-making-rust-workers-reliable-panic-and-abort-recovery-in-wasm-bindgen — canonical wiki instance. Disclosure of the two-step reliability arc (0.6 platform wrapper → 0.8 upstreamed exception-handling recovery) and the Rust-Wasm-error-class taxonomy workers-rs now handles.
Related¶
- systems/cloudflare-workers — host platform.
- systems/wasm-bindgen — binding generator workers-rs consumes; now co-maintained by Cloudflare.
- systems/webassembly — runtime substrate.
- systems/workerd — the V8 isolate runtime executing the compiled Wasm module.
- systems/emscripten — the
wasm32-unknown-emscriptentarget enabling native-Rust/Tokio Workers examples. - systems/tokio — the async runtime the Emscripten examples run.
- panic-unwind — the recovery primitive 0.8.0 unlocks.
- abort-recovery — last-resort reinit for the non-unwindable class.
- sandbox-poisoning — the failure class workers-rs 0.6 addressed platform-side and 0.8 addresses upstream.
- reinitialize-on-unrecoverable-error / proxy-based-entrypoint-encapsulation — the 0.6 pre-upstream recipes.
- companies/cloudflare — author.