Skip to content
CAI
Software that uses CAICheck a score

Xe/olin

63.6

Adequate · 21 September 2026

2.7k

lines of production code

Go

with Zig, Rust, JavaScript

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Features

Add CWA command-line tool for running WebAssembly modules

Introduces the cmd/cwa executable, a command-line interface for executing WebAssembly modules. The tool supports running both standard CWA modules and Go-compiled WebAssembly binaries, with configurable memory limits, gas-based execution limits, and policy-driven resource constraints. It also provides detailed VM statistics and timing information, and includes a test suite that validates the tool's behavior against sample WebAssembly files.

cmd/cwa · high confidence

Add CommonWA, Dagger, and WasmGo ABI implementations

The \abi\ package now includes three distinct ABI implementations for WebAssembly modules: CommonWA (cwa), which provides a process model with environment variables, logging, and resource handling; Dagger, which offers a file-descriptor-based API for reading, writing, and syncing files; and WasmGo, which bridges Go's WebAssembly runtime with the CommonWA process model, exposing JavaScript-like objects and file system constants. These additions expand the range of WebAssembly modules the system can execute by providing specific interfaces for each target environment.

abi · high confidence

Add HTTP client and core runtime modules

The Olin library now includes a new HTTP client implementation in \src/http/client.rs\, which handles serializing HTTP requests and parsing responses using the \http\ and \httparse\ crates. Additionally, core runtime modules have been added to \src/lib.rs\, including \log\ for logging, \env\ for environment variables, \sys\ for low-level FFI bindings, and \panic\ for custom panic handling. A new binary \allyourlogs.rs\ was also added to demonstrate logging capabilities.

rust/olin · high confidence

Add Olin runtime library in Zig

The Olin runtime library is introduced in Zig, providing a set of modules for system-level operations. This includes file and resource management (resource.zig), environment variable access (env.zig), error handling (error.zig), HTTP status codes (http/status\_codes.zig), and logging (log.zig). The library also provides utilities for random number generation (random.zig), time (time.zig), startup arguments (startup.zig), and process control (runtime.zig). A CGI-like interface (cwagi.zig) is also included, allowing for web application development within the Olin framework.

zig/src/olin · high confidence

Add Rust-based CWA gateway implementation

A new Rust implementation for the Common WebAssembly API (CWA) gateway has been added. This component handles HTTP requests by reading environment variables (REQUEST\_METHOD, PATH\_INFO, RUN\_ID, WORKER\_ID) and startup arguments, then returning a text/plain response. The gateway routes requests to /cadey with a specific message, while all other paths return detailed runtime information including the WebAssembly runtime version, current time, and environment details.

rust/cwagi · high confidence

Add Rust-based CWA implementation and build infrastructure

Introduces a new Rust implementation for the CommonWA (CWA) specification, including build scripts for the core library (olin), the CWA agent (cwagi), and tests. The setup configures the Rust toolchain to target wasm32-unknown-unknown and includes necessary configuration files (.cargo/config, .gitignore, .dockerignore) to support building and running the Rust components.

rust · high confidence

Add Zig-based WebAssembly examples and utilities

The repository now includes a collection of Zig source files in the \zig/src\ directory, providing a suite of WebAssembly examples and utilities. These include a Common WebAssembly Interface (CWA) entry point (\allyourargs.zig\), a base case (\allyourbase.zig\), logging tests (\allyourlogs.zig\), a file concatenation tool (\cat.zig\), a comprehensive runtime test suite (\coi.zig\), a Common WebAssembly Application Gateway Interface (CWAGI) HTTP handler (\cwagi.zig\), exit code demonstrations (\exit0.zig\, \exit1.zig\), an HTTP test client (\httptest.zig\), a crash test (\mincrash.zig\), a runtime metadata printer (\runtime\_name.zig\), a terminal-based rasterizer (\triangle.zig\), and a binary asset (\shaman.aa\ with its loader \shaman.zig\).

zig/src · high confidence

Add Zig-based WebAssembly examples with resource policies

The repository now includes a new set of WebAssembly examples implemented in Zig, including utilities like 'cat', 'httptest', and 'triangle'. Each example is accompanied by a corresponding .policy file that defines specific resource constraints, such as 'ram-page-limit' and 'gas-limit', ensuring predictable execution limits. A build script automates the compilation of these Zig sources into WebAssembly modules, and a test script validates their behavior using the 'cwa' runtime.

zig · high confidence

Added Nix build environment for Zig 0.6.0

The project now includes Nix build infrastructure to manage dependencies and compile the Zig compiler. This introduces a new \nix/zig.nix\ module that builds the Zig 0.6.0 release from the official binary distribution, alongside a \nix/deps.nix\ file that defines Go dependencies for the build process. These changes establish the foundation for building the project using the Nix package manager.

nix · high confidence

Added runtime support files for executing WebAssembly components

The 'run' directory now includes essential files to execute the application's WebAssembly modules. This adds a shell script (run.sh) to launch the CWA CGI binary, a JavaScript bridge (wasm\_exec.js) to handle Go/WASM runtime interactions in browser and Node.js environments, and an Emacs major mode configuration for editing policy files. These changes enable the actual runtime execution of the compiled WASM binaries.

run · high confidence

Initial release of Olin: a WebAssembly runtime and CLI tool

Olin is introduced as a runtime environment for WebAssembly, designed to wrap Wasm with functions to access the outside world and track metrics like instruction counts, syscalls, and memory usage for profiling purposes. The release includes support for the Common WebAssembly (CWA) specification and Go's WebAssembly ABI, alongside a Dockerfile for building the runtime and a Nix build file for the \cwa\ and \cwa-cgi\ binaries. The project also provides a CLI tool (\cwa\) and CGI helper (\cwa-cgi\) for running WebAssembly modules.

(repo-wide) · high confidence

Introduce cwa-cgi service with HTTP and Prometheus metrics support

A new Go-based HTTP server (cmd/cwa-cgi/main.go) is introduced to serve CWA modules over HTTP. It runs a CGI handler for the WASM binary and exposes a /metrics endpoint for Prometheus monitoring, alongside a /reboot endpoint for process management.

cmd/cwa-cgi · high confidence

Introduce file resolver and name generator utilities

Added the \fileresolver\ package providing various file-like abstractions for the Olin project, including HTTP transport, OS file descriptors, logging, null/zero/reader/writer wrappers, and random data sources. Also added the \namegen\ package, which generates random names based on tarot card ranks and suits. Both packages include corresponding test files to verify their behavior.

fileresolver, namegen · high confidence

Introduce innative-runtime as a Go-based runtime environment

Added the \cmd/innative-runtime\ package, which provides a Go implementation of a runtime environment for executing WebAssembly modules. This includes a main entry point that initializes a virtual machine and exposes various environment functions (such as logging, environment variable access, resource management, and random number generation) to support the execution of compiled code.

cmd/innative-runtime · high confidence

Introduce policy configuration for allowed and disallowed URLs

A new policy module has been added to the codebase, allowing users to define URL access rules via configuration files. The policy system parses allow and disallow lists of URL patterns, along with resource limits for RAM pages and gas instructions, enabling fine-grained control over which external resources can be accessed and the computational budget for operations.

policy · high confidence

Behavioural changes

Added CGI environment variable derivation

The cgi package now includes a new env.go file that provides a DeriveEnv function. This function constructs a map of environment variables from an HTTP request, including standard CGI fields like REQUEST\_METHOD, PATH\_INFO, and QUERY\_STRING, as well as custom RUN\_ID and WORKER\ID. It also iterates over HTTP headers to populate HTTP\\* environment variables, excluding any header named 'PROXY'.

cgi · medium confidence

Test coverage

Added Rust test suite for the Olin runtime

Added a new Rust test suite in the \rust/tests\ directory to verify the functionality of the Olin runtime. The suite includes tests for environment variables, random number generation, resource handling, runtime information, startup arguments, standard I/O, and time. It also includes regression tests for specific issues (22, 37, 39) and tests for various URL schemes (HTTP, LOG, NULL, RANDOM, ZERO).

rust/tests · high confidence

Dependencies

Initial release of Olin and CWAGI Rust crates

The Olin and CWAGI Rust crates are introduced, establishing the project's Rust-based runtime and library components. The Olin crate (v0.2.0) provides a small runtime library for programs targeting Olin, including binaries like 'shaman' and 'allyourlogs'. The CWAGI crate (v0.1.0) depends on Olin. Both crates are configured with specific dependencies such as 'chrono', 'http', and 'httparse', with their respective Cargo.lock files generated to pin exact versions.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 67 → 64 (-3.5)
  • Rubric changed (rubric-2026.08.18 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 96 → 92 (-3.7)
  • Architecture 100 → 96 (-4.4)
  • Maturity 60 → 60 (+0.0)
  • Readiness 81 → 66 (-15.1)
  • Security 58 → 57 (-0.2)

Resolved (18)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Duplicated block (10 lines × 3) (abi/cwa/core.go)
  • Duplicated block (12 lines × 4) (abi/wasmgo/abi.go)
  • High IaC: DS-0002 (run/rust-tools/Dockerfile)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • LLM evaluation failed
  • Medium IaC: DS-0001 (Dockerfile)
  • No exposed public API
  • OSV Dependency Vulnerabilities not included (check did not complete)
  • Test reliability not included
  • dormant codebase — no living knowledge left to concentrate

New (74)

  • (anonymous) (cognitive 49) (run/wasm_exec.js)
  • (anonymous) (cyclomatic 39) (run/wasm_exec.js)
  • Critical CVE: [GHSA redacted] (rust/Cargo.lock)
  • Critical vulnerability: [GHSA redacted] (rust/Cargo.lock)
  • Dependency pinned to a stale untagged commit: github.com/iancoleman/strcase
  • Dependency pinned to a stale untagged commit: github.com/pborman/uuid
  • Dependency pinned to a stale untagged commit: github.com/perlin-network/life
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Duplicated block (11 lines × 4) (abi/cwa/core.go)
  • Duplicated block (12 lines × 4) (abi/wasmgo/abi.go)
  • Duplicated block (7 lines × 3) (abi/cwa/core.go)
  • Duplicated block (8 lines × 4) (abi/cwa/core.go)
  • High CVE: [GHSA redacted] (go.mod)
  • High CVE: [GHSA redacted] (go.sum)
  • High CVE: [GHSA redacted] (go.mod)
  • High CVE: [GHSA redacted] (go.sum)
  • High CVE: [GHSA redacted] (go.sum)
  • High CVE: [GHSA redacted] (go.sum)
  • High CVE: [GHSA redacted] (go.sum)
  • …and 54 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

Xe/olin was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 0cf90810960ba4d7d80e20448ec08a71a3510deb — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.