SECURITY WARNING: Never run commands you don't understand. Always review code before execution. Use at your own risk.
WebAssembly New Added 12 September 2026

WebAssembly: SharedArrayBuffer is not defined

Threaded builds need shared memory, and browsers only expose SharedArrayBuffer to cross origin isolated pages. The module works on localhost and fails on the deployed site, because isolation comes from response headers that the dev server sets and the CDN in front of production does not.

Quick fix

Read the commands before running them. Anything that restarts a service, deletes data or changes permissions should be tried on a non-production system first.

Quick fix
# Both headers are required, on the document itself
Cross-Origin-Opener-Policy: same-origin
Cross-Origin-Embedder-Policy: require-corp

// Check from the page before assuming the headers arrived
if (!self.crossOriginIsolated) {
  console.error('not isolated: threads unavailable');
}

# Isolation also blocks every cross origin subresource that does not opt in.
# Images, fonts and scripts need CORP or CORS, or they stop loading:
Cross-Origin-Resource-Policy: cross-origin

# credentialless relaxes that for no-cors subresources where supported
Cross-Origin-Embedder-Policy: credentialless

# Ship a single threaded build as a fallback rather than a blank page
emcc app.c -o app.js -pthread -sPTHREAD_POOL_SIZE=4
emcc app.c -o app-st.js

How to diagnose WebAssembly errors

WebAssembly errors are precise about the layer that failed. A CompileError means the bytes are not a valid module: most often the file was served with the wrong MIME type, or an HTML error page was fetched instead of the .wasm file. A RuntimeError: memory access out of bounds means the module read or wrote outside its linear memory, which in a language like C or Rust is a genuine memory-safety bug caught by the sandbox.

If the quick fix above does not resolve it, work through these steps. They apply to this whole class of error, not just to this one message, which is usually what saves the time.

  1. Check what the server actually returned. The wasm file must be served as application/wasm for streaming compilation, and a 404 HTML page produces a misleading magic-number error.
  2. Validate the module offline with wasm-validate and inspect it with wasm-objdump -x from the WABT toolkit.
  3. For out-of-bounds errors, rebuild with sanitizers or debug assertions in the source language. The wasm runtime cannot tell you which source line was responsible without DWARF info.
  4. Confirm imports match: every function the module imports must be supplied by the host with the exact name and signature, or instantiation fails.
  5. Build with debug symbols and use the browser's DWARF support to step through original source rather than raw wasm.

Tools worth reaching for

  • wasm-validate / wasm-objdump (WABT)
  • browser DWARF debugging
  • wasmtime --invoke
  • curl -I (check MIME type)

Authoritative references

Primary documentation for this error, worth reading before applying any fix in production.

developer.mozilla.org web.dev

Related WebAssembly errors

See all 7 WebAssembly errors →

Browse other categories

Something missing or wrong?

This entry is maintained by hand. If the fix is out of date, incomplete, or you have a better one, email a correction and it will be reviewed.