Skip to content
CAI
Software that uses CAICheck a score

hyperlight-dev/hyperlight

77.9

Strong · 30 September 2026

74.4k

lines of production code

Rust

primary language

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Hyperlight is a lightweight virtualization framework that executes untrusted code in isolated sandboxes using hardware-assisted virtualization (KVM, HVF, MSHV, WHP). It supports guest workloads written in Rust or C, enabling them to communicate with the host via a virtqueue-based transport layer. The system provides capabilities for snapshotting and restoring sandbox state, detailed performance tracing, and debugging via GDB integration.

How it got here

2024 — virtqueue transport and sandbox API overhaul

39 changes.

The project overhauled guest-host communication by replacing legacy I/O with a virtqueue-based transport and introduced a new SandboxBuilder API to simplify sandbox creation and function invocation. This period also saw the removal of PE support, seccomp filtering, and complex state transitions, alongside significant refactoring of the C API, metrics, and build systems.

2025–2026 — aarch64 support and component model integration

36 changes.

This period focused on extending Hyperlight to support aarch64 architectures across both the host hypervisor and guest runtime, alongside the introduction of WebAssembly Component Model bindings via WIT. Significant infrastructure work included restructuring the guest runtime, implementing robust snapshot persistence with OCI layout support, and adding comprehensive debugging and tracing capabilities.

Features

AMD64 guest adds hardware exception handling and copy-on-write memory support

The AMD64 guest now implements a full hardware exception handling subsystem, including an Interrupt Descriptor Table (IDT), Task State Segment (TSS) with an exception stack, and assembly-level entry code that saves CPU context (general-purpose and FPU/SSE registers) before invoking Rust handlers. This enables the guest to manage its own stack dynamically by handling page faults to grow the stack and supports Copy-on-Write (CoW) memory semantics for snapshot regions, allowing safe modification of shared pages. Additionally, the entry point initializes processor control structures (GDT, IDT, TSS) and performs TLB flushing on dispatch to ensure memory consistency after snapshot restores.

_src/hyperlight\_guest\bin/src/arch/amd64 · high confidence

Add ELF core dump generation and hardware interrupt support for x86-64 guests

The hypervisor module now supports generating ELF core dumps when a guest crashes, capturing memory regions, registers, and XSAVE state for post-mortem debugging. Additionally, x86-64 guests can now receive hardware interrupts (such as timer interrupts) via a new interrupt handling subsystem that manages LAPIC and legacy PIC/PIT ports, improving compatibility with guest operating systems expecting standard hardware behavior.

_src/hyperlight\host/src/hypervisor · high confidence

Add OpenTelemetry tracing example for Hyperlight

A new example application (\tracing-otlp\) demonstrates how to integrate Hyperlight with OpenTelemetry for distributed tracing. The example configures an OTLP HTTP exporter to send trace data to a collector and shows how to capture spans from guest function executions, including scenarios involving concurrent threads and call cancellations.

_src/hyperlight\host/examples/tracing-otlp · high confidence

Add aarch64 architecture support for Hyperlight VMs

Hyperlight now supports running sandboxes on aarch64 processors. This change introduces the \aarch64.rs\ module implementing the \HyperlightVm\ interface, enabling the creation and initialization of virtual machines on Apple Silicon (via HVF) and Linux (via KVM). The implementation handles architecture-specific register setup, memory mapping, and interrupt handling, allowing the host to dispatch guest calls and manage execution on ARM64 targets.

_src/hyperlight\_host/src/hypervisor/hyperlight\vm · high confidence

Add aarch64 guest support with memory layout, page allocator, and MMIO exits

The aarch64 guest architecture now includes foundational support for memory management and host communication. A physical page allocator (prim\_alloc.rs) enables dynamic memory allocation using atomic operations, while the memory layout (layout.rs) defines stack limits and scratch space addresses. Additionally, an exit mechanism (exit.rs) allows the guest to trigger VM exits and send data to the host via MMIO ports, enabling basic hypercall functionality.

_src/hyperlight\guest/src/arch/aarch64 · high confidence

Add component model elaboration and bindgen utilities

The \hyperlight\_component\_util\ crate now includes utilities to parse WebAssembly Component Model binaries (WIT) and generate Rust bindings. This adds support for reading component type exports, elaborating component types according to the specification, and emitting Rust code for both host and guest implementations of component interfaces, including resource management and type marshalling.

_src/hyperlight\_component\util · high confidence

Add guest debugging example with GDB integration

The \src/hyperlight\_host/examples/guest-debugging\ directory now contains a new example demonstrating how to enable GDB debugging for Hyperlight guests. The example shows how to configure a \SandboxBuilder\ with \DebugInfo\ to expose a debug port (default 8080) and includes tests that spawn a GDB client to connect to the guest, set breakpoints, and verify execution flow. This provides a concrete reference for users who need to debug guest code using GDB.

_src/hyperlight\host/examples/guest-debugging · high confidence

Add initial MSHV hypervisor support for aarch64

The MSHV hypervisor backend now includes an aarch64 implementation, allowing the host to run on ARM64 systems when the MSHV API is available. This change adds the \aarch64.rs\ module with a placeholder \MshvVm\ structure and an \is\_hypervisor\_present\ check (currently returning false pending full implementation), while updating \mod.rs\ to conditionally compile the aarch64 module alongside the existing x86\_64 support.

_src/hyperlight\_host/src/hypervisor/virtual\machine/mshv · high confidence

Add initial aarch64 register handling for KVM

This change introduces the foundational register management infrastructure for aarch64 virtualization via KVM. It adds data structures for common CPU registers (general purpose, stack pointer, program counter, PSTATE) and FPU registers (V registers, FPSR, FPCR), alongside definitions for key system registers (TTBR0\_EL1, TCR\_EL1, MAIR\_EL1, SCTLR\_EL1, CPACR\_EL1, VBAR\_EL1). The implementation includes KVM-specific bindings to get and set these registers on a vCPU file descriptor, enabling the host to save and restore the architectural state of aarch64 guests.

_src/hyperlight\host/src/hypervisor/regs/aarch64 · high confidence

Add macros for type-safe guest entry points and function registration

The \hyperlight\_guest\_macro\ crate introduces \\#\[main\]\, \\#\[dispatch\]\, and \\#\[guest\_function\]\ attribute macros to simplify guest code development. The \\#\[main\]\ macro generates a C-compatible entry point (\hyperlight\_main\) that calls the user's function, while \\#\[dispatch\]\ allows defining a fallback handler for unregistered function calls. The \\#\[guest\_function\]\ macro registers functions with the host at initialization, supporting custom names and error-returning signatures, and enforces constraints such as prohibiting async functions and receiver arguments.

_src/hyperlight\_guest\macro · high confidence

Add trace\_dump utility for visualizing execution traces

A new \src/trace\_dump\ binary has been added to parse and visualize execution traces. It reads trace data files to display memory allocation and deallocation events, stack unwinding information, and binary hashes. The tool includes a symbol cache to resolve memory addresses to human-readable function names and line numbers, and supports generating visual outputs (bar charts and flame graphs) using the \piet\_common\ rendering library.

_src/trace\dump · high confidence

Add x86\_64 GDB stub for sandbox debugging

A new GDB debugging interface is now available for Hyperlight sandboxes on x86\_64. This change introduces the \gdb\ module containing an architecture-specific implementation (\arch.rs\) that interprets vCPU stop reasons (such as software/hardware breakpoints and single-stepping) via the DR6 register, and an event loop (\event\_loop.rs\) that manages the GDB protocol connection. The \x864\_target.rs\ file implements the \gdbstub\ target traits, allowing debuggers to read/write guest memory and registers, while \mod.rs\ defines the internal communication channels and error types. This enables external tools like GDB to attach to and debug running Hyperlight guests.

_src/hyperlight\host/src/hypervisor/gdb · high confidence

Added KVM performance mitigation and sandbox crashdump scripts

Two new scripts are now available in the host tools. The \apply-kvm-perf-mitigation.sh\ script addresses performance issues on Linux kernel 6.x by adjusting KVM module parameters (specifically \nx\_huge\_pages\) and cgroup mount options when the system is not affected by the ITLB multihit vulnerability. Additionally, \dump\_all\_sandboxes.gdb\ provides a GDB macro to generate crashdumps for all active sandboxes across multiple threads, aiding in debugging by iterating through threads and invoking the sandbox's crashdump generation function.

_src/hyperlight\host/scripts · high confidence

Added benchmarks and architecture-specific virtual memory implementations for Hyperlight

This change introduces performance benchmarks for the \SlotPool\ and \virtq\_api\ components in \src/hyperlight\_common/benches\, allowing users to measure allocation and round-trip throughput. It also adds architecture-specific virtual memory management code for aarch64 and amd64 in \src/hyperlight\_common/src/arch\, including page table manipulation, memory layout definitions, and exception syndrome decoding, which are required for proper guest memory handling on these platforms.

_src/hyperlight\common · high confidence

Added copy-on-write file mapping example for Windows

A new example, map-file-cow-test, demonstrates end-to-end copy-on-write file mapping using the SandboxBuilder. It creates both page-aligned and intentionally unaligned temporary files to verify that the Windows surrogate process can correctly map file-backed sections, specifically addressing previous failures where unaligned files caused access-denied errors during MapViewOfFileNuma2 calls.

_src/hyperlight\host/examples/map-file-cow-test · high confidence

Added crash dump example demonstrating automatic and on-demand core dump generation

A new example at src/hyperlight\_host/examples/crashdump demonstrates how to use Hyperlight's crash dump feature, which generates ELF core dump files containing vCPU state and guest memory for post-mortem debugging. The example illustrates automatic crash dumps triggered by VM-level faults (such as memory access violations) and on-demand dumps via the generate\_crashdump() API for guest-caught exceptions. It also shows how to disable crash dumps per sandbox and configure the output directory via the HYPERLIGHT\_CORE\_DUMP\_DIR environment variable.

_src/hyperlight\host/examples/crashdump · high confidence

Benchmarking tooling with resident sandbox and PR reporting

The \hyperlight-ci\ tool now includes a \bench\ subcommand that runs Criterion benchmarks in parallel and a \bench-report\ subcommand that generates markdown comparison tables from local or CI benchmark results. To ensure accurate measurements, the benchmark runner can hold a sandbox resident (the "ballast") for the duration of the run, preventing kernel overhead from VM teardown/teardown cycles from skewing the results. The reporting tool supports comparing results against previous CI runs, pull requests, or commits, and allows filtering benchmarks via configuration files.

_src/hyperlight\_ci, src/hyperlight\host/examples/ballast · high confidence

Initial Hypervisor.framework (HVF) support for macOS

Adds the initial implementation of the Hypervisor.framework backend, enabling Hyperlight to run virtual machines on macOS. This change introduces the core Rust bindings and C helper functions for managing vCPU SIMD/FPU registers, along with the main module logic that handles the specific constraints of HVF (such as single-address-space and thread-affinity limitations) to allow sandbox execution.

_src/hyperlight\_host/src/hypervisor/virtual\machine/hvf · high confidence

Initial KVM hypervisor implementation for aarch64

This change introduces the first KVM backend support for aarch64 architectures. The new \aarch64.rs\ module implements the \VirtualMachine\ trait, providing core capabilities such as VM creation, vCPU initialization, memory mapping/unmapping, and vCPU execution. It includes specific handling for ARM-specific KVM capabilities, such as \KVM\_CAP\_ARM\_NISV\_TO\_USER\, to mitigate issues with cache maintenance operations and self-modifying code that could otherwise poison the sandbox. The \mod.rs\ file now conditionally exports this aarch64 implementation alongside the existing x86\_64 backend, enabling Hyperlight to run on ARM64 Linux hosts using KVM.

_src/hyperlight\_host/src/hypervisor/virtual\machine/kvm · high confidence

Initial aarch64 guest support with exception handling and virtual memory management

The Hyperlight guest runtime now supports aarch64 architectures. This change introduces the core infrastructure required to run guests on ARM64, including assembly-level entry points, exception vector table setup, and context save/restore routines. It adds handlers for synchronous, IRQ, FIQ, and SError exceptions, with specific logic to manage stack expansion and copy-on-write memory faults. Additionally, it implements the virtual memory subsystem for aarch64, including page table operations, memory mapping, and physical-to-virtual address translation, enabling the guest to manage its own memory layout and handle hardware faults gracefully.

_src/hyperlight\_guest\bin/src/arch/aarch64 · high confidence

Initial devcontainer configuration for Hyperlight development

The project now includes a pre-configured development environment using VS Code Dev Containers. This setup provides a consistent workspace with Rust 1.94, LLVM 18, and necessary build tools (cmake, gdb, musl-tools). It automatically configures the container for KVM access, installs essential VS Code extensions (C/C++, CMake Tools, Rust Analyzer, LLDB), and sets up the nightly toolchain required for specific formatting features.

.devcontainer · high confidence

Introduce GuestHandle for safe user memory access

Added a new GuestHandle struct that provides a controlled interface for the guest to access user memory regions defined by the HyperlightPEB. This component exposes methods to initialize the handle with a PEB pointer and to safely read a specified number of bytes from user memory, including validation to ensure the requested size does not exceed the available data.

_src/hyperlight\_guest/src/guest\handle · high confidence

New Chrome tracing example for Hyperlight

Added a new example demonstrating how to integrate Chrome tracing with Hyperlight. The example shows how to set up a tracing subscriber with a Chrome layer, create a sandbox using the SandboxBuilder API, and execute a guest function while capturing performance metrics.

_src/hyperlight\host/examples/tracing-chrome · high confidence

New component bindgen macros for WIT-based host/guest interfaces

The \hyperlight\_component\_macro\ crate introduces \host\_bindgen!()\ and \guest\_bindgen!()\ procedural macros to generate Rust bindings for Wasm Component Model interfaces defined by WIT sources. These macros allow developers to specify interface definitions via WIT files, WAT text, inline strings, or wasm-encoded packages, automatically generating the necessary types, trait implementations, and registration functions to connect Hyperlight hosts and guests.

_src/hyperlight\_component\macro · high confidence

New development scripts and tooling for CI automation and release management

The repository now includes a suite of new shell scripts in the \dev/\ directory to automate and streamline development workflows. These include \auto-approve-dependabot.sh\ for automatically approving and merging Dependabot PRs that only modify Cargo files, \check-license-headers.sh\ to enforce license headers on Rust source files, and \check-release-blockers.sh\ to prevent releases if blocking issues are open. Additional utilities support the release process (\crates-to-publish.sh\, \extract-changelog.sh\, \update-cargo-hyperlight-version.sh\, \verify-version.sh\), CI failure notification (\notify-ci-failure.sh\), and macOS code signing (\macos-sign-and-run.sh\, \macos-entitlements.plist\). The existing \verify-msrv.sh\ script has been updated to correctly verify the Minimum Supported Rust Version for \hyperlight-guest\ and \hyperlight-guest-bin\ crates by targeting the \x86\_64-unknown-none\ architecture. The legacy \clean-github-artifacts.sh\ script has been removed.

dev · high confidence

New hyperlight-libc crate provides picolibc-based C standard library for guests

A new \hyperlight-libc\ crate has been introduced to supply a C standard library implementation for Hyperlight guest binaries, built from the picolibc source (version 1.8.11). This crate compiles picolibc from a vendored git submodule and generates Rust bindings for C types and functions, enabling guest code to use standard C features. The library is configured for a micro-VM environment with single-threading, a global errno, and minimal stdio, while relying on the Rust global allocator for memory management. It supports both x86\_64 and aarch64 architectures and requires downstream code to provide specific POSIX stubs (such as \read\, \write\, and \clock\_gettime\) for host interaction.

_src/hyperlight\libc · high confidence

New sandbox tracing and memory profiling infrastructure

The sandbox module now includes a new \trace\ subsystem that captures guest execution data. The \TraceContext\ handles general guest tracing by walking page tables to read trace batches from guest memory, managing OpenTelemetry spans, and calculating timestamps using the TimeStamp Counter (TSC) frequency. Additionally, when the \mem\_profile\ feature is enabled, the \MemTraceInfo\ component records memory allocation and free events, unwinding stack frames via \framehop\ and writing them to trace files. This replaces previous tracing implementations with a structured approach supporting both standard event tracing and detailed memory profiling.

_src/hyperlight\host/src/sandbox/trace · high confidence

OCI-based snapshot persistence with integrity verification and sparse storage

Snapshots are now persisted to and loaded from a local directory using the OCI Image Layout format, enabling structured storage with content-addressed blobs. The implementation validates blob integrity via SHA-256 digests against OCI manifests and rejects symbolic links to prevent path traversal. To optimize disk usage and save time, guest memory images are written sparsely, creating filesystem holes for zero-filled pages while maintaining byte-for-byte correctness. The snapshot format includes metadata for architecture, hypervisor backend, and CPU vendor to ensure compatibility on restore, and supports referencing snapshots by human-readable tags or content digests.

_src/hyperlight\host/src/sandbox/snapshot/file · high confidence

Removals

Removal of OTLP tracing example

The OTLP tracing example located at src/hyperlight\_host/examples/otlp\_tracing has been removed from the codebase. This deletion eliminates the demonstration code that previously showed how to send tracing events to an OTLP collector using the opentelemetry crate, including the setup of the OpenTelemetry layer and the execution of guest sandbox interactions for tracing purposes.

_src/hyperlight\_host/examples/otlp\tracing · high confidence

Removal of PE guest support

The host no longer supports loading or executing PE (Portable Executable) formatted guest binaries. The internal modules responsible for parsing PE headers, base relocations, and PE-specific memory layout (\src/hyperlight\_host/src/mem/pe\) have been removed, meaning PE files can no longer be used as guest payloads.

_src/hyperlight\host/src/mem/pe · high confidence

Removed chrome-tracing example

The chrome-tracing example has been removed from the repository. This example previously demonstrated how to use Hyperlight with Chrome tracing to profile guest function calls, including setup of the tracing subscriber and execution of a simple echo function within a multi-use sandbox.

_src/hyperlight\host/examples/chrome-tracing · high confidence

Architecture

New x86\_64 register abstraction layer for KVM, MSHV, and WHP backends

The x86\_64 hypervisor register handling has been restructured into a new modular abstraction layer (\src/hyperlight\_host/src/hypervisor/regs/x86\_64\) that unifies state management across KVM, MSHV, and Windows Hypervisor Platform (WHP). This change introduces dedicated modules for standard registers (\standard\_regs.rs\), special registers (\special\_regs.rs\), floating-point units (\fpu.rs\), debug registers (\debug\regs.rs\), and model-specific registers (\msrs.rs\). Each module provides a \Common\\ struct that normalizes backend-specific bindings (e.g., \kvm\_regs\, \StandardRegisters\, \WHV\_REGISTER\_VALUE\) into a unified internal representation, ensuring consistent snapshot persistence and restoration behavior regardless of the underlying hypervisor backend.

_src/hyperlight\_host/src/hypervisor/regs/x86\64 · high confidence

Behavioural changes

Build system overhaul: macOS Hypervisor.framework support, surrogate cross-compilation fix, and feature cleanup

The build process for hyperlight-host has been significantly updated. On macOS, enabling the new 'hvf' feature now automatically generates Rust bindings for the Hypervisor.framework and compiles necessary C stubs, allowing Hyperlight to run on Apple Silicon and Intel Macs. For Windows builds, the surrogate binary compilation logic was rewritten to correctly handle cross-compilation from Linux by explicitly setting the target triple and fixing path separators, ensuring the embedded surrogate executable is built and located correctly. Additionally, the build script now uses short-form license pragmas, updates the copyright year to 2025, and removes the 'inprocess' and 'mshv' features in favor of 'mshv3' and 'crashdump', while also deleting the legacy Justfile and fuzz target.

_src/hyperlight\host · high confidence

C API guest function wrappers now return hl\_ReturnValue\* instead of hl\_Vec\*

The C API wrapper macros (HYPERLIGHT\_WRAP\FUNCTION\\*) have been updated so that guest functions return an hl\ReturnValue\ constructed via hl\_result\from\\* functions, replacing the previous requirement to return flatbuffer-encoded hl\Vec\ via hl\_flatbuffer\_result\from\\*. This change also introduces support for ByteChunks parameters, which are passed as arrays of borrowed pointer and length spans, and renames internal FFI types (e.g., FfiByteChunk to ByteChunk) in the generated bindings.

_src/hyperlight\_guest\capi · high confidence

Guest function registration and dispatch logic restructured

The guest function handling logic has been reorganized into dedicated modules (call, definition, register) within the guest binary. This change introduces a \GuestFunctionRegister\ to manage the registry of exposed functions and refactors the dispatch mechanism in \internal\_dispatch\_function\ to validate function call types, verify parameter signatures against registered definitions, and route calls to either specific handlers or a default dispatcher. It also integrates trace instrumentation into the dispatch flow to capture execution timing for guest function calls.

_src/hyperlight\_guest\_bin/src/guest\function · high confidence

Guest runtime refactored to use virtqueue transport and simplified exit handling

The guest runtime now communicates with the host via a new virtqueue-based transport layer (src/hyperlight\_guest/src/transport), replacing the previous shared-memory input/output stacks and direct outb-based function dispatch. This change introduces a global transport context for managing host-to-guest and guest-to-host queues, with dedicated modules for message encoding/decoding (codec), memory access within the scratch region (mem), and context management (context). Concurrently, the exit mechanism has been simplified: the old entrypoint, custom stack-checking (chkstk), and alloca implementations have been removed in favor of a new exit module that handles aborts and debug printing through standardized OutB actions, while layout definitions now reference scratch-top addresses for shared memory regions.

_src/hyperlight\guest/src · high confidence

Guest runtime removes custom alloca and setjmp implementations

The guest runtime build process no longer compiles the custom alloca wrapper or the custom setjmp/longjmp header. The build.rs script, which previously conditionally compiled src/alloca/alloca.c and included src/hyperlight\_guest/include/setjmp.h, has been deleted, removing these custom C implementations from the guest binary.

_src/hyperlight\guest · high confidence

Hyperlight surrogate process optimized for reduced startup overhead

The hyperlight\_surrogate binary has been converted to a \#!\[no\_std\] application to eliminate the loading of unnecessary libraries (such as dbghelp.dll and VCRUNTIME140.dll), which previously added approximately 200ms of overhead during process creation on ARM64 Windows. This change reduces the time required to create the suspended surrogate process used for WHvMapGpaRange2 operations, improving overall host performance.

_src/hyperlight\_host/src/hyperlight\surrogate · high confidence

Introduce SandboxBuilder for simplified sandbox creation

The sandbox creation API has been refactored to use a new \SandboxBuilder\ pattern, replacing the previous \UninitializedSandbox\ and \SingleUseSandbox\ types. Users can now construct sandboxes fluently from a guest binary file, a memory buffer, or an existing snapshot using \SandboxBuilder::from\_file\, \from\_bytes\, or \from\_snapshot\. This builder supports chaining configuration methods for host functions, memory regions, and file mappings before calling \build()\. The legacy \SingleUseSandbox\ and its associated handler abstractions (like \OutBHandler\ and \MemAccessHandler\) have been removed in favor of this unified, state-machine-driven approach.

_src/hyperlight\host/src/sandbox · high confidence

Introduce dedicated hyperlight\_guest\_bin crate for guest runtime core

The guest runtime logic has been reorganized into a new \hyperlight\_guest\_bin\ crate, consolidating the guest entrypoint, panic handling, and error management. This change introduces a new guest logger that forwards log messages to the host via the virtqueue transport, and implements a new host-guest communication layer (\host\_comm\) for function calls. Additionally, the crate provides C-compatible memory management wrappers (\malloc\, \free\, etc.) that interface with the Rust global allocator, and initializes the guest transport queues using host-assigned scratch regions.

_src/hyperlight\_guest\bin/src · high confidence

Introduce virtqueue-based transport and sparse snapshot saving

Guest-host communication now uses virtqueues for all function calls and logging, replacing the legacy stack-based I/O. This change introduces a new ABI (v5) and config schema (v3), requiring existing snapshots to be regenerated. Additionally, \Snapshot::save\ now writes the guest memory blob sparsely, skipping all-zero blocks to significantly reduce the size of saved snapshots without changing the digest or layout.

(repo-wide) · high confidence

Introduces virtqueue-based host-guest communication and removes legacy memory management modules

The memory subsystem now uses a new virtqueue transport layer for host-guest communication, replacing the previous mechanism. This change adds a new \virtq\ module containing codec, memory operations, and snapshot/restore logic for the new transport, along with comprehensive tests. Concurrently, legacy memory management components—\custom\_drop.rs\, \loaded\_lib.rs\, and \shared\_mem\_snapshot.rs\—have been removed, and the ELF/PE loading logic has been refactored to support the new layout and transport requirements.

_src/hyperlight\host/src/mem · high confidence

Metrics subsystem refactored to use the \`metrics\` crate

The metrics implementation in \src/hyperlight\_host/src/metrics\ has been rewritten to use the \metrics\ crate instead of the previous \prometheus\-based wrappers. This removes the custom \Histogram\, \HistogramVec\, \IntCounter\, \IntCounterVec\, \IntGauge\, and \IntGaugeVec\ modules and their associated macros. The new approach introduces specific metrics such as \guest\_errors\_total\, \guest\_cancellations\_total\, and \erroneous\_vcpu\_kicks\_total\, and conditionally emits \guest\_call\_duration\_seconds\ and \host\_call\_duration\_seconds\ when the \function\_call\_metrics\ feature is enabled.

_src/hyperlight\host/src/metrics · high confidence

New generic C API for host-guest return values and byte chunks

The C API in the guest library has been refactored to replace the previous Flatbuffer-based return mechanism with a new generic result API. This change introduces \hl\_result\from\\*\ functions (supporting int, uint, long, ulong, float, double, bool, string, vecbytes, and byte chunks) and corresponding \hl\_get\_host\_return\_value\as\\*\ getters, allowing guests to exchange richer data types with the host. The implementation also adds support for \ByteChunks\ parameters and return values, enabling efficient zero-copy handling of multiple byte buffers. The old \hl\_flatbuffer\_result\from\\*\ functions have been removed in favor of this new typed approach.

_src/hyperlight\_guest\capi/src · high confidence

New guest-side tracing infrastructure with flatbuffers serialization

The \hyperlight\_guest\_tracing\ module has been replaced with a new implementation that captures spans and events in the guest and serializes them using flatbuffers. This change introduces a \GuestSubscriber\ to collect trace data, an \invariant\_tsc\ module for high-performance timestamping on x86\_64, and logic to flush trace batches to the host via \outb\ instructions. The new system includes deadlock protection for exception contexts and allows runtime updates to the log level filter.

_src/hyperlight\_guest\tracing · high confidence

Redesign of AMD64 guest memory layout and exception-safe I/O

The AMD64 guest architecture now manages its own stack and allocates physical memory from a dedicated scratch region, with new layout constants defining the main stack and scratch boundaries. To support this, a new exit handler provides an \out32\ function that safely sends 32-bit values to the host, specifically handling tracing state to prevent deadlocks or panics during exception contexts. Additionally, a primary allocator implementation uses atomic operations to manage memory within the scratch region, aborting with a clear error if physical memory limits are exceeded.

_src/hyperlight\guest/src/arch/amd64 · high confidence

Removal of evolving/devolving sandbox state transitions

The \sandbox\_state\ module has been removed, eliminating the \Sandbox\, \EvolvableSandbox\, \DevolvableSandbox\, and \TransitionMetadata\ traits. This removes the ability for sandboxes to transition between states via evolve and devolve operations, replacing that mechanism with a snapshotting API.

_src/hyperlight\_host/src/sandbox\state · high confidence

Removal of seccomp syscall filtering for guest execution

The seccomp filtering module, which previously enforced a strict allow-list of system calls for untrusted guest code execution within the hypervisor handler thread, has been removed. This eliminates the mechanism that trapped or killed threads attempting disallowed syscalls (such as \openat\, \write\, or \ioctl\), meaning guest code will no longer be restricted by these specific kernel-level syscall filters in this component.

_src/hyperlight\host/src/seccomp · high confidence

Removal of seccomp-based signal handling and panic hook

The seccomp feature has been removed from the signal handlers module, eliminating the SIGSYS handler that previously intercepted disallowed syscalls and the custom panic hook that suppressed 'DisallowedSyscall' panics. The \setup\_signal\_handlers\ function no longer registers SIGSYS handlers or modifies the global panic hook; it now only registers a real-time signal handler for VM termination (renamed to \vm\_kill\_signal\) and accepts a \SandboxConfiguration\ to determine the signal offset. The dedicated \sigsys\_signal\_handler.rs\ file has been deleted entirely.

_src/hyperlight\_host/src/signal\handlers · high confidence

Replace embedded musl libc with git subtree

The local copy of the musl libc source code and its associated patch files in the third\_party directory have been removed. This change reflects a migration to manage the musl dependency via a git subtree, simplifying updates and maintenance of the guest runtime's C library.

_src/hyperlight\_guest/third\party · high confidence

Restructured hypervisor abstraction and improved vCPU state reset on snapshot restore

The virtual machine module has been refactored to introduce a unified hypervisor abstraction layer, centralizing hypervisor detection and exposing a consistent API for VM operations across KVM, MSHV, WHP, and HVF backends. This change significantly improves the reliability of sandbox restoration by ensuring that vCPU state (including MSRs, debug registers, and XCR0) is fully reset during snapshot-restore operations, preventing state leakage between restored sandboxes. Additionally, the module now utilizes the \tracing\ crate for structured logging and implements richer, structured error handling for VM lifecycle events.

_src/hyperlight\_host/src/hypervisor/virtual\machine · high confidence

Sandbox API and metrics collection simplified in metrics example

The metrics example has been updated to use the new \SandboxBuilder\ API instead of the previous \UninitializedSandbox\ and \evolve\ pattern, significantly reducing boilerplate for sandbox creation. Guest function calls now use a generic \call\ method with native types rather than the verbose \call\_guest\_function\_by\_name\ with explicit parameter wrappers. Additionally, the example now uses the \metrics\ crate ecosystem with \metrics\_exporter\_prometheus\ for recording and rendering metrics, replacing the direct \prometheus\ crate usage and manual registry management.

_src/hyperlight\host/examples/metrics · high confidence

Sandbox API overhaul and improved error handling

The host runtime now uses a new \SandboxBuilder\ to construct sandboxes, replacing the previous \SingleUseSandbox\ and \SandboxRunOptions\ patterns. Error handling has been significantly refined: the \HyperlightError\ enum now includes a \GuestBinVersionMismatch\ variant to explicitly fail when guest and host versions do not match, and a \TransportError\ variant for virtqueue communication issues. Additionally, the crate has migrated from the \log\ crate to \tracing\ for error logging, and internal memory layout constants (such as the base address) have been updated.

_src/hyperlight\host/src · high confidence

Simplified guest function calling example with SandboxBuilder

The func\_ctx example has been rewritten to use the new SandboxBuilder API, replacing the previous multi-step process of initializing an UninitializedSandbox, evolving it, and managing MultiUseGuestCallContexts. Users can now create and call guest functions (such as Echo and CallMalloc) directly on a Sandbox instance using native Rust types, significantly reducing boilerplate and simplifying the developer experience for invoking guest code.

_src/hyperlight\_host/examples/func\ctx · high confidence

Simplified host function registration and type handling

The \hyperlight\_host\ function module has been refactored to unify host function registration and parameter/return type handling. The previous \HostFunction0\ through \HostFunction10\ traits and the \HyperlightFunction\ wrapper have been removed in favor of a single \HostFunction\ type and a \Registerable\ trait, allowing host functions to be registered on both \UninitializedSandbox\ and \MultiUseSandbox\ instances. Additionally, the local \SupportedParameterType\ and \SupportedReturnType\ traits have been replaced by re-exports from \hyperlight\_common\, and the \call\_ctx\, \guest\_dispatch\, and \guest\_err\ modules have been removed, indicating a shift in how guest function calls and error handling are managed within the host.

_src/hyperlight\host/src/func · high confidence

Simplified sandbox API and added interrupt support in examples

The logging and tracing examples now use the new SandboxBuilder pattern instead of the previous UninitializedSandbox/EvolvableSandbox workflow, resulting in cleaner code and the removal of verbose type annotations for guest function calls. Additionally, the examples demonstrate a new interrupt capability, allowing host-side cancellation of long-running guest functions via an interrupt handle.

_src/hyperlight\host/examples/tracing · high confidence

Simplified sandbox creation and function invocation in hello-world example

The hello-world example now uses the new SandboxBuilder API, replacing the previous multi-step process of creating an UninitializedSandbox, manually registering host functions, and evolving the sandbox state. Users can now build a sandbox with a registered host function in a single fluent chain. Additionally, calling guest functions has been simplified to use native Rust types (e.g., calling \`sandbox.call::\<i32\>(

_src/hyperlight\host/examples/hello-world · high confidence

Snapshot ABI versioning and validation safeguards

The snapshot module now includes compile-time assertions (tripwires) that pin critical ABI constants—such as the snapshot ABI version (5), OCI media types, OCI layout version (1.0.0), Hyperlight PEB size, OutB/VmAction port numbers, and base memory address. These checks ensure that any change to these underlying contracts will fail at compile time, preventing the accidental loading of incompatible older snapshots at runtime. Additionally, the module exposes public OCI reference types (digest, reference, tag) and defines the immutable Snapshot structure with metadata support, laying the groundwork for robust snapshot versioning and validation.

_src/hyperlight\host/src/sandbox/snapshot · high confidence

Testing utilities updated for new guest types, fuzzing support, and logging fixes

The testing library now provides path resolution for new guest types (witguest, dummyguest) and non-PIE simpleguest binaries, while removing support for the deprecated callbackguest. A new fuzzing helper prefers simpleguest binaries located in the same directory as the executable, and standard sandbox heap sizes are now exposed as constants. Additionally, guest logging targets have been corrected from 'hyperlight-guest' to 'hyperlight\_guest', and the tracing subscriber now includes a method to retrieve recorded spans and uses a safer interest strategy to prevent race conditions in parallel tests.

_src/hyperlight\testing · high confidence

Updated Rust toolchain to 1.86 and added developer helper scripts

The development environment now uses Rust 1.86, as reflected in the updated \rust-dependabot-patch.Dockerfile\. Additionally, two new scripts have been added to the \hack\ directory to improve developer workflows: \clippy-package-features.sh\ automates clippy checks across various package feature combinations, and \update-actions.sh\ helps scan and pin GitHub Actions to specific commit hashes for security and reproducibility.

hack · high confidence

Test coverage

Added .gitkeep files to test guest binary directories; Added WIT guest test definitions for component roundtrip and resource handling; Added WIT guest test harness and roundtrip tests; Added WIT roundtrip tests and updated sandbox integration tests; Added bindgen test cases for WIT package name disambiguation and versioning; Added snapshot golden tests for Hyperlight host; Clean up test helper modules and update license headers; New fuzzing targets for guest calls, tracing, and virtio queues; Refactored test helpers to use SandboxBuilder and removed in-process mode support; Removal of callbackguest test fixture; Rewritten benchmark suite with sandbox size dimensions and new lifecycle tests; Updated c\_simpleguest test to use picolibc and standard C functions; Updated dummyguest test to support aarch64 and modernize build configuration; Updated simpleguest test guest to use new guest-bin APIs and exception handling macros.

Dependencies

Rust workspace restructure and dependency modernization

The project has been restructured into a multi-crate workspace, introducing new packages for guest binaries (hyperlight-guest-bin), guest macros (hyperlight-guest-macro), guest tracing (hyperlight-guest-tracing), libc bindings (hyperlight-libc), and component utilities/macros (hyperlight-component-util, hyperlight-component-macro). The host fuzzing target was moved to a top-level fuzz directory, and the test guest workspaces were consolidated. Additionally, the workspace upgraded to Rust edition 2024 (MSRV 1.89) and updated core dependencies, including wasmparser, wit-parser, and flatbuffers, to align with the new component model support.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 77 → 78 (+0.7)
  • Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.

Lenses

  • Code Health 91 → 91 (-0.0)
  • Architecture 99 → 95 (-3.8)
  • Maturity 78 → 78 (+0.0)
  • Readiness 81 → 81 (-0.4)
  • Security 70 → 73 (+2.2)
  • Performance 94 (new)

Resolved (26)

  • Documentation: contradicts the code (docs/snapshot-versioning.md)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Documentation: written for insiders
  • Duplicated block (10 lines × 2) (src/hyperlight_host/src/mem/elf.rs)
  • Duplicated block (13 lines × 2) (src/hyperlight_common/src/flatbuffer_wrappers/function_call.rs)
  • Duplicated block (16–17 lines × 2) (src/hyperlight_common/src/flatbuffer_wrappers/function_call.rs)
  • Duplicated block (7 lines × 2) (src/hyperlight_guest_bin/src/guest_function/definition.rs)
  • Duplicated block (9 lines × 2) (src/hyperlight_common/src/flatbuffer_wrappers/function_types.rs)
  • Duplicated block (9 lines × 2) (src/hyperlight_common/src/flatbuffer_wrappers/function_types.rs)
  • Duplicated block (9 lines × 2) (src/hyperlight_host/src/sandbox/snapshot/file/mod.rs)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Hotspot: src/hyperlight_common/src/flatbuffer_wrappers/function_types.rs (src/hyperlight_common/src/flatbuffer_wrappers/function_types.rs)
  • Hotspot: src/hyperlight_component_util/src/hl.rs (src/hyperlight_component_util/src/hl.rs)
  • Hotspot: src/hyperlight_host/src/hypervisor/hyperlight_vm/x86_64.rs (src/hyperlight_host/src/hypervisor/hyperlight_vm/x86_64.rs)
  • Hotspot: src/hyperlight_host/src/hypervisor/regs/x86_64/special_regs.rs (src/hyperlight_host/src/hypervisor/regs/x86_64/special_regs.rs)
  • Hotspot: src/hyperlight_host/src/hypervisor/virtual_machine/mshv/x86_64.rs (src/hyperlight_host/src/hypervisor/virtual_machine/mshv/x86_64.rs)
  • Hotspot: src/hyperlight_host/src/hypervisor/virtual_machine/whp.rs (src/hyperlight_host/src/hypervisor/virtual_machine/whp.rs)
  • …and 6 more

New (32)

  • Ambiguous naming convention. In Rust, to_* typically implies a copy or conversion (borrowing), while into_* implies consuming the value. However, to_bytes() on Segments likely consumes the segments to create a contiguous Bytes object, making it semantically identical to into_bytes(). If to_bytes does not consume, it is confusingly named against standard idioms; if it does, it duplicates into_bytes.
  • ClassTooLong: SandboxMemoryManager (src/hyperlight_host/src/mem/mgr.rs)
  • Duplicated block (13 lines × 2) (src/hyperlight_host/src/mem/shared_mem.rs)
  • Duplicated block (7 lines × 2) (src/hyperlight_host/src/sandbox/snapshot/file/transport.rs)
  • Duplicated block (9 lines × 2) (src/hyperlight_ci/src/remote.rs)
  • Duplicated block (9 lines × 2) (src/hyperlight_guest/src/transport/mem.rs)
  • Duplicated block (9–10 lines × 2) (src/hyperlight_common/src/virtq/consumer.rs)
  • End-of-life runtime: Rust 1.94
  • FileTooLong: mem/mgr.rs (src/hyperlight_host/src/mem/mgr.rs)
  • FileTooLong: virtq/producer.rs (src/hyperlight_common/src/virtq/producer.rs)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Hotspot: src/hyperlight_host/src/sandbox/snapshot/file/mod.rs (src/hyperlight_host/src/sandbox/snapshot/file/mod.rs)
  • Low cohesion: HvfVm (LCOM4 5) (src/hyperlight_host/src/hypervisor/virtual_machine/hvf/mod.rs)
  • Low cohesion: Offset (LCOM4 4) (src/hyperlight_host/src/mem/ptr_offset.rs)
  • Medium advisory (unmaintained): RUSTSEC-2025-0119 (Cargo.lock)
  • Off the main sequence: hyperlight-common
  • Off the main sequence: hyperlight-component-util
  • Off the main sequence: hyperlight-guest-tracing
  • …and 12 more

Changes since last survey

  • 22 commits — 20 feature/other, 2 fixes

By area

  • (root) — 10 commits
  • src/hyperlight_host — 6 commits
  • .github/workflows — 3 commits
  • .github/dependabot.yml — 1 commit
  • src/hyperlight_ci — 1 commit
  • src/hyperlight_common — 1 commit

Notable commits

  • fix: fix: adjust scratch size for benchmarks (#1847)
  • fix: fix: use try_into instead of as u64 cast in push_buffer (#1825)
  • change: Add API for Snapshot metadata (#1860)
  • change: Comment benchmark results on pull requests (#1529)
  • change: Configure Dependabot cooldown and Windows crate groups (#1821)
  • change: Make ELF loading respect program header virtual addresses for non-PIE binaries (#1530)
  • change: Update pinned nightly toolchain (#1849)
  • change: chore(deps): bump bitflags from 2.13.1 to 2.13.2 (#1830)
  • change: chore(deps): bump cfg-if from 1.0.4 to 1.0.5 (#1853)
  • change: chore(deps): bump crate-ci/typos from 1.50.1 to 1.50.2 (#1846)
  • change: chore(deps): bump docker/build-push-action from 7.3.0 to 7.4.0 (#1845)
  • change: chore(deps): bump opentelemetry-semantic-conventions from 0.32.1 to 0.33.0 (#1857)
  • change: chore(deps): bump rand from 0.10.2 to 0.10.3 (#1858)
  • change: chore(deps): bump syn from 3.0.5 to 3.0.6 (#1852)
  • change: chore(deps): bump the wasm-tools group with 3 updates (#1841)
  • change: chore(deps): bump uuid from 1.26.0 to 1.26.1 (#1827)
  • change: chore(deps): bump wat from 1.258.0 to 1.259.0 (#1828)
  • change: ci: cut Miri test time from 16 minutes to 90 seconds (#1859)
  • change: feat: add virtqueue transport foundations (#1793)
  • change: feat: implement virtio based host-guest communication (#1794)
  • …and 2 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

hyperlight-dev/hyperlight was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 30 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 98312e9da3642d942270487321af1807f98b2eae — the exact code this score is about.
  • Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-cb25ca4feafa.