smol-machines/smolvm
50.9
Adequate · 29 September 2026
210.2k
lines of production code
Rust
primary language
2
measurements over time
What this system is
SmolVM is a hardware-isolated microVM runtime that enables the rapid, secure execution of arbitrary workloads—including GPU-accelerated AI inference and desktop environments—via a fork-pool architecture. It provides a containerd shim for Kubernetes integration, a declarative configuration system, and comprehensive tooling for checkpointing, credential management, and OCI artifact distribution. The system supports cross-platform deployment on Linux, macOS, and Windows, offering both embedded SDKs for in-process usage and a full API server for fleet management.
Features
Add Nix derivations for libkrun and libkrunfw
New Nix build definitions for libkrun (version 1.17.3) and libkrunfw (version 5.4.0) are now available, enabling the packaging of these virtualization components on Linux and Darwin. The libkrun derivation supports optional features including GPU, sound, input, timesync, and AWS Nitro, as well as SEV and TDX security variants, while libkrunfw handles the guest payload and includes specific build fixes for aarch64 and macOS cross-compilation.
nix · high confidence
Add k3s deployment scripts and Kubernetes manifests for the smolvm runtime
This change introduces the deployment infrastructure for the smolvm containerd shim v2 on k3s clusters. It adds shell scripts to install, uninstall, and run end-to-end validation tests for the runtime, ensuring it is correctly wired into k3s's embedded containerd without overwriting existing configurations. Additionally, it provides a Kubernetes RuntimeClass definition and an example pod manifest, enabling users to schedule workloads as per-pod microVMs with hardware-level isolation.
deploy · high confidence
Added cuBLAS and cuDNN remote execution support
The smolvm-cuda guest shim now forwards a broad set of cuBLAS and cuDNN operations to the host, enabling GPU-accelerated linear algebra and deep learning primitives inside the virtual machine. The generated guest and host bindings cover cuBLAS functions including matrix multiplications (Sgemm, Dgemm, Hgemm, GemmEx), strided-batched variants, vector operations (AxpY, Scal, Copy, Swap, Gemv, Ger, Geam, Ssymm, Ssyrk, Strsm, Dgmm, Ssbmv), and descriptor management, as well as cuDNN convolution setup and execution (Create/Destroy descriptors, SetStream, SetTensor/Filter/Convolution descriptors, GetConvolutionForwardWorkspaceSize, ConvolutionForward). Guest calls are serialized and sent to the host via a virtual handle system, allowing frameworks relying on these libraries to execute workloads remotely.
crates/smolvm-cuda/src/generated · high confidence
Added script to stage embedded Krun SDK libraries
A new shell script, \sdks/scripts/stage-embedded-libs.sh\, has been added to automate the deployment of embedded SDK libraries. This script copies platform-specific \libkrun\ and \libkrunfw\ binaries (\.so\ on Linux, \.dylib\ elsewhere) from a source directory into a target directory, supporting environment variable overrides for custom bundle locations.
sdks/scripts · high confidence
Added smolfile examples for Node.js and Python development environments
New example configuration files (node.smolfile and python.smolfile) have been added to the examples directory, demonstrating how to define hardware-isolated microVM environments for Node.js (v22) and Python (v3.12). These files specify base images, resource limits (2 CPUs, 512MB memory), network access, and development-specific settings such as port mappings and initialization commands (installing nodemon for Node and ipython for Python).
examples/node-app, examples/python-app · high confidence
CUDA Runtime API shim for guest VMs
The \smolvm-cudart-shim\ crate provides a drop-in replacement for \libcudart.so.11.0\ that allows CUDA Runtime API programs to run inside the guest VM. It intercepts CUDA calls and remotes them over a vsock, TCP, or Unix socket to the host GPU, lowering Runtime API calls to the existing Driver API RPC. The shim includes auto-generated forwarders for cuBLAS and cuDNN operations, stubs for unimplemented symbols, and live regression probes for graph capture and event handling.
crates/smolvm-cudart-shim · high confidence
Fork-pool benchmark harness and CUDA graph measurement tools
The bench directory now includes a comprehensive benchmark harness to validate the fork-pool architecture against native execution. This includes \bench.sh\ for running A/B comparisons (native vs. fork with weight sharing), \matrix.sh\ and \highn.sh\ for scaling experiments, and Python utilities like \graph\_pool\_memory.py\ and \segmented\_graph\_throughput.py\ to measure CUDA graph memory and throughput characteristics. The harness enforces strict fairness knobs (CPU pinning, cache state) and includes verification logic to ensure weight-sharing modes are actually honored by the daemon, addressing previous issues where sharing was inert due to zero-copy upload CRC mismatches.
bench · high confidence
Guest network configuration via environment variables for virtio-net
The agent now configures the guest's network interface (eth0) directly from host-provided environment variables (SMOLVM\NETWORK\\*) instead of relying on external tools like ip or DHCP. This change introduces a Linux-specific backend that programmatically sets the MAC address, MTU, IPv4/IPv6 addresses, default routes, and DNS resolver, ensuring the guest network is ready immediately during boot without requiring a full userspace environment.
crates/smolvm-agent/src/network · high confidence
Guest-side CUDA runner enables remote GPU execution over vsock
The new \smolvm-cuda-guest\ crate allows a guest VM to execute CUDA workloads by connecting to a host-side CUDA server via vsock. It implements a generalized Driver-API protocol, enabling the guest to load arbitrary PTX modules, launch kernels, and manage device memory remotely. The runner includes robustness features for VM forking, such as detecting stale connections and reusing session tokens to maintain GPU context across clones, and validates cross-VM device memory sharing through a shared-daemon model.
crates/smolvm-cuda-guest · high confidence
Guest-side NVML shim enables CUDA framework GPU detection
A new guest-side library (\libnvidia-ml.so\ shim) has been added to \crates/smolvm-nvml-shim\ to allow CUDA frameworks like vLLM to detect and query the remote GPU via NVML. Previously, these frameworks would fail to find a CUDA platform because NVML was not remoted; this shim intercepts NVML calls and resolves them against the already-loaded remoted CUDA driver (\libcuda.so.1\), providing device names, memory info, and compute capability. This removes the need for workload-side platform-detection patches.
crates/smolvm-nvml-shim · high confidence
Host-side CUDA Driver-API backend for remote GPU execution
The host component now implements a real CUDA Driver-API backend (gpu.rs) that dynamically loads the system CUDA driver library (libcuda.so.1 or nvcuda.dll) to forward guest GPU requests. This enables zero-copy memory access, CUDA graph capture/replay, and full support for cuBLAS/cuDNN operations by remoting Driver-API calls from the guest VM to the host GPU over vsock, replacing previous stubs with functional implementations for memory management, context handling, and kernel launches.
crates/smolvm-cuda/src/host · high confidence
Introduce CUDA fork pool admission control and fused rollout executors
The API server now includes a lease-aware admission controller for CUDA fork pools that dynamically adjusts worker limits based on real-time GPU telemetry (VRAM, utilization) and host CPU saturation to prevent resource exhaustion. Additionally, a new fused rollout system allows registering local inference backends (e.g., vLLM) with framework-neutral policy management, supporting device-resident LoRA handoff via private Unix sockets and providing a high-throughput generation path that falls back to isolated fork pools when necessary.
src/api · high confidence
Introduce containerd-shim-v2 for VM-per-pod isolation
This change adds the \crates/smolvm-shim\ crate, implementing a containerd shim v2 runtime that boots a dedicated smolvm microVM for each Kubernetes pod sandbox. The shim handles the full container lifecycle (create, start, stop, delete) by managing the VM via an embedded engine and communicating with an in-guest agent over vsock. It groups all containers within a pod under a single shim process to share the sandbox VM, fixes a containerd 2.2+ compatibility issue where containers failed to find their sandbox, and supports features like GPU passthrough via pod annotations and mock backends for testing without KVM.
crates/smolvm-shim · high confidence
Introduce embedded Node.js SDK for in-process microVMs
The \sdks/node/smolvm-embedded\ package is now available, providing an embedded Node.js SDK that runs microVMs directly within the Node.js process via NAPI-RS, eliminating the need for a separate daemon. This SDK exposes a \Machine\ class for managing VM lifecycle (create, start, connect, delete) and executing commands, along with convenience presets like \NodeMachine\ and \PythonMachine\ for running code in pre-configured environments. It includes a comprehensive error handling system with typed errors (e.g., \NotFoundError\, \InvalidStateError\) and supports configuration for mounts, port mappings, and resource limits.
sdks/node/smolvm-embedded · high confidence
Introduce embedded Node.js SDK for managing virtual machines and containers
The \sdks/node\ directory now contains the \smolvm-embedded\ workspace, providing a public Node.js SDK for creating and managing virtual machines (microVMs) and running container images. Users can install the \smolvm-embedded\ package to access APIs for machine lifecycle management (create, start, stop, delete), one-shot command execution via \quickExec\, and container execution via \quickRun\. The SDK supports configuring machine resources (CPU, memory, network), mounting host directories (read-only and read-write), and mapping host ports to guest services. It automatically resolves platform-specific binaries for macOS (Darwin) and Linux across x86\_64 and ARM64 architectures.
sdks/node · high confidence
Introduce guest CUDA driver shim for unmodified VM workloads
The smolvm guest now includes a drop-in \libcuda.so.1\ shim that intercepts CUDA Driver API calls and marshals them over RPC to the host GPU. This allows unmodified CUDA programs (such as PyTorch or vLLM) to run inside the VM without recompilation, with the shim handling transport via VSOCK, TCP, or Unix sockets. The shim advertises a CUDA 12.4 surface by default (with CUDA 13 support opt-in via environment variable) and includes stubs for unsupported driver functions to ensure ABI compatibility.
crates/smolvm-cuda-shim · high confidence
Introduce new virtio-net networking backend with egress policy and protocol relays
This change adds a new host-side virtio-net networking runtime (\crates/smolvm-network\) that replaces the previous networking path. It introduces a smoltcp-based gateway that relays guest TCP, UDP, ICMP (ping), and DNS traffic to the host, enforcing a configurable egress policy (allow-lists, CIDRs, and strict floor modes for multi-tenant isolation). The backend also supports named inter-VM networking via a Unix-socket fabric, published host port forwarding, and off-poll-thread DNS resolution to prevent blocking.
crates/smolvm-network/src · high confidence
Introduce per-machine credential interception with placeholder substitution
The \smolvm-credentials\ crate now provides a transparent HTTPS interceptor that allows guests to use credentials without exposing secret values. Guests receive opaque placeholders in environment variables instead of real secrets. The interceptor terminates TLS using a per-machine Certificate Authority (CA) that is name-constrained to the machine's allowed hosts, minting leaf certificates for each request. It inspects the TLS ClientHello to identify the destination, resolves the real credential value from a pluggable resolver, substitutes the placeholder in the HTTP request, and forwards the traffic over a verified TLS connection. This ensures credentials are never stored in the machine's policy or checkpoint state, supporting rotation and revocation without restarting the guest.
crates/smolvm-credentials · high confidence
Introduce pure-Rust OCI layer extraction with overlayfs whiteout support
Added a new \smolvm-oci-layer\ crate that extracts individual OCI image layers into an overlayfs lowerdir, handling gzip and zstd decompression and translating OCI whiteout markers into Linux overlayfs representations (character device whiteouts and opaque directory xattrs). The implementation includes path-joining logic that prevents symlink traversal attacks during extraction, ensuring that destructive operations like file removal or whiteout creation are safely confined to the intended directory structure.
crates/smolvm-oci-layer · high confidence
Introduce smolvm rollout client for fused LoRA policy execution
Adds the \smolvm\_rollout\ Python SDK, providing a \RolloutClient\ for submitting text or token-ID prompts to a fused vLLM executor that continuously batches compatible LoRA policies. The SDK supports automatic lease discovery from local environment assignments, device-resident adapter handoff via \publish\_device\_adapter\ for CUDA trainers, and a \DeviceAdapterServer\ for framework-neutral loading and unloading of policy versions.
sdks/python · high confidence
Introduce smolvm-pack crate for portable packed binary artifacts
The new \smolvm-pack\ crate provides the core logic for packaging microVMs into self-contained \.smolmachine\ artifacts. It defines the binary format (a zstd-compressed tar archive with a JSON manifest and footer), handles asset collection (OCI layers, agent rootfs, runtime libraries), and manages extraction on the host. The crate supports multiple execution modes: macOS single-file binaries with assets embedded in a Mach-O section, Linux/macOS binaries with assets appended, and sidecar-based execution. It also includes checkpoint streaming capabilities for packing VM state without temporary memory files, and ensures sparse file preservation and ownership integrity during extraction.
crates/smolvm-pack/src · high confidence
Introduces CUDA Driver-API remoting with shared-memory transport and protocol-versioning
The \smolvm-cuda\ crate now forwards guest CUDA Driver-API calls to the host GPU over a vsock connection, enabling GPU acceleration inside microVMs. It includes a shared-memory ring transport (\ring.rs\) that reduces synchronous round-trip latency to \~1-2µs by polling guest RAM instead of using vsock wakeups, and a POSIX shared-memory bulk-data channel (\shm.rs\) for zero-copy memory transfers. To prevent silent corruption from mismatched binaries, a build-time FNV-1a hash of the wire protocol (\proto.rs\) is embedded and checked during the connection handshake. The implementation supports CUDA graph capture/replay, cuBLAS/cuDNN forwarding, and fork-clone isolation via explicit connection preambles.
crates/smolvm-cuda/src · high confidence
Introduces protocol definitions for credential policies, host patterns, and forkpoint coordination
This change adds several new protocol modules to the \smolvm-protocol\ crate that define the data shapes and constants for new and refined capabilities. The \credentials\ module introduces a \CredentialPolicy\ and \CredentialBinding\ structure, allowing users to define named credentials with specific allowed hosts and injection locations (e.g., HTTP headers), ensuring credentials are never sent to unauthorized destinations. The \host\pattern\ module adds support for strict exact (\=host\) and wildcard (\\.host\) egress host patterns, providing finer-grained control over network allow-lists compared to the previous subdomain-only behavior. The \forkpoint\ module defines stable guest paths and typed error codes for the live branching protocol, enabling machines to pause and resume execution safely. Additionally, the \image\_ref\ module adds a \normalize\_image\_ref\ function to canonicalize OCI image references, ensuring consistent cache keys and log messages. The \secrets\ module defines \SecretRef\ types that point to host environment variables or files, removing the built-in secret store in favor of host-managed references. The \intercept\ module specifies the wire protocol for host-side stream interception, including preamble structures and verdict handling for credential substitution. The \guest\_env\ module defines environment variable constants used to signal features like GPU acceleration, Rosetta translation, and network configuration to the guest agent. The \publish\_socket\ module defines the protocol for dynamic Unix-socket bridges between host and guest. The \retry\ module provides shared retry configuration constants and logic for transient failures.
crates/smolvm-protocol/src · high confidence
Introduces spec-driven CUDA library marshaling generator
Adds a new code generator tool that automates the creation of guest stubs and host dispatchers for CUDA libraries (such as cuBLAS and cuDNN). By defining function signatures and parameter marshaling rules in a compact spec, the tool emits the necessary code to forward calls over the \LibCall\ transport, significantly reducing the manual effort required to support new CUDA operations and enabling zero-copy or handle-based remoting for device pointers and streams.
crates/smolvm-cuda-codegen · high confidence
New CLI commands for configuration, OpenAPI export, and pack management
The CLI now includes a \config\ command to show and edit registry settings, an \openapi\ command to export the server API specification in JSON or YAML, and a \pack\ command with subcommands for creating, running, pushing, pulling, inspecting, and pruning packed VM artifacts. These additions provide users with better control over registry configuration, enable SDK code generation via OpenAPI specs, and support self-contained VM executables.
src/cli · high confidence
New CUDA validation and fork-isolation examples
Added a suite of examples in \crates/smolvm-cuda/examples\ to validate the CUDA remote-execution stack and the new per-clone-process isolation features. \gpu\_loopback.rs\ and \ipc\_loopback.rs\ verify basic GPU operations and cross-session IPC over TCP loopback. \m1\_route\_probe.rs\, \m2\_reconstruct\_probe.rs\, \m3a\_probe.rs\, and \m3a\_stream\_probe.rs\ test the fork-isolation mechanism, including address-preserving memory mapping, module reconstruction, and inherited handle translation (streams, events, functions) between a golden process and its isolated clone workers. \path3\_ipc\_spike.rs\ validates the underlying address-preserving IPC primitives (export/import, fixed-address reservation), and \shim\_server.rs\ provides a host-side RPC server for exercising the guest CUDA shim without a full VM.
crates/smolvm-cuda/examples · high confidence
New DOOM-in-browser example with hardware-isolated microVM
Added a new example in the examples/doom-web directory that runs the DOOM shareware game inside a browser using js-dos, served from a hardware-isolated microVM. The example includes a new doom.smolfile configuration defining a Python-based web server container with 2 CPUs, 512MB memory, and port 8080 exposed, along with an index.html page that loads the js-dos runtime and serves the game. Users can now run this example via 'smolvm machine run' to access DOOM in their browser.
examples/doom-web · high confidence
New GPU-accelerated headless Chrome example
Added a new example configuration (gpu-chrome.smolfile) that provisions a Fedora 42 microVM with GPU acceleration enabled. This setup installs Chromium along with Mesa Vulkan drivers and tools, allowing users to run headless browser workloads (such as Playwright or Puppeteer) that require real GPU support for WebGL, Canvas, or CSS transforms. The example includes instructions for host-side dependencies on macOS and verification steps using vulkaninfo.
examples/gpu-chrome · high confidence
New OpenClaw microVM example with hardware isolation
Added an example configuration (openclaw.smolfile) that runs the OpenClaw LLM gateway inside a hardware-isolated microVM. This setup restricts outbound network traffic to specific LLM provider APIs to prevent data exfiltration, allocates 2 CPUs and 1024MB of memory, and exposes port 18789 for health checks and chat completions.
examples/openclaw-app · high confidence
New agent subsystems for boot, display, input, and fork lifecycle
The agent now includes dedicated modules for managing the VM lifecycle and interactive features. A new \boot\_config\ module serializes launch parameters (disks, ports, resources, CUDA, SSH agent) for the isolated \\_boot-vm\ subprocess, while a new \launcher\ module handles the low-level VM startup and CUDA ring cleanup. Interactive desktop support is added via \display\ (host-side virtio-gpu framebuffer) and \input\ (virtio-input keyboard/mouse) modules, enabling VNC-based remote control. Additionally, a new \fork\ module implements live branching mechanics, including cross-process locking and copy-on-write disk cloning, and the vsock \client\ module now supports file write metadata (ownership/permissions) and improved write-backpressure handling.
src/agent · high confidence
New artifact cache, credential, CUDA, and database modules
Added src/artifact\_cache.rs for reference-safe lifecycle management of shared pack caches and immutable COW disk bases, src/credentials.rs for per-machine credential substitution and CA management, src/cuda\_daemon.rs for a shared CUDA daemon serving proxied GPU connections, and src/db.rs for an ACID-compliant SQLite database with a connection pool and WAL mode. Also added src/checkpoint\_store.rs as a re-export of the standalone checkpoint crate, src/disk\_utils.rs for sparse disk creation and resizing, and src/dns\_filter.rs for host-side DNS filtering.
src · high confidence
New build and validation scripts for agent rootfs, libkrun, and release packaging
The scripts directory now includes a comprehensive set of build and validation tools: build-agent-rootfs.sh constructs the Alpine-based agent rootfs with support for cross-architecture builds and non-root user namespaces; build-libkrun-linux.sh handles native compilation of the libkrun stack with optional GPU features and glibc floor enforcement; build-dist-windows.sh assembles the Windows distribution with cross-compiled binaries and pre-formatted disk templates; and build-embedded-node.sh manages the Node SDK build. Additionally, new validation scripts (check-krun-exports.sh, check-krun-init-static.py, check-libkrun-glibc-floor.sh, check-libkrun-provenance.sh, check-secrets-guards.sh, check-cuda-shim-exports.sh) ensure bundled libraries meet symbol, static linking, glibc version, provenance, and security requirements, while cut-release.sh automates version bumping and tagging, and fetch-vulkan-guest-driver.sh stages the Vulkan driver bundle for GPU workloads.
scripts · high confidence
New docker-in-vm example with host socket access and storage fixes
Added a new example configuration (docker.smolfile) that runs Docker Engine inside a microVM. This setup includes a fix for overlay storage failures by bind-mounting /var/lib/docker and /var/lib/containerd to an ext4 disk, and enables running nested Kubernetes (K3d) by adding /dev/kmsg to the container device set. It also exposes the guest Docker daemon socket to the host via vsock for direct control from the host machine.
examples/docker-in-vm · high confidence
New embedded SDK runtime with machine lifecycle and execution APIs
The embedded runtime now exposes a structured API for managing VMs within the host process. Users can define machine configurations via \MachineSpec\ (including images, mounts, ports, labels, and forkability) and manage their lifecycle through \EmbeddedRuntime\ methods such as \create\_machine\, \start\_vm\, \pause\_machine\, and \resize\_machine\. The runtime supports running commands with cancellation (\ExecCancel\), per-command user context, and persistent OCI image overlays. It also provides checkpointing, egress policy management, and GPU/CUDA resource handling, all backed by a local SQLite database for persistence.
src/embedded · high confidence
New file I/O and command execution APIs for guest machines
The API now exposes endpoints to upload and download files to and from running machines, as well as to execute commands. The file upload endpoint writes data to a specified path inside the VM, while the download endpoint returns file contents or, if the path is a directory, a JSON listing of its entries. Command execution supports both foreground and background modes, allowing users to run scripts or long-lived daemons within the machine's environment, with support for environment variables, secrets, and stdin data.
src/api/handlers · high confidence
New headless browser example with GPU acceleration and forkable pool support
Added a new example in \examples/headless-browser\ that demonstrates running a GPU-accelerated headless Chromium instance. The \browser.smolfile\ configures an Alpine guest with Vulkan support via \mesa-vulkan-virtio\ for hardware-accelerated rendering, while the accompanying \README.md\ provides a guide for creating persistent, pre-warmed browser pools using the \--forkable\ feature. This setup allows users to fork a 'golden' browser instance to spawn warm clones in \~50–130 ms, significantly reducing cold-start latency for automated tasks.
examples/headless-browser · high confidence
New interactive Linux desktop example with GPU acceleration support
Adds a new \examples/desktop\ directory that demonstrates running a full interactive Linux desktop (Omarchy with Hyprland) inside a smolvm machine, served to the host via VNC. The example includes scripts (\omarchy.sh\, \omarchy-aarch64.sh\) that handle necessary container workarounds for input devices, D-Bus, and session management, along with a custom Mesa build script (\build-mesa-zink-aarch64.sh\) and patch to enable hardware-accelerated OpenGL on macOS hosts using the Zink driver. It also ships a guest Chromium wrapper with software WebGL enabled to ensure 3D content renders correctly in the virtualized environment.
examples/desktop · high confidence
New local LLM example with Apple Silicon GPU acceleration
Added a new example configuration for running local LLM inference using llama.cpp with GPU acceleration on Apple Silicon (M4 Max). The example demonstrates how to configure a microVM with Vulkan support via virtio-gpu, MoltenVK, and Metal, including setup instructions for building llama.cpp, downloading models, and verifying GPU usage.
examples/local-llm · high confidence
New shared data models for disk, image sources, and resource configuration
The \src/data\ module now provides the canonical data structures and validation logic for core VM operations. Users can attach host block devices or disk images via the \--disk\ flag, with support for read-only modes and automatic format detection (Raw vs. Qcow2). Image resolution has been standardized to explicitly classify inputs as registry references, local archives (including stdin streaming), or unpacked directories, with configurable size limits. Resource configuration now exposes options for GPU acceleration, CUDA-over-vsock, nested virtualization, and Rosetta 2 translation, alongside validation for CPU, memory, and disk sizes. Network configuration includes support for custom DNS resolvers, named inter-VM networks, and guest subnet customization to avoid conflicts with internal VPNs.
src/data · high confidence
New smolvm-checkpoint crate for incremental, content-addressed checkpoint storage
A new Rust crate, smolvm-checkpoint, provides an incremental checkpoint storage layer that chunks, verifies, and stores machine state as content-addressed objects. It supports incremental captures where unchanged data is reused across generations, and allows retaining a history of ancestor checkpoints so any generation can be restored from a single directory. The crate defines a formal checkpoint format (specified in FORMAT.md) with versions 4 and 5, using a container with a zstd-compressed tar payload and a JSON manifest, and includes a reference implementation with examples and tests demonstrating roundtrip capture and restore.
crates/smolvm-checkpoint · high confidence
OCI registry client with P2P blob sharing and robust pull/push
The smolvm-registry crate now provides a full OCI Distribution Spec client for pushing and pulling .smolmachine artifacts. Pulls use a content-addressed local blob cache (configurable via SMOLVM\_BLOB\_CACHE\_MAX\_BYTES) with LRU eviction, resume-and-retry for stalled downloads, and an optional brokered P2P layer-blob fetch from sibling fleet nodes before falling back to the registry. Pushes stream-upload large sidecar blobs with a chunked fallback for registries that reject monolithic uploads, and stamp manifests with OCI 1.1 artifactType and standard annotations. Multi-platform support is added via OCI image indexes keyed by guest platform, and all digest-addressed paths are validated to prevent filesystem traversal.
crates/smolvm-registry/src · high confidence
Official package repositories for Arch, Debian, RPM, and Nix
Users can now install smolvm directly from official package repositories for Arch Linux (pacman), Debian/Ubuntu (apt), Fedora/RHEL (dnf/yum), and Nix. The packaging includes an official Arch PKGBUILD that correctly handles sparse storage templates using GNU tar, ships zstd-compressed disk templates for Arch, and provides nfpm configuration for .deb and .rpm packages. A Nix flake package is also provided with an automated version-bumping script for releases. Repository metadata and installation instructions are served via a new static website.
packaging · high confidence
Smolfile specification and parser added
A new Smolfile specification and parser has been introduced, defining the TOML-based configuration format for declaratively describing microVM workloads. This change establishes the schema for top-level fields (such as image, entrypoint, cpus, memory, and networking), development overrides in the \[dev\] section, and artifact packaging settings in the \[artifact\] section. It also introduces support for network egress filtering via the \[network\] section (including credential substitution), branchable launch configurations with CUDA capacity in the \[branch\] section, health checks, restart policies, SSH agent forwarding, and secret injection via references in the \[secrets\] section.
crates/smolvm-smolfile/src · high confidence
Removals
Removal of smolvm-helper daemon and storage management code
The \smolvm-helper\ crate, which previously provided a daemon for managing microVMs via vsock, has been removed. This deletion eliminates the code responsible for OCI image pulling (using crane), layer extraction, overlay filesystem preparation, and storage status reporting within the helper VM. Users relying on this specific helper daemon for these container image management tasks will no longer have this component available.
crates/smolvm-helper · high confidence
Removed test\_disk\_root binary
The test\_disk\_root binary, which was used to test disk-based root filesystems with libkrun, has been removed from the project.
src/bin · high confidence
Behavioural changes
Forked VMs now serve with CUDA graphs
Forked VMs (clones) now support CUDA graph replay, allowing them to serve inference requests with significantly lower latency than the previous eager-mode socket remoting. This change resolves a stream-resolution bug that previously caused segfaults in clone workers and implements a capture-replay mechanism where the clone performs a warmup pass and re-captures the graph sequence in its own context. As a result, clone serving latency drops to approximately 215 ms steady-state (roughly 2.8x faster than eager clones), enabling higher density and throughput for fork-scaled workloads.
demo · high confidence
Migrate libkrun backend to dynamic library loading
The libkrun VM backend now loads the libkrun library dynamically at runtime instead of relying on static FFI bindings. This change improves availability detection by checking for the library's presence via \find\_lib\_dir()\ and removes the dependency on the \rootfs\ module, specifically eliminating the previous buildah container cleanup logic. Additionally, the \available\_backends\ utility function has been removed from the backend module.
src/vm/backend · high confidence
Native S3 volume mounting via in-agent FUSE filesystem
The agent now mounts S3-compatible buckets directly as POSIX filesystems using a built-in FUSE implementation, eliminating the previous requirement for the rclone binary in the guest image. This self-contained filesystem layer handles directory synthesis, staged local writes, and AWS SigV4 authentication natively, allowing S3 volumes to be mounted into any image—including distroless or scratch containers—without external dependencies.
crates/smolvm-s3fs · high confidence
New network backend selector and default routing to virtio-net
The system now supports selecting between two network backends: \tsi\ (the previous default, using libkrun TSI for outbound-only traffic) and \virtio-net\ (a new host-side smolvm network stack). For users, this means that VMs requiring inbound published ports, egress policies (CIDR/DNS filtering), named inter-VM networks, or credential substitution will automatically use the \virtio-net\ backend, as these features are only supported by it. Outbound-only VMs without these requirements continue to use the lighter \tsi\ backend by default. The legacy \virtio\ backend name is no longer accepted.
src/network · high confidence
Persistent DNS resolver refresh and signal shutdown evidence
The agent now automatically refreshes its DNS configuration during network reuse or remount events to maintain reliable connectivity in warm fleets. Additionally, a bounded JSON event is emitted to stderr upon shutdown to provide observational evidence of signal receipt, ensuring diagnostics are captured without impacting shutdown semantics or performance.
crates/smolvm-agent/src · high confidence
Unified platform abstraction for Linux, macOS, and Windows
The platform module has been refactored to centralize OS-specific logic behind a common trait interface, introducing distinct executor implementations for Linux, macOS, and Windows. This change standardizes how the host manages VM execution and inter-process communication: macOS now uses an explicit mount-wrapper script for virtiofs devices and includes native Rosetta 2 support for x86\_64 binary translation on Apple Silicon, whereas Linux and Windows execute commands directly without mount wrappers and stub out Rosetta. Additionally, a cross-platform Unix-domain socket abstraction (\UdsStream\) has been added to ensure consistent agent control channel and vsock-bridge communication across all supported operating systems.
src/platform · high confidence
Updated Windows binaries and provenance for libkrun and libkrunfw
The Windows x86\_64 build artifacts (krun.dll, libkrunfw.dll) have been updated to match the latest pinned libkrun and libkrunfw submodule commits (ce01d93 and b8c9994 respectively). This refresh ensures the bundled Windows libraries incorporate recent fixes and features from the upstream submodules, such as the TSI remote-half-close fix, Windows virtiofs DAX fixes, and other platform-specific improvements tracked in the libkrun repository.
_lib/windows-x86\64 · high confidence
Updated bundled libkrun and libkrunfw libraries for Linux x86\_64
The bundled Linux x86\_64 shared libraries (libkrun.so and libkrunfw.so) have been rebuilt and updated to newer submodule commits. This update includes a new provenance file to track the specific source commits used for the build, ensuring reproducibility and allowing CI to verify the binaries against pinned submodules. The libraries are now stored via Git LFS to manage their size.
_lib/linux-x86\64 · high confidence
VM configuration restructuring and new hardware support options
The VM configuration model has been refactored to flatten resource limits: the previous \Resources\ struct (containing memory, CPUs, and disk size) is removed, and \memory\_mib\ and \cpus\ are now direct fields on \VmConfig\, while disk size configuration is no longer exposed in this module. Additionally, a new \gpu\ boolean field has been added to \VmConfig\ to enable GPU acceleration via virtio-gpu, and the \HostMount\ type has been moved to a shared \data::storage\ module. The Rosetta x86\_64 translation support has also been updated to use a ptrace wrapper for better compatibility with libkrun on Apple Silicon.
src/vm · high confidence
macOS VirglRenderer patch applied
A patch for the VirglRenderer library has been added to the build system. This patch addresses logging behavior during fence polling and scanout reads, and enables GPU-accelerated rendering for the aarch64 Omarchy desktop environment on macOS hosts.
patches · medium confidence
Fixes
macOS forkable VMs now boot with the allow-jit entitlement
The smolvm binary on macOS now includes the \com.apple.security.cs.allow-jit\ entitlement, which is required for forkable virtual machines to boot successfully. This change resolves a boot failure (exit code -22) that occurred when the missing entitlement prevented the necessary JIT execution.
(repo-wide) · high confidence
Test coverage
Add CUDA 13 export fixtures and live RAM probe test; Added example programs to verify embedded runtime stability and correctness; Added tests for shared content-addressed pack extraction; New test infrastructure and integration suites for smolvm.
Dependencies
SmolVM engine and workspace bumped to version 1.20.2
The SmolVM engine, its core protocol crate, and the entire workspace of library crates have been updated to version 1.20.2. This release also includes the addition of the embedded Node.js SDK (smolvm-embedded) and the removal of the legacy smolvm-helper crate.
(dependencies) · high confidence
Updated macOS shared libraries for GPU and virtualization support
The bundled macOS dynamic libraries have been updated to support GPU workloads and improve virtualization stability. This includes new or refreshed binaries for libMoltenVK (Vulkan-to-Metal translation), libepoxy (OpenGL function pointer management), libvirglrenderer (Vulkan-based GPU rendering for VMs), and the core libkrun/libkrunfw virtualization libraries. A provenance file has also been added to track the specific submodule commits used to build these binaries, ensuring reproducibility and allowing CI to verify the bundled libs against pinned submodules.
lib · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 53 → 51 (-1.7)
- Rubric changed (rubric-2026.09.10 → rubric-2026.09.18) — scores are not directly comparable.
Lenses
- Code Health 87 → 87 (+0.1)
- Architecture 98 → 94 (-4.5)
- Maturity 61 → 60 (-0.7)
- Readiness 63 → 54 (-8.7)
- Security 66 → 73 (+6.8)
- Accessibility 36 → 36 (+0.0)
- Performance 85 (new)
Resolved (67)
- AgentManager::kill (cognitive 23) (src/agent/manager.rs)
- AgentManager::stop (cognitive 19) (src/agent/manager.rs)
- Boundary-crossing change coupling: lib.rs ↔ machine.rs (crates/smolvm-protocol/src/lib.rs)
- Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (no pnpm-resolved versions to grade)
- Documentation: no architecture or design documentation (README.md)
- Documentation: no licence statement (docs/install-nix.md)
- Documentation: written for insiders (docs/hardware-video.md)
- Duplicated block (10 lines × 2) (src/api/handlers/files.rs)
- Duplicated block (10 lines × 2) (src/cli/machine.rs)
- Duplicated block (12 lines × 2) (src/db.rs)
- Duplicated block (12 lines × 3) (src/cuda_daemon.rs)
- Duplicated block (12–13 lines × 2) (crates/smolvm-pack/src/assets.rs)
- Duplicated block (14 lines × 2) (crates/smolvm-agent/src/storage.rs)
- Duplicated block (15 lines × 2) (src/cli/machine.rs)
- Duplicated block (15–17 lines × 2) (src/embedded/runtime.rs)
- Duplicated block (15–18 lines × 2) (src/api/handlers/machines.rs)
- Duplicated block (16 lines × 2) (src/api/handlers/machines.rs)
- Duplicated block (18 lines × 2) (src/config.rs)
- Duplicated block (20–22 lines × 2) (crates/smolvm-agent/src/main.rs)
- Duplicated block (21 lines × 2) (src/cli/pack_run.rs)
- …and 47 more
New (198)
- AgentManager::ensure_running_with_full_config (cognitive 26) (src/agent/manager.rs)
- AgentManager::ensure_running_with_full_config (cyclomatic 16) (src/agent/manager.rs)
- AgentManager::kill_and_wait (cognitive 26) (src/agent/manager.rs)
- AgentManager::stop_inner (cognitive 19) (src/agent/manager.rs)
- AgentManager::stop_vm_process (cognitive 19) (src/agent/manager.rs)
- Ambiguous 'find' operations. find_generation_source and find_lineage both take a store path and an ID. It is unclear if they search for different entities or if one is a wrapper for the other. The names suggest different intents (source vs lineage record) but the signatures are identical, which is confusing.
- Ambiguous naming for resolution operations. resolve_generation takes a directory path to look up a generation, while resolve_in takes an explicit slice of generations. The verb 'resolve' is used for both, but the input domains (filesystem path vs in-memory collection) are distinct. However, resolve_generation is less descriptive than resolve_from_directory or similar, creating a slight inconsistency in how the source of truth is communicated in the name.
- AssetCollector::compress_with (cognitive 25) (crates/smolvm-pack/src/assets.rs)
- CheckpointLogCmd::run (cognitive 22) (src/cli/pack.rs)
- CheckpointStream::append (cognitive 24) (crates/smolvm-pack/src/checkpoint_stream.rs)
- CheckpointStream::read (cognitive 17) (crates/smolvm-pack/src/checkpoint_stream.rs)
- ClassTooLong: VmRecord (src/config.rs)
- CredentialPolicy::validate (cognitive 19) (crates/smolvm-protocol/src/credentials.rs)
- Documentation: no contributor guidance (README.md)
- Documentation: no project overview (README.md)
- Duplicate method signatures with identical names and parameter types exist on the same type. The second signature uses an underscore-prefixed parameter name, suggesting a copy-paste error or an unresolved overload conflict.
- Duplicate method signatures with identical names and parameter types exist on the same type. The second signature uses underscore-prefixed parameter names, indicating a likely copy-paste error.
- Duplicated block (10 lines × 2) (crates/smolvm-agent/src/main.rs)
- Duplicated block (10 lines × 2) (src/api/handlers/files.rs)
- Duplicated block (11 lines × 2) (crates/smolvm-pack/src/extract.rs)
- …and 178 more
Changes since last survey
- 178 commits — 169 feature/other, 9 fixes
By area
- (root) — 23 commits
- src/agent — 22 commits
- src/cli — 21 commits
- src/api — 20 commits
- crates/smolvm-pack — 15 commits
- src/checkpoint_store.rs — 10 commits
- nix/smolvm.nix — 9 commits
- lib/linux-aarch64 — 8 commits
- crates/smolvm-agent — 7 commits
- src/process.rs — 7 commits
- crates/smolvm-network — 5 commits
- crates/smolvm-checkpoint — 4 commits
- crates/smolvm-registry — 4 commits
- src/embedded — 3 commits
- src/portable_checkpoint.rs — 3 commits
- crates/smolvm-credentials — 2 commits
- src/db.rs — 2 commits
- .github/workflows — 1 commit
- crates/smolvm-cuda-shim — 1 commit
- crates/smolvm-cudart-shim — 1 commit
Notable commits
- fix: Bump libkrun for the restored-inode, vsock restore, kqueue and fork generation fixes (#1399)
- fix: Bump libkrun to live resource resizing and restored-branch pause fixes (#1450)
- fix: Bump libkrun to the macOS branch pause fix (#1460)
- fix: Fix exports from stopped branches (#1251)
- fix: Fix failures when restoring the same checkpoint concurrently (#1272)
- fix: Fix interactive stdin buffer bug on unix (#1314)
- fix: Fix packed disk attachment and status broken-pipe VM shutdown (#1369)
- fix: Size the pack extraction cache from the disk instead of a fixed 5 GiB (#1249)
- fix: fix: propagate machine exec database lookup errors (#1331)
- change: Accept published-port connections without periodic polling (#1274)
- change: Add --guest-subnet so a guest running Tailscale or another CGNAT VPN keeps its gateway and DNS (#1362)
- change: Add opt-in exact and wildcard egress host patterns (#1438)
- change: Allow configuring branch-continue policy via SMOLVM_BRANCH_CONTINUE (#1376)
- change: Allow releases after the version bump has merged (#1281)
- change: Allow renameat on arm64 so a guest file rename does not kill the VM under seccomp enforce (#1381)
- change: Allow retrying machines after failed image pulls (#1250)
- change: Allow the path-following getxattr and setxattr so a systemd guest is not killed by seccomp (#1357)
- change: Allow writev in the VMM seccomp filter so the credential interceptor is not killed (#1371)
- change: Attach host disks to a machine with --disk (#1326)
- change: Avoid recopying retained checkpoint disks on every restore (#1283)
- …and 158 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
smol-machines/smolvm was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 29 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 209e0b4bb8c7a7b861bf653deba9679eefffd6cc — the exact code this score is about.
- Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-5ff527f25b99.