Skip to content

Releases: hyperlight-dev/hyperlight

Latest prerelease from main branch

Pre-release

Choose a tag to compare

@github-actions github-actions released this 09 Oct 17:15
dcb53c0

What's Changed

Added

  • Namespaced application metadata on immutable snapshots.
  • Guest paging operations and AArch64 system-register macros in hyperlight-guest.
  • Per-direction virtqueue configuration through SandboxConfiguration and
    SandboxBuilder, with allocations included in scratch sizing.
  • Shared virtqueue framing with a 12-byte MsgHeader and external byte values.
  • ExternalValueSource implementations for RecvChain and Segments.
  • Producer batch completion without notification and segmented payload
    assembly and extraction without flattening.

Changed

  • Sandbox is the primary initialized sandbox type. MultiUseSandbox remains
    as a deprecated alias.
  • Sandbox lives in the private sandbox::initialized module and is reached
    through hyperlight_host::Sandbox or hyperlight_host::sandbox::Sandbox.
    sandbox::initialized_multi_use remains as a deprecated public path.
  • C guests may omit c_guest_dispatch_function when they do not need custom
    fallback dispatch.
  • Support overriding the guest log level when building or restoring initialized
    snapshots.
  • Expose C guest ByteChunks values as pointer and length arrays.
  • Return typed hl_ReturnValue objects from C guest functions through
    hl_result_from_* constructors.
  • Guest tracing skips its per-call and per-callsite work while the guest log
    level is OFF. hyperlight_guest_tracing::is_trace_enabled reports whether
    the configured level is above OFF rather than whether the tracing state was
    allocated.
  • Breaking: Virtqueue rings and pools occupy host-owned scratch before page
    tables. Snapshots use ABI 5 and config schema v3. Existing snapshots must be
    regenerated.
  • Host virtqueue access uses checked copies and atomics across mapped scratch.
    Snapshot admission checks geometry, canonical rings, and distinct, aligned
    H2G pool slots.
    Consumers validate descriptors and payload accesses during use.
  • Virtqueue producers use concrete SlotPool allocation and BufferLease
    ownership. BufferMap supplies complete owners exposing initialized bytes.
  • VirtqProducer::reset and GuestContext::prepare_snapshot are unsafe.
    Peers must stay stopped with no live consumer-side chain handles until
    their consumers are reset or replaced.
  • ChainBuilder::build() allocates readable and writable requests.
    writable_avail() reserves available upper-tier slots within the descriptor
    budget. It may add zero slots to a nonempty chain.
  • Require guest logs and all host and guest function calls to use virtqueues.
  • Keep registered Rust guest return values typed until transport encoding so
    external byte results avoid intermediate FlatBuffer copies.
  • Store canonical virtqueue rings in versioned OCI transport layers. Config v3
    rejects snapshots without transport state.
  • Running snapshots checkpoint dirty virtqueues before capture. Ordinary calls
    keep their deferred result path.
  • Reject snapshot capture while guest-owned transport buffers are retained.
  • Use the reclaimed stack pages to raise the default G2H and H2G pools to 12
    and 8 pages.
  • hyperlight_guest_bin::exception::arch, previously available on
    amd64 only, has been deprecated in favour of new
    architecture-independent exception handling hooks. The new
    interfaces are significantly more liminited, but more portable; they
    will be extended in the future.
  • MSHV: vCPU creation reads the partition's XSAVE format once. This removes
    one hypercall from every restore.

Removed

  • RunPool and the run-specific AllocError::InvalidAlign variant.
  • Remove legacy stack I/O, its GuestHandle methods, and its sandbox
    configuration and builder options.
  • Embedded byte payload tables and their value-union variants.

Fixed

  • AMD64 exception handlers clear the direction flag before calling Rust.
  • Linear-time segment consumption for fragmented virtqueue messages.
  • Allow reclaimed virtqueue completions to span multiple ring reuse cycles.
  • Virtqueue consumers return errors when payload copies or runtime bookkeeping
    cannot be allocated.
  • Use a 16 KiB-aligned default scratch size for Apple Silicon compatibility.
  • Guest virtqueue copies reject overlapping buffers before accessing memory.
  • Keep sandboxes usable after an H2G request exceeds available virtqueue capacity.
  • Snapshot checkpoints ignore idle cancellation and clear partial abort state.
  • Keep sandboxes usable when G2H calls exhaust reply capacity.
  • Reject incompatible transport snapshots before changing sandbox state.
  • Allow guest host-return conversions to call or log to the host.

Full Changelog (excl. dependencies)

Read more

Release v0.17.0

Choose a tag to compare

@github-actions github-actions released this 28 Aug 19:12
388ea8e

What's Changed

Added

  • macOS/Apple Silicon support using Hypervisor.framework (single-address-space backend) by @syntactically in #1674
  • SandboxBuilder, the entry point for creating a sandbox. It gathers machine configuration, host functions, init data and memory mappings, then builds a MultiUseSandbox from a guest binary on disk, a guest binary in memory, or a snapshot by @jprendes in #1725
  • MultiUseSandbox::status(), which returns SandboxStatus for inspecting sandbox lifecycle state (poisoned, unrecoverable) by @ludfjig in #1727
  • Support WIT source inputs directly in host_bindgen! / guest_bindgen! component bindgen macros by @andreiltd in #1589

Changed

  • Breaking: Guest MSR state is now saved and restored across snapshots. SandboxConfiguration::guest_msrs declares the MSRs a guest depends on: declared MSRs are captured in a snapshot and restored, while every other MSR resets to a clean default. On KVM the guest may only read or write declared MSRs, on MSHV and WHP this is not enforced by @ludfjig in #991
  • Breaking: Filesystem paths are now represented using PathBuf. GuestBinary::FilePath now stores a PathBuf instead of a String, and MultiUseSandbox::generate_crashdump_to_dir accepts Into<PathBuf> instead of Into<String>. Callers passing a String to GuestBinary::FilePath must convert it using .into() by @midsterx in #1652
  • Breaking: GuestBinary::Buffer owns its bytes as a Vec<u8>, so GuestBinary no longer borrows and carries no lifetime parameter by @jprendes in #1760
  • Deprecate MultiUseSandbox::poisoned in favor of MultiUseSandbox::status().is_poisoned() by @ludfjig in #1727
  • MultiUseSandbox::restore has been made more flexible and now accepts snapshots from any guest binary or memory layout when host functions are compatible by @ludfjig in #1728
  • Certain fixed guest addresses were changed on AArch64 to more easily accommodate 16k pages without wasting memory. Snapshots taken from sandboxes using the old addresses will not be loadable by new hyperlight versions by @syntactically in #1674
  • Improvements to component bindgen: expose fallibility of host API calls, properly track positivity/negativity, disambiguate chains of associated types, support reading WAT text components by @syntactically in #1724, #1723, #1721, and #1732

Removed

Fixed

  • Improved snapshot/OCI validation, rejecting malformed metadata and non-regular artifact files during load by @ludfjig in #1668
  • Fix RSS peak on Windows by replacing scratch zeroing with a fresh allocation on restore by @danbugs in #1765
  • Mark a sandbox unrecoverable in rare cases when snapshot restore fails while updating its VM mappings by @ludfjig in #1727
  • Fix symbol resolution in guest core dumps for sandboxes created from snapshots by @ludfjig in #1618
  • Fix dynamic mapping ownership on unmap failure by @ludfjig in #1675
  • Reset XCR0 during x86 snapshot restore by @ludfjig in #1718
  • Reseed guest libc rand() and random() after restoring a snapshot to avoid multiple sandboxes sharing PRNG state by @ludfjig in #1667
  • Validate ELF program headers in ElfInfo::new() to prevent host process abort from malformed guest binaries. PT_LOAD segments are now bounds-checked, base_va/va_size are stored as fields, and load_at() uses fully checked arithmetic by @danbugs

Full Changelog (excl. dependencies)

Full Changelog (dependencies)

  • chore(deps): bump actions/cache from 5.0.5 to 6.1.0 by @dependabot[bot] in #1598
  • chore(deps): bump actions-rust-lang/setup-rust-toolchain from 1.16.1 to 1.17.0 by @dependabot[bot] in #1582
  • chore(deps): bump addr2line from 0.2...
Read more

Release v0.16.0

Choose a tag to compare

@github-actions github-actions released this 26 Jun 23:11
6a044d2

What's Changed

Added

  • Initial aarch64/KVM guest and host support, including memory layout, virtual memory operations, exception handlers, MMIO exits, register handling, and CI workflows by @syntactically in #1474
  • Snapshot::save, Snapshot::load, and Snapshot::checked_load for persisting and loading sandbox snapshots as OCI Image Layout directories by @ludfjig in #1465. Note that Hyperlight is at version 0.x, so a snapshot taken on one version may not load on another version.
  • Create sandboxes directly from snapshots by @ludfjig in #1459
  • Cross-sandbox snapshot restore (snapshots are no longer tied to the sandbox that created them) by @ludfjig in #1499
  • Support for WHP no-surrogate mode via HYPERLIGHT_MAX_SURROGATES=0 by @danbugs in #1578
  • Wasmtime flags! macro support for WIT flags types by @jsturtevant in #1327

Changed

  • Breaking: MultiUseSandbox::map_file_cow and UninitializedSandbox::map_file_cow no longer take a label argument. The APIs now accept only (file_path, guest_base) by @simongdavies in #1525.
  • Updated Rust toolchain to 1.94 by @simongdavies in #1527
  • Updated surrogate process to no_std, reducing overhead of loading unnecessary libraries by @simongdavies in #1533
  • Replaced tracing-log with native tracing macros for guest log forwarding by @cshung in #1500
  • MSHV: use VP register page for RIP/RAX writes in run_vcpu for improved performance by @ludfjig in #1366
  • MSHV: skip RIP advance on VmAction::Halt fast path by @ludfjig in #1476
  • Faster memcpy/memset implementations by @ludfjig in #1473

Removed

  • Removed the experimental i686-guest, nanvix-unstable, and guest-counter feature flags, along with 32-bit (i686) guest support and its page-table/snapshot code paths. Hyperlight guests are now 64-bit only (x86_64 and aarch64) by @simongdavies in #1525.

Fixed

Full Changelog (excl. dependencies)

Full Changelog (dependencies)

Read more

Release v0.15.0

Choose a tag to compare

@github-actions github-actions released this 07 May 15:01
9749e04

What's Changed

Added

  • #[main] and #[dispatch] macros for type-safe guest entry points by @jprendes in #1384
  • Implement Registerable for MultiUseSandbox by @danbugs in #1392
  • Guest compilation support for aarch64 by @ludfjig in #1297
  • i686 page tables, snapshot compaction, and copy-on-write support by @danbugs and @ludfjig in #1385

Changed

  • Breaking: Replace musl with picolibc as C standard library for guests by @andreiltd in #831
  • Replace nanvix-unstable feature flag with i686-guest and guest-counter features by @danbugs and @ludfjig in #1385

Fixed

Full Changelog (excl. dependencies)

  • feat: enable guest compilation for aarch64 by @ludfjig in #1297
  • feat(clippy): add disallowed macros for asserts in clippy.toml by @simongdavies in #1376
  • fix(whp): use NULL DACL for map_file_cow file mapping sections by @danbugs in #1386
  • Re-export guest types and error utilities from hyperlight_guest_bin by @jprendes in #1383
  • fix(whp): respect IO port access size in IoPortAccess exit handler by @danbugs in #1387
  • fix(whp): handle unaligned files in map_file_cow by @danbugs in #1388
  • feat: Add #[main] and #[dispatch] macros for type-safe guest entry points by @jprendes in #1384
  • feat(host): implement Registerable for MultiUseSandbox by @danbugs in #1392
  • don't let scratch region overlap with kvm apic page by @ludfjig in #1393
  • feat(guest): replace musl with picolibc by @andreiltd in #831
  • Remove disallowed-macros lint by @simongdavies in #1397
  • feat: i686 page tables, snapshot compaction, and CoW (standalone) by @danbugs in #1385
  • fix(ci): pin cargo-hyperlight version by @andreiltd in #1413
  • Use static picolibc.h file instead of generating it at buildtime by @jprendes in #1407
  • fix(ci): force install cargo-hyperlight by @andreiltd in #1420
  • Fix picolibc submodule commit by @ludfjig in #1427
  • Fix flaky gdb tests by detaching from inside the bp commands by @ludfjig in #1435
  • Move libc from hyperlight-guest-bin to hyperlight-libc by @jprendes in #1437
  • Add hyperlight-libc to CI publishing by @jprendes in #1439
  • Bump crates to 0.15.0 and CHANGELOG entries by @jprendes in #1440
  • Fix C headers archive for picolibc by @jprendes in #1438
  • Use latest cargo-hyperlight in release workflow by @jprendes in #1441
  • Checkout picolibc submodule before building includes.tar.gz by @jprendes in #1443
  • Checkout picolibc submodule before publishing crates by @jprendes in #1444

Full Changelog (dependencies)

Full Changelog: v0.14.0...v0.15.0

Release v0.14.0

Choose a tag to compare

@github-actions github-actions released this 01 Apr 23:05
1a90040

What's Changed

Changed

Fixed

  • Windows surrogate process manager now uses SHA-stamped filenames to avoid conflicts when multiple Hyperlight versions coexist, and surrogate pool size is configurable via HYPERLIGHT_INITIAL_SURROGATES and HYPERLIGHT_MAX_SURROGATES environment variables by @simongdavies in #1339
  • Fix a race where guest cancellation could cause a pending TLB flush to be lost by @ludfjig in #1333
  • Fix spurious GuestAborted errors after repeated cancel+restore cycles by @ludfjig in #1335

Full Changelog (excl. dependencies)

Full Changelog (dependencies)

Full Changelog: v0.13.1...v0.14.0

Release v0.13.1

Choose a tag to compare

@github-actions github-actions released this 19 Mar 20:44
cb17894

What's Changed

Fixed

  • Explicitly error out on host-guest version mismatch by @ludfjig in #1252

Added

Full Changelog (excl. dependencies)

Full Changelog (dependencies)

Full Changelog: v0.13.0...v0.13.1

Release v0.13.0

Choose a tag to compare

@github-actions github-actions released this 06 Mar 17:30
e930c91

What's Changed

Fixed

  • fix(windows): prevent WHvDeletePartition race by @ludfjig in #1101
  • Fix guest tracing filter by @dblnz in #977
  • Add crashdump example and include snapshot/scratch in core dumps by @jsturtevant in #1264

Changed

Added

Removed

Full Changelog (excl. dependencies)

Full Changelog (dependencies)

Read more

Release v0.12.0

Choose a tag to compare

@github-actions github-actions released this 09 Dec 19:19
3be7ad9

What's Changed

Fixed

  • Fix guest tracing deadlock when exception happens during tracing data serialization by @dblnz in #1066
  • Fix StackOverflow produced by guest logging by @dblnz in #1067
  • Fix guest call to halt not dropping allocated trace data leading to memory leak by @dblnz in #1072
  • Update the interrupt handler for 16byte alignment by @jsturtevant in #1037

Added

  • Guest function improvements and macros by @jprendes in #851
  • Add metric for erroneous vCPU kicks from stale cancellations by @Copilot in #1034

Removed

  • Remove outdated is_supported_platform (use is_hypervisor_present instead) and unused ExtraAllowedSyscall by @ludfjig in #1062

Full Changelog (excl. dependencies)

Full Changelog (dependencies)

Full Changelog: v0.11.0...v0.12.0

Release v0.11.0

Choose a tag to compare

@github-actions github-actions released this 04 Nov 23:10
d5aea38

What's Changed

Fixed

Changed

  • Unify register representation across hypervisors by @ludfjig in #907
  • Guest tracing improvements to use tracing crate by @dblnz in #844
  • Serialize guest trace data using flatbuffers by @dblnz in #999

Added

Removed

Full Changelog (excl. dependencies)

  • Restructure guest/host error handling by @ludfjig in #868
  • Fix join github actions job by @ludfjig in #944
  • Adding FFI functions for Hyperlight Guest CAPI by @vshailesh in #950
  • Fix unused import error in nightly musl clippy exhaustive check by @Copilot in #948
  • Unify register representation across hypervisors by @ludfjig in #907
  • Add support for mmapped memory in crashdumps and guest debugging by @dblnz in #943
  • Guest tracing improvements to use tracing crate by @dblnz in #844
  • Remove seccomp by @dblnz in #971
  • Crashdump on demand by @simongdavies in #972
  • Add poison state to sandbox by @ludfjig in #931
  • Fixes a race condition in killing Sandboxes by @simongdavies in #959
  • Revert temporary fuzz fix by @ludfjig in #1000
  • Allow windows more time to enter guest func for interrupt benchmark by @ludfjig in #1004
  • Serialize guest trace data using flatbuffers by @dblnz in #999

Full Changelog (dependencies)

Full Changelog: v0.10.0...v0.11.0

Release v0.9.1

Choose a tag to compare

@github-actions github-actions released this 29 Oct 13:53
418b3c6

What's Changed

Fixed

Changed

Full Changelog (excl. dependencies)

Full Changelog: v0.9.0...v0.9.1