The format is based on Keep a Changelog.
Prerelease - Unreleased
- Namespaced application metadata on immutable snapshots.
- Per-direction virtqueue configuration through
SandboxConfigurationandSandboxBuilder, with allocations included in scratch sizing. - Shared virtqueue framing with a 12-byte
MsgHeaderand external byte values. ExternalValueSourceimplementations forRecvChainandSegments.- Producer batch completion without notification and segmented payload assembly and extraction without flattening.
Sandboxis the primary initialized sandbox type.MultiUseSandboxremains as a deprecated alias.Sandboxlives in the privatesandbox::initializedmodule and is reached throughhyperlight_host::Sandboxorhyperlight_host::sandbox::Sandbox.sandbox::initialized_multi_useremains as a deprecated public path.- C guests may omit
c_guest_dispatch_functionwhen they do not need custom fallback dispatch. - Support overriding the guest log level when building or restoring initialized snapshots.
Snapshot::savenow writes the guest memory blob sparsely, skipping all-zero blocks instead of writing them. A guest memory image is mostly untouched pages, so this cuts the bytes actually written by roughly the proportion of the guest's memory it never touched. The saved layout is byte-for-byte identical and its digest is unchanged, so this is transparent to readers and to previously saved snapshots. Filesystems that do not support sparse files store the blob as before.- Expose C guest
ByteChunksvalues as pointer and length arrays. - Return typed
hl_ReturnValueobjects from C guest functions throughhl_result_from_*constructors. - Guest tracing skips its per-call and per-callsite work while the guest log
level is
OFF.hyperlight_guest_tracing::is_trace_enabledreports whether the configured level is aboveOFFrather than whether the tracing state was allocated. - Breaking: Virtqueue rings and pools occupy host-owned scratch before page tables. Snapshots use ABI 5 and config schema v3. Existing snapshots must be regenerated.
- Host virtqueue access uses checked copies and atomics across mapped scratch. Snapshot admission checks geometry, canonical rings, and distinct, aligned H2G pool slots. Consumers validate descriptors and payload accesses during use.
- Virtqueue producers use concrete
SlotPoolallocation andBufferLeaseownership.BufferMapsupplies complete owners exposing initialized bytes. VirtqProducer::resetandGuestContext::prepare_snapshotare unsafe. Peers must stay stopped with no live consumer-side chain handles until their consumers are reset or replaced.ChainBuilder::build()allocates readable and writable requests.writable_avail()reserves available upper-tier slots within the descriptor budget. It may add zero slots to a nonempty chain.- Require guest logs and all host and guest function calls to use virtqueues.
- Keep registered Rust guest return values typed until transport encoding so external byte results avoid intermediate FlatBuffer copies.
- Store canonical virtqueue rings in versioned OCI transport layers. Config v3 rejects snapshots without transport state.
- Running snapshots checkpoint dirty virtqueues before capture. Ordinary calls keep their deferred result path.
- Reject snapshot capture while guest-owned transport buffers are retained.
- Use the reclaimed stack pages to raise the default G2H and H2G pools to 12 and 8 pages.
RunPooland the run-specificAllocError::InvalidAlignvariant.- Remove legacy stack I/O, its
GuestHandlemethods, and its sandbox configuration and builder options. - Embedded byte payload tables and their value-union variants.
- AMD64 exception handlers clear the direction flag before calling Rust.
- Linear-time segment consumption for fragmented virtqueue messages.
- Allow reclaimed virtqueue completions to span multiple ring reuse cycles.
- Virtqueue consumers return errors when payload copies or runtime bookkeeping cannot be allocated.
- Use a 16 KiB-aligned default scratch size for Apple Silicon compatibility.
- Guest virtqueue copies reject overlapping buffers before accessing memory.
- Keep sandboxes usable after an H2G request exceeds available virtqueue capacity.
- Snapshot checkpoints ignore idle cancellation and clear partial abort state.
- Keep sandboxes usable when G2H calls exhaust reply capacity.
- Reject incompatible transport snapshots before changing sandbox state.
- Allow guest host-return conversions to call or log to the host.
v0.17.0 - 2026-08-27
- macOS/Apple Silicon support using Hypervisor.framework (single-address-space backend) by @syntactically in #1674
SandboxBuilder, the entry point for creating a sandbox. It gathers machine configuration, host functions, init data and memory mappings, then builds aMultiUseSandboxfrom a guest binary on disk, a guest binary in memory, or a snapshot by @jprendes in #1725MultiUseSandbox::status(), which returnsSandboxStatusfor inspecting sandbox lifecycle state (poisoned, unrecoverable) by @ludfjig in #1727- Support WIT source inputs directly in
host_bindgen!/guest_bindgen!component bindgen macros by @andreiltd in #1589
- Breaking: Guest MSR state is now saved and restored across snapshots.
SandboxConfiguration::guest_msrsdeclares the MSRs a guest depends on: declared MSRs are captured in a snapshot and restored, while every other MSR resets to a clean default. On KVM the guest may only read or write declared MSRs, on MSHV and WHP this is not enforced by @ludfjig in #991 - Breaking: Filesystem paths are now represented using
PathBuf.GuestBinary::FilePathnow stores aPathBufinstead of aString, andMultiUseSandbox::generate_crashdump_to_diracceptsInto<PathBuf>instead ofInto<String>. Callers passing aStringtoGuestBinary::FilePathmust convert it using.into()by @midsterx in #1652 - Breaking:
GuestBinary::Bufferowns its bytes as aVec<u8>, soGuestBinaryno longer borrows and carries no lifetime parameter by @jprendes in #1760 - Deprecate
MultiUseSandbox::poisonedin favor ofMultiUseSandbox::status().is_poisoned()by @ludfjig in #1727 MultiUseSandbox::restorehas been made more flexible and now accepts snapshots from any guest binary or memory layout when host functions are compatible by @ludfjig in #1728- Certain fixed guest addresses were changed on AArch64 to more easily accommodate 16k pages without wasting memory. Snapshots taken from sandboxes using the old addresses will not be loadable by new hyperlight versions by @syntactically in #1674
- Improvements to component bindgen: expose fallibility of host API calls, properly track positivity/negativity, disambiguate chains of associated types, support reading WAT text components by @syntactically in #1724, #1723, #1721, and #1732
- Improved snapshot/OCI validation, rejecting malformed metadata and non-regular artifact files during load by @ludfjig in #1668
- Fix RSS peak on Windows by replacing scratch zeroing with a fresh allocation on restore by @danbugs in #1765
- Mark a sandbox unrecoverable in rare cases when snapshot restore fails while updating its VM mappings by @ludfjig in #1727
- Fix symbol resolution in guest core dumps for sandboxes created from snapshots by @ludfjig in #1618
- Fix dynamic mapping ownership on unmap failure by @ludfjig in #1675
- Reset XCR0 during x86 snapshot restore by @ludfjig in #1718
- Reseed guest libc
rand()andrandom()after restoring a snapshot to avoid multiple sandboxes sharing PRNG state by @ludfjig in #1667 - Validate ELF program headers in
ElfInfo::new()to prevent host process abort from malformed guest binaries. PT_LOAD segments are now bounds-checked,base_va/va_sizeare stored as fields, andload_at()uses fully checked arithmetic by @danbugs MultiUseSandbox::from_snapshotnow honours the guest log level set viaSandboxConfiguration::set_max_guest_log_levelinstead of ignoring it and falling back toRUST_LOGby @sethryanrollins in #1699
v0.16.0 - 2026-06-26
- Initial aarch64/KVM guest and host support, including memory layout, virtual memory operations, exception handlers, MMIO exits, register handling, and CI workflows by @syntactically in #1474
Snapshot::save,Snapshot::load, andSnapshot::checked_loadfor persisting and loading sandbox snapshots as OCI Image Layout directories by @ludfjig in #1465. Note that Hyperlight is at version 0.x, so a snapshot taken on one version may not load on another version.- Create sandboxes directly from snapshots by @ludfjig in #1459
- Cross-sandbox snapshot restore (snapshots are no longer tied to the sandbox that created them) by @ludfjig in #1499
- Support for WHP no-surrogate mode via
HYPERLIGHT_MAX_SURROGATES=0by @danbugs in #1578 - Wasmtime
flags!macro support for WIT flags types by @jsturtevant in #1327
- Breaking:
MultiUseSandbox::map_file_cowandUninitializedSandbox::map_file_cowno longer take a label argument. The APIs now accept only(file_path, guest_base)by @simongdavies in #1525. - Updated Rust toolchain to 1.94 by @simongdavies in #1527
- Updated surrogate process to
no_std, reducing overhead of loading unnecessary libraries by @simongdavies in #1533 - Replaced
tracing-logwith nativetracingmacros for guest log forwarding by @cshung in #1500 - MSHV: use VP register page for RIP/RAX writes in
run_vcpufor improved performance by @ludfjig in #1366 - MSHV: skip RIP advance on
VmAction::Haltfast path by @ludfjig in #1476 - Faster
memcpy/memsetimplementations by @ludfjig in #1473
- Removed the experimental
i686-guest,nanvix-unstable, andguest-counterfeature flags, along with 32-bit (i686) guest support and its page-table/snapshot code paths. Hyperlight guests are now 64-bit only (x86_64 and aarch64) by @simongdavies in #1525.
- Fix colliding WIT import names by @jsturtevant in #1562
- Fix empty namespace paths in component codegen by @jsturtevant in #1331
- Fix
nomemconstraint onout32OUT-trap asm by @ludfjig in #1534 - Validate guest address ranges for overlapping regions in
map_regionby @Richard-Durkee in #1464
v0.15.0 - 2026-05-06
#[main]and#[dispatch]macros for type-safe guest entry points by @jprendes in #1384- Implement
RegisterableforMultiUseSandboxby @danbugs in #1392 - Guest compilation support for aarch64 by @ludfjig in #1297
- i686 page tables, snapshot compaction, and copy-on-write support by @danbugs and @ludfjig in #1385
- Breaking: Replace musl with picolibc as C standard library for guests by @andreiltd in #831
- Replace
nanvix-unstablefeature flag withi686-guestandguest-counterfeatures by @danbugs and @ludfjig in #1385
- Fix flaky gdb tests by detaching from inside the breakpoint commands by @ludfjig in #1435
- Fix scratch memory overlapping APIC on i686 by @ludfjig in #1393
- Several WHP fixes by @danbugs in #1388, #1387, and #1386
v0.14.0 - 2026-04-01
- Snapshot restore now uses copy-on-write, reducing restore latency by up to 99% (see paging notes) by @syntactically in #1315
map_regiononMultiUseSandboxnow works on Windows by @jsturtevant in #1330- Maximum sandbox memory size increased from ~1 GiB to ~16 GiB by @simongdavies in #1340
- Windows surrogate process manager now uses SHA-stamped filenames to avoid conflicts when multiple Hyperlight versions coexist, and surrogate pool size is configurable via
HYPERLIGHT_INITIAL_SURROGATESandHYPERLIGHT_MAX_SURROGATESenvironment variables by @simongdavies in #1339 - Fix a race where guest cancellation could cause a pending TLB flush to be lost by @ludfjig in #1333
- Fix spurious
GuestAbortederrors after repeated cancel+restore cycles by @ludfjig in #1335
v0.13.1 - 2026-03-19
- Explicitly error out on host-guest version mismatch by @ludfjig in #1252
- Hardware interrupt support by @danbugs in #1272
- Copy-on-write file mapping support with labels by @simongdavies in #1320, #1322
- Re-export host functions from the
hyperlight_hostpackage by @jsturtevant in #1314 - Make
map_regionpublic by @jsturtevant in #1293 - Nanvix:
GuestCounterAPI and i686 guest layout behindnanvix-unstablefeature flag by @danbugs in #1270, #1271
v0.13.0 - 2026-03-06
- fix(windows): prevent WHvDeletePartition race by @ludfjig in #1101
- Fix guest tracing filter by @dblnz in #977
- Add crashdump example and include snapshot/scratch in core dumps by @jsturtevant in #1264
- Make mem::exe::LoadInfo a struct, instead of an alias by @simongdavies in #1099
- Update snapshots by @simongdavies in #1098
- Breaking:
GuestFunctionDefinition::newnow takes a typed function pointer instead ofusizeby @ludfjig in #1241
- Enable CoW by @syntactically in #1229
- Remove host function definition regions by @syntactically in #1178
v0.12.0 - 2025-12-09
- Fix guest tracing deadlock when exception happens during tracing data serialization by @dblnz in #1066
- Fix StackOverflow produced by guest logging by @dblnz in #1067
- Fix guest call to
haltnot dropping allocated trace data leading to memory leak by @dblnz in #1072 - Update the interrupt handler for 16byte alignment by @jsturtevant in #1037
- Guest function improvements and macros by @jprendes in #851
- Add metric for erroneous vCPU kicks from stale cancellations by @Copilot in #1034
- Remove outdated
is_supported_platform(useis_hypervisor_presentinstead) and unusedExtraAllowedSyscallby @ludfjig in #1062
v0.11.0 - 2025-11-04
- Fixes a race condition in killing Sandboxes by @simongdavies in #959
- Unify register representation across hypervisors by @ludfjig in #907
- Guest tracing improvements to use
tracingcrate by @dblnz in #844 - Serialize guest trace data using flatbuffers by @dblnz in #999
- Add support for mmapped memory in crashdumps and guest debugging by @dblnz in #943
- Add poison state to sandbox by @ludfjig in #931
- Crashdump on demand by @simongdavies in #972
v0.10.0 - 2025-10-02
- Fix error code conversion for Exception enum TryFrom implementation by @vshailesh in #869
- Remove Allocations from Panic Handler by @adamperlin in #818
- Update rust to 1.89 by @simongdavies in #883
- Update mshv crates for Azure Linux to v0.6.1 (from v0.3.2) by @simongdavies in #891
- Only clear io buffer after unsuccessful guest call by @ludfjig in #811
v0.9.0 - 2025-08-28
- fix release blocker so it only blocks on release branches by @simongdavies in #777
- Enforce release builds for benchmarks and simplify command interface by @Copilot in #741
- fix(guest-bin): align user memory allocations by @andreiltd in #753
- Fix unbounded growth of panic hook after each new sandbox by @ludfjig in #827
- Update the like-ci recipe by @simongdavies in #837
- Fixes to Host Call Fuzzing by @adamperlin in #840
- Optimize function call serializing by @ludfjig in #778
- Make the component macros support passing host resources to guests by @syntactically in #839
- Build c guests as required by benchmarks by @ludfjig in #822
- Remove DbgMemAccessHandlerCaller trait and DbgMemAccessHandlerWrapper abstractions by @Copilot in #824
v0.8.0 - 2025-08-08
hyperlight_component_macro::host_bindgen and hyperlight_component_macro::guest_bindgen used the Callable trait which no longer restores state after each function call and requires an explicit Snapshot Restore using the newly exposed Snapshot API. See #697 and #761
- gdb: fix issue "Debug not enabled" when
gdbfeature was enabled by @dblnz in #678 - Fix Windows build with
--no-default-featuresby @danbugs in #712 - fix(guest-bin): move logger initialization by @andreiltd in #755
- Fix mem mgr not initialized by @dblnz in #745
- Remove some dev-dependencies and cargo features to speed up compilation by @ludfjig in #535
- Introduce a separate KVM error variant of HyperlightError. by @ludfjig in https://github.com/hyperlight-dev/hyperlight/pull/771API. by @jprendes in #697
- Evolving and Devolving apis replaced by Snapshot API
- Memory Mapping Support
- Support mapping host memory into the guest by @syntactically in #696
- Make MultiUseSandbox::map_file_cow public by @ludfjig in #725
- Add memory mapping support with KVM by @jprendes in #709
- Make sure mmapped memory is not mapped writable into sandbox in kvm by @ludfjig in #740
- Make snapshots region aware by @ludfjig in #742
- Restrict restoring sandboxes to snapshot taken on self by @ludfjig in #746
- Enable guest tracing by @dblnz in #695
- Removed the OutBHandler and MemAccessHandler abstractions and related implementations. by @simongdavies in #732
v0.7.0 - 2025-06-26
- gdb: fix sandbox function cancellation when gdb enabled by @dblnz in #621
- Let windows decide at which address to map shared memory in surrogate process by @ludfjig in #637
- Don't log expected error on each guest function call by @ludfjig in #662
- Adds a missing clippy allow by @jsturtevant in #663
- improve the performance of building page tables by @simongdavies in #635
- Make interrupt retry delay methods Linux-only by @copilot-swe-agent in #647
- Support ELF core dump creation on guest crash by @dblnz in #417
- Added capability to load extra blob data in sandbox by @danbugs in #605
- Add license scan report and status by @fossabot in #598
- Create GOVERNANCE.md by @benazirk in #556
- [host] adds init-paging feature by @danbugs in #639
- Enable guest debugging for HyperV on windows by @dblnz in #478
- Remove support for building PE files from hyperlight-guest-bin build.rs by @simongdavies in #572
v0.6.1 - 2025-06-12
- Make OS_PAGE_SIZE public again by @jprendes in #609
- Bring back HostFunctionDefinitions Region by @danbugs in #600
- Allow hyperlight-host to build with x86_64-unknown-linux-musl target by @simongdavies in #601
v0.6.0 - 2025-06-06
- Prevent openat from trapping on seccomp thread, by making it return EACCES instead by @ludfjig in #573
- Remove hypervisor_handler thread by @ludfjig in #533
- Make GuestBinary::Buffer variant take slice instead of owned vec by @ludfjig in #559
- Add component bindgen macros by @syntactically in #376
- Adding ws2025 to the dep_rest matrix by @marosset in #551
v0.5.1 - 2025-06-02
- Fixed an issue with the
hyperlight_hostnot building on v0.5.0
v0.5.0 - 2025-05-28
- Change base address from 0x200_000 to 0x0 by @danbugs in #450
- Unify HostFunctionXX traits into a single HostFunction by @jprendes in https://github.com/hyperlight-dev/hyperlight/pull/
- Improve the ergonomics of registering host functions by @jprendes in #468
- Remove generics from SupportedParameterType and SupportedReturnType traits by @jprendes in #475
- Improve ergonomics of SupportedParameterType and SupportedReturnType by @jprendes in #476
- Add error logging when MapViewOfFileNuma2 fails by @ludfjig in #460
- Make common and guest libs portable by @danbugs in #524
- Fix breaking changes for hyperlight js by @simongdavies in #531
- Gdb debug improvements by @dblnz in #456
- Remove kernel stack and boot stack memory regions by @danbugs in #451
- Removing HostFunctionDefinitions region by @danbugs in #453
- Removed host error region by @danbugs in #457
- Remove dependency on the paste crate by @jprendes in #467
- Remove support from hyperlight_host for PE formatted guests by @simongdavies in #485
- Remove in process mode from hyperlight-host by @simongdavies in #490
- Remove
host_print_writerfrom the arguments toUninitializedSandbox::newby @jprendes in #487
v0.4.0 - 2025-04-30
- Fixed race condition causing thread to incorrectly believe it finished executing by @ludfjig in #385
- Fixed incorrect logging levels in guest by @simongdavies in #410
- Fixed missing compiler flags for building c guests by @prydt in #421
v0.3.0 - 2025-03-27
- Gdb support for mshv guests #327 by @dblnz in #327
- Add fuzzing targets for fuzzing guest and host call parameters and return value by @ludfjig in #259
- Make host-guest result API generic by @ludfjig in #259
- Fixed devcontainer permission issues by @myadav in #326
v0.2.0 - 2025-02-25
- Adds support for Azure Linux 3 by @simongdavies in #51
- Add GDB support by @dblnz in #111
- Document DCO by @devigned in #22
- Run CI on intel machines by @danbugs in #32
- Run spell checks on repo by @andreiltd in #58
- Add devcontainer config by @dblnz in #54
- Add exception handling to Hyperlight guest by @danbugs in #250
- Add community meeting info to our README.md by @marosset in #231
- Avoid eagerly doing unnecessary string formatting by @ludfjig in #73
- Use
CreateFileMapping\MapViewOfFileandUnmapViewOfFile\CloseHandleinstead ofVirtualAllocExandVirtualFreeExon Windows by @simongdavies in #135 - Avoid requiring specific environment variables during testing by @ludfjig in #108
- Fix issues with using
CreateMapViewOfFilewithinprocessfeature by @simongdavies in #2340 - Reset guest memory when guest function fails by @ludfjig in #208
- Improve error when guest binary not found by @ludfjig in #55
- Ensure windows version is supported by @simongdavies in #110
v0.1.0 - 2024-11-24
The Initial Hyperlight Release 🎉