What's Changed
Added
- Per-direction virtqueue configuration through
SandboxConfigurationand
SandboxBuilder, with allocations included in scratch sizing. - Shared virtqueue framing with a 12-byte
MsgHeaderand external byte values. ExternalValueSourceimplementations forRecvChainandSegments.- Producer batch completion without notification and segmented payload
assembly and extraction without flattening.
Changed
- Support overriding the guest log level when building or restoring initialized
snapshots. Snapshot::savenow writes the guest memory blob sparsely, skipping all-zero
blocks instead of writing them. A guest memory image is mostly untouched
pages, so this cuts the bytes actually written by roughly the proportion of
the guest's memory it never touched. The saved layout is byte-for-byte
identical and its digest is unchanged, so this is transparent to readers and
to previously saved snapshots. Filesystems that do not support sparse files
store the blob as before.- Expose C guest
ByteChunksvalues as pointer and length arrays. - Return typed
hl_ReturnValueobjects from C guest functions through
hl_result_from_*constructors. - Guest tracing skips its per-call and per-callsite work while the guest log
level isOFF.hyperlight_guest_tracing::is_trace_enabledreports whether
the configured level is aboveOFFrather than whether the tracing state was
allocated. - Breaking: Virtqueue rings and pools occupy host-owned scratch before page
tables. Snapshots use ABI 5 and config schema v3. Existing snapshots must be
regenerated. - Host virtqueue access uses checked copies and atomics across mapped scratch.
Snapshot admission checks geometry, canonical rings, and distinct, aligned
H2G pool slots.
Consumers validate descriptors and payload accesses during use. - Virtqueue producers use concrete
SlotPoolallocation andBufferLease
ownership.BufferMapsupplies complete owners exposing initialized bytes. VirtqProducer::resetandGuestContext::prepare_snapshotare unsafe.
Peers must stay stopped with no live consumer-side chain handles until
their consumers are reset or replaced.ChainBuilder::build()allocates readable and writable requests.
writable_avail()reserves available upper-tier slots within the descriptor
budget. It may add zero slots to a nonempty chain.- Require guest logs and all host and guest function calls to use virtqueues.
- Keep registered Rust guest return values typed until transport encoding so
external byte results avoid intermediate FlatBuffer copies. - Store canonical virtqueue rings in versioned OCI transport layers. Config v3
rejects snapshots without transport state. - Running snapshots checkpoint dirty virtqueues before capture. Ordinary calls
keep their deferred result path. - Reject snapshot capture while guest-owned transport buffers are retained.
- Use the reclaimed stack pages to raise the default G2H and H2G pools to 12
and 8 pages.
Removed
RunPooland the run-specificAllocError::InvalidAlignvariant.- Remove legacy stack I/O, its
GuestHandlemethods, and its sandbox
configuration and builder options. - Embedded byte payload tables and their value-union variants.
Fixed
- Linear-time segment consumption for fragmented virtqueue messages.
- Allow reclaimed virtqueue completions to span multiple ring reuse cycles.
- Virtqueue consumers return errors when payload copies or runtime bookkeeping
cannot be allocated. - Use a 16 KiB-aligned default scratch size for Apple Silicon compatibility.
- Guest virtqueue copies reject overlapping buffers before accessing memory.
- Keep sandboxes usable after an H2G request exceeds available virtqueue capacity.
- Snapshot checkpoints ignore idle cancellation and clear partial abort state.
- Keep sandboxes usable when G2H calls exhaust reply capacity.
- Reject incompatible transport snapshots before changing sandbox state.
- Allow guest host-return conversions to call or log to the host.
Full Changelog (excl. dependencies)
- Fix crates.io publish detection by @jsturtevant in #1781
- Update community meetings to Monday's by @jsturtevant in #1779
- perf(snapshot): write the guest memory blob sparsely by @jprendes in #1788
- docs: add external byte stream proposal by @andreiltd in #1791
- docs: add HIP 0001 ring buffer proposal for Hyperlight I/O by @andreiltd in #1112
- docs: clarify host function access control in security.md by @JM00NJ in #1799
- feat: add external byte codecs by @andreiltd in #1792
- Fix ARM workflow runner routing by @simongdavies in #1814
- plumb
max_guest_log_levelthroughMultiUseSandbox::from_snapshotby @sethryanrollins in #1699 - Fix unused sandbox test import on ARM64 by @simongdavies in #1812
- Fix metrics test cancellation race by @simongdavies in #1816
- fix: use checked arithmetic in push_buffer (defense in depth) by @JM00NJ in #1820
- ci: add fuzz_push_pop_buffer to the CI fuzzing workflow by @JM00NJ in #1822
- feat: support guest log level overrides for initialized snapshots by @jprendes in #1833
- perf: skip guest tracing work while the log level is off by @jprendes in #1840
- fix: use try_into instead of as u64 cast in push_buffer by @JM00NJ in #1825
- feat: add virtqueue transport foundations by @andreiltd in #1793
- fix: adjust scratch size for benchmarks by @andreiltd in #1847
- feat: implement virtio based host-guest communication by @andreiltd in #1794
- ci: cut Miri test time from 16 minutes to 90 seconds by @jprendes in #1859
- Make ELF loading respect program header virtual addresses for non-PIE binaries by @cshung in #1530
Full Changelog (dependencies)
- chore(deps): bump crate-ci/typos from 1.49.0 to 1.50.1 by @dependabot[bot] in #1797
- chore(deps): bump smallvec from 1.15.2 to 1.16.0 by @dependabot[bot] in #1800
- chore(deps): bump crossbeam-channel from 0.5.16 to 0.5.17 by @dependabot[bot] in #1808
- chore(deps): bump cc from 1.4.4 to 1.4.5 by @dependabot[bot] in #1806
- chore(deps): bump syn from 3.0.4 to 3.0.5 by @dependabot[bot] in #1805
- chore(deps): bump Swatinem/rust-cache from 2.9.1 to 2.9.2 by @dependabot[bot] in #1710
- chore(deps): bump crossbeam-queue from 0.3.13 to 0.3.14 by @dependabot[bot] in #1809
- chore(deps): update and group mshv crates together by @simongdavies in #1813
- chore(deps): bump actions-rust-lang/setup-rust-toolchain from 1.17.0 to 2.0.0 by @dependabot[bot] in #1818
- chore(deps): bump the wasm-tools group across 1 directory with 3 updates by @dependabot[bot] in #1780
- Configure Dependabot cooldown and Windows crate groups by @simongdavies in #1821
- chore(deps): bump bitflags from 2.13.1 to 2.13.2 by @dependabot[bot] in #1830
- chore(deps): bump wat from 1.258.0 to 1.259.0 by @dependabot[bot] in #1828
- chore(deps): bump uuid from 1.26.0 to 1.26.1 by @dependabot[bot] in #1827
- chore(deps): bump docker/build-push-action from 7.3.0 to 7.4.0 by @dependabot[bot] in #1845
- chore(deps): bump cfg-if from 1.0.4 to 1.0.5 by @dependabot[bot] in #1853
- chore(deps): bump syn from 3.0.5 to 3.0.6 by @dependabot[bot] in #1852
- chore(deps): bump crate-ci/typos from 1.50.1 to 1.50.2 by @dependabot[bot] in #1846
- chore(deps): bump the wasm-tools group with 3 updates by @dependabot[bot] in #1841
New Contributors
- @JM00NJ made their first contribution in #1799
- @sethryanrollins made their first contribution in #1699
Full Changelog: v0.17.0...dev-latest