Releases
v0.1.0
Compare
Sorry, something went wrong.
No results found
Added
Core VM Execution: Secure code execution in isolated QEMU microVMs with KVM/HVF hardware acceleration
Warm Pool: Pre-started VM pool with 1-2ms acquisition time and health check retry with exponential backoff
L0 Memory Snapshots: 50-200ms VM restore using memory snapshots
Memory Optimization: zram swap and balloon memory reclamation for ~30% more capacity
Guest Agent: Rust-based PID1 with zombie reaping for orphaned processes
Asset Auto-download: Automatic download of VM images from GitHub releases with local cache
TCG Support: Comprehensive TCG/nested virtualization support with TCG-aware memory limits
Security: Mandatory SO_PEERCRED socket authentication and control character validation for env vars
Graceful Shutdown: SIGTERM→SIGKILL process termination with proper cleanup
Cold Start Timing: Detailed timing breakdown for boot diagnostics
QEMU Debugging: Enhanced boot failure debugging output
Type Stubs: zstd type stubs for compression
CI Monitoring: GitHub Actions monitoring and diagnostics tools
Performance
Custom initramfs for optimized boot time
Parallel processing flags for qemu-img operations
BuildKit cache mounts for faster image builds
Optimized VM boot timing and compression
Local cache check before asset download
Kernel validation caching to reduce I/O
Fixed
LZ4 legacy format validation in initramfs
Init script included in kernel hash calculation
Connection preservation on channel timeout errors
Socket permissions and output buffering for VM
Pre-connect chardev sockets to prevent QEMU poll race
Async file operations (replaced sync unlink)
Base image accessibility for qemu-vm user
OOM race prevention with strict overcommit and memory tuning
Heuristic overcommit for JIT runtime compatibility
Haswell CPU for x86 TCG to support AVX2
Warm pool semaphore to prevent replenish race condition
Snapshot sudo for qemu-img commit when overlay owned by qemu-vm
gvproxy-wrapper build for macOS in CI
Changed
Replaced pip with uv for Python package management
Shell init logic moved to Rust guest-agent
File operations converted to async with aiofiles
Platform detection logic centralized
Temp files consolidated into VmWorkingDirectory
Acceleration detection logic centralized
Resource limiting centralized in dedicated cgroup module
Permission operations centralized in dedicated module
qemu-vm user made optional for broader compatibility
CI/CD
Restructured workflows with buildx caching
Cross-platform support for test workflows
Unprivileged user namespaces enabled on Linux
Functional tests isolated in cgroup subtree
Tests
Comprehensive cache hierarchy tests for snapshots
RNG quality validation suite
Health check logic unit tests
Hardware acceleration verification
Missing images dir with auto download test case
Streaming tests extended to 500MB with throughput benchmarks
Unified fixture patterns in conftest
Documentation
Comprehensive README with examples and best practices
Virtualization and security reference links
Memory optimization details
Socket authentication security layer documentation
VM images section with pre-installed software details
You can’t perform that action at this time.