Every BoxLite box runs in its own micro-VM, and today libkrun runs that VM. We're replacing it with a VMM we write ourselves. This series builds it in public, one merged PR at a time.
BoxLite is the compute substrate for AI agents light enough to embed on your laptop, elastic enough to power an agentic cloud. Each box is a hardware-isolated micro-VM that runs any OCI image and keeps its state across turns.
Figure 1. One engine in two places: the embedded BoxLite runtime starts one micro-VM per box, on your machine or on a cloud runner.
The part that runs each micro-VM is the VMM, the virtual machine monitor. That part is the subject of this series.
libkrun describes itself as "a dynamic library that allows programs to easily acquire the ability to run processes in a partially isolated environment", on KVM (Linux) and HVF (macOS on Apple silicon), behind "a simple C API". That fit BoxLite:
libkrun is how BoxLite runs boxes on macOS and Linux today.
libkrun is clear about what it isn't: its README lists "Become a generic VMM" and "Be compatible with all kinds of workloads" as non-goals. BoxLite's needs grew past those goals:
-EINVAL. dlopen, and that keeps breaking on some hosts; IrqsExhausted (
Figure 2. Inside one machine. The runtime spawns a jailed boxlite-shim per box, and the VMM inside it runs the micro-VM. PROPOSED marks what this series replaces.
A hypervisor (KVM or Hypervisor.framework) runs guest instructions on the CPU. The VMM is the ordinary process around it: it gives the guest memory, creates vCPUs, loads the kernel and emulates every device. Its heart is one loop:
Figure 3. Run a vCPU until it exits, handle the exit, and run it again.
The first guest our new KVM backend ran was 7 bytes long:
mov dx, 0x3f8 ; COM1 serial port
mov al, 'K'
out dx, al ; KVM exits to the VMM: port 0x3f8, byte 'K'
hlt
Everything else is detail, and each detail gets a part in this series:
| Piece | What it is | Part |
|---|---|---|
| Memory | Guest RAM is host memory; an unmapped address is a device | #1 |
| Exits | One exit contract for KVM, Hypervisor.framework and, later, WHP | #2 |
| Stopping | Pulling a vCPU out of the guest, safely | #3 |
| CPU state | Registers, CPUID and MSRs on x86 | #4 |
| Boot | The VMM is the boot | #6 |
| Devices | Serial, RTC and reset first, then virtio | #7, #1012 |
Status as of October 11, 2026. A part goes out only after its code merges, so every claim links to a merged PR.
| Arc | Parts | Ships when |
|---|---|---|
| 1. First instructions | #1 Your first VM is 7 bytes #2 Design the exit contract first #3 Stopping a vCPU is the hard part #4 x86 CPU state, by hand #5 A kernel we build ourselves | Code merged |
| 2. First boot (M1) | #6 You are the boot #7 Boring devices first #8 On Apple silicon, you decode the exits #9 One kernel, three hosts | As M1 lands |
| 3. First box (M2M3) | #10 virtio from scratch #11 Disks, sockets, network #12 One virtio-fs device for every volume #13 Our agent as PID 1 | M2M3 |
| 4. Ship it (M4M5) | #14 Guest input must never panic the host #15 Measured against libkrun #16 Deleting libkrun | M4M5 |
| Later | Memory snapshots, hot-plug mounts, GPUs, our own network stack | After M5 |
Follow along on the RSS feed and in every PR on GitHub.
BoxLite is open source, and so is every step of this VMM. We'd love your help:
Start with CONTRIBUTING.md. Your first PR asks you to sign our contributor license agreement.