Building a VMM from scratch, #0: Why BoxLite is replacing libkrun BoxLite is replacing libkrun with a virtual machine monitor it is writing itself, according to a BoxLite blog post dated October 11, 2026, because libkrun's README lists "Become a generic VMM" and "Be compatible with all kinds of workloads" as non-goals that BoxLite's needs have outgrown. BoxLite runs each box as a hardware-isolated micro-VM that executes any OCI image and preserves state across turns, and the company is building the new VMM in public across 16 planned parts, from a 7-byte first guest to deleting libkrun in part #16. The first KVM backend guest was 7 bytes long, writing the byte 'K' to COM1 serial port 0x3f8 before halting. Every BoxLite box runs in its own micro-VM, and today libkrun runs that VM. We're replacing it with a VMM we write ourselves. This series builds it in public, one merged PR at a time. BoxLite is the compute substrate for AI agents light enough to embed on your laptop, elastic enough to power an agentic cloud. Each box is a hardware-isolated micro-VM that runs any OCI image and keeps its state across turns. Figure 1. One engine in two places: the embedded BoxLite runtime starts one micro-VM per box, on your machine or on a cloud runner. The part that runs each micro-VM is the VMM, the virtual machine monitor. That part is the subject of this series. libkrun describes itself as "a dynamic library that allows programs to easily acquire the ability to run processes in a partially isolated environment", on KVM Linux and HVF macOS on Apple silicon , behind "a simple C API". That fit BoxLite: libkrun is how BoxLite runs boxes on macOS and Linux today. libkrun is clear about what it isn't: its README https://github.com/containers/libkrun readme lists "Become a generic VMM" and "Be compatible with all kinds of workloads" as non-goals. BoxLite's needs grew past those goals: -EINVAL . dlopen , and that keeps breaking on some hosts; IrqsExhausted Figure 2. Inside one machine. The runtime spawns a jailed boxlite-shim per box, and the VMM inside it runs the micro-VM. PROPOSED marks what this series replaces. A hypervisor KVM or Hypervisor.framework runs guest instructions on the CPU. The VMM is the ordinary process around it: it gives the guest memory, creates vCPUs, loads the kernel and emulates every device. Its heart is one loop: Figure 3. Run a vCPU until it exits, handle the exit, and run it again. The first guest our new KVM backend ran was 7 bytes long: mov dx, 0x3f8 ; COM1 serial port mov al, 'K' out dx, al ; KVM exits to the VMM: port 0x3f8, byte 'K' hlt Everything else is detail, and each detail gets a part in this series: | Piece | What it is | Part | |---|---|---| | Memory | Guest RAM is host memory; an unmapped address is a device | 1 | | Exits | One exit contract for KVM, Hypervisor.framework and, later, WHP | 2 | | Stopping | Pulling a vCPU out of the guest, safely | 3 | | CPU state | Registers, CPUID and MSRs on x86 | 4 | | Boot | The VMM is the bootloader | 6 | | Devices | Serial, RTC and reset first, then virtio | 7, 1012 | Status as of October 11, 2026. A part goes out only after its code merges, so every claim links to a merged PR. | Arc | Parts | Ships when | |---|---|---| | 1. First instructions | 1 Your first VM is 7 bytes 2 Design the exit contract first 3 Stopping a vCPU is the hard part 4 x86 CPU state, by hand 5 A kernel we build ourselves | Code merged | | 2. First boot M1 | 6 You are the bootloader 7 Boring devices first 8 On Apple silicon, you decode the exits 9 One kernel, three hosts | As M1 lands | | 3. First box M2M3 | 10 virtio from scratch 11 Disks, sockets, network 12 One virtio-fs device for every volume 13 Our agent as PID 1 | M2M3 | | 4. Ship it M4M5 | 14 Guest input must never panic the host 15 Measured against libkrun 16 Deleting libkrun | M4M5 | | Later | Memory snapshots, hot-plug mounts, GPUs, our own network stack | After M5 | Follow along on the RSS feed https://blog.boxlite.ai/rss.xml and in every PR on GitHub https://github.com/boxlite-ai/boxlite . BoxLite is open source, and so is every step of this VMM. We'd love your help: Start with CONTRIBUTING.md https://github.com/boxlite-ai/boxlite/blob/main/CONTRIBUTING.md . Your first PR asks you to sign our contributor license agreement.