# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 77 → 78 (+0.7)
- Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.

## Lenses

- Code Health 91 → 91 (-0.0)
- Architecture 99 → 95 (-3.8)
- Maturity 78 → 78 (+0.0)
- Readiness 81 → 81 (-0.4)
- Security 70 → 73 (+2.2)
- Performance 94 (new)

## Resolved (26)

- Documentation: contradicts the code (docs/snapshot-versioning.md)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- Documentation: written for insiders
- Duplicated block (10 lines × 2) (src/hyperlight_host/src/mem/elf.rs)
- Duplicated block (13 lines × 2) (src/hyperlight_common/src/flatbuffer_wrappers/function_call.rs)
- Duplicated block (16–17 lines × 2) (src/hyperlight_common/src/flatbuffer_wrappers/function_call.rs)
- Duplicated block (7 lines × 2) (src/hyperlight_guest_bin/src/guest_function/definition.rs)
- Duplicated block (9 lines × 2) (src/hyperlight_common/src/flatbuffer_wrappers/function_types.rs)
- Duplicated block (9 lines × 2) (src/hyperlight_common/src/flatbuffer_wrappers/function_types.rs)
- Duplicated block (9 lines × 2) (src/hyperlight_host/src/sandbox/snapshot/file/mod.rs)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Hotspot: src/hyperlight_common/src/flatbuffer_wrappers/function_types.rs (src/hyperlight_common/src/flatbuffer_wrappers/function_types.rs)
- Hotspot: src/hyperlight_component_util/src/hl.rs (src/hyperlight_component_util/src/hl.rs)
- Hotspot: src/hyperlight_host/src/hypervisor/hyperlight_vm/x86_64.rs (src/hyperlight_host/src/hypervisor/hyperlight_vm/x86_64.rs)
- Hotspot: src/hyperlight_host/src/hypervisor/regs/x86_64/special_regs.rs (src/hyperlight_host/src/hypervisor/regs/x86_64/special_regs.rs)
- Hotspot: src/hyperlight_host/src/hypervisor/virtual_machine/mshv/x86_64.rs (src/hyperlight_host/src/hypervisor/virtual_machine/mshv/x86_64.rs)
- Hotspot: src/hyperlight_host/src/hypervisor/virtual_machine/whp.rs (src/hyperlight_host/src/hypervisor/virtual_machine/whp.rs)
- …and 6 more

## New (32)

- Ambiguous naming convention. In Rust, `to_*` typically implies a copy or conversion (borrowing), while `into_*` implies consuming the value. However, `to_bytes()` on `Segments` likely consumes the segments to create a contiguous `Bytes` object, making it semantically identical to `into_bytes()`. If `to_bytes` does not consume, it is confusingly named against standard idioms; if it does, it duplicates `into_bytes`.
- ClassTooLong: SandboxMemoryManager (src/hyperlight_host/src/mem/mgr.rs)
- Duplicated block (13 lines × 2) (src/hyperlight_host/src/mem/shared_mem.rs)
- Duplicated block (7 lines × 2) (src/hyperlight_host/src/sandbox/snapshot/file/transport.rs)
- Duplicated block (9 lines × 2) (src/hyperlight_ci/src/remote.rs)
- Duplicated block (9 lines × 2) (src/hyperlight_guest/src/transport/mem.rs)
- Duplicated block (9–10 lines × 2) (src/hyperlight_common/src/virtq/consumer.rs)
- End-of-life runtime: Rust 1.94
- FileTooLong: mem/mgr.rs (src/hyperlight_host/src/mem/mgr.rs)
- FileTooLong: virtq/producer.rs (src/hyperlight_common/src/virtq/producer.rs)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Hotspot: src/hyperlight_host/src/sandbox/snapshot/file/mod.rs (src/hyperlight_host/src/sandbox/snapshot/file/mod.rs)
- Low cohesion: HvfVm (LCOM4 5) (src/hyperlight_host/src/hypervisor/virtual_machine/hvf/mod.rs)
- Low cohesion: Offset (LCOM4 4) (src/hyperlight_host/src/mem/ptr_offset.rs)
- Medium advisory (unmaintained): RUSTSEC-2025-0119 (Cargo.lock)
- Off the main sequence: hyperlight-common
- Off the main sequence: hyperlight-component-util
- Off the main sequence: hyperlight-guest-tracing
- …and 12 more

## Changes since last survey

- 22 commits — 20 feature/other, 2 fixes

## By area

- (root) — 10 commits
- src/hyperlight_host — 6 commits
- .github/workflows — 3 commits
- .github/dependabot.yml — 1 commit
- src/hyperlight_ci — 1 commit
- src/hyperlight_common — 1 commit

## Notable commits

- fix: fix: adjust scratch size for benchmarks (#1847)
- fix: fix: use try_into instead of as u64 cast in push_buffer (#1825)
- change: Add API for Snapshot metadata (#1860)
- change: Comment benchmark results on pull requests (#1529)
- change: Configure Dependabot cooldown and Windows crate groups (#1821)
- change: Make ELF loading respect program header virtual addresses for non-PIE binaries (#1530)
- change: Update pinned nightly toolchain (#1849)
- change: chore(deps): bump bitflags from 2.13.1 to 2.13.2 (#1830)
- change: chore(deps): bump cfg-if from 1.0.4 to 1.0.5 (#1853)
- change: chore(deps): bump crate-ci/typos from 1.50.1 to 1.50.2 (#1846)
- change: chore(deps): bump docker/build-push-action from 7.3.0 to 7.4.0 (#1845)
- change: chore(deps): bump opentelemetry-semantic-conventions from 0.32.1 to 0.33.0 (#1857)
- change: chore(deps): bump rand from 0.10.2 to 0.10.3 (#1858)
- change: chore(deps): bump syn from 3.0.5 to 3.0.6 (#1852)
- change: chore(deps): bump the wasm-tools group with 3 updates (#1841)
- change: chore(deps): bump uuid from 1.26.0 to 1.26.1 (#1827)
- change: chore(deps): bump wat from 1.258.0 to 1.259.0 (#1828)
- change: ci: cut Miri test time from 16 minutes to 90 seconds (#1859)
- change: feat: add virtqueue transport foundations (#1793)
- change: feat: implement virtio based host-guest communication (#1794)
- …and 2 more
