VMSH: hypervisor-agnostic guest overlays for VMs
Jörg Thalheim, Peter Okelmann, Harshavardhan Unnibhavi, Redha Gouicem, Pramod Bhatotia
Abstract
Lightweight virtual machines (VMs) are prominently adopted for improved performance and dependability in cloud environments. To reduce boot up times and resource utilisation, they are usually "pre-baked" with only the minimal kernel and userland strictly required to run an application. This introduces a fundamental trade-off between the advantages of lightweight VMs and available services within a VM, usually leaning towards the former. We propose VMSH, a hypervisor-agnostic abstraction that enables on-demand attachment of services to a running VM---allowing developers to provide minimal, lightweight images without compromising their functionality. The additional applications are made available to the guest via a file system image. To ensure that the newly added services do not affect the original applications in the VM, VMSH uses lightweight isolation mechanisms based on containers. We evaluate VMSH on multiple KVM-based hypervisors and Linux LTS kernels and show that: (i) VMSH adds no overhead for the applications running in the VM, (ii) de-bloating images from the Docker registry can save up to 60% of their size on average, and (iii) VMSH enables cloud providers to offer services to customers, such as recovery shells, without interfering with their VM's execution.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext e05948e7-9124-4db5-9636-a512110e1894Cited by top-tier papers3
- Towards VM Rescheduling Optimization Through Deep Reinforcement LearningXianzhong Ding, Yunkai Zhang, Binbin Chen, Donghao Ying et al.EuroSys 2025 · 10 citations
- F3: An FPGA-accelerated FaaS FrameworkCharalampos Mainas, Martin Lambeck, Bruno Scheufler, Laurent Bindschaedler et al.HPDC 2025 · 1 citation
- Proteus: Heterogeneous FPGA VirtualizationFelix Gust, Shu Anzai, Charalampos Mainas, Atsushi Koshiba et al.EuroSys 2026
Builds on6
- Firecracker: Lightweight Virtualization for Serverless ApplicationsAlexandru Agache, Marc Brooker, Alexandra Iordache, Anthony Liguori et al.NSDI 2020 · 197 citations
- Breaking Kernel Address Space Layout Randomization with Intel TSXYeongjin Jang, Sangho Lee, Taesoo KimCCS 2016 · 174 citations
- Benchmarking, analysis, and optimization of serverless function snapshotsDmitrii Ustiugov, Plamen Petrov, Marios Kogias, Edouard Bugnion et al.ASPLOS 2021 · 162 citations
- Unikraft: fast, specialized unikernels the easy waySimon Kuenzer, Vlad-Andrei Badoiu, Hugo Lefeuvre, Sharan Santhanam et al.EuroSys 2021 · 116 citations
- A Secure and Formally Verified Linux KVM HypervisorShih-Wei Li, Xupeng Li, Ronghui Gu, Jason Nieh et al.S&P 2021 · 72 citations
Related papers
- Nephele: Extending Virtualization Environments for Cloning Unikernel-based VMsCostin Lupu, Andrei Albisoru, Radu Nichita, Doru-Florin Blânzeanu et al.EuroSys 2023 · 10 citations
- PVM: Efficient Shadow Paging for Deploying Secure Containers in Cloud-native EnvironmentHang Huang, Jiangshan Lai, Jia Rao, Hui Lu et al.SOSP 2023 · 4 citations
- A Linux in unikernel clothingHsuan-Chi Kuo, Dan Williams, Ricardo Koller, Sibin MohanEuroSys 2020 · 57 citations
- CofferOS: Hardening OS-level Virtualization with RustMinkyu Jung, Chanshin Kwak, Junho Ahn, Sunho Park et al.EuroSys 2026
- Security Namespace: Making Linux Security Frameworks Available to ContainersYuqiong Sun, David Safford, Mimi Zohar, Dimitrios Pendarakis et al.USENIX Security 2018 · 79 citations
