Microsoft Releases LiteBox 0.1 — a Rust-Based Library OS for Application Isolation
Microsoft has announced LiteBox 0.1, the debut version of an open-source library operating system written in Rust. The project’s main goal is to separate applications from the host system, narrowing their interaction with the host and thereby reducing the potential attack surface. The v0.1.0 release was published to the repository on October 7, 2026.
A library OS — unlike the familiar Linux or Windows — does not act as a standalone system and does not provide a full-fledged user environment. All the OS functions an application needs are packaged into a library that is used inside an isolated environment. This approach makes it possible to keep only the necessary interfaces and minimize calls to the host system.
How LiteBox Is Structured
LiteBox’s architecture is built on two interfaces — North and South. The upper layer, North, gives applications access to OS functions through a Rust API modeled after the nix and rustix libraries. The lower layer, South, handles communication with the platform on which LiteBox runs.
This separation makes it possible to combine application and platform support without reworking the entire system. The repository lists adaptation layers for Linux, OP-TEE, WebAssembly, and the Rust standard library. Supported platforms include Linux, Windows, and FreeBSD user environments, the LVBS mechanism, and the Linux kernel in an AMD SEV-SNP environment.
What LiteBox Is For
Microsoft is building LiteBox to work in both user mode and kernel mode. One of the key scenarios is running ordinary Linux applications in a sandbox on Linux. Another is executing Linux programs on Windows without modifying their code. At the same time, LiteBox does not replace the Windows Subsystem for Linux: the project does not provide a universal Linux environment.
Some scenarios involve secure execution environments. These include AMD SEV-SNP with hardware-based memory protection for virtual machines, the open trusted environment OP-TEE, and the Linux Virtualization-Based Security (LVBS) mechanism, which moves some security checks into an isolated virtual machine.
Project Status and License
LiteBox is still at an early stage of active development. The authors warn that the API and other interfaces will change as the architecture evolves. For those who need long-term stability, Microsoft recommends waiting for a stable release. In the meantime, users should be prepared to make changes to their code when updates arrive.
The source code, development documentation, and contribution guidelines are available on GitHub. The project is distributed under the MIT license. Work on it has been underway since December 2024. At the time of publication, the repository had around 2,800 stars and 148 forks, with 22 people contributing to development.