mrkeyoor.com_
Thu 01 Oct 19:38 UTC
Dev Toolsevaluationupdated 26 Aug 2026

webvm review

WebVM runs an x86 Linux environment inside a web browser, using WebAssembly instead of a server-side virtual machine. It gives people a disposable Debian terminal or graphical Linux workspace on devices where installing a normal VM is inconvenient or impossible.

+0stars / 7d
Verdict

Our WebVM checkout installed 233 packages and built in 61 seconds combined, but it offered no test target for checking the virtualization layer. Use it for a bounded browser lab, demo, or classroom where you can test every required command yourself. Choose a server-side container or full VM for arbitrary Linux software, and settle CheerpX licensing before organizational deployment.

We ran it

Lab card: what happened when we ran webvmScreenshot of webvm (webvm.io)
Install✓ · 49s233 packages · 313 MB
Build✓ · 12s
Testsn/ano test script
Known vulns00 critical · 0 high · 0 moderate · 0 low (npm audit)
Repo94 files~2,320 lines of source · 10.6 MB · 1 CI workflows

Answers from our run

Does webvm build from source?

Dependencies installed in 49 seconds (233 packages), and the build succeeded in 12 seconds. We cloned commit 4b8991d into a clean Debian container with 3 CPUs and no project-specific setup.

Does webvm have tests you can run?

Not through a standard command: the project exposes no test script or target that our harness could run.

Does webvm have known vulnerabilities in its dependencies?

npm audit found none in the dependency tree at the time of our run.

Who should not use webvm?

Organizations assuming Apache 2.0 covers the complete deployed stack: the README says organizational use of the public CheerpX deployment requires a license, and separate hosting of a downloaded CheerpX build needs a commercial license.

What are the alternatives to webvm?

v86, WebContainers. Our WebVM checkout installed 233 packages and built in 61 seconds combined, but it offered no test target for checking the virtualization layer.

Setup4/549-second install and 12-second build; custom images add work
Docs4/5Clear image, networking, deployment, and license instructions
Community4/517,351 stars with an August 2026 push and issue activity
Maturity3/5Useful browser VM, but no test target and syscall gaps remain

Discussed on

  1. hnWebVM: Server-less x86 virtual machines in the browser352 points
  2. hnWebVM: WASM virtual machine in browser with networking via Tailscale226 points
  3. hnWebvm: Virtual Machine for the Web205 points
  4. hnWebVM 2.0: A complete Linux Desktop Environment in the browser via WebAssembly97 points
  5. hnMini.WebVM: Your own Linux box from Dockerfile, virtualized in-browser via WASM37 points

Who it’s for

Educators who want learners to open a Linux userland from one link.
Developers building browser sandboxes, command-line demos, or security exercises.
Chromebook and locked-down-device users who need more than a JavaScript console.
Teams prepared to test every required binary against an emulated Linux syscall layer.

Who it’s NOT for

Organizations assuming Apache 2.0 covers the complete deployed stack: the README says organizational use of the public CheerpX deployment requires a license, and separate hosting of a downloaded CheerpX build needs a commercial license.
Workloads that require every Linux binary to behave as it would on a normal kernel: issue 199 shows a small Go program failing before its allocator starts because it cannot obtain the system page size.
Network labs that depend on raw sockets or ping: the README says ICMP is unavailable, while public internet access requires Tailscale plus an exit node.
Teams planning to publish the documented large Debian image on GitHub Pages: the README says that image is too large for that route.
Buyers who require an upstream test suite before adopting a virtualization layer: our checkout had no test script or test directory.

Setup reality

Our sandbox installed 233 npm packages in 49 seconds and used 313 MB on disk. The build succeeded in 12 seconds. There was no test script or target, so we skipped tests; npm audit reported 0 known vulnerabilities.

The hosted demo needs only a browser. A local deployment needs an ext2 disk image, a configuration edit, npm, and Nginx. Private networking needs Tailscale, while public internet access also needs an exit node. Claude integration needs an Anthropic API key.

The checkout had 94 files, about 2,320 source lines, 1 CI workflow, and no Dockerfile or tests directory. GitHub Pages cannot take the documented large Debian image, and organizations must resolve the separate CheerpX license terms before deployment.

Linux in a browser works best for bounded labs

WebVM opens an x86 Linux environment in a browser tab. The guest is an unmodified Debian distribution rather than a shell imitation written in JavaScript. Leaning Technologies' CheerpX engine translates x86 code to WebAssembly, provides a block-based file system, and emulates Linux system calls. This is a strong fit for a class, product demo, coding exercise, or security challenge where every required command is known in advance. Learners get root inside the guest without receiving shell access to a shared teaching server.

The repository is smaller than the idea sounds: our checkout contained 94 files and about 2,320 lines of source. Most of the hard work lives in CheerpX, while WebVM supplies the browser interface, configuration, terminal, networking integration, and image-loading path. That division makes the application approachable to inspect. It also means the Apache-licensed repository is only one part of the product and cannot answer every runtime question on its own.

A hosted session is easier than a custom image

The official webvm.io instance opens without local setup. A fork can be published through GitHub Pages by enabling Actions and running the included Deploy workflow. That workflow can build an ext2 image from a Dockerfile and publish the static site. Root access is enabled inside the guest, although the README notes that sudo is absent unless the image author adds it.

Owning the full experience takes more work. Local instructions require an ext2 disk image, a change to config_public_terminal.js, an npm install and build, then Nginx with the supplied configuration. The documented large Debian image is too big for GitHub Pages. Image size therefore affects both startup and hosting, and a useful custom environment still needs package-by-package acceptance testing. Browser storage policy and the way learners keep their work also need an explicit product decision.

What happened when we ran it

Our sandbox installed 233 npm packages in 49 seconds, leaving 313 MB on disk, and the build succeeded in another 12 seconds. Npm audit found 0 known vulnerabilities. Those are good repository mechanics for commit 4b8991d in a fresh Debian container with 3 CPUs and 8 GB of RAM. They do not measure guest boot time, command speed, or compatibility, so we make no claim about those.

There was no test script or target, and the repository had no tests directory, so we skipped tests. The checkout did include 1 CI workflow and no Dockerfile. That missing test entry point matters more here than it would in a simple static page because WebVM sits between browsers, disk images, an x86 translator, and emulated syscalls. A clean build proves the site bundles; it does not prove a particular Linux program runs correctly.

Tailscale supplies networking, with limits

WebVM can join a Tailscale network through an interactive login or an ephemeral auth key placed in the URL fragment. Reaching the public internet requires an exit node on another device. Headscale is supported as a control server, but its default lack of cross-origin headers means operators need a proxy configuration. Those dependencies are reasonable for a client-side VM, yet they are more involved than the network attached to an ordinary cloud instance.

ICMP is unavailable, so the README tells users to check connections with curl or wget instead of ping. Issue 199 gives a different compatibility warning: a minimal 32-bit Go program fails during runtime initialization because it cannot obtain the system page size. That report concerns one reproduced program, not all Go software, but it is enough to reject the assumption that Linux ABI compatibility equals a normal kernel.

Apache 2.0 does not settle CheerpX use

The WebVM repository carries Apache 2.0, while the README gives the public CheerpX deployment separate terms. It says individuals may use it for exploration, testing, and personal work. Organizational use, including nonprofit, academic, and public-sector use, requires a license. The same section says downloading a CheerpX build for hosting elsewhere is not permitted without a commercial license. Any organization should resolve that distinction before building a custom image or promising WebVM to users.

GitHub showed 17,351 stars, 14 combined issues and pull requests, and a last push on August 17, 2026. The newest listed release is an ext2 image from May 2023, but recent repository and issue activity are better health signals than that old asset alone. Issue 229, updated August 26, reports display resizing hanging the VM in CheerpX 1.3.8 and 1.3.9. Pin the runtime you test, keep a short compatibility script, and rerun it whenever the image or CheerpX package changes.

Alternatives

ProjectWhat it isPick it when
v86 gh↗An x86 PC emulator for browsers and Node.js that can boot several operating systems.pick this instead when you need lower-level machine emulation or want to boot an operating system outside WebVM's prepared Linux path.
WebContainersA browser runtime centered on Node.js projects and web development tools.pick this instead when your whole workload is JavaScript development and broad x86 Linux compatibility adds no value.

What people are saying

  1. [github-trending] leaningtech/webvm

Sources

  1. WebVM repository and README
  2. WebVM release history
  3. Issue 199: Go runtime initialization failure
  4. Issue 229: display mode regression
  5. CheerpX licensing documentation

More dev tools reviews

nyaterm · yoinks · tilelang · vintage-latex · NavierStokesAndEuler · UMR · the whole board →