Can VMAware Detect Multiple Virtual Machines Running Simultaneously?
No, VMAware cannot detect multiple virtual machines running simultaneously; it is architected as a single-process library that identifies only the virtualization environment of the current process.
VMAware is a C++ library maintained in the kernelwernel/vmaware repository that determines whether the executing process is running inside a hypervisor. While it employs over 150 detection techniques to identify specific brands like VirtualBox, VMware, or QEMU, its design fundamentally aggregates results into a single VM brand for the current environment, not an inventory of all VMs on a physical host.
How Single-Process Detection Works
The library centers on the VM::detect() function, which triggers the core detection routine. Inside src/vmaware.hpp, the core::run_all() method (lines 11946-11950) executes the technique table—an enumeration of checks defined in enum enum_flags (lines 00557-00653)—that inspect CPU features, firmware signatures, BIOS tables, and device names.
Results are stored in a brand score array (brand_array_t, defined at lines 00884-00886), where each technique contributes points to specific hypervisor brands. After execution, the highest-scoring brand is returned as the definitive result. This architecture inherently limits output to one environment per process execution.
The MULTIPLE Flag Misconception
The MULTIPLE flag does not enable detection of multiple VMs. According to the source code at lines 11861-11876 in src/vmaware.hpp, this flag only controls internal default flag-generation behavior during library initialization.
Furthermore, the public VM::check() function explicitly rejects MULTIPLE when passed as a technique argument (lines 12027-12033). This confirms that the library treats every query as a question about one specific environment—the virtualization layer hosting the current process.
Nested Virtualization vs. Concurrent VMs
VMAware handles nested virtualization (a VM inside another VM) by reporting only the innermost visible hypervisor. For instance, if the process runs inside a VirtualBox VM that itself runs on a VMware host, VMAware identifies the immediate VirtualBox environment rather than listing both hypervisors. This differs fundamentally from detecting multiple independent VMs running side-by-side on a physical host, which remains outside the library's scope.
Code Example
The following demonstrates VMAware's single-environment API:
#include "vmaware.hpp"
#include <iostream>
int main() {
// Detects whether the current process runs inside *any* VM.
bool vm_present = VM::detect(); // Single-environment detection
std::cout << "VM detected? " << vm_present << '\n';
// Retrieves the most likely VM brand for this process.
std::string brand = VM::brand(); // e.g., "VirtualBox", "VMware"
std::cout << "Detected brand: " << brand << '\n';
// Queries a specific technique, still referring to *this* VM only.
bool hypervisor_bit = VM::check(VM::HYPERVISOR_BIT);
std::cout << "CPUID hypervisor bit set? " << hypervisor_bit << '\n';
}
When executed on a host running multiple concurrent VMs, this code reports exclusively on the virtualization layer containing the process itself. There is no API to retrieve a list of other active VMs or query their individual configurations.
Core Implementation Files
src/vmaware.hpp: Contains all public APIs (VM::detect(),VM::brand(),VM::check()), theenum_flagstechnique enumeration, and the detection engine includingcpu::vmid_template(lines 01136-01197) for mapping hypervisor signatures like"Microsoft Hv"to specific brands.src/cli.cpp: Command-line wrapper demonstrating library usage.docs/documentation.md: Human-readable descriptions of detection techniques and settings.
Summary
- VMAware operates as a single-process library that inspects its own execution environment, not the entire host system.
- The technique table and brand scoring array (
brand_array_t) aggregate evidence into one definitive hypervisor brand per execution. - The
MULTIPLEflag controls internal API behavior during initialization, not multiple VM enumeration, and is explicitly rejected byVM::check(). - Nested virtualization is reported as a single hypervisor (the innermost layer), not as multiple simultaneous detections.
- The library cannot enumerate external VMs or differentiate between multiple independent virtual machines running concurrently on the same physical hardware.
Frequently Asked Questions
Can VMAware list all VMs currently running on a physical host?
No. VMAware lacks any API for enumerating virtual machines present on the host system. It only determines whether the process calling the library is executing inside a VM, returning a single boolean result and brand identifier for that specific environment.
What does the MULTIPLE flag actually do in VMAware?
The MULTIPLE flag modifies how the library generates default flag sets during initialization (lines 11861-11876 in src/vmaware.hpp). It does not enable detection of multiple virtual machines, and the VM::check() function explicitly rejects it as an invalid technique flag (lines 12027-12033).
How does VMAware handle nested virtualization?
When running inside a nested virtual machine, VMAware identifies only the innermost hypervisor that directly hosts the process. It does not return a chain or list of all hypervisors in the stack, as it aggregates detection results into a single brand score via the brand_array_t structure.
Which source file contains the core detection logic?
The primary detection engine resides in src/vmaware.hpp, specifically within the core struct's run_all() method and the VM::detect() wrapper function. This file also defines the technique enumeration (enum_flags), brand scoring array (brand_array_t), and CPUID inspection templates like cpu::vmid_template (lines 01136-01197).
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →