Read

Glossary

The vocabulary used across this site, defined plainly — from boot sectors and range requests to microkernels and WebAssembly.

9p
A network filesystem protocol from Plan 9 that the Linux kernel speaks natively through the v9fs driver — no NFS server, no daemon, just mount -t 9p and a transport. Carried over virtio it lets a guest mount a root filesystem served over HTTP, fetching individual files as they are opened instead of downloading a disk image first. A shell prompt can appear after a couple of megabytes.
A20 gate
The hardware switch that controls whether address line 20 works at all. The 8086 wrapped around at 1 MB and enough software depended on that bug for the 286 to preserve it, holding the line low through the keyboard controller at port 0x64 until an operating system asked otherwise. Opening it exposes the 65,520 bytes of the HMA just above 1 MB, where DOS=HIGH puts most of MS-DOS. Modern chipsets offer the quicker port 0x92 route, but a bootloader still has to do it.
ACPI
The standard, published in 1996 by Intel, Microsoft and Toshiba, by which firmware describes power management and hardware layout to an operating system. It works by handing over tables — RSDP, FADT, DSDT — containing bytecode the kernel interprets. Modern systems need it to shut down cleanly; systems written before it simply ignore it, and a few older ones are confused by its presence.
AT&T syntax
The assembly notation GNU as and objdump use by default, and the reason boot-sector examples look different from one book to the next. Source comes first and destination second, registers take a percent sign and immediates a dollar, and the operand size is a suffix: movl $0x10, %eax. Intel syntax reverses the operands and drops the sigils. Same instructions, same bytes; pass -M intel to objdump and the disassembly changes shape entirely.
BIOS
The firmware that runs first on an x86 PC, introduced with the IBM PC in 1981. It initialises hardware, offers a set of real-mode interrupt services for disk, video and keyboard, then loads the first 512 bytes of the first bootable device to address 0x7C00 and jumps into them. It knows nothing about filesystems, partitions or operating systems, and it never did.
Boot order
The sequence of devices the firmware tries when looking for something to boot: floppy, hard disk, CD, network. The first device with a valid boot sector wins and the rest are never consulted, which is why an installer ISO left first in the list will cheerfully reinstall itself forever. On the machines here the order is part of the machine's configuration, not a setting inside the guest.
Boot sector
The first 512 bytes of a disk. If its final two bytes are 0x55 0xAA the BIOS loads it to 0x7C00 and executes it in real mode; that is the entire test, and a sector of zeros ending in those two bytes will be run quite happily. Those 512 bytes must then find and load everything else, which is why almost every one of them is a loader for a second stage.
BPB (BIOS Parameter Block)
The block of geometry fields inside a FAT boot sector, starting at offset 0x0B: bytes per sector, sectors per cluster, reserved sectors, number of FATs, media descriptor and the rest. The first three bytes of the sector are a jump over it, traditionally EB xx 90. Get one field wrong when building an image by hand and DOS will read the wrong sectors quite happily and hand you nonsense.
bzImage
A compressed Linux kernel image — big zImage, not bzip2, a misreading almost everybody makes once. It carries a real-mode setup header at offset 0x1F1 describing the boot protocol, and a self-extracting body that unpacks itself to 0x100000, above the 640 KB ceiling that limited the older zImage. Because the format can be loaded directly, a machine here can start from a bzImage and an initramfs with no disk and no bootloader at all.
cgroups
Control groups: the kernel accounting machinery that limits how much CPU, memory and I/O a group of processes may consume, and how many of them there may be. Written at Google by Paul Menage and Rohit Seth and merged in 2007, then rebuilt as the unified v2 hierarchy under /sys/fs/cgroup. Namespaces hide the rest of the machine from a container; cgroups stop it eating the machine.
CHS
Cylinder, head and sector: the geometric way of naming a place on a disk, from when those numbers described real platters. A cylinder is the same track on every surface at once. Sectors are numbered from 1 while cylinders and heads start at 0, which has caused an endless supply of off-by-one bugs. BIOS limits of 1024 cylinders, 255 heads and 63 sectors cap the scheme at about 8.4 GB; the earlier 504 MB barrier came out of the same arithmetic.
Container
A process, or group of processes, isolated by kernel features rather than by emulated hardware. There is no second kernel, no firmware and no boot: a container starts in milliseconds and shares the host's kernel, which is exactly why it cannot run a different operating system. Docker images of Alpine or Debian are containers; nothing inside one ever executes a boot sector.
Copy-on-write
A way of sharing data until somebody changes it: readers use the original, and the first writer gets a private copy of only the block it touched. Disk images here are opened read-only and every written sector is kept in a separate overlay, so the underlying file is never modified and one copy serves every visitor. qcow2, overlayfs and fork() all work this way.
CORS
The browser rule that a page may only read data from another origin if that origin says so, through an Access-Control-Allow-Origin header. It is why an image you can download by hand may still fail to load here: the browser fetches the bytes and then refuses to hand them over. An ordinary image tag is exempt from the rule; a scripted fetch of a disk image is not.
CR0
The first x86 control register. Bit 0, PE, switches the processor into protected mode; bit 31, PG, turns paging on; bit 16, WP, decides whether ring 0 may write to pages marked read-only. The three-instruction sequence that reads CR0, sets bit 0 and writes it back is the most reproduced fragment of boot code in existence, and the far jump that must follow it is the step people forget.
Disk image
A file holding the exact bytes a disk would contain — not the files on it, but the disk itself, boot sector and partition table included. Usually .img, .iso or .bin; qcow2 and vmdk add compression and copy-on-write on top of the same idea. Because the layout is byte-for-byte, you can loop-mount one on Linux, edit a file inside it and boot the result unchanged.
Emulation
Imitating hardware in software so that programs written for it run unmodified. The emulator decodes guest instructions itself and keeps a device model for each chip: a few hundred lines of code that answer reads and writes on the ports the real part would have owned. It works on any host whatever its processor, at a cost of roughly an order of magnitude in speed.
Ephemeral
Existing only for the duration of use. An ephemeral, non-persistent machine keeps nothing after it closes: no disk file, no account, no directory on a server. Everything it did was writes into page memory, and reloading the tab is a factory reset. That is a feature when you are running something you do not trust, and a trap once you have spent twenty minutes configuring it.
ESP (EFI System Partition)
The FAT partition a UEFI firmware reads at boot, marked with the type GUID C12A7328-F81F-11D2-BA4B-00A0C93EC93B and usually between 100 and 500 MB. Bootloaders live in it as ordinary files, so you can repair one by copying a file. With no configuration at all, firmware will fall back to running /EFI/BOOT/BOOTX64.EFI from it.
FAT
File Allocation Table: the filesystem MS-DOS shipped with, and the one everything can still read. A file is a chain of clusters, each entry in the table naming the next; FAT12, FAT16 and FAT32 differ mainly in how wide those entries are. It has no permissions, no journal and a file size limit of 4 GB minus one byte, but it is simple enough to implement inside a boot sector, which is why UEFI insists on it.
Firmware
Software that lives in a chip on the board rather than on a disk, and runs before anything else does. On a PC it brings memory and buses up, runs the power-on self test — the POST, whose beep codes were once the only diagnostic you had — and then hands control to whatever it can find to boot. Modern boards keep it in an SPI flash chip of 8 to 32 MB.
GDT
The Global Descriptor Table: an array of eight-byte descriptors defining the segments a protected-mode processor may use. Entry zero must be null, and loading it deliberately raises a fault. You point the processor at the table with lgdt and a six-byte structure holding a 16-bit limit and a 32-bit base; a selector is then an index shifted left by three, with the low bits carrying the requested privilege. A minimal table has three entries: null, code, data.
GPT
The GUID Partition Table, part of the UEFI specification and the replacement for the MBR. LBA 0 holds a protective MBR so that old tools see one large unknown partition instead of empty space; LBA 1 holds the header; entries follow, 128 bytes each and 128 of them by default. Everything is CRC32-checked and a full copy sits at the end of the disk. Partitions are named by type GUID rather than by a single byte.
GRUB
The GRand Unified Bootloader, the second stage on most Linux installations. Its first sector sits in the MBR and does nothing but load core.img, which lives in the gap between the MBR and the first partition — 62 sectors on old layouts, usually 2047 today — and that in turn reads filesystems well enough to find /boot/grub/grub.cfg and your kernel. GRUB 2 also speaks Multiboot, so it can start systems that are not Linux.
Guest
The operating system running inside the virtual machine, as opposed to the host, which runs the emulator. A guest is written for hardware and normally has no way of knowing it is emulated; it finds out only by probing for paravirtual devices or reading the CPUID vendor string. Here the guest is whatever image you booted, and the host is your browser tab.
Host
The system running the emulator, as opposed to the guest running inside it. Here the host is your browser, and behind it your real operating system and processor. The distinction matters whenever something looks slow or wrong: a guest that prints a clock speed at boot has measured the emulator against an emulated timer, not the processor on your desk.
Hypervisor
The layer that creates and runs virtual machines and mediates their access to hardware. Type 1 runs on bare metal (Xen, ESXi, KVM in practice); type 2 runs as a program on an ordinary operating system (VirtualBox, VMware Workstation). Popek and Goldberg set out the formal requirements in 1974. v86 is a type 2 hypervisor whose host operating system happens to be a browser tab.
initramfs
A compressed cpio archive — the newc format, from an archiver older than tar's dominance — that the kernel unpacks into rootfs, a small tmpfs, and then runs /init from. Nothing has to be mounted and no filesystem driver is required, which is the whole advantage over initrd. Its usual job is to load modules and pivot to the real root; on a browser machine it is often the entire system.
initrd
The older of the two early-userspace mechanisms: a complete filesystem image, gzipped, that the kernel exposes as a ramdisk block device and then mounts. Because it is a filesystem, the kernel needs a driver for it compiled in, and its size is fixed when it is built. Superseded by initramfs during the 2.6 series, though the file on your boot partition is usually still called initrd.img.
Inode
The structure holding everything about a Unix file except its name: size, owner, permissions, timestamps and where the data lives — as a list of blocks in ext2, as extents in ext4, which describe runs of contiguous blocks instead. Names live in directories and point at inodes, so two names can share one file. Their number is fixed when the filesystem is created, so a disk with free space can still refuse to create a file.
INT 13h
The BIOS disk service, and the only way a boot sector can read anything at all. AH=02h reads sectors by cylinder, head and sector into a buffer at ES:BX; AH=42h is the later extension that takes a packet with a 64-bit LBA and lifts the 8.4 GB ceiling. A bootloader that must still work on a 1990s machine calls the first form, one sector at a time.
Interrupt
A signal that makes the processor stop, save where it was and run a handler. Hardware interrupts arrive from devices through the PIC: a keypress, a timer tick, a finished disk read. Software interrupts are the int instruction, which is how real-mode code calls BIOS services. Exceptions are the processor complaining. Without them a system would have to poll everything, and the timer interrupt is what makes pre-emptive multitasking possible at all.
ISO
A CD or DVD image in ISO 9660 format: 2048-byte sectors, a primary volume descriptor at sector 16, and read-only by nature, which is why live systems ship this way. Booting from one uses the El Torito extension of 1995, in which a boot catalog points either at a floppy image the BIOS pretends is drive A, or at a no-emulation sector the firmware loads directly.
IVT
The Interrupt Vector Table: the first 1024 bytes of memory in real mode, holding 256 entries of four bytes each, a segment and an offset per interrupt. The pointer for INT 13h sits at address 0x4C. Nothing protects it, so a stray write can redirect the disk service, and DOS-era software hooked it on purpose. The BIOS Data Area follows immediately at 0x400 with the equipment list and the tick count.
JIT
Just-in-time compilation. Rather than interpreting guest instructions one at a time, the emulator cuts hot code into basic blocks — straight runs of instructions ending in a jump — translates each block once into a WebAssembly function, and reuses it. Cold code stays interpreted. It is why an emulated machine visibly speeds up a few seconds in, and why tight loops cost far less than sprawling code.
Journalling
Writing down what you are about to do before doing it, so that an interrupted write leaves a filesystem that can be repaired in seconds instead of scanned in full. ext3 added it to ext2 in 2001; ext4 journals metadata only by default, with data=ordered making sure data reaches the disk first. On an ephemeral machine none of this matters, which is one reason a browser VM feels quicker than it ought to.
Kernel
The core of an operating system: the part that manages memory, schedules processes, owns the hardware and is the only code running in ring 0. Everything else is a program that asks it for things through system calls. It is also the one component that cannot be restarted while the machine runs, which is why kernel bugs end in a panic rather than an error message.
LBA
Logical Block Addressing: number every sector from 0 and let the drive work out where it physically lives. It replaced CHS because geometry stopped being real once drives packed more sectors onto outer tracks. 28-bit LBA reaches 128 GB; LBA48, standardised in ATA-6 in 2003, reaches far beyond any disk you will meet. An MBR partition entry stores a 32-bit LBA, which is exactly why MBR disks stop at 2 TB.
Live system
An operating system that runs from removable media without being installed, unpacking itself into RAM and mounting a read-only image as its root. Knoppix made the idea ordinary from 2000 onwards. Because a live system already expects a disk it cannot write to and a clean state on every boot, it is by far the easiest kind of system to run in a browser.
Long mode
The 64-bit mode AMD added in 2003 and Intel adopted a year later. It requires paging to be enabled before you can enter it, discards segmentation almost entirely, and adds eight more general registers. v86 does not implement it, so a 64-bit kernel here either stops with a complaint about the processor or simply resets. Pick 32-bit images and the question never arises.
MBR
The Master Boot Record: the first sector of a disk, holding up to 446 bytes of code, four 16-byte partition entries at offset 0x1BE and the signature 0x55 0xAA at 0x1FE. Four primary partitions is all it can express — extended partitions are a chained hack around that — and its 32-bit sector counts stop at 2 TB. It has been the layout of PC disks since 1983, and it is still what most images here use.
Microkernel
A kernel design that keeps only scheduling, memory and message passing in privileged mode and runs drivers and filesystems as ordinary processes. A crashing driver takes nothing with it and can be restarted; the cost is that every operation crossing a boundary becomes a message rather than a call. MINIX 3, QNX, Redox and HelenOS are microkernels, and several of them boot here in a few seconds.
Monolithic kernel
A kernel design in which drivers, filesystems and the network stack all run inside the kernel's own address space in ring 0. Calls between them are ordinary function calls, which is fast; a faulty driver can corrupt anything at all, which is not. Linux is the canonical example, though loadable modules mean it is far less of an immovable block than the word suggests — most of a running Linux kernel arrived after boot.
musl
A small, permissively licensed C library, the alternative to glibc that Alpine Linux is built on. It produces genuinely static binaries and much smaller images, which matters when the whole system has to cross the network before it boots. The trade-off is that a program compiled against glibc will not simply run on it: same kernel, different library ABI, and even the dynamic loader sits at a different path.
Namespace (Linux)
The kernel mechanism that gives a process its own view of one global resource. There are eight kinds — mount, PID, network, IPC, UTS, user, cgroup and time — and each is entered through clone() or unshare(). A process in a fresh PID namespace sees itself as PID 1 and cannot see anything outside it. Namespaces are what make a container look like a whole machine.
NE2000
A Novell Ethernet card from around 1990, cloned so widely that nearly every operating system carries a driver for it — which is precisely why emulators still pretend to be one. v86 emulates it, but a browser cannot open a raw socket, so packets must be tunnelled to a WebSocket relay before anything reaches the network. Guest networking here is experimental, and on most machines simply absent.
Option ROM
Firmware carried on an expansion card rather than on the motherboard. During boot the BIOS scans memory from 0xC0000 to 0xDFFFF in 2 KB steps looking for the signature 0x55 0xAA, and calls the entry point three bytes later. The VGA BIOS at 0xC0000 is one of these; network boot ROMs are another. It is how a 1981 firmware learned to drive hardware invented after it.
Paging
The mechanism that maps virtual addresses onto physical ones in 4 KB pages, so each process gets its own address space and cannot see anyone else's. On 32-bit x86 the map has two levels: CR3 points at a page directory of 1024 entries, each naming a page table of 1024 more. Translations are cached in the TLB, which is why writing CR3 during a context switch is expensive, and why invlpg exists to invalidate a single entry instead.
Paravirtualisation
Virtualisation in which the guest knows it is virtualised and cooperates, replacing imitated hardware with a direct channel to the hypervisor. Xen made the idea mainstream in 2003; the virtio drivers are its modern form. Emulating an NE2000 card faithfully means simulating a chip designed in 1990, register by register; a paravirtual device posts buffers on a shared ring and skips the theatre entirely.
PIC (8259)
The Programmable Interrupt Controller: two 8259 chips cascaded to give sixteen interrupt lines. The master answers at ports 0x20 and 0x21, the slave at 0xA0 and 0xA1, and IRQ2 carries the slave. By default IRQ0 to IRQ7 arrive as interrupts 0x08 to 0x0F, which collide with the processor's own exceptions, so one of the first jobs of a protected-mode kernel is to remap them to 0x20-0x2F. Every handler must end by writing 0x20 back to the chip.
PIT (8253)
The Programmable Interval Timer, an 8253 or 8254 driven at 1.193182 MHz — one twelfth of the 14.31818 MHz colour-burst crystal the original PC already carried. Channel 0 raises IRQ0, and the default divisor of 65536 gives the familiar 18.2 ticks per second. Its ports are 0x40 to 0x43. Guests calibrate delay loops against it, which is why an emulated timer that drifts makes a guest believe the wrong speed.
Privilege ring
The four privilege levels x86 defines, 0 to 3, checked on every memory access and every privileged instruction. Kernels use ring 0 and user programs ring 3; rings 1 and 2 have been nearly unused since OS/2, with Xen's 32-bit paravirtual guests as the famous exception. When a Linux process traps into the kernel that transition is a ring change, and it is why a system call costs more than a function call.
Protected mode
The 32-bit x86 mode with memory protection, privilege levels and optional paging, introduced by the 386 in 1985 (the 286 had a 16-bit version nobody enjoyed). You enter it by loading a GDT and setting bit 0 of CR0, then far-jumping to flush the prefetch queue. Every serious kernel switches within a few hundred instructions of taking control, and never goes back.
PS/2
The keyboard and mouse interface IBM introduced with the PS/2 line in 1987, and still the way firmware and small systems read input. An 8042 controller sits at ports 0x60 and 0x64, keyboard on IRQ1 and mouse on IRQ12, delivering scancodes rather than characters — turning those into letters is the operating system's job. USB keyboards are usually made to look like this at boot, and it is what the emulator here presents.
Range request
An HTTP request for part of a file — Range: bytes=0-511 — answered with status 206 and those bytes alone. Because a booting system touches only a small fraction of a disk, a server that advertises Accept-Ranges lets a 1 GB image start after a few megabytes have crossed the network, with later sectors fetched as they are read. Without range support the whole file must arrive first.
Real mode
The 16-bit mode every x86 processor still starts in, for compatibility with the 8086 of 1978. An address is a segment and an offset combined as segment times sixteen plus offset, giving twenty bits and 1,048,576 bytes. There is no protection and no privilege: any program can write anywhere, including the interrupt table at address zero. Firmware and boot sectors live here; almost nothing else does.
Reset vector
The address an x86 processor executes first after reset: physical 0xFFFFFFF0, sixteen bytes below the top of the 4 GB address space, reached through a hidden segment base that survives until the first far jump. There is room for one instruction there, and it is always a jump into the firmware proper. Every boot on every PC since the 386 has started at that address.
Rolling release
A distribution with no versions: packages are updated continuously and there is never a release to upgrade to. Arch Linux is the model — pacman -Syu and you are current. It keeps software new at the price of the occasional manual intervention, and it makes any stored snapshot of such a system stale within weeks, which is worth knowing before you trust a pre-booted image of one.
Root filesystem
The filesystem mounted at / — the one everything else hangs off. The kernel must find it before it can run a single program, which it does from the root= parameter on its command line; failing that it stops with VFS: Unable to mount root fs on unknown-block(0,0). Here it may come from a disk image, from an initramfs unpacked into memory, or over 9p from a web server.
SeaBIOS
The open-source BIOS implementation used by QEMU, KVM, coreboot and v86. It provides the same real-mode services as an IBM BIOS from 1981 — INT 10h for video, INT 13h for disk, INT 16h for keyboard — but written as ordinary C compiled down to 16-bit code. When a machine here prints a line or two before the guest takes over, that is SeaBIOS talking.
Sector
The smallest unit a disk will read or write: 512 bytes since the 1980s, and still 512 as far as software is concerned even on Advanced Format drives that use 4096 internally and translate. Everything above is built on that number — partition tables count sectors, filesystems group them into clusters — and a block device is simply one that must be addressed in whole sectors rather than byte by byte.
Secure Boot
A UEFI feature that refuses to run a boot executable unless it is signed by a key in the firmware's db list, with revoked keys held in dbx. In practice nearly every machine trusts one Microsoft certificate, so Linux distributions ship a small signed shim that then loads their own bootloader. None of it applies to a BIOS machine, and none of it applies here.
Segment
A region of memory named by a selector rather than by a plain address. In real mode a segment is simply an address divided by sixteen; in protected mode the selector indexes the GDT, and the descriptor found there carries a base, a limit and permissions. Nearly every modern system uses the flat model — every segment based at zero with a 4 GB limit — so that segmentation exists on paper while paging does the real work.
Serial console
A terminal delivered over a serial port instead of a screen and keyboard. COM1 sits at port 0x3F8 on IRQ4, and adding console=ttyS0,115200 to a Linux command line sends every kernel message there. It costs almost nothing to emulate, survives a broken graphics driver, and produces text you can copy — which makes it the most useful window onto a machine that will not finish booting.
Snapshot
A complete capture of a running machine — registers, memory, device state and modified disk sectors — that can be restored later to resume exactly where it left off, mid-command if you like. It is not a backup of your files; it is a photograph of the whole machine, and it will only restore into the same emulator with the same devices attached.
tmpfs
A Linux filesystem that lives in RAM, backed by the page cache and able to spill into swap. It has no on-disk format at all, which is why df reports a size for it but fsck has nothing to check. /run and usually /tmp are tmpfs mounts, and an initramfs is unpacked into one. On an ephemeral machine, effectively the entire system is tmpfs.
UEFI
The modern replacement for the BIOS: a small operating system in firmware that reads a FAT partition, loads a PE executable and calls it with a table of services. It boots from files rather than from a magic 512 bytes, handles disks beyond 2 TB through GPT, and can require signatures. It is not emulated here, so systems that insist on it have nothing to boot from.
v86
The open-source x86 emulator this site runs on, developed at github.com/copy/v86. It emulates a 32-bit PC — processor, PIC, PIT, PS/2 controller, VGA, IDE, floppy, NE2000 and virtio — and compiles hot guest code to WebAssembly while the machine runs. It implements neither long mode nor UEFI, and those two absences decide most of what will and will not boot here.
VGA
The graphics standard IBM shipped in 1987 that every PC still supports at power-on. Text mode writes to a buffer at 0xB8000, two bytes per cell — a character and a colour attribute — across 80 columns and 25 rows; mode 13h gives 320 by 200 in 256 colours at 0xA0000. The card emulated here is a plain framebuffer with no acceleration, so anything expecting a modern GPU falls back to software rendering or gives up.
virtio
A family of paravirtual devices — disk, network, console, filesystem — that skip hardware imitation and pass buffers through shared rings both guest and hypervisor understand. Introduced by Rusty Russell around 2007 and now present in every serious hypervisor. v86 uses virtio to carry 9p, which is how a machine here can mount a root filesystem served over HTTP instead of reading a disk image.
Virtual machine
A computer built out of software: an emulated processor, memory, disk and display, on which an unmodified operating system can run. The guest cannot tell the difference, because every register, port and interrupt it touches is answered by code rather than by silicon. Here the whole machine lives in one browser tab and vanishes when that tab closes.
Virtualisation
Running guest code directly on the host processor with hardware assistance — Intel VT-x and AMD-V, both shipped around 2005 — rather than simulating each instruction. It often comes within a few per cent of native speed, but guest and host must share an architecture, and a browser exposes no such instructions to a web page. That is why this site emulates instead.
WebAssembly
A low-level binary format that browsers execute at close to native speed, standardised as version 1.0 in 2017 and shipped by every major engine. Its memory is a single resizable ArrayBuffer, so the whole of a guest's RAM is one flat block of bytes that JavaScript can also read. That is what makes emulating a processor in a tab practical rather than merely possible.
x86
The processor architecture that has run PCs since the 8086 of 1978, widened to 32 bits by the 386 in 1985 and to 64 by AMD in 2003. Distributions that say i386 usually mean i686 in practice — the Pentium Pro generation of 1995, which added CMOV — and will fault on anything older. Here it is emulated in its 32-bit form, so 64-bit code will not run.
zstd
A compression format released by Facebook in 2016 and specified in RFC 8878, chosen here for decompression speed rather than for ratio. The pre-booted snapshots in the catalog are stored this way and unpacked by the emulator as it loads them, which is why a machine can appear already logged in and idle a few seconds after you click it.