Part 6 · 1 chapters · ~8 min

Hypervisors and KVM

Type 1 and type 2 hypervisors, trap-and-emulate and hardware virtualisation (VT-x, AMD-V), KVM as a kernel module, the VMM in user space, VM exits, nested paging (EPT, NPT), virtio devices, live migration, and how cloud VMs are built (Nitro, KVM-based clouds).

7

The kernel as a hypervisor

code
// the KVM API in outline (C, Linux): every VMM starts like this
int kvm  = open("/dev/kvm", O_RDWR);
int vm   = ioctl(kvm, KVM_CREATE_VM, 0);
void *mem = mmap(NULL, 1 << 20, PROT_READ | PROT_WRITE, MAP_SHARED | MAP_ANONYMOUS, -1, 0);
struct kvm_userspace_memory_region region = { .slot = 0, .guest_phys_addr = 0, .memory_size = 1 << 20, .userspace_addr = (uint64_t)mem };
ioctl(vm, KVM_SET_USER_MEMORY_REGION, &region);           // guest physical memory = this mapping
int vcpu = ioctl(vm, KVM_CREATE_VCPU, 0);
// copy guest code into mem, set registers, then loop:
for (;;) { ioctl(vcpu, KVM_RUN, 0); switch (run->exit_reason) { case KVM_EXIT_IO: /* emulate a port */ break; case KVM_EXIT_HLT: return 0; } }
containerVM
kernelshared with hostits own guest kernel
boundarysyscall interface (hundreds of syscalls)virtual hardware (a few devices)
start timemillisecondsseconds for a full VM; ~100 ms class for microVMs
density and overheadhighestmemory per guest kernel

Nested paging (Intel EPT, AMD NPT) lets hardware translate guest addresses to host addresses without hypervisor help, which made VMs fast for memory-heavy work. AWS Nitro moved device emulation into dedicated hardware cards.

A VIRTUAL MACHINE WITH KVM
hardware virtualisation with the kernel as hypervisor
VMM (QEMU, Firecracker)user-space process/dev/kvmioctl: create VM, vCPUs, memoryguest kernel + appsruns directly on the CPUVM exitI/O, privileged instructiondevice emulationvirtio in the VMM
swipe the figure sideways, or tap expand for full screen
1/4
hardware support
Intel VT-x and AMD-V let a CPU run a guest kernel directly in a special mode, trapping only sensitive operations. KVM exposes this to Linux processes through /dev/kvm.
VT-x, AMD-V via /dev/kvmLinux becomes the hypervisor