Part 6 · 1 chapters · ~8 min
Hypervisors and KVM
Type 1 and type 2 hypervisors, trap-and-emulate and hardware virtualisation (VT-x, AMD-V), KVM as a kernel module, the VMM in user space, VM exits, nested paging (EPT, NPT), virtio devices, live migration, and how cloud VMs are built (Nitro, KVM-based clouds).
7
The kernel as a hypervisor
code
// the KVM API in outline (C, Linux): every VMM starts like this
int kvm = open("/dev/kvm", O_RDWR);
int vm = ioctl(kvm, KVM_CREATE_VM, 0);
void *mem = mmap(NULL, 1 << 20, PROT_READ | PROT_WRITE, MAP_SHARED | MAP_ANONYMOUS, -1, 0);
struct kvm_userspace_memory_region region = { .slot = 0, .guest_phys_addr = 0, .memory_size = 1 << 20, .userspace_addr = (uint64_t)mem };
ioctl(vm, KVM_SET_USER_MEMORY_REGION, ®ion); // guest physical memory = this mapping
int vcpu = ioctl(vm, KVM_CREATE_VCPU, 0);
// copy guest code into mem, set registers, then loop:
for (;;) { ioctl(vcpu, KVM_RUN, 0); switch (run->exit_reason) { case KVM_EXIT_IO: /* emulate a port */ break; case KVM_EXIT_HLT: return 0; } }| container | VM | |
|---|---|---|
| kernel | shared with host | its own guest kernel |
| boundary | syscall interface (hundreds of syscalls) | virtual hardware (a few devices) |
| start time | milliseconds | seconds for a full VM; ~100 ms class for microVMs |
| density and overhead | highest | memory per guest kernel |
Nested paging (Intel EPT, AMD NPT) lets hardware translate guest addresses to host addresses without hypervisor help, which made VMs fast for memory-heavy work. AWS Nitro moved device emulation into dedicated hardware cards.
A VIRTUAL MACHINE WITH KVM
hardware virtualisation with the kernel as hypervisor
swipe the figure sideways, or tap expand for full screen
1/4
hardware support
Intel VT-x and AMD-V let a CPU run a guest kernel directly in a special mode, trapping only sensitive operations. KVM exposes this to Linux processes through /dev/kvm.
VT-x, AMD-V via /dev/kvmLinux becomes the hypervisor