Diff for /wikisrc/ports/xen/howto.mdwn between versions 1.195 and 1.204

version 1.195, 2021/03/03 15:03:13 version 1.204, 2021/03/15 00:25:54
Line 1 Line 1
 [[!meta title="Xen HowTo"]]  [[!meta title="Xen Status and HowTo"]]
   
 Xen is a Type 1 hypervisor which supports running multiple guest operating  Xen is a Type 1 hypervisor which supports running multiple guest operating
 systems on a single physical machine. One uses the Xen kernel to control the  systems on a single physical machine. One uses the Xen kernel to control the
Line 8  systems which operate in an unprivileged Line 8  systems which operate in an unprivileged
 from the domU systems are forwarded by the Xen hypervisor to the dom0 to be  from the domU systems are forwarded by the Xen hypervisor to the dom0 to be
 fulfilled.  fulfilled.
   
 This HOWTO presumes a basic familiarity with the Xen system  This document provides status on what Xen things work on NetBSD
 architecture, with installing NetBSD on amd64 hardware, and with  (upstream documentation might say something works if it works on some
 installing software from pkgsrc.  See also the [Xen  particular Linux system).
   
   This document is also a HOWTO that presumes a basic familiarity with
   the Xen system architecture, with installing NetBSD on amd64 hardware,
   and with installing software from pkgsrc.  See also the [Xen
 website](http://www.xenproject.org/).  website](http://www.xenproject.org/).
   
   If this document says that something works, and you find that it does
   not, it is best to ask on port-xen and if you are correct to file a
   PR.
   
 [[!toc]]  [[!toc]]
   
 # Overview  # Overview
   
 The basic concept of Xen is that the hypervisor (xenkernel) runs on  The basic concept of Xen is that the hypervisor (xenkernel) runs on
 the hardware, and runs a privileged domain ("dom0") that can access  the hardware, and runs a privileged domain ("dom0") that can access
 disks/networking/etc.  One then runs additonal unprivileged domains  disks/networking/etc.  One then runs additional unprivileged domains
 (each a "domU"), presumably to do something useful.  (each a "domU"), presumably to do something useful.
   
 This HOWTO addresses how to run a NetBSD dom0 (and hence also build  This HOWTO addresses how to run a NetBSD dom0 (and hence also build
Line 35  approach and limits discussion of altern Line 43  approach and limits discussion of altern
 Xen supports different styles of guests.  Xen supports different styles of guests.
   
 [[!table data="""  [[!table data="""
 Style of guest  |Supported by NetBSD  Style of guest  |description                            |NetBSD dom0?   |NetBSD domU?
 PV              |Yes (dom0, domU)  PV              |Paravirtualization (hypercalls)        |yes            |yes
 HVM             |Yes (domU)  HVM             |unmodified guest - domU perceives HW   |can run guests |yes
 PVHVM           |current-only (domU)  PVHVM           |Like HVM but also PV drivers           |can run guests |current only
 PVH             |current-only (domU, dom0 not yet)  PVH             |Lightweight HVM (no qemu) and PV       |not yet        |current only
 """]]  """]]
   
 In Para-Virtualized (PV) mode, the guest OS does not attempt to access  In Para-Virtualized (PV) mode, the guest OS does not attempt to access
Line 49  See [PV](https://wiki.xen.org/wiki/Parav Line 57  See [PV](https://wiki.xen.org/wiki/Parav
   
 In HVM mode, no guest modification is required; however, hardware  In HVM mode, no guest modification is required; however, hardware
 support is required, such as VT-x on Intel CPUs and SVM on AMD CPUs.  support is required, such as VT-x on Intel CPUs and SVM on AMD CPUs.
 The dom0 runs qemu to emulate hardware.  The dom0 runs qemu to emulate hardware.  It is therefore non-sensical
   to have an HVM dom0.
   
 In PVHVM mode, the guest runs as HVM, but additionally can use PV  In PVHVM mode, the guest runs as HVM, but additionally can use PV
 drivers for efficiency.  drivers for efficiency.  Therefore it is non-sensical for to have a
 See [PV on HVM](https://wiki.xen.org/wiki/PV_on_HVM).  PVHVM dom0.  See [PV on HVM](https://wiki.xen.org/wiki/PV_on_HVM).
   
 There have been two PVH modes: original PVH and PVHv2.  Original PVH  There have been two PVH modes: original PVH and PVHv2.  Original PVH
 was based on PV mode and is no longer relevant at all.  PVHv2 is  was based on PV mode and is no longer relevant at all.  Therefore
 basically lightweight HVM with PV drivers.  A critical feature of it  PVHv2 is abreviated PVH.  PVHv2 is basically lightweight HVM with PV
 is that qemu is not needed; the hypervisor can do the emulation that  drivers.  A critical feature of it is that qemu is not needed; the
 is required.  Thus, a dom0 can be PVHv2.  hypervisor can do the emulation that is required.  Thus, a dom0 can be
 The source code uses PVH and config files use pvh; this refers to PVHv2.  PVHv2.  The source code uses PVH and config files use pvh, but NB that
 See [PVH(v2)](https://wiki.xenproject.org/wiki/PVH_(v2\)_Domu).  this refers to PVHv2.  See
   [PVH(v2)](https://wiki.xenproject.org/wiki/PVH_(v2\)_Domu).
   
 At system boot, the dom0 kernel is loaded as a module with Xen as the kernel.  At system boot, the dom0 kernel is loaded as a module with Xen as the kernel.
 The dom0 can start one or more domUs.  (Booting is explained in detail  The dom0 can start one or more domUs.  (Booting is explained in detail
Line 75  There is a concept of Xen running on ARM Line 85  There is a concept of Xen running on ARM
   
 The dom0 system should be amd64.  (Instructions for i386PAE dom0 have been removed from the HOWTO.)  The dom0 system should be amd64.  (Instructions for i386PAE dom0 have been removed from the HOWTO.)
   
 The domU can be i386PAE or amd64.  The domU can be i386 PAE or amd64.
 i386PAE at one point was considered as [faster](https://lists.xen.org/archives/html/xen-devel/2012-07/msg00085.html) than amd64.  i386 PAE at one point was considered as [faster](https://lists.xen.org/archives/html/xen-devel/2012-07/msg00085.html) than amd64.
   However, as of 2021 it is normal to use amd64 as the domU architecture, and use of i386 is dwindling.
   
 ## Xen Versions  ## Xen Versions
   
Line 95  Xen Version |Package Name |Xen CPU Suppo Line 106  Xen Version |Package Name |Xen CPU Suppo
   
 See also the [Xen Security Advisory page](http://xenbits.xen.org/xsa/).  See also the [Xen Security Advisory page](http://xenbits.xen.org/xsa/).
   
 Older Xen had a python-based management tool called xm, now replaced  Older Xen had a python-based management tool called xm; this has been
 by xl.  replaced by xl.
   
 ## NetBSD versions  ## NetBSD versions
   
 Xen has been supported in NetBSD for a long time, at least since 2005.  Xen has been supported in NetBSD for a long time, at least since 2005.
 Initially Xen was PV only.  Initially Xen was PV only.
   
 NetBSD 8 and up support PV and HVM modes.  NetBSD Xen has always supported PV, in both dom0 and domU; for a long
   time this was the only way.  NetBSD >=8 as a dom0 supports HVM mode in
 Support for PVHVM and PVH is available only in NetBSD-current.  domUs (HVM as a dom0 does not make sense).
   
 NetBSD up to and including NetBSD 9 as a dom0 does not run SMP,  Support for PVHVM and PVH is available only in NetBSD-current; this is
 because some drivers are not yet safe for this.  NetBSD-current  currently somewhat experimental, although PVHVM appears reasonably
 supports SMP in dom0.  solid.
   
 NetBSD, when run as a domU, can and does typically run SMP.  NetBSD up to and including NetBSD 9 as a dom0 cannot safely run SMP.
   Even if one added "options MULTIPROCESSOR" and configured multiple
   vcpus, the kernel is likely to crash because of drivers without
   adequate locking.
   
   NetBSD-current supports SMP in dom0, and XEN3_DOM0 includes "options
   MULTIPROCESSOR".
   
   NetBSD (since NetBSD 6), when run as a domU, can run SMP, using
   multiple CPUs if provided.  The XEN3_DOMU kernel is built
   with "options MULITPROCESSOR".
   
 Note that while Xen 4.13 is current, the kernel support is still  Note that while Xen 4.13 is current, the kernel support is still
 called XEN3, because the hypercall interface has not changed  called XEN3, because the hypercall interface has not changed
Line 160  ftp.netbsd.org/pub/NetBSD/NetBSD-9.1/amd Line 181  ftp.netbsd.org/pub/NetBSD/NetBSD-9.1/amd
   
 ### Configuring booting  ### Configuring booting
   
 Read boot.cfg(8) carefully.  Add lines to /boot.cfg to boot Xen:  Read boot.cfg(8) carefully.  Add lines to /boot.cfg to boot Xen,
   adjusting for your root filesystem:
   
 [[!template id=filecontent name="/boot.cfg" text="""  [[!template id=filecontent name="/boot.cfg" text="""
 menu=Xen:load /netbsd-XEN3_DOM0.gz console=pc;multiboot /xen.gz dom0_mem=512M  menu=Xen:load /netbsd-XEN3_DOM0.gz root=wd0a console=pc;multiboot /xen.gz dom0_mem=512M
 menu=Xen single user:load /netbsd-XEN3_DOM0.gz console=pc -s;multiboot /xen.gz dom0_mem=512M  menu=Xen single user:load /netbsd-XEN3_DOM0.gz root=wd0a console=pc -s;multiboot /xen.gz dom0_mem=512M
 """]]  """]]
   
 This specifies that the dom0 should have 512MB of ram, leaving the rest  This specifies that the dom0 should have 512MB of ram, leaving the rest
Line 179  fixing problems is the standard prudent  Line 201  fixing problems is the standard prudent 
 \todo Explain why rndseed is not set with Xen as part of the dom0  \todo Explain why rndseed is not set with Xen as part of the dom0
 subconfiguration.  subconfiguration.
   
   Note that you are likely to have to set root= because the boot device
   from /boot is not passed via Xen to the dom0 kernel.  With one disk,
   it will work, but e.g. plugging in USB disk to a machine with root on
   wd0a causes boot to fail.
   
 Beware that userconf statements must be attached to the dom0 load, and  Beware that userconf statements must be attached to the dom0 load, and
 may not be at top-level, because then they would try to configure the  may not be at top-level, because then they would try to configure the
 hypervisor, if there is a way to pass them via multiboot .  It appears  hypervisor, if there is a way to pass them via multiboot .  It appears
Line 211  console input. Line 238  console input.
   
 The hypervisor can be configured to use a serial port console, e.g.  The hypervisor can be configured to use a serial port console, e.g.
 [[!template id=filecontent name="/boot.cfg" text="""  [[!template id=filecontent name="/boot.cfg" text="""
 menu=Xen:losad /netbsd-XEN3_DOM0.gz console=com0;multiboot /xen.gz dom0_mem=512M console=com1 com1=9600,8n1  menu=Xen:load /netbsd-XEN3_DOM0.gz console=com0;multiboot /xen.gz dom0_mem=512M console=com1 com1=9600,8n1
 """]]  """]]
 This example uses the first serial port (Xen counts from 1; this is  This example uses the first serial port (Xen counts from 1; this is
 what NetBSD would call com0), and sets speed and parity.  (The dom0 is  what NetBSD would call com0), and sets speed and parity.  (The dom0 is
Line 355  the dom0.  NetBSD's /dev/random system w Line 382  the dom0.  NetBSD's /dev/random system w
   
 ## Config files  ## Config files
   
 See /usr/pkg/share/examples/xen/xlexample*  See /usr/pkg/share/examples/xen/xlexample* for a very small number of
 for a small number of well-commented examples, mostly for running  examples for running GNU/Linux.
 GNU/Linux.  
   
 The following is an example minimal domain configuration file. The domU  The following is an example minimal domain configuration file. The domU
 serves as a network file server.  serves as a network file server.
Line 380  are stored in files and Xen attaches the Line 406  are stored in files and Xen attaches the
 dom0 on domain creation.  The system treats xbd0 as the boot device  dom0 on domain creation.  The system treats xbd0 as the boot device
 without needing explicit configuration.  without needing explicit configuration.
   
 There is not type line; that implicitly defines a pv domU.  There is not type line; that implicitly defines a pv domU.  Otherwise,
   one sets type to the lower-case version of the domU type in the table
   above, e.g. `type = "hvm"`.
   
 By convention, domain config files are kept in `/usr/pkg/etc/xen`.  Note  By convention, domain config files are kept in `/usr/pkg/etc/xen`.  Note
 that "xl create" takes the name of a config file, while other commands  that "xl create" takes the name of a config file, while other commands
Line 412  file by "memory = N" (in megabytes).  In Line 440  file by "memory = N" (in megabytes).  In
 sum of the the memory allocated to the dom0 and all domUs must be less  sum of the the memory allocated to the dom0 and all domUs must be less
 than the available memory.  than the available memory.
   
 Xen also provides a "balloon" driver, which can be used to let domains  ## Balloon driver
 use more memory temporarily.  
   Xen provides a `balloon` driver, which can be used to let domains use
   more memory temporarily.
   
   \todo Explain how to set up a aystem to use the balloon scheme in a
   useful manner.
   
 ## Virtual disks  ## Virtual disks
   
Line 572  missing with Xen.) Line 605  missing with Xen.)
 Note that NetBSD by default creates only xbd[0123].  If you need more  Note that NetBSD by default creates only xbd[0123].  If you need more
 virtual disks in a domU, run e.g. "./MAKEDEV xbd4" in the domU.  virtual disks in a domU, run e.g. "./MAKEDEV xbd4" in the domU.
   
 ## Creating a Linux domU  ## Creating a Linux PV domU
   
 Creating unprivileged Linux domains isn't much different from  Creating unprivileged Linux domains isn't much different from
 unprivileged NetBSD domains, but there are some details to know.  unprivileged NetBSD domains, but there are some details to know.
Line 617  tty to the xen console. Line 650  tty to the xen console.
   
 ## Creating a NetBSD HVM domU  ## Creating a NetBSD HVM domU
   
 Use type='hmv', probably.  Use a GENERIC kernel within the disk image.  Use type='hvm', probably.  Use a GENERIC kernel within the disk image.
   
 ## Creating a NetBSD PVH domU  ## Creating a NetBSD PVH domU
   
 Use type='pvh'.  This only works with a current kernel in the domU.
   
   Use type='pvh'.  Probably, use a GENERIC kernel within the disk image,
   which in current has PV support.
   
   \todo Verify.
   
 \todo Explain where the kernel comes from.  \todo Verify if one can have current PVH domU on a 9 dom0.
   
 ## Creating a Solaris domU  ## Creating a Solaris domU
   
Line 633  See possibly outdated Line 671  See possibly outdated
 ## PCI passthrough: Using PCI devices in guest domains  ## PCI passthrough: Using PCI devices in guest domains
   
 NB: PCI passthrough only works on some Xen versions and as of 2020 it  NB: PCI passthrough only works on some Xen versions and as of 2020 it
 is not clear that it works on any version in pkgsrc.  Reports  is not clear that it works on any version in pkgsrc.  \todo Reports
 confirming or denying this notion should be sent to port-xen@.  confirming or denying this notion should be sent to port-xen@.
   
 The dom0 can give other domains access to selected PCI  The dom0 can give other domains access to selected PCI

Removed from v.1.195  
changed lines
  Added in v.1.204


CVSweb for NetBSD wikisrc <wikimaster@NetBSD.org> software: FreeBSD-CVSweb