5 ms·
I didn't realise you can use direct hardware access in a VM! (Other than HDD) That'd be pretty good
by malbs 11y ago
I didn't realise you can use direct hardware access in a VM! (Other than HDD)
That'd be pretty good
- glogla 11y agoYou can, but only on AMD GPUs. Nvidia GPUs have this disable unless you buy very expensive "cloud" model.
- otis_inf 11y agoYeah I ran into that wall 2 weeks ago. I tried to switch to Linux for the host and run my Windows 8 VMs in VMWare on Mint. After fighting with the nvidia drivers at install for a bit I got it working but VMWare using dual monitors is super slow on nvidia (780 here) in mint: the windows in the guest VM were drawn as if it was done by a single core on half the speed, instead of on the GPU. Single monitor, no problem. Had to roll back to windows for the host to make the VMs work nicely. A bummer, considering moving away from Windows takes that first step and I now have to stick around for longer. Perhaps next year...
- dale-cooper 11y agoNot true, you can work around this. I'm running a 970 gtx in a vm. See https://bbs.archlinux.org/viewtopic.php?id=162768 https://bbs.archlinux.org/viewtopic.php?id=162768
- JoachimS 11y agoDidn't know you could do it either. And the security aware (paranoid) part of me screams loudly when reading this. ;-)
- wtallis 11y agoThe IOMMU hardware ensures security of the VM's raw device access while the VM is running. The only significant security risk I'm aware of is if the VM has a chance to update some firmware (like an option ROM) on the device you give it access to, which may enable it to do evil things when the host system next reboots.
- scrupulusalbion 11y agoNot all new hardware provides IOMMU. For instance, the i7-4770K does not have the VT-d extension, which is Intel's version of IOMMU. [1] [1] = http://ark.intel.com/products/75123/Intel-Core-i7-4770K-Processor-8M-Cache-up-to-3_90-GHz http://ark.intel.com/products/75123/Intel-Core-i7-4770K-Proc...
- wtallis 11y agoRight, Intel's an ass about product segmentation. But most hypervisors don't offer the option of doing any sort of PCI passthrough without a functional IOMMU, so they're not accidentally exposing anyone.
- scrupulusalbion 11y agoIt would be sensible for hypervisors to require IOMMU for all PCI passthrough, but it looks like Xen allows it without IOMMU for paravirtualised guests: "VT-d Pass-Through is a technique to give a domU exclusive access to a PCI function using the IOMMU provided by VT-d. It is primarily targeted at HVM (fully virtualised) guests because PV (paravirtualized) pass-through does not require VT-d (altough it may be utilized too)."[1] [1] = http://wiki.xenproject.org/wiki/VTd_HowTo http://wiki.xenproject.org/wiki/VTd_HowTo
- deleted 11y ago[deleted]