I-O Virtualization - Emulation PV and Passthrough
Definition
I/O virtualization gives guests controlled access to networking, storage, and other devices. The lecture compares device emulation, paravirtualized devices, and direct assignment.
Comparison
| Approach | Guest driver | How access works | Main tradeoff |
|---|---|---|---|
| Device emulation | Ordinary driver for the modeled device | Software implements the expected hardware interface | Compatible and shareable, but extra CPU work and latency |
| PV device | Dedicated virtualization-aware driver | Guest frontend cooperates with host backend | Efficient interface, needs driver support |
| Direct assignment / passthrough | Ordinary driver for the assigned device | Guest controls the allocated physical device | Less mediation, limited sharing and mobility |
Study example: the same physical NIC can back several emulated or PV interfaces. Assigning that entire NIC directly to one VM excludes other guests from using it in the lecture’s basic model.
DMA and the IOMMU
A device performs Direct Memory Access using addresses supplied for its transfers. Guest physical addresses are not automatically real host physical addresses. Uncontrolled DMA can corrupt another guest’s or the host’s memory.
The IOMMU remaps device-visible addresses and constrains DMA to permitted memory. It solves an I/O-address/isolation problem; CPU EPT/NPT solves the processor’s address-translation problem. Their tables and programming interfaces should not be assumed identical merely because the lecture compares their roles.
SR-IOV
Supporting PCIe hardware exposes virtual functions (VFs) that can be assigned to different VMs. The device handles multiplexing, relaxing the whole-device exclusivity limitation.
Study clarification: SR-IOV supplies assignable hardware functions; the IOMMU supplies DMA translation/protection. They address different requirements and may be used together.
Important rules
- A guest can combine emulated, PV, and assigned devices.
- PV devices do not require converting every part of the OS to classical PV.
- Direct assignment changes which state and resources must be managed during migration.
- The slide’s speed ordering is a design tradeoff, not a universal benchmark for every device/workload.
Common mistakes
- Assuming passthrough automatically preserves safe DMA boundaries.
- Equating an SR-IOV VF with a purely software-emulated NIC.
- Assuming the lowest mediation overhead always gives the best overall deployment choice.
Related: Paravirtualization and Hypercalls, Virtio Virtqueues and vhost-net, Memory Virtualization - Shadow Page Tables and EPT, VM Migration - Cold Hot and Live.
Source
Lecture 03 PDF pages 52-63 (printed slides 55-66). Context: Lecture 03 - Computing Virtualization Technologies and Tools. Examples, separation of IOMMU/SR-IOV roles, and cautions are study explanations.