Virtual Machines and Hypervisors

Definitions

TermRole in the lecture’s model
Physical hostThe real machine providing CPU, memory, NICs, and storage
Host OSThe OS managing the physical machine in the illustrated architecture
Hypervisor / VMMThe layer controlling virtualization and VM resource access
Virtual machineAn environment exposing virtual hardware to a guest OS and applications
Guest OSThe operating system inside a VM

Slide 24 architecture

  VM 1                VM 2                VM 3
  Guest OS + apps     Guest OS + apps     Guest OS + apps
  Virtual hardware   Virtual hardware   Virtual hardware
                  Hypervisor / VMM
                      Host OS
        Physical CPU/cache, memory, NICs, storage

Study clarification: the slide illustrates one stack. A conventional host OS is not a universal requirement for every hypervisor architecture. Lecture 02 does not develop a separate hypervisor-type taxonomy; Lecture 03 does, in Hypervisor Architectures.

Partitioning versus arbitration

The hypervisor must enforce boundaries and control access:

  • Partitioning: assign separate resources where possible. The lecture gives disjoint memory regions as an example.
  • Arbitration: mediate access to a shared resource that is not simply allocated as disjoint pieces. The lecture gives a single NIC shared by VMs as an example.

Study example: three VMs can receive separate memory allocations while their network traffic is mediated through the same physical NIC.

Host environment and devices

Slide 26 describes a host OS that is often stripped down and Linux-based, with native drivers for physical hardware. The virtualization layer exports standard devices to guests, reducing the range of hardware the guest must support. Special hardware can be harder to expose, as slide 16 notes.

Important rules / study clarification

  • Virtual hardware is an interface presented to the guest; it is backed by physical resources.
  • The host and hypervisor remain part of the security boundary and can themselves be attacked.
  • Smaller host software can reduce the amount to defend, but does not eliminate risk.
  • The initial description of an unaware guest is qualified by the later paravirtualization model.

Common mistakes

  • Confusing the host OS with a guest OS.
  • Assuming each virtual NIC requires a separate physical NIC.
  • Assuming VM separation alone eliminates resource contention.

Source

Fulvio Risso, Introduction to Computing Virtualization, slides 16, 24-27. Lecture context: Lecture 02 - Introduction to Computing Virtualization. Sections marked as study clarification and the worked example add explanation to the source.

Virtual hardware profiles in Lecture 03

The virtual hardware profile defines the devices and resources visible to the guest. The VMM implements that profile even when it differs from the real hardware: the lecture’s example has one physical NIC from vendor X backing two virtual NICs from vendor Y. A profile describes an interface, not an independent supply of physical capacity.

Source: Lecture 03 - Computing Virtualization Technologies and Tools, PDF pages 4-6 (printed slides 5-7). Follow Libvirt virsh and virt-manager for the later XML-profile example.