Virtual Machines and Hypervisors
Definitions
| Term | Role in the lecture’s model |
|---|---|
| Physical host | The real machine providing CPU, memory, NICs, and storage |
| Host OS | The OS managing the physical machine in the illustrated architecture |
| Hypervisor / VMM | The layer controlling virtualization and VM resource access |
| Virtual machine | An environment exposing virtual hardware to a guest OS and applications |
| Guest OS | The operating system inside a VM |
Slide 24 architecture
VM 1 VM 2 VM 3
Guest OS + apps Guest OS + apps Guest OS + apps
Virtual hardware Virtual hardware Virtual hardware
Hypervisor / VMM
Host OS
Physical CPU/cache, memory, NICs, storageStudy clarification: the slide illustrates one stack. A conventional host OS is not a universal requirement for every hypervisor architecture. Lecture 02 does not develop a separate hypervisor-type taxonomy; Lecture 03 does, in Hypervisor Architectures.
Partitioning versus arbitration
The hypervisor must enforce boundaries and control access:
- Partitioning: assign separate resources where possible. The lecture gives disjoint memory regions as an example.
- Arbitration: mediate access to a shared resource that is not simply allocated as disjoint pieces. The lecture gives a single NIC shared by VMs as an example.
Study example: three VMs can receive separate memory allocations while their network traffic is mediated through the same physical NIC.
Host environment and devices
Slide 26 describes a host OS that is often stripped down and Linux-based, with native drivers for physical hardware. The virtualization layer exports standard devices to guests, reducing the range of hardware the guest must support. Special hardware can be harder to expose, as slide 16 notes.
Important rules / study clarification
- Virtual hardware is an interface presented to the guest; it is backed by physical resources.
- The host and hypervisor remain part of the security boundary and can themselves be attacked.
- Smaller host software can reduce the amount to defend, but does not eliminate risk.
- The initial description of an unaware guest is qualified by the later paravirtualization model.
Common mistakes
- Confusing the host OS with a guest OS.
- Assuming each virtual NIC requires a separate physical NIC.
- Assuming VM separation alone eliminates resource contention.
Related concepts
- Hypervisor Architectures
- QEMU and KVM
- Memory Virtualization - Shadow Page Tables and EPT
- I-O Virtualization - Emulation PV and Passthrough
- Computing Virtualization
- VM Isolation and Server Consolidation
- x86 Virtualization Techniques
- COTS Hardware and OEM vs ODM
Source
Fulvio Risso, Introduction to Computing Virtualization, slides 16, 24-27. Lecture context: Lecture 02 - Introduction to Computing Virtualization. Sections marked as study clarification and the worked example add explanation to the source.
Virtual hardware profiles in Lecture 03
The virtual hardware profile defines the devices and resources visible to the guest. The VMM implements that profile even when it differs from the real hardware: the lecture’s example has one physical NIC from vendor X backing two virtual NICs from vendor Y. A profile describes an interface, not an independent supply of physical capacity.
Source: Lecture 03 - Computing Virtualization Technologies and Tools, PDF pages 4-6 (printed slides 5-7). Follow Libvirt virsh and virt-manager for the later XML-profile example.