Skip to content

[VFIO] Chapter 2, Section 5: Wire it all up - #6219

Open
ShadowCurse wants to merge 8 commits into
firecracker-microvm:feature/vfiofrom
ShadowCurse:vfio_part_2_5
Open

ShadowCurse wants to merge 8 commits into
firecracker-microvm:feature/vfiofrom
ShadowCurse:vfio_part_2_5

Conversation

@ShadowCurse

Copy link
Copy Markdown
Contributor

Changes

This PR finally wires all the parts of VFIO together and allows VM to boot with VFIO devices attached

License Acceptance

By submitting this pull request, I confirm that my contribution is made under
the terms of the Apache 2.0 license. For more information on following Developer
Certificate of Origin and signing off your commits, please check
CONTRIBUTING.md.

PR Checklist

  • I have read and understand CONTRIBUTING.md.
  • I have run tools/devtool checkbuild --all to verify that the PR passes
    build checks on all supported architectures.
  • I have run tools/devtool checkstyle --no-clippy to verify that the PR
    passes the automated style checks.
  • I have described what is done in these changes, why they are needed, and
    how they are solving the problem in a clear and encompassing way.
  • I have updated any relevant documentation (both in code and in the docs)
    in the PR.
  • I have mentioned all user-facing changes in CHANGELOG.md.
  • If a specific issue led to this PR, this PR closes the issue.
  • When making API changes, I have followed the
    Runbook for Firecracker API changes.
  • I have tested all new and changed functionalities in unit tests and/or
    integration tests.
  • I have linked an issue to every new TODO.

  • This functionality cannot be added in rust-vmm.

@ShadowCurse ShadowCurse self-assigned this Sep 15, 2026
@codecov

codecov Bot commented Sep 15, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 26.79426% with 153 lines in your changes missing coverage. Please review.
✅ Project coverage is 81.99%. Comparing base (934fc37) to head (d8bbe1e).

Files with missing lines Patch % Lines
src/vmm/src/device_manager/pci_mngr.rs 4.00% 48 Missing ⚠️
src/vmm/src/vfio.rs 30.88% 47 Missing ⚠️
src/vmm/src/device_manager/mod.rs 8.00% 23 Missing ⚠️
src/vmm/src/resources.rs 33.33% 20 Missing ⚠️
src/vmm/src/lib.rs 25.00% 9 Missing ⚠️
src/vmm/src/builder.rs 78.94% 4 Missing ⚠️
src/vmm/src/rpc_interface.rs 60.00% 2 Missing ⚠️
Additional details and impacted files
@@               Coverage Diff                @@
##           feature/vfio    #6219      +/-   ##
================================================
- Coverage         82.35%   81.99%   -0.37%     
================================================
  Files               280      280              
  Lines             32112    32293     +181     
================================================
+ Hits              26446    26478      +32     
- Misses             5666     5815     +149     
Flag Coverage Δ
5.10-m5n.metal 82.12% <26.79%> (-0.39%) ⬇️
5.10-m6a.metal 81.48% <26.79%> (-0.40%) ⬇️
5.10-m6g.metal 79.02% <26.79%> (-0.40%) ⬇️
5.10-m6i.metal 82.12% <26.79%> (-0.39%) ⬇️
5.10-m7a.metal-48xl 81.47% <26.79%> (-0.40%) ⬇️
5.10-m7g.metal 79.02% <26.79%> (-0.40%) ⬇️
5.10-m7i.metal-24xl 82.10% <26.79%> (-0.39%) ⬇️
5.10-m7i.metal-48xl 82.10% <26.79%> (-0.39%) ⬇️
5.10-m8g.metal-24xl 79.01% <26.79%> (-0.40%) ⬇️
5.10-m8g.metal-48xl 79.01% <26.79%> (-0.40%) ⬇️
5.10-m8i.metal-48xl 82.10% <26.79%> (-0.39%) ⬇️
5.10-m8i.metal-96xl 82.10% <26.79%> (-0.39%) ⬇️
5.10-m9g.metal-48xl 79.01% <26.79%> (-0.40%) ⬇️
6.1-m5n.metal 82.15% <26.79%> (-0.39%) ⬇️
6.1-m6a.metal 81.51% <26.79%> (-0.39%) ⬇️
6.1-m6g.metal 79.01% <26.79%> (-0.40%) ⬇️
6.1-m6i.metal 82.15% <26.79%> (-0.38%) ⬇️
6.1-m7a.metal-48xl 81.49% <26.79%> (-0.40%) ⬇️
6.1-m7g.metal 79.01% <26.79%> (-0.40%) ⬇️
6.1-m7i.metal-24xl 82.16% <26.79%> (-0.39%) ⬇️
6.1-m7i.metal-48xl 82.16% <26.79%> (-0.39%) ⬇️
6.1-m8g.metal-24xl 79.01% <26.79%> (-0.39%) ⬇️
6.1-m8g.metal-48xl 79.01% <26.79%> (-0.40%) ⬇️
6.1-m8i.metal-48xl 82.16% <26.79%> (-0.40%) ⬇️
6.1-m8i.metal-96xl 82.16% <26.79%> (-0.39%) ⬇️
6.1-m9g.metal-48xl 79.01% <26.79%> (-0.40%) ⬇️
6.18-m5n.metal 82.15% <26.79%> (-0.39%) ⬇️
6.18-m6a.metal 81.50% <26.79%> (-0.39%) ⬇️
6.18-m6g.metal 79.12% <26.79%> (-0.40%) ⬇️
6.18-m6i.metal 82.15% <26.79%> (-0.39%) ⬇️
6.18-m7a.metal-48xl 81.49% <26.79%> (-0.40%) ⬇️
6.18-m7g.metal 79.12% <26.79%> (-0.40%) ⬇️
6.18-m7i.metal-24xl 82.16% <26.79%> (-0.39%) ⬇️
6.18-m7i.metal-48xl 82.16% <26.79%> (-0.39%) ⬇️
6.18-m8g.metal-24xl 79.11% <26.79%> (-0.40%) ⬇️
6.18-m8g.metal-48xl 79.12% <26.79%> (-0.40%) ⬇️
6.18-m8i.metal-48xl 82.17% <26.79%> (-0.38%) ⬇️
6.18-m8i.metal-96xl 82.16% <26.79%> (-0.39%) ⬇️
6.18-m9g.metal-48xl 79.12% <26.79%> (-0.40%) ⬇️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@ShadowCurse
ShadowCurse force-pushed the vfio_part_2_5 branch 5 times, most recently from 4438b37 to b387a96 Compare September 17, 2026 15:52
We already ensure that the Msix is present in the device. The
`vfio_calculate_bar_areas` was one weird place that still was accepting
it as an `Option`

Signed-off-by: Egor Lazarchuk <yegorlz@amazon.co.uk>
Add utility functions for DMA mapping guest memory to the device. This
must be done only once on first device setup/teardown. PciMng will be
handling this in the future commits.

Signed-off-by: Egor Lazarchuk <yegorlz@amazon.co.uk>
Add functions for creation of KVM VFIO device and VFIO container.
These will need to be created once on the first device init.

Signed-off-by: Egor Lazarchuk <yegorlz@amazon.co.uk>
Add logic to the PciDevices to create new VFIO devices. As an additional
step in VFIO device setup, guest RAM regions are mapped into the VFIO
container's IOMMU so the device can DMA directly to guest memory.

Signed-off-by: Egor Lazarchuk <yegorlz@amazon.co.uk>
Since `device-passthrough` API is now connected, we need to not set
dummy values for it before starting the VM. Otherwise the VM startup
will fail.

Signed-off-by: Egor Lazarchuk <yegorlz@amazon.co.uk>
Current device passthrough implementation has some restrictions:
- Does not work without PCI since VFIO devices are PCI devices
- Does not work with virtio-mem device since we don't update DMA
  mappings on hot-plug/unplug
- Does not work with virtio-balloon since it can `fadvise` on memory

In order to prevent VMs being launched with invalid configurations,
implement multiple checks for invalid configurations:
- At API level, prevent adding of incompatible combinations (VFIO after
  balloon/mem or in reverse)
- At VM creation or snapshot restoration since they get VmResources from
  other sources.

Checks are a bit spread out. Most are in the `rpc_interface.rs` but
there is one in the `device_manager.rs` as well. This is just an
annoyance of dealing with `VmResources`. In the future we should delete
`VmResources` and add devices directly to the `DeviceManager` which can
implement all necessary compatibility checks.

Signed-off-by: Egor Lazarchuk <yegorlz@amazon.co.uk>
Passthrough device state is opaque to the VMM and cannot be serialized
or restored. Add these devices to the list of snapshot-incompatible
devices so that snapshot requests are rejected with a clear error
instead of producing a corrupt snapshot.

Signed-off-by: Egor Lazarchuk <yegorlz@amazon.co.uk>
During runtime VFIO devices will use pread64/pwrite64 syscalls on Vcpu
thread to interact with BARs. During teardown VFIO device is reset and
vfio-ioctls does additional syscalls to clean it up.

Signed-off-by: Egor Lazarchuk <yegorlz@amazon.co.uk>
@ShadowCurse
ShadowCurse marked this pull request as ready for review September 18, 2026 16:26
@ShadowCurse ShadowCurse added the Status: Awaiting review Indicates that a pull request is ready to be reviewed label Sep 18, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Status: Awaiting review Indicates that a pull request is ready to be reviewed

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant