feat: use the igb nic model for the guest

This commit is contained in:
2026-09-06 05:04:18 +02:00
parent 6473a33b2c
commit 47e7011519
3 changed files with 10 additions and 9 deletions

View File

@@ -75,11 +75,11 @@ Enable-NetFirewallRule -DisplayGroup "Remote Desktop"
Put your public key in `C:\ProgramData\ssh\administrators_authorized_keys` for an Administrator Put your public key in `C:\ProgramData\ssh\administrators_authorized_keys` for an Administrator
account. `vm-native-verify` uses that key. account. `vm-native-verify` uses that key.
SSH into the guest fails with `Corrupted MAC on input` until the host has the e1000e offload rule SSH into the guest fails with `Corrupted MAC on input` until the host has the NIC offload rule
from the `vfio-native` package. The emulated NIC's TX offloads corrupt integrity-checked traffic on from the `vfio-native` package. The emulated NIC's TX offloads corrupt integrity-checked traffic on
the host side of the tap; SMB tolerates it, SSH does not. The package installs a udev rule that the host side of the tap; SMB tolerates it, SSH does not. This holds for both `igb` and `e1000e`.
turns the offloads off on every libvirt tap as it appears, and `vm-native-setup` says so if it is The package installs a udev rule that turns the offloads off on every libvirt tap as it appears,
missing. and `vm-native-setup` says so if it is missing.
## 3. Make the NVMe driver boot-critical ## 3. Make the NVMe driver boot-critical
@@ -127,9 +127,10 @@ Two things it asks or warns about:
Before the first boot, if the host has less free memory than the guest's RAM, free and compact Before the first boot, if the host has less free memory than the guest's RAM, free and compact
it so the guest lands on transparent hugepages; `vm-native-setup` prints the two commands when it it so the guest lands on transparent hugepages; `vm-native-setup` prints the two commands when it
applies. The NIC stays `e1000e`, so the network survives the driver removal in the next step. Do not use applies. The NIC stays `igb`, so the network survives the driver removal in the next step: Windows
virtiofs for host files: it is a virtio device the scanner names, and its shared memory backing has an in-box driver for the Intel 82576 it emulates. Do not use virtiofs for host files: it is a
blocks transparent hugepages for the whole guest. Share over SMB on the e1000e link instead. virtio device the scanner names, and its shared memory backing blocks transparent hugepages for the
whole guest. Share over SMB on the `igb` link instead.
## 5. Remove the virtio drivers and the agents ## 5. Remove the virtio drivers and the agents

View File

@@ -48,7 +48,7 @@ package() {
# this coexists with whatever hook the host already has. # this coexists with whatever hook the host already has.
install -Dm755 scripts/libvirt-hook-cpu-isolation.sh \ install -Dm755 scripts/libvirt-hook-cpu-isolation.sh \
"${pkgdir}/etc/libvirt/hooks/qemu.d/10-cpu-isolation.sh" "${pkgdir}/etc/libvirt/hooks/qemu.d/10-cpu-isolation.sh"
# e1000e offloads corrupt integrity-checked traffic on libvirt taps; host-wide by nature # emulated NIC offloads corrupt integrity-checked traffic on libvirt taps; host-wide by nature
install -Dm644 scripts/99-vfio-native-vnet-offload.rules \ install -Dm644 scripts/99-vfio-native-vnet-offload.rules \
"${pkgdir}/usr/lib/udev/rules.d/99-vfio-native-vnet-offload.rules" "${pkgdir}/usr/lib/udev/rules.d/99-vfio-native-vnet-offload.rules"
} }

View File

@@ -661,7 +661,7 @@ if conformant and E["CONVERT"] == "1":
s = re.sub(r"\s*<input type='[^']*' bus='virtio'/>", "", s) s = re.sub(r"\s*<input type='[^']*' bus='virtio'/>", "", s)
s = re.sub(r"<memballoon model='virtio'>.*?</memballoon>", "<memballoon model='none'/>", s, flags=re.S) s = re.sub(r"<memballoon model='virtio'>.*?</memballoon>", "<memballoon model='none'/>", s, flags=re.S)
s = re.sub(r"<memballoon model='virtio'/>", "<memballoon model='none'/>", s) s = re.sub(r"<memballoon model='virtio'/>", "<memballoon model='none'/>", s)
s = re.sub(r"<model type='virtio'/>(\s*<driver [^/]*/>)?", "<model type='e1000e'/>", s) s = re.sub(r"<model type='virtio'/>(\s*<driver [^/]*/>)?", "<model type='igb'/>", s)
if prof == "full": if prof == "full":
s = re.sub(r"<video>.*?</video>", "<video>\n <model type='none'/>\n </video>", s, flags=re.S) s = re.sub(r"<video>.*?</video>", "<video>\n <model type='none'/>\n </video>", s, flags=re.S)