3 Commits
Author SHA1 Message Date
sandwich 983df80132 chore: bump to 1.2.0 2026-09-06 05:04:18 +02:00
sandwich 47e7011519 feat: use the igb nic model for the guest 2026-09-06 05:04:18 +02:00
sandwich 6473a33b2c fix: buffered disk cache so btrfs checksums stay valid 2026-09-06 05:04:12 +02:00
3 changed files with 16 additions and 12 deletions
+8 -7
View File
@@ -75,11 +75,11 @@ Enable-NetFirewallRule -DisplayGroup "Remote Desktop"
Put your public key in `C:\ProgramData\ssh\administrators_authorized_keys` for an Administrator
account. `vm-native-verify` uses that key.
SSH into the guest fails with `Corrupted MAC on input` until the host has the e1000e offload rule
SSH into the guest fails with `Corrupted MAC on input` until the host has the NIC offload rule
from the `vfio-native` package. The emulated NIC's TX offloads corrupt integrity-checked traffic on
the host side of the tap; SMB tolerates it, SSH does not. The package installs a udev rule that
turns the offloads off on every libvirt tap as it appears, and `vm-native-setup` says so if it is
missing.
the host side of the tap; SMB tolerates it, SSH does not. This holds for both `igb` and `e1000e`.
The package installs a udev rule that turns the offloads off on every libvirt tap as it appears,
and `vm-native-setup` says so if it is missing.
## 3. Make the NVMe driver boot-critical
@@ -127,9 +127,10 @@ Two things it asks or warns about:
Before the first boot, if the host has less free memory than the guest's RAM, free and compact
it so the guest lands on transparent hugepages; `vm-native-setup` prints the two commands when it
applies. The NIC stays `e1000e`, so the network survives the driver removal in the next step. Do not use
virtiofs for host files: it is a virtio device the scanner names, and its shared memory backing
blocks transparent hugepages for the whole guest. Share over SMB on the e1000e link instead.
applies. The NIC stays `igb`, so the network survives the driver removal in the next step: Windows
has an in-box driver for the Intel 82576 it emulates. Do not use virtiofs for host files: it is a
virtio device the scanner names, and its shared memory backing blocks transparent hugepages for the
whole guest. Share over SMB on the `igb` link instead.
## 5. Remove the virtio drivers and the agents
+2 -2
View File
@@ -8,7 +8,7 @@
# vfio-native-qemu QEMU 11.1.1 with the platform-identity patches, in /opt
pkgname=vfio-native
pkgver=1.1.1
pkgver=1.2.0
pkgrel=1
pkgdesc="Present a libvirt guest as a self-consistent physical machine, and tune it"
arch=('any')
@@ -48,7 +48,7 @@ package() {
# this coexists with whatever hook the host already has.
install -Dm755 scripts/libvirt-hook-cpu-isolation.sh \
"${pkgdir}/etc/libvirt/hooks/qemu.d/10-cpu-isolation.sh"
# e1000e offloads corrupt integrity-checked traffic on libvirt taps; host-wide by nature
# emulated NIC offloads corrupt integrity-checked traffic on libvirt taps; host-wide by nature
install -Dm644 scripts/99-vfio-native-vnet-offload.rules \
"${pkgdir}/usr/lib/udev/rules.d/99-vfio-native-vnet-offload.rules"
}
+6 -3
View File
@@ -637,8 +637,11 @@ if conformant and E["CONVERT"] == "1":
if "device='disk'" not in d or ("bus='nvme'" in d and "<serial>" in d):
return d
d = re.sub(r"<target dev='([^']*)' bus='(virtio|sata|scsi)'/>", r"<target dev='\1' bus='nvme'/>", d)
# cache='none' is O_DIRECT: on btrfs the guest can change a page while the
# write is in flight, so the stored checksum never matches and later reads
# fail with EIO. Buffered writes hand the filesystem a stable page.
d = re.sub(r"<driver name='qemu' type='([^']*)'[^/]*/>",
r"<driver name='qemu' type='\1' cache='none' io='native' discard='unmap'/>", d)
r"<driver name='qemu' type='\1' cache='writeback' io='threads' discard='unmap'/>", d)
d = re.sub(r"\s*<address type='(pci|drive)'[^/]*/>", "", d)
if "<serial>" not in d:
serial = E["NVME_SERIAL"] if n[0] == 0 else E["NVME_SERIAL"][:-1] + "0123456789ABCDEF"[n[0] % 16]
@@ -658,7 +661,7 @@ if conformant and E["CONVERT"] == "1":
s = re.sub(r"\s*<input type='[^']*' bus='virtio'/>", "", s)
s = re.sub(r"<memballoon model='virtio'>.*?</memballoon>", "<memballoon model='none'/>", s, flags=re.S)
s = re.sub(r"<memballoon model='virtio'/>", "<memballoon model='none'/>", s)
s = re.sub(r"<model type='virtio'/>(\s*<driver [^/]*/>)?", "<model type='e1000e'/>", s)
s = re.sub(r"<model type='virtio'/>(\s*<driver [^/]*/>)?", "<model type='igb'/>", s)
if prof == "full":
s = re.sub(r"<video>.*?</video>", "<video>\n <model type='none'/>\n </video>", s, flags=re.S)
@@ -824,7 +827,7 @@ if [ "$PROFILE" = full ]; then
fi
if [ ! -e /usr/lib/udev/rules.d/99-vfio-native-vnet-offload.rules ] && [ ! -e /etc/udev/rules.d/99-vfio-native-vnet-offload.rules ]; then
echo "NOTE: the e1000e offload udev rule is not installed. SSH into the guest will fail with"
echo "NOTE: the NIC offload udev rule is not installed. SSH into the guest will fail with"
echo " 'Corrupted MAC on input' until it is:"
echo " sudo install -Dm644 $SELF/scripts/99-vfio-native-vnet-offload.rules /etc/udev/rules.d/ && sudo udevadm control --reload-rules"
fi