For Xen, an IOMMU paravirtualization mechanism is being developed.

The developers of the XCP-NG project, which develops an open platform for deploying and managing cloud infrastructure, have introduced the PV-IOMMU project, allowing guest systems to access limited IOMMU functionality implemented using the Xen paravirtualization infrastructure. In practice, PV-IOMMU can be used to implement DMA protection in Dom0 or to provide support for the Linux kernel's VFIO subsystem. Previously, the Xen hypervisor used IOMMU to pass through access to PCI devices and restrict device access to memory; however, for stability and security reasons, guest systems could not directly access the IOMMU block provided by the hardware.

IOMMU is a specialized memory management unit that translates virtual addresses visible to the hardware device into physical addresses, allowing DMA operations to be executed and filtered by virtual addresses, as well as restricting and isolating I/O operations. In the context of virtualization, IOMMU allows guest systems to directly access peripheral devices such as Ethernet adapters, graphics cards, and storage device controllers. The IOMMU implementation by Intel is known as VT-d (Virtualization Technology for Directed I/O), AMD offers AMD-Vi (I/O Virtualization), and ARM provides SMMU (System Memory Management Unit).

The proposed paravirtualized implementation (PV-IOMMU) enables guest systems to utilize the basic capabilities of IOMMU while abstracting all low-level hardware details. A new hypercall (similar to a system call for hypervisors) called HYPERVISOR_iommu_op has been proposed for inclusion in Xen, which guest systems can utilize to perform IOMMU operations. Among other things, guest systems can now create and modify domains IOMMU (IOMMU domain), referred to in Xen as IOMMU contexts to avoid confusion with the term 'domain' in Xen. IOMMU contexts allow the guest system to organize access to device memory and specify memory translation operations applied to one or more devices.

At the current stage of development, the PV-IOMMU only supports the Intel VT-d technology, but support for AMD-Vi and SMMUv3 is planned to be added soon.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster