News: 0001633825

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Cloud Hypervisor 52 Now Supports Launching AMD SEV-SNP Confidential VMs With KVM

([Virtualization] 6 Hours Ago Cloud Hypervisor 52)


For what originally began as an open-source Intel software project, Cloud Hypervisor continues seeing robust development outside the confines of Intel Corp these days with ongoing improvements driven by Microsoft, Cyberus Tech, Ant, and other organizations for this Rust-based VMM for cloud workloads.

Cloud Hypervisor 52 was released on Thursday and most notable with this release is now having confidential virtual machine support when using Linux's KVM on AMD SEV-SNP capable EPYC processors. AMD SEV-SNP confidential VMs can now be launched on KVM via Cloud Hypervisor, in addition to supporting such CoCo VMs on Microsoft MSHV. This includes measured boot support and all similar functionality now wired up for a nice AMD Secure Encrypted Virtualization (Secure Nested Paging) experience.

In addition to the KVM SEV-SNP support, Cloud Hypervisor 52 has a fix for a use-after-free vulnerability in the VirtIO-Block async I/O path, VFIO device passthrough support via iommufd/vfio-cdev, multi-connection TCP live migration, async QCOW2 back-end with IO_uring support, and a new core scheduling option for vCPU threads.

There are also many smaller improvements in Cloud Hypervisor 52 among various fixes. Overall this is quite a feature-packed release with a lot of exciting improvements for this VMM targeting cloud workloads on Linux and Windows.

Cloud Hypervisor 52 downloads via [1]GitHub . More details on this new feature release at [2]CloudHypervisor.org .



[1] https://github.com/cloud-hypervisor/cloud-hypervisor/releases/tag/v52.0

[2] https://www.cloudhypervisor.org/blog/cloud-hypervisor-v52.0-released/



Maier's Law:
If the facts do not conform to the theory, they must be disposed of.
-- N. R. Maier, "American Psychologist", March 1960

Corollaries:
(1) The bigger the theory, the better.
(2) The experiment may be considered a success if no more than
50% of the observed measurements must be discarded to
obtain a correspondence with the theory.