中文日本語

Features

SR-IOV networking

What you get

A VF is passed through to a VM like a whole device, so the VM talks to the card with its own driver at close to line rate. One card serves several VMs.

  • A VM can ask for a fixed VF number or for auto: a free VF is picked at start, so changing the number of VFs does not mean editing VMs.
  • The MAC address stays the same when a VF is created again.
  • In the web interface you pick a network and the way to connect: virtual NIC, VF or whole port. The network page shows which VF goes to which VM and network.
  • If the card cannot put a VF on the network's VLAN, the VM does not start and says why. It is not quietly connected some other way.

Cards

Intel X710 VFs work with the stock FreeBSD driver. For the common Intel I350, FreeBSD has only the guest-side VF driver, not the host side. keelOS adds its own host driver, about 700 lines written from the Intel datasheet, loaded at boot without a new kernel. It gives up to 7 VFs per port, with mailbox, VF reset, MAC anti-spoofing and port VLAN. It was tested on a real I350-T2: both ports, traffic in both directions and line rate.

What was tested

SR-IOV breaks most often in the odd cases, so there is a list of 13: too few VFs, two VMs asking for the same VF, changing the VF count while VMs run, a missing or replaced card, the host's port going down, a host restart, and others. Most pass on hardware; two need someone at the machine (a real cable pull, and recovery after a failed VF creation).

Limits

  • A VM with a VF is still shut down and started again on a host restart; its VFs are created again with the same MACs. Keeping it running (the VF is rebuilt and the guest driver recovers) is written and in testing.
  • FreeBSD's own VF driver does not notice a reset by itself; the interface needs a down/up in the guest. Linux recovers on its own.
  • If you need a network port that never drops, pass the whole port through instead. That already survives a host restart.

Read the article (Chinese) →

← All features