Red Hat Releases Windows Virtualization Code 183
dan_johns writes "Only one month after Microsoft released Linux code to improve the performance of Linux guests on Windows, Red Hat has done the reverse. Red Hat has quietly released a set of drivers to improve the performance of Windows guests hosted on Linux's Kernel-based Virtual Machine (KVM) hypervisor. The netkvm driver is a network driver and viostor is a Storport driver to improve the performance of high-end storage. This release includes paravirtual block drivers for Windows. Linux and Windows — virtually coming together at last."
Gentoo?? (Score:2, Funny)
I use Gentoo; how does this affect me?
Re:Gentoo?? (Score:5, Funny)
Re: (Score:2, Funny)
Yeah, the shame of avoiding DLL- *and* dependency hell crushes me. Thank you for understanding it.
And that horribly beautiful desktop of mine [radiantempire.com]*... I mean how can I live with that? I should shoot myself right now, in front of an Apple shrine.
___ ;)
* Aliasing enabled to make it harder to read the shameful things.
Re: (Score:3, Funny)
Re: (Score:3, Insightful)
Re: (Score:2)
Oh come-on! Can't you moderators see a funny thing, when it bites you in the ass?
Or have you just proven, what I was only joking about? ^^
Re: (Score:2, Funny)
Re:Gentoo?? (Score:5, Funny)
Now you can run Windows in a VM when people come over to avoid the shame of admitting you run Gentoo
What shame? Absolutely nothing can establish your Alpha Geek status faster than saying "Umm, I don't have a graphical desktop right now, it's still compiling", and firing up lynx to check your email.
Re: (Score:2)
Re:Gentoo?? (Score:4, Funny)
Real geeks decrypt their mail by hand.
Re: (Score:2)
I will admit to having checked my email over telnet, typing in pop3 protocol.
I have also done http (both as the client and server), ftp and xmpp (aka Jabber IM aka google talk).
A few of those required a telnet-like I wrote which accepts a connection instead of connecting to someone else.
Re: (Score:2)
Real geeks decrypt their mail by hand.
Quoted-printable =3D=3D fun!=20
Re: (Score:2)
people still use email?
Re: (Score:3, Funny)
Are you from South Korea?
Re: (Score:2)
It doesn't. You'll still spend 99.5% of your computing time waiting for your programs to build. ;)
Re:Gentoo?? (Score:4, Informative)
Protip:
Re: (Score:3, Informative)
I like my protip better: Mount /usr/portage/var (or whatever portage's working directory is) on a 9GB ramdisk, and set MAKEOPTS to -j9.
Re: (Score:2)
Protip:
Even better.
Plus distcc and crossdev make building a small cluster braindead simple, even with many different architectures.
Re: (Score:2)
LOL. I had to check if that typo actually is in my make.conf. Turns out the file is correct and it was a typo while re-formatting it.
Re: (Score:2)
ionice is a great feature, however I've never understood why you need to be root to "be ionice to other users". With nice, you can always do 'nice -n 19 mycommand' to indicate that your command needs but the lowest of priorities. With ionice, you cannot do that as a user.
See! (Score:2, Redundant)
Re: (Score:3, Insightful)
Isn't it better when we all play nicely?
Gestures are good, but the proof is in the pudding. If Microsoft keeps up actions like this on a consistent basis, then good things will happen.
I just worry that this is more of a "Oh look, judge, the prosecution's arguments are invalid. Look at these two examples where we worked with open source! See?! We're not bad!"
Re:See! (Score:5, Insightful)
It might be a legit improvement and a strategic move from Microsoft. Windows doesn't care if they are being run in a VM on a Linux box. They still sell support, licenses and all that other good stuff. In fact, VM's might mean more windows installs, more license keys sold, more support requests, and more money for Microsoft. Why would they want to stop paying customers from doing what they want on their box. Hell, Microsoft is probably thrilled that people are running Linux on a licensed copy of Windows in a VM rather than native and they are probably thrilled that windows is being installed on VM's on a Linux host. Win win for Microsoft and Linux. Soon they will both have 100% market share. lol.
Re: (Score:3, Informative)
This is actually entirely false for servers - server vendors make damn sure Linux works out the box. Dell, Sun or HP would never release an x86 server these days that doesn't run Linux perfectly. All of them will deal with Red Hat in paid support and (in my experience) happily treat CentOS as Red Hat for problem solving purposes.
Random desktop crapware, yeah. But this virtualisation exercise is for the benefit of servers, after all.
Re: (Score:3, Insightful)
Re: (Score:2)
Though that's the original saying, the OP may be referring to whiskey pudding [grouprecipes.com] where the pudding is supposed to remain 86 proof. Really. The proof is in the pudding. Eat up me hearties yo-ho. Errr...
On a more serious note, I didn't even know this existed until I dreamt up "whiskey pudding", put it into google, and found this as the first hit. A non-porn version of rule 34 [xkcd.com], I suppose.
Re:See! (Score:5, Insightful)
Since when has Linux /not/ played nicely with windows?
It's the other direction that's strewn with landmines
Re:See! (Score:4, Insightful)
Re: (Score:2)
Landmines explode in either direction. I think it's more like the metal spikes coming out of the ground when you try to drive out of a parking garage after paying.
I sorta improved your open-source English code there for ya...
Re: (Score:2)
Or FACE TOWARDS ENEMY.
Re: (Score:2)
I would argue that microsoft plays with knives and tries to cut down the competition but linux plays with sharp toungs and sharp minds and chips away at FUD. So its no so much like those parking garage danger spikes :)
Re: (Score:3, Insightful)
Re: (Score:2)
Re: (Score:2)
Samba? That's a pretty common file system. But yeah I get what you mean.
Samba isn't the kind of file system he was talking about. Did you mean NFS?
Re: (Score:3, Funny)
Sure, samba would be great for a universal file system if USB drives had Ethernet ports.
Re: (Score:2)
Sure, samba would be great for a universal file system if USB drives had Ethernet ports.
You mean like this one [dabs.com]? NAS FTW.
Re:See! (Score:5, Interesting)
With computers so cheap, and getting ever cheaper, and networking going from common to ubiquitous, and little network storage widgets popping up even on home networks, not to mention the increasing amount of stuff that lives on a remote server somewhere, I just don't find myself needed to access one OS's partition from the other very much. If I really do need to grab some file, NTFS-3G's inefficiency just isn't a big deal.
The overwhelming majority of file transfers between OSes(or between the same OS on different machines) that I end up doing these days are via some network protocol, http, sftp, smb, IMAP, etc. that abstracts away the filesystem on the other end, and is spoken just fine by most anything. With virtualization becoming an increasingly common, and for most purposes superior, alternative to dual booting, network transfers even work for two OSes on the same machine.
It would be nice if there were a properly interoperable filesystem in common use(if only so we could shove a stake through exFAT's black heart before it takes off); but it just hasn't been a big deal for a while now, for me.
Re: (Score:2)
Re: (Score:2)
I believe Direct3D already has a software renderer. If not, Direct3D could be rendered via using Wine's Direct3D implementation [nongnu.org] and a software OpenGL renderer. Issue: this would be slow.
However, VirtualBox, Parallels and VMware seem to implement Direct3D in virtual machines as OpenGL calls passed to the host.
Re: (Score:2)
I haven't had NTFS-3G do this.
Granted, it's not always fast, but I haven't had it freeze.
Re: (Score:3, Interesting)
Come to think of it, I've only had it actually lock up when running VMWare from that ntfs partition. VMWare can be very disk intenstive (snapshots, suspend+resume) and runs largely in kernel mode, maybe it's choking on the delays?
I'd be very curious what you get from the following test - here is my output from running the following command on both ntfs and ext3 filesystems:
time dd if=/dev/zero of=test bs=1024 count=2000000
On NTFS:
2000000+0 records in
2000000+0 records out
2048000000 bytes (2.0 GB) copied, 14
Re: (Score:2)
You're using 1k blocks. That's going to be much slower. Here's your test (shortened, because I didn't want to wait):
> dd if=/dev/zero of=test bs=1024 count=20000
20000+0 records in
20000+0 records out
20480000 bytes (20 MB) copied, 1.33289 s, 15.4 MB/s
> dd if=/dev/zero of=test bs=1048576 count=20
20+0 records in
20+0 records out
20971520 bytes (21 MB) copied, 0.469102 s, 44.7 MB/s
Slightly more data, yet faster. And it does somewhat sustain that:
> dd if=/dev/zero of=test bs=1048576 count=2048
2048+0 record
Re:See! (Score:5, Informative)
* Inodes that are larger than 128 bytes are not supported.
* Access rights are not maintained. All users can access all the directories and files of an Ext2 volume. If a new file or directory is created, it inherits all the permissions, the GID and the UID from the directory where it has been created. There is one exception to this rule: a file (but not a directory) the driver has created always has cleared "x" permissions, it inherits the "r" and the "w" permissions only. See also section "What limitations arise from not maintaining access rights?".
* The driver does not allow accessing special files at Ext2 volumes, the access will be always denied. (Special files are sockets, soft links, block devices, character devices and pipes.)
* Alternate 8.3-DOS names are not supported (just because there is no place to store them in an Ext2 file system). This can prevent legacy DOS applications, executed by the NTVDM of Windows, from accessing some files or directories.
* Currently the driver does not implement defragging support. So defragmentation applications will neither show fragmentation information nor defragment any Ext2 volume.
* This software does not achieve booting a Windows operating system from an Ext2 volume.
* LVM volumes are not supported, so it is not possible to access them.
Re: (Score:2, Interesting)
IMHO filesystem compatibility is a great example of how Linux devs are bad at leaving boring, but critical applications half done.
Re: (Score:2)
IMHO filesystem compatibility is a great example of how Linux devs are bad at leaving boring, but critical applications half done.
No, it's an excellent example of how Linux devs manage to get something working despite having to reverse engineer a complex and completely undocumented system.
Have you ever reverse engineered a totally undocumented filesystem?
Re: (Score:2)
I've had problems using VMware on Linux, apparently caused by lots of RAM (and consequently a large cache), long cache writeback timeouts, and once the timeout was triggered, the cache being filled faster than changes were being written. The VM's physical memory space is apparently implemented via a memory mapped file; the changes to this fi
Re: (Score:2)
A NT filesystem driver more recent that EXT2 would be nice, for a start.
Lack of Caring (Score:4, Interesting)
Reason To Care (Score:2)
Windows itself may not be compelling, but a few of the apps sure are to a whole lot of people.
I'm OS-agnostic, but certain apps (IE: Access) keep me locked-in to at least a Windows terminal server. Many mission-critical apps are not easily ported to other platforms.
Likewise, qmail is a compelling reason to run Linux.
Re: (Score:2)
I suppose this is a good thing, and I'm a big fan of the virtualization, but really, why? Windows fails to compel.
Fortunately, whether or not you personally see the use of something is not a deciding factor whether it gets done ;)
Re: (Score:2)
Re: (Score:3, Informative)
Way to display your ignorance! We're talking about paravirtualization, not the crappy performance you'll get from workstation or virtualbox. This is on par with esx, hyperv and xen. So, having better paravirtualization support for windows on kvm really leaves virtualbox completely in the dust. And I'm sure this is all done by ms and rh with a view to the server, not the guy who wants to virtualize xp to run cstrike.
Re: (Score:2)
I agree that KVM (and XEN) absolutely smoke virtualbox. I run a XenServer cluster at work and have a couple esxi test boxes and a couple Fedora11 (for testing with KVM+virt-manager+PCI mapping) and can say with some experience that all of those solutions are vastly faster than virtualbox on similar hardware.
I do utilize virtualbox for some testing when I need function and quick deployment over speed. It is a good program, but there are much better options for serious virtualization.
How does this affect security? (Score:5, Interesting)
I've always wondered how paravirtualizing some functions such as I/O or networking affects security.
Say a VM gets compromised, and is able to do what it wants with the block devices, how tough would it be to get out of the VM? If malicious code is able to access the host's block device that runs in kernel mode and start running code directly on the host's OS, game over.
Re: (Score:2)
You can think of it a little like an application and memory protection - yeah if the process could suddenly circumvent the virtualized address space and access kernel memory the machine is rooted, but otherwise it can only trash its own memory space. Yes, a compromised VM can do anything to the virtualized block devices but unless it can disable the translation and access the real block devices it can only trash its own disk. In both cases there's some fairly simple, solid and well understood locks in place
Re:How does this affect security? (Score:5, Interesting)
Re: (Score:2)
Re:How does this affect security? (Score:5, Informative)
Re: (Score:3, Interesting)
when I worked at VMware we used to just call it "cheating". You'd often hear engineers referring to "the drivers we use to cheat", and communicating through the "backdoor port".
Re: (Score:3, Funny)
"communicating through the backdoor port" == "talking out of your ass"?
Re:How does this affect security? (Score:5, Funny)
8 years and finally someone outside the company gets that joke.
Re:How does this affect security? (Score:5, Informative)
I've always wondered how paravirtualizing some functions such as I/O or networking affects security.
Say a VM gets compromised, and is able to do what it wants with the block devices, how tough would it be to get out of the VM? If malicious code is able to access the host's block device that runs in kernel mode and start running code directly on the host's OS, game over.
Unlike Hyper-V and Xen, in KVM a paravirtual device looks an awful lot like an emulated device. For instance, virtio-net appears to the guest as a normal PCI device. It's quite conceivable that a hardware vendor could implement a physical virtio-net card if they were so inclined. In our backend, we implement virtio-net like any other emulated device.
This means from a security perspective, it's just as secure as an emulated driver. It's implemented in userspace and can be sandboxed as an unprivileged user or through SELinux.
VMware uses a similar model. Hyper-V and Xen prefer to not model hardware at all and use special hypervisor-specific paths. From a security perspective, the fact that these devices are on a different code path means that they have different security characteristics than emulated devices. For instance, in Xen, a paravirtual network device is backed directly in the domain-0 kernel so an exploit in the xenpv network device is much more severe than an exploit in a Xen emulated network device (since the device emulation happens in an unprivileged stub domain).
This just in (Score:2)
A good thing. (Score:5, Interesting)
Cooperation like this is a great gesture. MS releasing code to help Linux run better in their VM's is a good thing and I am glad Red Hat returned the favor. With shops today running a mixed environment this helps them with transitioning or running apps side by side. Great for Linux development/testing on Windows and now better Windows development/testing on Linux systems. Now if only Apple would allow OSX to run in a VM. Developers could have one system running the OS of their choice and do all their cross platform development and testing on one system. Great for small developers who might code on a laptop or prefer to have a single system for development.
Never happen with Apple (Score:4, Interesting)
For better or worse, right or wrong, Apple is convinced they are a hardware company. They make their money on hardware in their mind, they just use their software to help sell their hardware. So they don't want you doing virtualization. They are not at all interested in your running their software on other people's hardware. For that matter, they aren't really interested in you running VMs all on their stuff. They'd much rather you have to buy 5 Xserves than buy 1 and do 5 VMs.
Just life, and it isn't likely to change unless Apple starts losing money (and probably not even then).
Re: (Score:3, Interesting)
The nice thing is that if you need to run VMs on OS X, you can move VMs from VMWare ESXi to VMWare Parallels on the Mac with little effort. Most of the time, it can copy directly. Worst case, you might need to copy the hard disk files and reinstall the VMWare client stuff.
Though it would be nice for Apple to have VM functionality built into the OS, or available easily, thankfully there are programs that allow Macs to be VM hosts. VMWare is a big one, but I have used Sun's VirtualBox as well, and even tho
Re: (Score:2)
Running virtual machines on top of OS X is not what Sycraft-fu was talking about.
The ability to run Mac OS X virtually without violating the license is extremely limited: only the Server version is permitted to be virtualized, and only on Apple's hardware. This doesn't mean it's not technically possible to run OS X on a VM on non-Apple hardware, but only virtualized OS
Re: (Score:2)
You can vitualize Leopard server on a Mac (Score:2)
Re: (Score:2)
I don't know what idiot modded you offtopic, you summed up the situation perfectly.
Apple is a hardware driven company, if they were to sell OS X on its own (like Windows) they would make huge losses. Apple and Microsoft are asymmetric competitors. Microsoft is reliant on 3rd parties to build nice PCs to run its software. Apple does it themselves, and retains full control over all the little details.
If Apple were to start losing money (and I don't think it'll happen anytime soon), it would be a huge mistake
Re: (Score:3, Informative)
MS only released it because they got caught violating the GPL.
Re:A good thing. (Score:5, Insightful)
Not really. The authors of the code wanted it released in such a way that it could be incorporated into the kernel source code. This meant it had to be GPL or the kernel maintainers would not add it. It is irrelevant whether or not releasing it some other way would violate the GPL, as the authors never intended to do that.
The real news is that somehow magically Microsoft was not forced to GPL every bit of code that they ever wrote, despite their repeated claims that the GPL is a "virus" that "infects everything it touches". They basically proved that they directly lied about this.
Re: (Score:2)
They had already release it. They had already distributed it.
Re: (Score:2)
We had an article about it IIRC.
Re: (Score:2)
It's about time, really, that MS quit saying "We don't want people running Linux" and started saying "If they're gonna run it, we want them running it on top of Windows".
Re: (Score:2)
It's just good business sense. If they can sell more copies of Windows and Office, that's good for them. It's the same way that Microsoft has interests in the Mac world: the more people buy Windows to run as a VM on their Mac, and the more people buy Office for Mac, the better.
But the moment you're no longer reliant on Windows or Office, that's when MS will start panicking.
Re: (Score:2)
It Is simpler then that. If virtualized windows runs slow on a Linux host. Then windows Looks bad as Linux would run much faster. Making Linux seem faster then windows. And vice versa. Also if you are virtualizing you want your virtualizing softwae to seem it runs faster then the competition. So any attempt to hinder such work will only hurt yourself.
How is this new news? (Score:4, Insightful)
How is this new news? Xen and VMWare have had PV drivers for Windows for ages...
Re: (Score:2)
The Xen PV drivers have historically been closed source for Windows. Fortunately a brave soul in the community stepped up and wrote a set of GPL drivers but Citrix still maintains their proprietary drivers. In general, there's a great deal of fragmentation with Xen PV drivers because they haven't been Open Source from the start.
I think the fact that KVM is avoiding this is quite good.
Re:How is this new news? (Score:4, Informative)
Yes. Me. :)
Re: (Score:2)
And Citrix's failure to follow through with Xen's primarily GPL development path is a big problem with their purchase of Xen. I also suspect it is a big factor in why RedHat is openly espousing KVM over Xen, although they still nominally support Xen.
Re: (Score:2)
Windows only just did the same thing a month ago. What is this ages thing you speak of?
Re: (Score:2)
Re: (Score:2)
This story is about *linux the kernel*, the only real linux and not "linux the operating system"
Actually this story is about Windows and KVM...
Quiet release (Score:4, Insightful)
Tell me, since when does a press release for Techworld + a front-page /. article count as releasing "quietly"?
Re: (Score:2)
There's this interesting fourth dimension that you might have heard of. Its ordering makes it possible for something to be quiet and be released *at the same place*, as long as the one follows the other. You should try it! :)
But beware: It can be deadly beyond 1.893456-3.15576 Gs from your starting point.
Re: (Score:2)
Since Microsoft hired the Rolling Stones to play "Start Me Up" at the Windows 95 launch. After that, Red Hat could hire Natalie Portman to cliff dive 30m into a vat of hot grits, and that would count as "restrained".
At parity once again (Score:3, Interesting)
No longer does Microsoft enjoy an advantage hosting mixed VM's. I am sure the boys in Redmond are not amused. Kudos to the folks at RedHat.
Re: (Score:2, Redundant)
Microsoft and Red Hat agreed to support each others' operating systems in their virtual environments [redhat.com], so this action is to be expected.
Re: (Score:3, Interesting)
Microsoft and Red Hat agreed to support each others' operating systems in their virtual environments [redhat.com], so this action is to be expected.
Yes, they expected it just like they expected people to extend Kerebos Authentication and XML filetypes right back at them. Microsoft embraces and extends OTHERS, they don't GET embraced and extended.
Windows Server able to run Linux VMs easily means more people willing to move from Linux to Windows, cause they can virtualize their Linux apps until they've ported them over -- and since they went to all that trouble to pay for Windows server... Might as well keep it.
It doesn't really "work" for Microsoft th
Re:At parity once again (Score:5, Informative)
No; Microsoft and Red Hat joined each others' virtualization validation programs. As a result, Red Hat will support Windows server operating systems on Red Hat's virtualization software. This support is a direct result of Red Hat participating in Microsoft's validation program [windowsservercatalog.com].
The list of vendors participating in Microsoft's program includes other companies, such as VMware, Citrix, Cisco, Oracle, and Sun.
Re: (Score:2)
Re: (Score:2)
Mmm, we're one of the companies on the flip side. We really really like Linux on our servers, but (sadly) there's no good replacement for Active Directory. Which means we need to keep at least a handful of Windows servers around for authentication.
So we run Windows inside of a Xen HVM. If we can do that in a PV manner, all the better.
Re: (Score:2)
Eh, MS still gets money for the licenses of those virtualized systems. I doubt they're *too* upset over it.
Asp.net (Score:2, Interesting)
Re: (Score:2)
Some would argue that the lack of Perl scripts is something to offer.
Is it OK to say this? (Score:2)
I, for one, welcome our new Virtual Operating System, Linux/Windows powered, Bi-Curious overlords!
Oh wait, I used too many commas, damn.
Not yet all it's made out to be (Score:2)
The win32 virtio-net drivers have been available for ages, albeit closed-source, and the win32 virtio-blk drivers haven't been through performance optimization yet and are slower than qemu's default IDE emulation. So -- *yawn*.
Wake me up when the virtio-blk port is fast; until then, this is interesting to anyone with a copy of the Windows DDK and an interest in helping out, but not necessarily so much for the rest of the world.
exchange/ad on linux (haha) (Score:5, Interesting)
The problem for me with this is that Windows is a poor server OS. The only compelling reason to run Windows servers is active directory and exchange. IIS is not nearly as good as apache or nginx or comanche or lighttpd (specifically, overhead, flexability, security, and performance!)
The costs for many organizations to engineer, deploy, and support windows servers for exchange and sharepoint is equal to or greater that the cost of outsourced/hosted. You can get hosted exchange for under $12/user/month at rackspace which compares well enough to a MCTS for Windows server and exchange as that 55,000 can do well over 350 exchange accounts without a power bill.
A linux server may take some expertise to setup but needs far far less daily upkeep. You can employ many less techs and hire in from the local tech shop for big deployments. I have an email server (ubuntu 6.04) that has been running for over 3 years without any effort on my part. The only downtime it has ever had was when the power failed and it shut down after the UPS was drained. $1200+ about 6 hours config (say $85/h) and no maintenance is something is am sure no windows server can or ever has matched.
back on point here, stop investing time and money is getting windows to run faster virtualized, put those dollars into alternatives to windows software. it has happened before that an OSS alternative (apache) has become so dominant that the big vendors have the alternatives rather than the standard. (bind, apache, sendmail and postfix, courier etc)
Microsoft / Red Hat Child (Score:3, Funny)
What do you think the demon baby these two are going to have is going to look like?