Skip to content

Add vhost-user support with RNG device implementation#527

Open
dorindabassey wants to merge 5 commits intocontainers:mainfrom
dorindabassey:vhost-user-support
Open

Add vhost-user support with RNG device implementation#527
dorindabassey wants to merge 5 commits intocontainers:mainfrom
dorindabassey:vhost-user-support

Conversation

@dorindabassey
Copy link
Collaborator

This PR adds vhost-user frontend support to libkrun, enabling virtio devices to run in separate processes using rust-vmm's vhost-device backends for improved isolation and flexibility. The RNG frontend is implemented as the initial use case, and is designed to easily support additional devices (sound, GPU, can, etc).

@dorindabassey dorindabassey marked this pull request as ready for review February 5, 2026 15:59
Copy link
Collaborator

@mtjhrc mtjhrc left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I had a look at the tests, and honestly I don't see much value in them, we don't have any arbitrary coverage percent metric for merging stuff, so I would just remove most of them.

The rest of the code looks good, but I've only had a quick look so far, when this was still a draft, I'll try running this and have another look later.

Having vhost-user support in libkrun seems pretty cool, thanks!

@tylerfanelli
Copy link
Member

tylerfanelli commented Feb 6, 2026

Not really a review, just a comment:

@dorindabassey This is some great work and a huge addition to the project.

@slp passt uses vhost-user to provide near-native network performance in user mode for QEMU. Perhaps we should consider doing the same here, especially as the main network driver for the v2 API.

@sbrivio-rh
Copy link

@slp passt uses vhost-user to provide near-native network performance in user mode for QEMU. Perhaps we should consider doing the same here, especially as the main network driver for the v2 API.

Right, that would be great to have! It's mostly about throughput and latency, but also, perhaps, one day, to implement live migration of TCP connections, as it's only available via vhost-user interface.

I'm not sure how much effort networking support would take on top of this pull request, and whether it's beyond its scope or not, but let me share a couple of pointers just in case. The part of API that's implemented by passt is this:

https://passt.top/passt/tree/vhost_user.c?id=af7b81b5408da8c56bb22dd11679f2b4024a45c8#n1128

And there's a bit of documentation about how it can be used with QEMU here:

https://www.qemu.org/docs/master/system/devices/net.html#using-passt-as-the-user-mode-network-stack

Let me know if you have any question! I'll also tag @vivier, the author of the vhost-user implementation in passt, for good measure.

@tylerfanelli
Copy link
Member

I'm not sure how much effort networking support would take on top of this pull request, and whether it's beyond its scope or not

It's fine for this PR to stand as-is. This can be used as a base for another series adding the network implementation.

@mtjhrc
Copy link
Collaborator

mtjhrc commented Feb 9, 2026

passt uses vhost-user to provide near-native network performance in user mode for QEMU. Perhaps we should consider doing the same here, especially as the main network driver for the v2 API.

I'm not sure how much effort networking support would take on top of this pull request, and whether it's beyond its scope or not

Adding support for virtio-net over vhost doesn't require any changes to any of our networking code. Our virtio-net is not attached by default.

All the user would have to do to enable it is:

  1. Disable the implicit vsock device to get rid of TSI (krun_disable_implicit_vsock). Optionally add a vsock device back (krun_add_vsock) to use vsock for other purpose
  2. Use something like krun_add_vhost_user_device to attach the net device

@dorindabassey dorindabassey force-pushed the vhost-user-support branch 3 times, most recently from 9cfb1ea to fe4e9ba Compare February 10, 2026 11:28
@dorindabassey dorindabassey force-pushed the vhost-user-support branch 2 times, most recently from b3bfb2e to 3feb780 Compare February 12, 2026 11:59
@dorindabassey dorindabassey force-pushed the vhost-user-support branch 2 times, most recently from e5c413f to 5b0b670 Compare February 16, 2026 16:03
@dorindabassey dorindabassey marked this pull request as draft February 17, 2026 09:54
@dorindabassey dorindabassey marked this pull request as ready for review February 18, 2026 11:45
@mtjhrc
Copy link
Collaborator

mtjhrc commented Feb 18, 2026

/gemini review

Copy link

@gemini-code-assist gemini-code-assist bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces significant new functionality by adding vhost-user frontend support, with an initial implementation for the RNG device. The changes are well-structured across the C FFI, device layer, and VMM builder. A key aspect is the correct implementation of file-backed guest memory using memfd, which is crucial for vhost-user. My review includes suggestions to improve robustness, clarify the API, and clean up the example code.

.iter()
.any(|dev| dev.device_type == VIRTIO_ID_RNG);

if !vm_resources.disable_implicit_rng && !has_vhost_user_rng {
Copy link
Collaborator

@mtjhrc mtjhrc Feb 18, 2026

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The idea I mentioned with krun_disable_implicit_rng was that it would replace this automatic disablement of the internal device. I'm not saying that the automatically disabling of the built-in device is necessarily bad though - in fact it will often be more user friendly.

However, having the user explicitly call krun_disable_implicit_rng has one big advantage though, that this will definitely be consistent with future devices - imagine in the future we could have vhost alternatives for basically every device, but adding more auto detection rules here will not be backwards compatible, potentially causing great confusion with regards to what is in fact enabled.

To be clear, I am not saying this has to necessarily be changed, It's just an observation.

Copy link
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yeah, good point about future compatibility. For now I think the auto-detection provides a better user experience, but I'll keep this in mind if we add vhost-user support for other device types in the future.

Dorinda Bassey added 5 commits February 19, 2026 13:27
Implement vhost-user support for connecting
to external virtio device backends running
in separate processes.
Add vhost-user feature flag, vhost dependency,
and krun_add_vhost_user_device() generalized
API for adding vhost-user devices.

Signed-off-by: Dorinda Bassey <dbassey@redhat.com>
Add memfd-backed memory region creation to enable memory
sharing with vhost-user backends via FD passing. When
vhost-user is enabled, all guest RAM regions are created
with memfd backing instead of anonymous mmap.

This lays the groundwork for vhost-user device support
while maintaining backward compatibility such that the
VM boots normally with standard memory when vhost-user
is not configured.

Signed-off-by: Dorinda Bassey <dbassey@redhat.com>
Implement generic vhost-user device wrapper
with connection, feature negotiation, and
Guest physical address(GPA) to Virtual
address(VA) translation. Supports protocol
feature negotiation (CONFIG, MQ) and forwards
backend interrupts to guest.

Signed-off-by: Dorinda Bassey <dbassey@redhat.com>
Implements a vhost-user RNG device. The
VMM now switches between the standard RNG device
and vhost-user RNG depending on whether a socket
path is configured via krun_add_vhost_user_device()

This allows us to use the RNG device from the
rust-vmm vhost-device running in a separate
process for better isolation and flexibility.

Signed-off-by: Dorinda Bassey <dbassey@redhat.com>
Adds --vhost-user-rng command line option to
specify a vhost-user RNG backend socket path.
When provided, the VM uses the external
vhost-user RNG device instead of the built-in
virtio-rng implementation.

Example usage:  ./examples/chroot_vm \
--vhost-user-rng=/tmp/vhost-rng.sock0 \
/ /bin/sh -c "head -c 32 /dev/hwrng | xxd"

Signed-off-by: Dorinda Bassey <dbassey@redhat.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

Comments