tfh
Volume 15, Number 6 -- February 6, 2006

Reader Feedback: VMware Weighs in on X86 Virtualization Criticisms

Published: February 6, 2006

In last week's issue, our Mad Dog 21/21 column, written by Hesh Wiener, did a historical and technical review of various kinds of virtualization that have been woven into systems and servers in the past three decades. He made an assertion that there were some limits to X86 virtualization. VMware's technical staff took issue with some of those characterizations, and its press relations team was set in motion by the article. We let the techies do the talking.

First up, the letter from Keith Adams, a staff engineer at VMWare:

Greetings. As a staff engineer in VMware's virtual machine monitor group, I read Hesh Wiener's recent retrospective on virtualization with a keen interest. His characterization of VMware's virtual machine monitor is inaccurate, and I think interestingly so. He claims that the X86 architecture "offers an insufficient basis for virtualization," presumably referring to Popek and Goldberg's criteria for a VMM, set forth in their rightly classic paper "Formal Requirements for Virtualization of Third Generation Architectures" (See http://www.logos.ic.i.u-tokyo.ac.jp/~tau/lecture/os/gen/articles/p412-popek.pdf).

The idea that the X86 is not virtualizable has long been so commonplace that, as in Mr. Wiener's piece, few even bother making the reference to Popek and Goldberg explicit. Unfortunately, like so much other folk wisdom, this notion is simply wrong, and results from an elementary misreading of the paper. The X86, in the absence of VT, Pacifica, et al., is virtualizable, as VMware's virtual machine monitor demonstrates, and nothing Popek or Goldberg has ever written would suggest otherwise.

The confusion stems from Popek and Goldberg's "Theorem 1," which is the principal result of their paper:

"For any conventional third generation computer, a virtual machine monitor may be constructed if the set of sensitive instructions for that computer is a subset of the set of privileged instructions."

Notice that the structure of this theorem only allows us to decide that an architecture affirmatively allows virtualization; the theorem does not provide any basis for the sorts of claims that Mr. Wiener makes. The theorem cannot tell us when a virtual machine monitor (hence VMM) cannot be constructed: in fact, Popek and Goldberg point out the dangers of attempting to reason from the converse of this theorem in their very paper.

Mr. Wiener is hardly the first to make this error; indeed, this instance of reasoning from the converse is so widespread that "the X86 is not a virtualizable architecture" has long been part of computing conventional wisdom. However, like much folklore, this meme's popularity provides no information about its truth value. VMware's virtual machine monitor runs unmodified X86 operating systems, at near native performance, with no risk of hostile operating systems escalating their privilege. This is the very definition of VMM that Popek and Goldberg put forth. So, to casually slough off our VMM a "lab curiosity" shows not only ignorance, but a contempt for the intelligence of our many customers entrusting their computation to the integrity of our VMM.

Thanks,
Keith Adams, kma@vmware.com


Hesh Wiener responds:

Hi Keith

I would like to apologize for misinterpreting some of the material I read as I worked on the article.

I still have a little difficulty reconciling some of the questions raised about virtualization on the X86 with the helpful case made by you.

At the very least I should have said that some experts in the computing community express doubts about the fortitude of virtual machine monitors running on current X86 circuitry, while others feel VMware (and other virtualization software technologies) are sufficiently robust for commercial deployment.

The skeptic in me keeps wanting to ask, "If X86 virtualization is so good, how come Intel and AMD are adding features to their chips specifically to support virtualization?"

If the chip makers' efforts are underway strictly to improve the performance of virtual machine monitors and not to address issues of system integrity, I erred and hope that the publication of your letter and this note dispel any doubts about the viability of virtualization software that is available here and now.

I'm not writing this to get off the hook. If I've blundered, I'm pleased to see a correction added to the record.

On the other hand, I don't want to encourage users eager to enjoy the benefits of virtualized X86 systems to take risks that will no longer be at issue if they simply wait a little while.

Thanks again for your patient and courteous criticism of my article.

Regards,
Hesh Wiener


Adams responds:

Mr. Wiener,

Thanks for the thoughtful (and prompt!) response. I'm not sure what I can do to assuage your doubts about VMware's virtual machine monitor; can you propose a demonstration that you'd find convincing? While I can't provide source code to the monitor, we have in fact provided that source code to the NSA. As a result of their audit, the NSA considers the VMware virtual machine boundary as good as an air gap for isolation purposes. (See, e.g. http://www.dgl.com/itinfo/2001/it010202.html.)

Keith Adams



Sponsored By
BCD INT'L

========== Experience the Art of WebSmart with your iSeries ============

          · Try the proven WebSmart technology iSeries People truly understand.

          · WebSmart and Catapult are now included on IBM's Try & Buy CD that
             is shipped with every i5/OS upgrade and new iSeries sales.

          · Succeed with a proven Web tool that's installed in 1,000+ iSeries organizations.

          · Develop using a Flexible Web tool that creates ILE-CGI or JAVA.

          · Receive a FREE* license of the Integrated Nexus Portal for controlled, secured
             access to applications, reports and tools. Also receive a FREE* License of
             RDW, RPG / DDS to Web Conversion.

          · Charter Member of IBM's iSeries Developer Roadmap.

          · Receive the Best support to insure your success.

======= Proven and Integrated Products =======

BCD's Integrated iSeries - Web Deployment Bundle

iSeries - Web App Development, Web Portal & Automated Report Distribution

WebSmart     ·     Nexus     ·     Catapult

______________________________________

Click Here for FREE DOWNLOAD · Click Here for Price Quote

Click here to view more WebSmart details www.bcdsoftware.com/progenwebsmart.htm

These products offer significant advantages and lots of real world experience. Combined, these products are field proven by over 500,000 end-users. Most iSeries shops launch WebSmart apps directly from their iSeries. Many also launch from Linux, NT and Unix.

Create new iSeries-browser based applications or extend existing ones as do 1,000+ iSeries organizations. BCD's robust product line has earned the respect of iSeries - AS/400 professionals.


Now is a Great time to get WebSmart.


Purchase WebSmart and get Free licenses of Nexus Portal & RDW -
Savings of up to $22,500!


Please view the technical resources, user guides and sample sites by visiting www.progenwebsmart.com.


Try BCD products with confidence:

They've all won major Industry Awards:

                          · iSeries News - APEX Award Winner
                          · Search400.com - Products of the Year Gold Winner
                          · eServer - iSeries Magazine - iSeries Magazine - Honor Roll Winner


Trust BCD, Winner of 30+ Industry Awards
10,000+ worldwide customers · 30,000+ products sold
630-986-0800 · sales@bcdsoftware.com · www.bcdsoftware.com

* Maintenance required for Free products.



Editor: Timothy Prickett Morgan
Contributing Editors: Dan Burger, Joe Hertvik, Shannon O'Donnell,
Mary Lou Roberts, Victor Rozek, Kevin Vandever, Hesh Wiener, Alex Woodie
Publisher and Advertising Director: Jenny Thomas
Advertising Sales Representative: Kim Reed
Contact the Editors: To contact anyone on the IT Jungle Team
Go to our contacts page and send us a message.

Sponsored Links

Advanced Systems Concepts:  iSeries data access like nothing else with SEQUEL
COMMON:  Join us at the Spring 2006 conference, March 26-30, in Minneapolis, Minnesota
Vision Solutions:  The Industry Standard in eServer High Availability

 


 
Subscription Information:
You can unsubscribe, change your email address, or sign up for any of IT Jungle's free e-newsletters through our Web site at http://www.itjungle.com/sub/subscribe.html.

Copyright © 1996-2008 Guild Companies, Inc. All Rights Reserved.
Guild Companies, Inc., 50 Park Terrace East, Suite 8F, New York, NY 10034

Privacy Statement