[Tails-dev] Good news wrt. nested virtualization

2014-07-18 Thread intrigeri
Hi,

FWIW, Intel Haswell architecture adds features (Shadow VMCS, nEPT)
that, when using a recent enough qemu/kvm, make nested virtualization
actually usable to run our test suite. Works fine for me :)

Details: https://github.com/kashyapc/nvmx-haswell/blob/master/SETUP-nVMX.rst

The bad news is that one needs a super-recent Intel CPU to take
advantage of this. Others will still need to either run the test suite
directly on their usual system, or to get a dedicated machine to
run it.

Cheers,
-- 
intrigeri
___
Tails-dev mailing list
Tails-dev@boum.org
https://mailman.boum.org/listinfo/tails-dev
To unsubscribe from this list, send an empty email to 
tails-dev-unsubscr...@boum.org.


Re: [Tails-dev] Good news wrt. nested virtualization

2014-07-18 Thread boyska
On 18/07/2014 14:59, intrigeri wrote:
 FWIW, Intel Haswell architecture adds features (Shadow VMCS, nEPT)
 that, when using a recent enough qemu/kvm, make nested virtualization
 actually usable to run our test suite. Works fine for me :)

we're also experimenting with nested virtualization. For what I could
see, it basically works, but actually I have not done extensive
testings, nor I managed to setup tails unit tests inside a virtual machine.

 The bad news is that one needs a super-recent Intel CPU to take
 advantage of this. Others will still need to either run the test suite
 directly on their usual system, or to get a dedicated machine to
 run it.

I think there's room for colaboration at a hardware level, then ;)
We have one of those.

-- 
boyska
gpg --recv-keys 0x58289ca9
___
Tails-dev mailing list
Tails-dev@boum.org
https://mailman.boum.org/listinfo/tails-dev
To unsubscribe from this list, send an empty email to 
tails-dev-unsubscr...@boum.org.


Re: [Tails-dev] Good news wrt. nested virtualization

2014-07-18 Thread intrigeri
Hi,

boyska wrote (18 Jul 2014 13:33:53 GMT) :
 we're also experimenting with nested virtualization. For what I could
 see, it basically works,

FYI, our past experience (with pre-Haswell CPUs) was so painful (read:
super-slow) that we've given up.

 The bad news is that one needs a super-recent Intel CPU to take
 advantage of this. Others will still need to either run the test suite
 directly on their usual system, or to get a dedicated machine to
 run it.

 I think there's room for colaboration at a hardware level, then ;)
 We have one of those.

Great :)

Note that in a few months, we'll have a server dedicated to running
our test suite, so the advantage of using your box instead will
vanish. Also, for people doing any kind of intensive Tails
development, IMO being able to run the test suite locally is waaay
more practical.

Cheers,
-- 
intrigeri
___
Tails-dev mailing list
Tails-dev@boum.org
https://mailman.boum.org/listinfo/tails-dev
To unsubscribe from this list, send an empty email to 
tails-dev-unsubscr...@boum.org.