IGVM Image

The Independent Guest Virtual Machine (IGVM) format describes an isolated VM's initial state. OpenHCL is delivered as an IGVM image.

Note: For more details on the IGVM specification, see the IGVM repository.

Purpose

The IGVM file serves as the firmware image for the OpenHCL paravisor. It instructs the host VMM on how to:

  1. Load the OpenHCL components into VTL2 memory.
  2. Place them at required physical addresses in a defined order so launch measurements are reproducible.
  3. Pass initial configuration data to the paravisor.

IGVM Image Contents

An OpenHCL IGVM image bundles the following artifacts:

  • Boot Shim (openhcl_boot): The entry point for VTL2 execution.
  • Linux Kernel: The operating system kernel.
  • Sidecar Kernel (x86_64): The lightweight kernel for APs.
  • Initial Ramdisk (initrd): The root filesystem containing userspace binaries such as underhill_init and openvmm_hcl.
  • Memory Layout: Directives specifying where each component should be loaded in memory.
  • Measurements: Data used by the platform to confirm that the expected image was loaded.
  • Configuration: Measured build-time parameters and permitted launch-time data such as CPU topology and device settings.

See ParavisorMeasuredVtl0Config and ParavisorMeasuredVtl2Config for examples of measured configuration.

Build Process

The IGVM artifact is generated by the OpenHCL build system. See Building OpenHCL for build instructions.

The igvmfilegen page documents manifest generation, image inspection, launch identity, and CoRIM signing.