IGVM Image
The Independent Guest Virtual Machine (IGVM) format describes an isolated VM's initial state. OpenHCL is delivered as an IGVM image.
Note: For more details on the IGVM specification, see the IGVM repository.
Purpose
The IGVM file serves as the firmware image for the OpenHCL paravisor. It instructs the host VMM on how to:
- Load the OpenHCL components into VTL2 memory.
- Place them at required physical addresses in a defined order so launch measurements are reproducible.
- Pass initial configuration data to the paravisor.
IGVM Image Contents
An OpenHCL IGVM image bundles the following artifacts:
- Boot Shim (
openhcl_boot): The entry point for VTL2 execution. - Linux Kernel: The operating system kernel.
- Sidecar Kernel (x86_64): The lightweight kernel for APs.
- Initial Ramdisk (initrd): The root filesystem containing userspace
binaries such as
underhill_initandopenvmm_hcl. - Memory Layout: Directives specifying where each component should be loaded in memory.
- Measurements: Data used by the platform to confirm that the expected image was loaded.
- Configuration: Measured build-time parameters and permitted launch-time data such as CPU topology and device settings.
See
ParavisorMeasuredVtl0Config
and
ParavisorMeasuredVtl2Config
for examples of measured configuration.
Build Process
The IGVM artifact is generated by the OpenHCL build system. See Building OpenHCL for build instructions.
The igvmfilegen page documents
manifest generation, image inspection, launch identity, and CoRIM signing.