LabHub

Blog

[Virtualization] 01. Virtualization Fundamentals: Type 1 vs Type 2 Hypervisors

한국어English日本語

Introduction

Virtualization is the technology of creating multiple isolated virtual environments on top of physical hardware. It enables running several operating systems simultaneously on a single server, maximizing hardware utilization and reducing infrastructure costs.

Why Virtualization Matters

What Is a Hypervisor?

A hypervisor is the software layer that creates and manages virtual machines (VMs). Also called a VMM (Virtual Machine Monitor), it abstracts physical resources (CPU, memory, storage, network) and distributes them to each VM.

Type 1 Hypervisors (Bare-Metal)

Type 1 hypervisors are installed directly on hardware. They operate without a host OS, resulting in lower overhead and better performance.

+-------------------------------------------+
|   VM 1      |   VM 2      |   VM 3        |
|  (Ubuntu)   |  (Windows)  |  (CentOS)     |
+-------------------------------------------+
|          Type 1 Hypervisor                 |
|     (ESXi / Hyper-V / Xen)                |
+-------------------------------------------+
|          Physical Hardware                 |
|   (CPU, RAM, Storage, NIC)                |
+-------------------------------------------+

Notable Type 1 Hypervisors:

HypervisorVendorKey Features
VMware ESXiVMware (Broadcom)Enterprise standard, vSphere ecosystem
Microsoft Hyper-VMicrosoftBuilt into Windows Server, AD integration
XenLinux FoundationParavirtualization pioneer, early AWS foundation
KVMOpen Source (Red Hat)Linux kernel module, paired with QEMU

Type 2 Hypervisors (Hosted)

Type 2 hypervisors run as regular applications on top of a host operating system.

+-------------------------------------------+
|   VM 1      |   VM 2      |   VM 3        |
|  (Ubuntu)   |  (Windows)  |  (Fedora)     |
+-------------------------------------------+
|          Type 2 Hypervisor                 |
|  (VirtualBox / VMware Workstation)        |
+-------------------------------------------+
|           Host OS (Windows/macOS/Linux)    |
+-------------------------------------------+
|          Physical Hardware                 |
|   (CPU, RAM, Storage, NIC)                |
+-------------------------------------------+

Notable Type 2 Hypervisors:

HypervisorVendorKey Features
Oracle VirtualBoxOracleOpen-source, cross-platform, free
VMware WorkstationVMware (Broadcom)Professional desktop virtualization
VMware FusionVMware (Broadcom)macOS only, Apple Silicon support
Parallels DesktopParallelsmacOS optimized, excellent integration

KVM: A Hybrid Approach

KVM (Kernel-based Virtual Machine) occupies a unique position. It operates as a Linux kernel module that transforms Linux itself into a Type 1 hypervisor.

+-------------------------------------------+
|   VM 1      |   VM 2      |   VM 3        |
|  (Ubuntu)   |  (Windows)  |  (Fedora)     |
+-------------------------------------------+
|     QEMU (Device Emulation / Management)  |
+-------------------------------------------+
|  Linux Kernel + KVM Module (Type 1-like)  |
+-------------------------------------------+
|          Physical Hardware                 |
|   (CPU + VT-x/AMD-V, RAM, Storage, NIC)  |
+-------------------------------------------+

Virtualization Techniques Compared

Full Virtualization

In full virtualization, the guest OS runs completely unmodified. The hypervisor intercepts and translates privileged instructions from the guest.

Binary Translation approach:

Guest OS (runs in Ring 1)
    |
    v  Attempts privileged instruction
    |
Hypervisor (Ring 0) traps it
    |
    v  Translates to safe instructions and executes
    |
Physical Hardware

Paravirtualization

In paravirtualization, the guest OS is aware it runs in a virtualized environment. Instead of privileged instructions, it uses hypercalls to directly request services from the hypervisor.

Guest OS (modified - includes hypercall interface)
    |
    v  Issues hypercall (direct communication instead of traps)
    |
Hypervisor (processes request)
    |
    v
Physical Hardware

Hardware-Assisted Virtualization

In 2005-2006, Intel and AMD introduced CPU-level virtualization support.

Key Technologies:

+--------------------------------------------------+
|  Guest OS (Ring 3: User, Ring 0: Kernel)          |
|  --> Runs in VMX non-root mode                     |
+--------------------------------------------------+
|  Hypervisor (Ring -1 / VMX root mode)              |
|  --> Only intervenes on VM Exit                    |
+--------------------------------------------------+
|  Hardware (VT-x/AMD-V, EPT/NPT, VT-d/AMD-Vi)     |
+--------------------------------------------------+

Comparison of Three Virtualization Techniques

AspectFull VirtualizationParavirtualizationHW-Assisted
Guest OS ModificationNot requiredRequiredNot required
CPU OverheadHigh (binary translation)Medium (hypercalls)Low (HW traps)
I/O PerformanceSlow (emulation)Fast (hypercalls)Optimal with VirtIO
Windows SupportYesKernel modification difficultYes
Key TechnologyVMware BTXen PV, VirtIOVT-x, AMD-V
Current UsageLegacyUsed for I/O optimizationMainstream

Hands-On: Verifying KVM-Based Virtualization

# Check if CPU supports virtualization
# Look for vmx (Intel VT-x) or svm (AMD-V) flags
grep -E '(vmx|svm)' /proc/cpuinfo | head -1

# Verify KVM module is loaded
lsmod | grep kvm

# Example output:
# kvm_intel            368640  0
# kvm                 1028096  1 kvm_intel

# Create a VM using libvirt
virt-install \
  --name test-vm \
  --ram 2048 \
  --vcpus 2 \
  --disk size=20 \
  --os-variant ubuntu22.04 \
  --cdrom /path/to/ubuntu-22.04.iso

CPU Privilege Level (Ring) Architecture

[Before HW Virtualization]           [After HW Virtualization]

Ring 3: User Applications            Ring 3: User Applications
Ring 2: (unused)                     Ring 2: (unused)
Ring 1: (Guest OS - full virt)       Ring 1: (unused)
Ring 0: Hypervisor                   Ring 0: Guest OS (non-root)
                                      Ring -1: Hypervisor (VMX root)

With hardware virtualization, the guest OS operates normally at Ring 0 while the hypervisor controls everything from a higher privilege level (Ring -1).

VM Exits and Performance

In hardware-assisted virtualization, when a guest performs certain operations, the CPU switches from VMX non-root to root mode. This is called a VM Exit.

Common VM Exit Triggers:

VM Exits cost hundreds to thousands of CPU cycles, so reducing their frequency is key to performance. Paravirtual drivers like VirtIO reduce VM Exits in the I/O path.

[VM Exit Processing Flow]

Guest Execution (non-root)
    |
    v  Executes sensitive instruction
    |
VM Exit (non-root -> root transition, ~hundreds of cycles)
    |
    v  Hypervisor processes the instruction
    |
VM Entry (root -> non-root transition)
    |
    v  Guest execution resumes

Summary

CriterionType 1Type 2
InstallationDirectly on hardwareOn top of host OS
PerformanceHighMedium
Primary UseServer virtualization, cloudDevelopment, testing
Management ComplexityHighLow
Key ProductsESXi, Hyper-V, KVMVirtualBox, VMware Workstation

Virtualization is the foundation of modern cloud infrastructure. Type 1 hypervisors serve production environments while Type 2 serves desktop use cases. The advent of hardware virtualization support (VT-x/AMD-V) dramatically reduced performance overhead, enabling the cloud computing era we live in today.


Quiz: Virtualization Fundamentals Check

Q1. What is the primary difference between Type 1 and Type 2 hypervisors?

Type 1 installs directly on hardware without a host OS, while Type 2 runs as an application on an existing host OS. Type 1 has lower overhead and is better suited for production environments.

Q2. Why is KVM classified as a "hybrid"?

KVM is a Linux kernel module that transforms Linux itself into a Type 1 hypervisor, but it operates within a full Linux OS environment. This gives it both Type 1 performance and Type 2 convenience.

Q3. What are "hypercalls" in paravirtualization?

Hypercalls are an interface through which the guest OS directly requests services from the hypervisor. Similar to how system calls request services from the kernel, hypercalls request services from the hypervisor, with less overhead than the trap mechanism.

Q4. What problem does Intel VT-x's "Ring -1" solve?

Previously, both the guest OS (Ring 0) and the hypervisor (Ring 0) conflicted at the same privilege level. Ring -1 (VMX root mode) was introduced so the hypervisor operates at a higher privilege level while the guest OS runs normally at Ring 0.

Q5. How does VirtIO improve performance?

VirtIO is a paravirtualization standard for I/O devices (network, storage) where the guest OS recognizes the virtualized environment and communicates with the hypervisor through an optimized path. This reduces VM Exits compared to full hardware emulation, improving performance.

Comments

No comments yet.

Sign in to leave a comment