zlacker

[parent] [thread] 4 comments
1. Syonyk+(OP)[view] [source] 2023-07-11 19:40:32
You can. It's just neither recommended nor enabled by default.

https://forum.qubes-os.org/t/nested-virtualization/14790

Poke around /etc/libvirt/libxl and your particular VM's config file. You'll find some lines like:

<feature name='vmx' policy='disable'/> <feature name='svm' policy='disable'/>

Enable it, and you should have working nested virtualization.

replies(2): >>flashb+S3 >>flashb+X4
2. flashb+S3[view] [source] 2023-07-11 19:58:54
>>Syonyk+(OP)
I did that very thing about a year ago when I still had QubesOS installed, and it did not work. There seems to be a lot of misinformation about this swirling around the web. It simply does not work. There is a post somewhere that confirms it but I don't have the link. Unless the QubesOS devs/maintainers made a 180 degree turn since I tried it and decided to start compiling QubesOS with xen nested virtualization enabled, but I doubt it because their reason was that xen's nested virtualization feature is basically broken anyway.
3. flashb+X4[view] [source] 2023-07-11 20:06:32
>>Syonyk+(OP)
Shoot, as soon as I hit reply some neurons lit up and now I remember I was actually able to enable nested virtualization in QubesOS, and the relevant options in the VirtualBox preferences inside a qube became enabled once I did that, but whenever I tried booting any VM the whole system hanged. The same system and BIOS settings worked in Ubuntu to boot a nested VM in VirtualBox, so I think I had the BIOS settings correct. Anyhow, it seemed like a dead-end, so I abandoned it.
replies(1): >>Syonyk+q5
◧◩
4. Syonyk+q5[view] [source] [discussion] 2023-07-11 20:09:41
>>flashb+X4
I'll have to look at it more. I mostly use AMD systems these days, which don't support nested virt in Xen, as I understand it, but it looks like it should work on Intel.
replies(1): >>flashb+Qg
◧◩◪
5. flashb+Qg[view] [source] [discussion] 2023-07-11 21:14:04
>>Syonyk+q5
I was on Intel when I tried. No worries though, not really planning on trying it again.
[go to top]