AMD-Vi IOMMU: Device Virtualization and DMA Isolation
AMD-Vi is AMD's IOMMU, handling device DMA address translation and interrupt remapping. It is key to device passthrough and a hardware barrier against DMA attacks.
Core Concepts
DMA Remapping
DMA addresses seen by devices are translated by the IOMMU to real physical addresses, preventing arbitrary memory access.
Device Passthrough
Assigning a physical device directly to a VM lets the guest driver drive it at near-native performance.
Interrupt Remapping
Mapping device MSI/MSI-X safely to guest virtual interrupts, preventing interrupt injection attacks.
IVHD Structures
IVHD entries in the ACPI IVRS table describe IOMMU capabilities and device sets, parsed at boot.
Security Value
Enabling the IOMMU blocks direct memory access (DMA) attacks such as hardware keyloggers and PCIe exploits.
Working with SVM
SVM virtualizes the CPU and AMD-Vi virtualizes I/O; together they form AMD's full virtualization stack.
Key Code
# 检查 Linux 下 AMD-Vi 是否启用
dmesg | grep -i -E "AMD-Vi|IOMMU"
# 预期输出类似:
# AMD-Vi: AMD IOMMUv2 functionality not available ...
# AMD-Vi: Lazy IO/TLB flushing enabled
# 内核参数启用(/etc/default/grub):
# GRUB_CMDLINE_LINUX="... iommu=pt amd_iommu=on"Structure Cheat Sheet
| DMA 重映射 | Device DMA address → physical address translation |
|---|---|
| 中断重映射 | MSI/MSI-X → guest virtual interrupt mapping |
| 设备直通 | Assigning a physical device directly to a guest |
| IVRS 表 | ACPI table describing IOMMU configuration |
| DMA 防护 | Blocks arbitrary memory access from malicious devices |
Related Reading
A systematic introduction to virtualization concepts, evolution and taxonomy, and the roles of Intel VT-x and AMD-V.
→A retrospective of three decades of x86 hardware virtualization: binary translation, Intel VT-x, AMD SVM, EPT/NPT, and the modern virtualization security ecosystem.
→In-depth explanation of Intel VT-x VMX root/non-root modes, the VM-exit/VM-entry mechanism, and the VMCS virtual machine control structure.
→Detailed semantics of VMXON/VMXOFF/VMLAUNCH/VMRESUME/VMREAD/VMWRITE and the six field areas of the VMCS layout.
→Explains VMX root/non-root dual-mode switching, the VM-exit event flow, and how VT debuggers exploit dual modes for invisible monitoring.
→How nested virtualization works: nested VMCS/VMCB, shadow-VMCS optimization, and its use in WSL2 and cloud environments.
→A full breakdown of AMD SVM (Secure Virtual Machine): VMCB, #VMEXIT, guest/host modes and AMD's hardware virtualization design.
→Field-by-field analysis of the AMD VMCB memory layout: control area, save area, intercept bitmap and precise offsets.
→Explains AMD NPT two-level address translation, the nCR3 root pointer, TLB control, and its impact on performance and security monitoring.
→Step-by-step guide to enabling SVM on AMD platforms: BIOS entry points, naming differences…
→A systematic comparison of AMD SVM vs Intel VT-x: mode design, state structures, interception, nested paging, and ecosystem support.
→A full breakdown of AMD SVM (Secure Virtual Machine): VMCB, #VMEXIT, guest/host modes and …
→Field-by-field analysis of the AMD VMCB memory layout: control area, save area, intercept …
→Step-by-step guide to enabling SVM on AMD platforms: BIOS entry points, naming differences, verification and common issues.
→An overview of the VT Debugger: hypervisor-layer isolation, EPT-based residue-free breakpoints, VM-exit event handling and invisible memory access.
→A feature-by-feature breakdown of the VT Debugger: invisible breakpoints, invisible hooks, kernel-level memory access, process protection and anti-anti-debugging.
→A complete getting-started tutorial from download and install to your first breakpoint: requirements, driver loading, attaching and troubleshooting.
→Quickly confirm CPU virtualization support and enablement via Task Manager, systeminfo, CPU-Z and command-line methods.
→Deep dive into the two core VT Hook implementations: EPT page-remapping hooks and write-protect hooks, and how they defeat integrity checks.
→From the detection surface of traditional breakpoints to EPT page-level and virtualized hardware breakpoints: implementation and anti-detection power.
→The VT-layer process protection stack: EPT memory hiding, TerminateProcess interception, anti-injection and anti-debugging.
→The role of virtualization in anti-cheat: from kernel-level detection to hypervisor-grade monitoring, and the bypass/counter-bypass arms race.
→