VRT-110 · Virtualization & Containers
VFIO & Device Passthrough
Giving a guest direct access to real hardware — the mechanism behind GPU passthrough.
Who this course is for
Engineers who must give VMs direct access to real hardware — GPUs, NICs, accelerators — and need passthrough that survives contact with real IOMMU topologies, reset bugs and firmware quirks.
Prerequisites
Course outline
Day 1 — IOMMU foundations
- DMA remapping and why assignment without an IOMMU is not isolation
- IOMMU groups as the unit of assignment
- ACS and why PCIe topology decides group boundaries
- Interrupt remapping and what it protects
- Reading a real platform: group layout, firmware tables and their mistakes
Day 2 — VFIO in practice
- VFIO architecture: containers, groups and devices
- The vfio-pci driver and the binding workflow
- Userspace DMA through VFIO without a VM
- Assigning a device to a QEMU/KVM guest and verifying DMA and MSI-X inside
- SR-IOV: enabling VFs, assigning them, and the limits of the model
Day 3 — GPU passthrough and systematic debugging
- GPU passthrough specifics: function-level reset bugs and their workarounds
- BAR sizing, resizable BAR and guest address space
- vBIOS/ROM quirks and vendor lockout behaviours
- A debugging procedure for 'binds but does not work': group, driver, DMA, interrupt, in that order
- Operational concerns: driver rebind races, persistence and host stability
Hands-on labs
Labs follow the academy model — 35% principles, 20% guided investigation, 45% engineering studio. Every claim you make in a lab is backed by a trace, a counter or a measurement you captured yourself. How we teach
- Lab: map a machine's IOMMU groups from sysfs and explain each grouping against the PCIe topology and ACS capability
- Lab: bind a device to vfio-pci and drive it from a VFIO userspace program — DMA and interrupts, no QEMU involved
- Lab: pass a PCIe device into a QEMU/KVM guest and prove DMA and MSI-X delivery from inside
- Lab: create SR-IOV virtual functions on a capable device and assign one to a guest, documenting what the VF cannot do
- Lab: debug an injected broken passthrough — wrong group, missing reset, host driver rebind — to a working state with evidence at each step
Capstone project
Deliver a validated passthrough configuration for a real device (or an emulated equivalent): the platform's IOMMU group analysis, the binding and QEMU configuration, in-guest verification of DMA and interrupts, and a written debugging trail covering the failure you hit on the way — plus a runbook someone else can follow to reproduce the setup and re-diagnose it after a host upgrade.
What you leave with
- The ability to read any platform's IOMMU groups and predict assignment problems
- A complete vfio-pci binding and QEMU assignment workflow
- Hands-on SR-IOV VF creation and assignment
- A convergent debugging procedure for passthrough failures
- A runbook template you can apply to your own hardware fleet
How it runs
Every course follows the same model: 35% principles, 20% guided investigation, 45% engineering studio. You leave with working code, raw measurements and an evidence-based report — not a certificate of attendance. Read the methodology or see a full sample lesson.
Material is adapted to your kernel version, hardware and workload before a private delivery. For public cohorts, the environment is provided and configured.
Questions
Who is this course for?
Engineers who must give VMs direct access to real hardware — GPUs, NICs, accelerators — and need passthrough that survives contact with real IOMMU topologies, reset bugs and firmware quirks. It sits at advanced level within the Virtualization & Containers track.
What do I need to know already?
Specific prerequisites for this course: KVM/QEMU basics (VRT-101 or equivalent experience); PCIe fundamentals: BARs, configuration space; Comfort with kernel modules and sysfs. We confirm levels before the cohort starts and adapt if a group is stronger or weaker than expected.
Can this run privately for my team?
Yes. Any course runs on-site at your offices anywhere, or live online for a distributed team, with labs adapted to your hardware and codebase.
What is the difference between in-person and online?
In person is 3 full days with hardware on your desk, capped at 14. Online is 6 half-day sessions across about two weeks so you can keep working, capped at 20, with remote lab access.
Do you invoice companies?
Yes. Purchase orders are accepted and invoicing is available in USD, EUR, GBP, SAR and CAD.
Upcoming dates
| Dates | Where | Seats | Early bird | Regular | |
|---|---|---|---|---|---|
| 15 Nov – 17 Nov 20263 full days | RiyadhIn person · KAFD Conference Centre | 8 of 14 | SAR 8,100until 16 Oct | ||
| 22 Nov – 24 Nov 20263 full days | Kuwait CityIn person · Al Hamra Tower | 3 of 14 | KWD 670until 23 Oct | ||
| 22 Nov – 24 Nov 20263 full days | MuscatIn person · Knowledge Oasis Muscat | 8 of 14 | OMR 830until 23 Oct | ||
| 29 Nov – 6 Dec 20266 half-days | Gulf bandLive online · 09:00–13:00 GMT+3 | 14 of 20 | US$1,580until 30 Oct | ||
| 30 Nov – 2 Dec 20263 full days | OttawaIn person · Kanata North Tech Park | 3 of 14 | CAD 2,930until 31 Oct | ||
| 7 Dec – 9 Dec 20263 full days | TorontoIn person · MaRS Discovery District | 8 of 14 | CAD 2,930until 7 Nov | ||
| 7 Dec – 9 Dec 20263 full days | LondonIn person · Shoreditch Works | 3 of 14 | GBP 1,680until 7 Nov | ||
| 7 Dec – 14 Dec 20266 half-days | Europe bandLive online · 09:00–13:00 CET | 3 of 20 | US$1,580until 7 Nov | ||
| 7 Dec – 14 Dec 20266 half-days | Americas bandLive online · 13:00–17:00 ET | 8 of 20 | US$1,580until 7 Nov | ||
| 14 Dec – 16 Dec 20263 full days | BerlinIn person · Factory Görlitzer Park | 8 of 14 | EUR 1,990until 14 Nov |
Dates shown for the next few months. If nothing fits, tell us where and when — cohorts are added on demand, and private delivery can be scheduled any week.
More in Virtualization & Containers
VRT-1014 days
KVM Internals
How Linux becomes a hypervisor: vCPU execution, memory virtualisation and the QEMU relationship.
Practitioner-taught
SAR 12,000Next 18 Oct
VRT-1203 days
virtio Device Drivers
The paravirtualised device model: virtqueues, transports and writing a virtio driver.
Practitioner-taught
SAR 9,000Next 1 Nov
VRT-2013 days
Namespaces & cgroups from Scratch
Build a container by hand with the primitives, so the abstraction stops being magic.
Practitioner-taught
SAR 7,880Next 8 Nov
VRT-2103 days
Container Runtimes & the OCI Spec
What runc, containerd and the OCI specifications actually define, and how images become running processes.
Practitioner-taught
SAR 7,880Next 18 Oct
VRT-2203 days
Container Security & seccomp
Making containers a real security boundary rather than an organisational one.
Practitioner-taught
SAR 9,000Next 22 Nov