NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
crates.io · #4697 most downloaded on crates.io
Safe wrappers over KVM ioctls
Last release 3 months ago
15 Jun 2026
Release timing varies
gaps range from 4 weeks to 8 months
Most releases are documented
notes for 26 of 30 stable releases
Nothing withdrawn
no release was ever pulled
8 years old
30 releases · first in 2019
Plumb through KVM_CAP_COUNTER_OFFSET as Cap::CounterOffset .
KVM_CAP_COUNTER_OFFSET as Cap::CounterOffset.KVM_CAP_DIRTY_LOG_RING as Cap::DirtyLogRing.KVM_SET_MSR_FILTER vm ioctl on x86_64.kvm-bindings to v0.14.1.Plumb through KVM_CAP_X2APIC_API as X2ApicApi cap.
KVM_HAS_DEVICE_ATTR and KVM_SET_DEVICE_ATTR vm ioctl on aarch64.One column per quarter.
[#322] Added VcpuFd::nested_state() and VcpuFd::set_nested_state() to work with nested KVM state. Only works on x86 . The helper type KvmNestedStateBu
VcpuFd::nested_state()and VcpuFd::set_nested_state() to work with nested KVM state. Only works on x86. The helper type KvmNestedStateBuffermakes these new functions easily usable.kvm-bindings to v0.13.0Nothing published for this version
[#324] Upgrade kvm-bindings to v0.12.0
[ #310 ]: Added support for KVM_CAP_XSAVE2 and the KVM_GET_XSAVE2 ioctl.
KVM_CAP_XSAVE2 and the KVM_GET_XSAVE2 ioctl.set_xsave() unsafe because the C kvm_xsave struct was extended to have a flexible array member (FAM) in the end in Linux 5.16 and KVM_SET_XSAVE may copy data beyond the traditional size (i.e. 4096 bytes). If any features are enabled dynamically on Linux 5.16+, it is recommended to use set_xsave2() instead.KVM_CAP_XSAVE2 and the KVM_GET_XSAVE2 ioctl.set_xsave()
unsafe because the C kvm_xsave struct was extended to have a flexible
array member (FAM) in the end in Linux 5.16 and KVM_SET_XSAVE may copy data
beyond the traditional size (i.e. 4096 bytes). If any features are enabled
dynamically on Linux 5.16+, it is recommended to use set_xsave2() instead.set_gsi_routing() to use the newly created KvmIrqRouting type which is a
FamStruct wrapper over kvm_irq_routing. This way we can safely call the
ioctl without relying on the caller making sure the memory layout of
kvm_irq_routing is sane.[#288]: Introduce Cap::GuestMemfd, Cap::MemoryAttributes and Cap::UserMemory2 capabilities enum variants for use with VmFd::check_extension.
Cap::GuestMemfd, Cap::MemoryAttributes and
Cap::UserMemory2 capabilities enum variants for use with VmFd::check_extension.VmFd::check_extension_raw and VmFd::check_extension_int to allow KVM_CHECK_EXTENSION to return integer.ioctl_wit_ref in the
create_device method. Replace it with ioctl_wit_mut_ref as the passed parameter may be mutated by the
ioctl.Nothing published for this version
[#275]: Introduce riscv64 ioctls.
[#264]: Added KVM_SET_USER_MEMORY_REGION2, KVM_CREATE_GUEST_MEMFD and KVM_SET_MEMORY_ATTRIBUTES ioctls.
[#255]: Fixed a soundness issue when accessing the kvm_run struct. VcpuFd::run() and VcpuFd::set_kvm_immediate_exit() now take &mut self as a conseque
[#242] x86: add support for SMI injection via Vcpu::smi() (KVM_SMI ioctl).
[#230] Added check_extension_raw method to use raw integer values instead of Cap enum.
[#219] Support for KVM_GET_MSR_FEATURE_INDEX_LIST and KVM_GET_MSRS system ioctls.
[#213] Add Kvm::new_with_path() and Kvm::open_with_cloexec_at() to allow using kvm device files other than /dev/kvm.
Kvm::new_with_path()
and Kvm::open_with_cloexec_at() to allow using kvm device files other than
/dev/kvm.[ #298 ]: Fixed incorrect usage of ioctl_with_ref in the create_device method. Replace it with ioctl_with_mut_ref as the passed parameter may be mutat
ioctl_with_ref in the create_device method. Replace itioctl_with_mut_ref as the passed parameter may be mutated by[#187] Support for KVM_SET_IDENTITY_MAP_ADDR
KVM_SET_IDENTITY_MAP_ADDRKVM_SET_ and
KVM_HAS_DEVICE_ATTR for vcpuKVM_TRANSLATE support and
the translate_gva function that translates guest virtual address to the physical addresssync_regs
to allow bulk getting and setting of general purpose registers, reducing the number of
ioctls needed.KVM_EXIT_FAIL_ENTRY in vCPU runregister_irqfd_with_resample
so that irqfd + resaplefd can be registered through KVM_IRQFDKVM_CAP_GUEST_DEBUG_HVM_DPS/WPScheck_extension_int
which allows checking the capabilities that return numbers instead of booleansKVM_EXIT reasonkvm_run structure to allow proper handling of unsupported exit reasonstarget_arch gate
preventing set_guest_debug from being exported on ARMu128 in get/set_on_reg[#178] Support for the AMD Security Encrypted Virtualization (SEV) through the following VM ioctls: encrypt_op, encrypt_op_sev, register_enc_memory_re
Now depends on kvm-bindings >=0.5.0 which replaced the v4.20 KVM bindings with the v5.13 ones.
VcpuExit::Debug to return architecture specific information for the
debug event.Support for accessing and controlling the Time Stamp Counter on x86 platforms through the get_tsc_khz and set_tsc_khz functions.
get_tsc_khz and set_tsc_khz functions.create_vm on aarch64 to create a VM fd from the KVM fd using the
host's maximum IPA size.Support for specifying VM type (an opaque platform and architecture specific constant) when creating a VM (KVM_CREATE_VM ioctl) via the Kvm::create_vm
KVM_CREATE_VM ioctl) via the
Kvm::create_vm_with_type function.Support for the system API that returns the maximum allowed vCPU ID (KVM_CAP_MAX_VCPU_ID).
KVM_CAP_MAX_VCPU_ID).KVM_MEMORY_ENCRYPT_OP.get_supported_cpuid and
get_emulated_cpuid.create_vcpu to use u64 as the parameter for the number of vCPUs.Nothing published for this version
Support for the vcpu ioctls: KVM_SET_GUEST_DEBUG, KVM_KVMCLOCK_CTRL, and KVM_GET_REG_LIST.
KVM_SET_GUEST_DEBUG, KVM_KVMCLOCK_CTRL, and
KVM_GET_REG_LIST.KVM_GET_DEVICE_ATTR.KVM_HAS_DEVICE_ATTR.VcpuExit::Debug.Vcpu::enable_cap.HypervSynic and HypervSynic2), MSI
(MsiDevid), and IPA Size (ArmVmIPASize) capabilities.
using kvm.check_extension.Vm::check_extension.Kvm::create_vm_with_ipa_size.Kvm::new_with_fd_number. The same functionality is offered by the
Kvm FromRawFd
trait implementation.unregister_ioevent now correctly unregisters the events that
correspond to the data match passed as a parameter.SystemEvent Vcpu Exit now also contains the relevant type and flags.get_dirty_log such that it does not assume the page size is 4K,
but instead reads it using libc::sysconf.Support for the vcpu ioctls KVM_GET/SET_VCPU_EVENTS and KVM_GET_DIRTY_LOG on aarch64.
KVM_GET/SET_VCPU_EVENTS and KVM_GET_DIRTY_LOG
on aarch64.KVM_IRQ_LINE.Support for unregistering ioeventfds through KVM_IOEVENTFD.
KVM_IOEVENTFD.Support for setting vcpu kvm_immediate_exit flag
kvm_immediate_exit flagKVM_GET_CPUID2KVM_GET_MP_STATEKVM_SET_MP_STATEKVM_GET_VCPU_EVENTSKVM_SET_VCPU_EVENTSKVM_GET_DEBUGREGSKVM_SET_DEBUGREGSKVM_GET_XSAVEKVM_SET_XSAVEKVM_GET_XCRSKVM_SET_XCRSKVM_GET_IRQCHIPKVM_SET_IRQCHIPKVM_GET_CLOCKKVM_SET_CLOCKKVM_GET_PIT2KVM_SET_PIT2KVM_GET_ONE_REGKVM_SET_MSRS also returns the number
of MSR entries successfully written.Add support for KVM_ENABLE_CAP.
KVM_ENABLE_CAP.KVM_SIGNAL_MSI.First release of the kvm-ioctls crate.
First release of the kvm-ioctls crate.
The kvm-ioctls crate provides safe wrappers over the KVM API, a set of ioctls used for creating and configuring Virtual Machines (VMs) on Linux. The ioctls are accessible through four structures:
The kvm-ioctls can be used on x86_64 and aarch64. Right now the aarch64 support is considered experimental.
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →