NHoursForOSXKVMAndIDV

系统硬件

主要信息:

华擎Z370M主板
Intel i7-9700K
32G 内存
200G SSD存储

/images/2023_04_18_09_51_43_990x574.jpg

附加显卡信息:

$ sudo lspci | grep -i vga
00:02.0 VGA compatible controller: Intel Corporation CoffeeLake-S GT2 [UHD Graphics 630]
01:00.0 VGA compatible controller: Advanced Micro Devices, Inc. [AMD/ATI] Baffin [Radeon RX 550 640SP / RX 560/560X] (rev ff)
03:00.0 VGA compatible controller: Advanced Micro Devices, Inc. [AMD/ATI] Turks [Radeon HD 7600 Series]

BIOS配置及选项详解

BIOS 高级->CPU配置中,打开Intel虚拟化技术,关闭Software Guard Extensions (SGX):

/images/2023_04_18_09_54_10_1232x252.jpg

BIOS 高级->芯片组配置中,打开VT-d功能,关闭Above 4G Decoding, 主图形适配器选择为板载:

/images/2023_04_18_09_55_18_1198x437.jpg

BIOS 高级->芯片组配置中,设置显卡的共享内存为1G, 打开IGPU多监视器选项,使得在外部有显卡的情况下集显保持开启:

/images/2023_04_18_09_58_09_1130x153.jpg

(可选)关闭可信赖计算:

/images/2023_04_18_09_59_00_1115x241.jpg

引导->CSM(兼容性支持模块)中,将启动视频OpROM策略设置为仅传统:

/images/2023_04_18_10_03_57_1201x270.jpg

调整启动顺序为从U盘启动,进入到系统的安装过程。

Host系统安装

将网上下载的Ubuntu22.04安装盘写入U盘:

$ sudo dd if=ubuntu-22.04.2-live-server-amd64.iso of=/dev/sdb bs=1M && sudo sync

选择UEFI分区的USB设备进入到安装过程:

/images/2023_04_18_10_24_27_844x331.jpg

Grub栏中,选择Try or Install Ubuntu Server:

/images/2023_04_18_10_05_47_1120x296.jpg

选择语言为English,自动配置网络, 忽略proxy address配置,mirror address保持默认(也可以改变为网速较好的源) :

/images/2023_04_18_10_10_20_828x234.jpg

(非必选)分区这里选择基本(避免LVM可能给新学者带来的困扰):

/images/2023_04_18_10_11_08_1039x286.jpg

检查下存储layout是否正常,无问题则下一步:

/images/2023_04_18_10_11_22_1209x570.jpg

/images/2023_04_18_10_12_05_876x301.jpg 配置用户名/密码:

/images/2023_04_18_10_25_59_1091x440.jpg

忽略Ubuntu Pro选项后继续,选择Install OpenSSH server:

/images/2023_04_18_10_26_44_919x365.jpg

在子功能选单中,什么都不选,进入到安装过程,直到所有安装都完成。Ubuntu live server在安装时最好保持联网状态,否则可能出现部分包安装不成功导致整个系统安装失败的情况。

看到这个界面则显示成功:

/images/2023_04_18_10_31_49_1509x1014.jpg

安装后登陆界面:

/images/2023_04_18_10_33_43_860x394.jpg

Host系统安装问题解决

在安装过pve的磁盘上,或者以前用LVM安装过系统的硬盘上,全新安装Ubuntu时,会出现以下的错误:

/images/2023_04_18_10_21_19_1400x506.jpg 解决方法为:

vgremove xxxxxx(这里填你的vg的名字,通过vgs查看)
pvremove /dev/xxxx(这里填你的pvs所在的实际物理设备,通过pvs查看)

完全删除掉已有的逻辑卷分区后,重新进入到安装过程后方可成功。

系统配置

确保系统更新到最新状态:

sudo apt update
sudo apt upgrade -y

选择KDE作为默认的桌面工作环境, 并安装其他的一些包,选择KDE的原因在于它使用sddm+Xorg, 后续用libvirt钩子用于gvt-d透传集成显卡到虚机的时候,可以卸载得比较完整。默认的Ubuntu-desktop有时会出现在主机/虚机之间切换时失败的情况,推测与gdm3的工作方式有关:

sudo apt install -y kubuntu-desktop virt-manager build-essential

配置vfio相关选项:

# sudo vim /etc/default/grub
......
GRUB_CMDLINE_LINUX_DEFAULT="intel_iommu=on intel_iommu=pt kvm.ignore_msrs=1"
......
# sudo update-grub2
# sudo vim /etc/initramfs-tools/modules
......
vfio
vfio_iommu_type1
vfio_pci
vfio_virqfd

使用lspci查看两块AMD独显的VGA及Audio配置信息,记录下相应字段:

/images/2023_04_18_11_08_58_945x326.jpg

# echo "options vfio-pci ids=1002:67ff,1002:675b,1002:aae0,1002:aa90" >> /etc/modprobe.d/vfio.conf
# sudo vim /etc/modprobe.d/blacklist.conf
......
blacklist amdgpu
# update-initramfs -u -k all && reboot

配置KDE的屏幕锁屏选项:

/images/2023_04_18_11_34_32_930x490.jpg

关闭Energy Saving:

/images/2023_04_18_11_35_14_832x441.jpg

Login Screen(SDDM)选择 Bahavior:

/images/2023_04_18_11_36_33_951x832.jpg 使能登出后自动登入:

/images/2023_04_19_14_41_02_962x411.jpg

之后选择子选项:

/images/2023_04_18_11_37_28_1057x607.jpg

KDE桌面下其实是存在大量的可优化空间的,后面可以深入探讨。

OSX-KVM落地

主要参考了: https://github.com/kholia/OSX-KVM:

按仓库要求,安装相应包, 准备相关文件 :

sudo apt-get install qemu uml-utilities virt-manager git \
    wget libguestfs-tools p7zip-full make dmg2img -y
sudo reboot
sudo usermod -aG kvm $(whoami)
sudo usermod -aG libvirt $(whoami)
sudo usermod -aG input $(whoami)
git clone --depth 1 --recursive https://github.com/kholia/OSX-KVM.git

下载Ventura (13):

$ cd OSX-KVM
$ ./fetch-macOS-v2.py 
1. High Sierra (10.13)
2. Mojave (10.14)
3. Catalina (10.15)
4. Big Sur (11.7) - RECOMMENDED
5. Monterey (12.6)
6. Ventura (13)

Choose a product to download (1-6): 6
Ventura (13)
Downloading 032-66586...
Saving http://oscdn.apple.com/content/downloads/54/39/032-66586/dtdkth7btmat4w68aohv87st5j33d2puna/RecoveryImage/BaseSystem.dmg to BaseSystem.dmg...
Note: The total download size is 675.59 MB
$ dmg2img -i BaseSystem.dmg BaseSystem.img
$ qemu-img create -f qcow2 mac_hdd_ng.img 64G
$ ./OpenCore-Boot.sh 

进入到安装界面:

/images/2023_04_18_12_10_54_517x492.jpg

选择Disk Utitity:

/images/2023_04_18_12_11_45_1088x442.jpg

而后选择Reinstall开始安装, 注意选择格式化后的macOS 64GB的盘:

/images/2023_04_18_12_13_57_583x567.jpg

安装配置阶段:

/images/2023_04_18_13_10_06_801x599.jpg

选择not now:

/images/2023_04_18_13_10_35_797x602.jpg 选择 Set Up Later:

/images/2023_04_18_13_11_00_809x605.jpg

创建用户:

/images/2023_04_18_13_11_35_711x403.jpg

装完后:

/images/2023_04_18_13_15_45_290x510.jpg

开启ssh和vnc:

/images/2023_04_18_14_09_08_710x390.jpg

在命令行下,拷贝OpenBoot的EFI分区到硬盘下:

test@tests-iMac-Pro ~ % sudo diskutil list
.......这里需要识别出哪个分区是ISO的,哪个是硬盘上的
test@tests-iMac-Pro ~ % sudo diskutil mount disk0s1
Volume EFI on disk0s1 mounted
test@tests-iMac-Pro ~ % sudo diskutil mount disk1s1
Volume EFI on disk1s1 mounted
test@tests-iMac-Pro ~ % mount
/dev/disk2s5s1 on / (apfs, sealed, local, read-only, journaled)
devfs on /dev (devfs, local, nobrowse)
/dev/disk2s4 on /System/Volumes/VM (apfs, local, noexec, journaled, noatime, nobrowse)
/dev/disk2s2 on /System/Volumes/Preboot (apfs, local, journaled, nobrowse)
/dev/disk2s6 on /System/Volumes/Update (apfs, local, journaled, nobrowse)
/dev/disk2s1 on /System/Volumes/Data (apfs, local, journaled, nobrowse)
map auto_home on /System/Volumes/Data/home (autofs, automounted, nobrowse)
/dev/disk0s1 on /Volumes/EFI (msdos, asynchronous, local, noowners)
/dev/disk1s1 on /Volumes/EFI 1 (msdos, asynchronous, local, noowners)
test@tests-iMac-Pro ~ % cp -r /Volumes/EFI/EFI /Volumes/EFI\ 1 
test@tests-iMac-Pro ~ % sudo sync     
test@tests-iMac-Pro ~ % sudo shutdown -h now

重新启动后,更改Boot的等待时延(挂在EFI分区后):

 % cat EFI/OC/config.plist| grep '<key>Timeout' -A2
			<key>Timeout</key>
			<integer>5</integer>
		</dict>

OSX-KVM with rx550(Ventura)

直接使用脚本测试,得到的结果:

cp boot-passthrough.sh testrx550.sh
lspci | grep 550
01:00.0 VGA compatible controller: Advanced Micro Devices, Inc. [AMD/ATI] Baffin [Radeon RX 550 640SP / RX 560/560X] (rev ff)
01:00.1 Audio device: Advanced Micro Devices, Inc. [AMD/ATI] Baffin HDMI/DP Audio [Radeon RX 550 640SP / RX 560/560X]
vim testrx550.sh
  -vnc 0.0.0.0:8 -k en-us
  -netdev user,hostfwd=tcp::2288-:22,hostfwd=tcp::15900-:5900,id=net0 -device vmxnet3,netdev=net0,id=net0,mac=52:54:00:c9:18:27

效果: 最初引导的时候会出现画面,且可以一直操作(OpenCore),但是进入到苹果后黑屏。ssh可以登陆到成功启动后的macOS,但是vnc登陆则一直显示黑屏。

OSX-KVM(Monterey)

重新安装一台Monterey虚机:

/images/2023_04_18_15_14_39_508x574.jpg

/images/2023_04_18_16_15_35_595x362.jpg

ssh/vnc启用:

/images/2023_04_18_16_16_21_657x516.jpg

Monterey会正常启动

vendor-reset

AMD显卡需要引入这个模块以便在vfio的时候reset为可用状态:

git clone https://github.com/gnif/vendor-reset.git
cd vendor-reset/
sudo apt install -y dkms
sudo dkms install .
sudo vim /etc/initramfs-tools/modules
vendor-reset
sudo update-initramfs -u -k all
sudo reboot

重启成功后:

$ lsmod | grep vendor
vendor_reset          114688  0

使用下面的vfio_bind.sh用来初始化显卡, 注意vendor_reset需要一个bug-fix(device_specific):

#!/bin/bash
modprobe vfio-pci
for dev in "$@"; do
vendor=$(cat /sys/bus/pci/devices/$dev/vendor)
device=$(cat /sys/bus/pci/devices/$dev/device)
if [ -e /sys/bus/pci/devices/$dev/driver ]; then
echo $dev > /sys/bus/pci/devices/$dev/driver/unbind
fi
echo $vendor $device > /sys/bus/pci/drivers/vfio-pci/new_id
echo 'device_specific' > /sys/bus/pci/devices/$dev/reset_method
done

vbflash

使用工具dump出显卡的vbflash:

/images/2023_04_18_16_52_25_1024x467.jpg

7600看起来似乎无法驱动。临时换成了5700xt显卡用来测试。
5700xt需要添加:

test@tests-iMac-Pro EFI % cat EFI/OC/config.plist| grep boot-args -A3
				<key>boot-args</key>
				<string>-v keepsyms=1 tlbto_us=0 vti=9 agdpmod=pikera</string>

网络配置(桥接)

桥接是为了让虚拟机获得同网段地址:

# sudo apt install bridge-utils -y
# sudo vim /etc/default/grub
GRUB_CMDLINE_LINUX_DEFAULT="intel_iommu=on intel_iommu=pt kvm.ignore_msrs=1 net.ifnames=0 biosdevname=0"
# sudo update-grub2
# vim /etc/netplan/00-installer-config.yaml 
# This is the network config written by 'subiquity'
network:
  ethernets:
    eth0:
      dhcp4: false
  bridges:
    br0:
      interfaces: [eth0]
      dhcp4: true
  version: 2
# reboot

libvirtd集成

准备镜像:

test@server:~/OSX-KVM-Monterey$ sudo cp mac_hdd_ng.img /var/lib/libvirt/images/ && sudo sync
test@server:~/OSX-KVM-Monterey$ sudo cp OVMF_VARS-1024x768.fd /var/lib/libvirt/images/
test@server:~/OSX-KVM-Monterey$ sudo cp OVMF_CODE.fd /var/lib/libvirt/images/
root@server:/var/lib/libvirt/images# qemu-img create -f qcow2 -b mac_hdd_ng.img -F qcow2 amd5700xt.qcow2
root@server:/var/lib/libvirt/images# qemu-img create -f qcow2 -b mac_hdd_ng.img -F qcow2 rx560.qcow2
root@server:/var/lib/libvirt/images# cp OVMF_VARS-1024x768.fd rx560_OVMF_VARS-1024x768.fd amd5700_OVMF_VARS-1024x768.fd

libvirtd配置文件(RX 5700 8GB及 RX 550 4GB):

https://gist.githubusercontent.com/purplepalmdash/dfba3d32b72901f75d39a84288689692/raw/eb15ad7cd59f86566dd8fb5cfc6786639c0cb6a8/macOS5700.xml
https://gist.githubusercontent.com/purplepalmdash/dfba3d32b72901f75d39a84288689692/raw/eb15ad7cd59f86566dd8fb5cfc6786639c0cb6a8/macOSrx550.xml

guest配置

阻止虚拟机进入到节能状态:

/images/2023_04_19_14_15_42_642x477.jpg

禁止锁定屏幕:

/images/2023_04_19_14_17_15_622x403.jpg

禁止自动更新:

/images/2023_04_19_14_18_38_638x318.jpg

禁用屏幕保护:

/images/2023_04_19_14_19_26_627x551.jpg

win10核显透传

准备libvirtd钩子脚本:

 cd /etc/libvirt/hooks/
 mv /home/test/hooks/* .
 ln -s /etc/libvirt/hooks/vfio-startup.sh /bin/
 ln -s /etc/libvirt/hooks/vfio-teardown.sh /bin/

如果要透传核显,则grub的参数需要做相应的修改:

GRUB_CMDLINE_LINUX_DEFAULT="intel_iommu=on intel_iommu=pt kvm.ignore_msrs=1 net.ifnames=0 biosdevname=0 video=efifb:off,vesafb:off"

因为以前已经做过相关的内容,这里就不再详细说明。

已知/偶现问题

一次失败的核显透传后,重启失败, 更改grub默认选项后修复:

/images/2023_04_19_14_45_26_1018x372.jpg Android studio无法运行?

WorkingTipsOnIGPUPassthroughOSX

Use diskutil for Change the EFI partition:

/images/2023_04_12_10_41_07_510x533.jpg

Copy from iso’s EFI to disk’s EFI:

% cp -r /Volumes/EFI/EFI /Volumes/EFI\ 1/
% sudo sync
% sudo shutdown -h now

Enable ssh:

/images/2023_04_12_10_45_08_525x420.jpg

Then we could use ssh via:

# ssh test@192.168.1.129
X11 forwarding request failed on channel 0
Last login: Wed Apr 12 10:45:16 2023 from 192.168.1.222
test@tests-iMac-Pro ~ % uname -a
Darwin tests-iMac-Pro.local 21.6.0 Darwin Kernel Version 21.6.0: Thu Mar  9 20:08:59 PST 2023; root:xnu-8020.240.18.700.8~1/RELEASE_X86_64 x86_64

Copy and replace EFI using igpu optimized version.
above 4G decoding forbid the hackintosh igpu passthrough.

ConfigurationOn4GDecoding

Above 4G Decoding (Available if the system supports 64-bit PCI decoding) Select Enabled to decode a PCI device that supports 64-bit in the space above 4G Address. The options are Enabled and Disabled.

翻译:

G以上解码(如果系统支持64位PCI解码,则可用)选择 “已启用 “来解码一个支持64位的PCI设备,在4G地址以上的空间。选项是已启用和已禁用。

禁用的情况:

root@mac:~# lspci -v | grep "Memory.*64-bit"
	Memory at d0000000 (64-bit, prefetchable) [disabled] [size=256M]
	Memory at e0000000 (64-bit, prefetchable) [disabled] [size=2M]
	Memory at fcf60000 (64-bit, non-prefetchable) [size=16K]
	Memory at fce04000 (64-bit, non-prefetchable) [size=4K]
	Memory at fce00000 (64-bit, non-prefetchable) [size=16K]
	Memory at b0000000 (64-bit, prefetchable) [size=256M]
	Memory at c0000000 (64-bit, prefetchable) [size=2M]
	Memory at fca00000 (64-bit, non-prefetchable) [size=1M]
	Memory at fc900000 (64-bit, non-prefetchable) [size=1M]

开启的情况:

idv@idv-TC-9070:~$ sudo lspci -v | grep "Memory.*64-bit"
	Memory at de000000 (64-bit, non-prefetchable) [size=16M]
	Memory at c0000000 (64-bit, prefetchable) [size=256M]
	Memory at df110000 (64-bit, non-prefetchable) [size=64K]
	Memory at df12d000 (64-bit, non-prefetchable) [size=4K]
	Memory at df120000 (64-bit, non-prefetchable) [size=16K]
	Memory at df100000 (64-bit, non-prefetchable) [size=64K]
	Memory at df12a000 (64-bit, non-prefetchable) [size=256]
	Memory at df000000 (64-bit, non-prefetchable) [size=4K]
	Memory at d0000000 (64-bit, prefetchable) [size=16K]

Other options in bios

peci:

PECI是用于监测CPU及芯片组温度的一线总线(one-wire bus),全称是Platform Environment Control Interface。

OSXKVMGVTPASSTHROUGH

Install Prerequisite packages:

$ sudo apt-get install qemu uml-utilities virt-manager git \
    wget libguestfs-tools p7zip-full make dmg2img -y
$ cat kvm.conf 
options kvm_intel nested=1
options kvm_intel emulate_invalid_guest_state=0
options kvm ignore_msrs=1 report_ignored_msrs=0
$ sudo cp kvm.conf /etc/modprobe.d/
$ echo 1 | sudo tee /sys/module/kvm/parameters/ignore_msrs
$ sudo usermod -aG kvm $(whoami)
$ sudo usermod -aG libvirt $(whoami)
$ sudo usermod -aG input $(whoami)

Clone related repository:

git clone https://github.com/vivekmiyani/OSX_GVT-D
git clone --recursive https://github.com/kholia/OSX-KVM.git
cd OSX-KVM
git checkout 88154b5bac079473660afc2a89704874cc7edf03

Choose Monterey for downloading:

$ ./fetch-macOS-v2.py 
1. High Sierra (10.13)
2. Mojave (10.14)
3. Catalina (10.15)
4. Big Sur (11.6) - RECOMMENDED
5. Monterey (latest)

Choose a product to download (1-5): 5
Monterey (latest)

Format the disk and install macos in kvm:

dmg2img -i BaseSystem.dmg BaseSystem.img
qemu-img create -f qcow2 mac_hdd_ng.img 128G
./OpenCore-Boot.sh

IDVRelease

Install cubic(ubuntu 22.04.2):

sudo apt-add-repository universe
sudo apt-add-repository ppa:cubic-wizard/release
sudo apt update
sudo apt install --no-install-recommends cubic

Then start cubic and following the guideline.

/images/2023_04_03_09_41_47_744x543.jpg

/images/2023_04_03_09_42_46_960x651.jpg

In terminal do:

root@cubic:~# history
    1  dpkg -l
    2  gsettings set org.gnome.desktop.session idle-delay 0
    3  gsettings set org.gnome.desktop.screensaver ubuntu-lock-on-suspend false
    4  vi /etc/default/apport 
    5  passwd
    6  which vim
    7  apt install openssh-server
    8  vim /etc/ssh/sshd_config 
    9  vi /etc/ssh/sshd_config 
   10  dpkg -l | grep thunderbird
   11  sudo apt remove thunderbird
   12  dpkg -l | grep libreoffice
   13  sudo apt remove libreoffice
   14  sudo apt remove libreoffice*
   15  sudo apt remove libreoffice-core
   16  dpkg -l | more
   17  apt install -y sddm
   18  apt-cache search sddm
   19  apt update
   20  vi /etc/apt/sources.list
   21  ap tupdate
   22  apt update
   23  apt install sddm
   24  apt-cache search sddm
   25  apt-cache search build-essential
   26  apt-get policy build-essential
   27  apt-get search build-essential
   28  apt-cache policy build-essential
   29  vi /etc/apt/sources.list
   30  apt-get update
   31  apt-cache search sddm
   32  sudo apt install -y sddm
   33  df -h
   34  history
   35  useradd -m ctyunidv
   36  passwd ctyunidv
   37  mkdir -p /etc/sddm.conf.d/
   38  vim /etc/sddm.conf.d/autologin.conf
   39  vi /etc/sddm.conf.d/autologin.conf
   40  apt install -y iotop
   41  history
   42  clear
   43  ls
   44  vi /etc/default/grub 
   45  update-grub2 
   46  vim /etc/initramfs-tools/modules 
   47  vi /etc/initramfs-tools/modules 
   48  update-initramfs -u -k all
   49  which scp
   50  scp ctyunidv@172.23.119.211:~/CtyunDesktopIDV_1.0.2_101000200_x64_03-17-11-20.deb .
   51  scp ctyunidv@172.23.119.211:~/ctgcd-clouddesktop-idvagent.war .
   52  ls
   53  sudo apt install -y ./CtyunDesktopIDV_1.0.2_101000200_x64_03-17-11-20.deb 
   54  ssh-keygen 
   55  cat /root/.ssh/id_rsa.pub 
   56  scp root@172.23.119.211:/root/ljr/linux-image-5.10.90-c1dc2c9a39ac_5.10.90-c1dc2c9a39ac-17_amd64.deb .
   57  apt install -y ./linux-image-5.10.90-c1dc2c9a39ac_5.10.90-c1dc2c9a39ac-17_amd64.deb 
   58  ls
   59  history