Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The ELCE 2016 tutorial Bootstrapping the Partitioning Hypervisor Jailhouse is a Siemens Corporate Technology session presented by Jan Kiszka. It walks through Jailhouse’s Linux-based, static partitioning model, then demonstrates a staged bring-up: first in QEMU/KVM, then on x86 hardware and ARM64. Its commands and hardware examples are historical; use current project documentation and validate configurations against the target machine before deploying them.

What the ELCE 2016 tutorial teaches

Jailhouse is a partitioning hypervisor based on Linux. Linux boots first and manages the system; Jailhouse is enabled afterward, and selected CPUs, memory, and devices can then be assigned to isolated domains called cells. The Linux instance that retains system management is the root cell. Other cells can run a bare-metal application, another Linux instance, or a real-time workload. The project documentation describes Jailhouse as a partitioning hypervisor based on Linux.

This is static partitioning, not general-purpose virtual-machine scheduling. Jailhouse does not overcommit CPUs, RAM, or devices and does not dynamically schedule workloads across shared resources. That keeps its operating model comparatively simple, but it makes resource planning and accurate platform configuration essential. The tutorial’s agenda moves from the design philosophy to QEMU/KVM exercises, x86 bring-up, and ARM64 bring-up. The ELCE 2016 slide deck presents this late-partitioning workflow.

How to follow the tutorial workflow

1. Begin with the QEMU/KVM lab

The 2016 session’s initial environment calls for an Intel VT-x host, Linux kernel 4.4 or newer, QEMU 2.7 or newer, a Linux guest image, and build tools for guest modules. These are the tutorial’s requirements at the time of presentation, not current minimum-version guidance. Check the current project documentation for compatibility with your kernel, QEMU build, and target architecture before reproducing the lab.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

2. Enable Jailhouse and create a sample cell

The deck demonstrates a sequence like the following. Run commands with the privileges and from the locations required by your build and configuration; the example filenames are tutorial artifacts, not files supplied by every installation.

  1. insmod jailhouse.ko loads the Jailhouse kernel module.
  2. jailhouse enable qemu-vm.cell enables Jailhouse using the QEMU system configuration.
  3. jailhouse cell create apic-demo.cell creates a cell from its configuration.
  4. jailhouse cell load apic-demo apic-demo.bin -a 0xf0000 loads the demo binary at the specified guest address.
  5. jailhouse cell start apic-demo starts the cell.
  6. jailhouse cell list lists cells, and jailhouse cell stats apic-demo displays statistics for the demo cell.
  7. jailhouse cell destroy apic-demo destroys that cell; jailhouse disable disables Jailhouse after cells have been dealt with.

The exact command behavior depends on the installed Jailhouse version and the target configuration. Consult the project’s current command and configuration documentation rather than treating a 2016 example as a universal runbook.

3. Start Linux in a non-root cell

The tutorial also demonstrates the jailhouse cell linux workflow: supply a kernel, initrd, and command line for the cell, start it, and connect to the running instance. This illustrates that a cell need not be a bare-metal program; a second Linux instance can run with its own statically assigned resources. The kernel, boot parameters, memory map, and devices must all match the cell configuration.

4. Move from simulation to physical x86

The x86 demonstration used a Supermicro X10SDV-TLN4F system with a Xeon D-1540, eight cores with two threads each, 32 GB of RAM, and multiple Ethernet interfaces. Those specifications identify the 2016 demonstration machine only; they are not a current hardware recommendation or a guarantee that another system with similar headline specifications will work.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

5. Prepare an ARM64 platform

The ARM64 portion used a LeMaker HiKey board with a Hi6220 SoC, eight Cortex-A53 cores, 2 GB of RAM, and 8 GB of eMMC. The deck noted that ARM64 support and tooling were still developing in 2016, so its setup reflects that period rather than the present state of support.

How Jailhouse configuration is organized

Jailhouse uses a system configuration describing the root cell and platform resources, plus a separate .cell configuration for each additional cell. The project documentation states: “Jailhouse requires one configuration file for the complete system and one for each additional cell besides the primary Linux.” See the Jailhouse repository documentation for the current format and tools.

A cell definition is more than a CPU list. Depending on the platform and use case, it describes:

  • CPU bitmaps and physical or virtual memory regions.
  • Permissions and uses for regions, including read, write, execute, DMA, MMIO, communication, loadable, and shared-memory flags.
  • PCI devices and capabilities, IOMMU associations, and debug UART mappings.

On an x86 target, the documentation describes jailhouse hardware check for checking required capabilities and jailhouse config create sysconfig.c for generating a starting system configuration. Treat generated output as a starting point to review, not proof that a finished partition layout is safe or correct.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Bring-up checks and common configuration faults

The tutorial presents failures as part of hardware bring-up. Before assigning memory or I/O regions, inspect the platform’s resource map and account for areas reserved by firmware. On Linux, the deck calls out /proc/iomem and /proc/ioports as useful references. Invalid MMIO or RAM accesses, invalid PIO writes, and PCI configuration writes are examples of faults that can point to an incorrect mapping.

x86 regions to protect

The x86 checklist warns against exposing or overlapping sensitive platform regions. In particular, verify the configuration around:

  • APIC and IOAPIC regions.
  • MSI-X areas and IOMMU units.
  • Memory-mapped PCI configuration space.
  • Shared-memory regions that overlap other assigned resources.

ARM64 regions to protect

For ARM64, check that assigned memory does not overlap the hypervisor, that reservations are present and large enough, and that a cell is not given accidental direct access to Generic Interrupt Controller (GIC) regions. These are platform-specific mapping concerns; a configuration that works on one board should not be assumed valid on another.

What the tutorial does—and does not—establish

The session is useful as a guided introduction to Jailhouse’s static ownership model and the practical work of configuring cells. It is not evidence of a particular latency, runtime overhead, or safety certification. The tutorial sources publish no independent performance benchmark or certification figure, so such numbers should not be inferred from the demonstration or the design description.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Class Central lists the tutorial at about 1 hour 45 minutes; that is a course-catalog duration, not a measured runtime for a particular viewer or playback platform. Class Central’s course listing identifies the session and its approximate length.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.