Xen is a hypervisor which supports running multiple guest operating systems on a single machine. Guest OSes (also called "domains") can be either paravirtualised (i.e. make hypercalls in order to access hardware), run in HVM (Hardware Virtualisation Mode) where they will be presented with virtual devices, or a combination where they use hypercalls to access hardware but manage memory themselves. At boot, the xen kernel is loaded along with the guest kernel for the first domain (called domain0). domain0 has privileges to access the physical hardware (PCI and ISA devices), administrate other domains and provide virtual devices (disks and network) to other domains. This package contains the 4.20 Xen kernel itself. PCI passthrough is not supported. PAE is mandatory; on i386 one must use XEN3PAE_DOMU. Note that unlike upstream Xen, pv-linear-pt defaults to true. You can disable it using pv-linear-pt=false on the Xen command line, but then you can't boot NetBSD in PV mode. 32bits PV guests are not officially supported any more. Switch to pvshim (for netbsd-9 or older) or pvh (for netbsd-10 or newer). Unline upstream, SHADOW_PAGING is enabled by default as NetBSD PV guests relies on it. Note that this is not security-supported upstream any more.
| OS | Architecture | Version |
|---|---|---|
| NetBSD 10.0 | x86_64 | xenkernel420-20260610.tgz |
| NetBSD 10.0 | x86_64 | xenkernel420-20260610.tgz |
| NetBSD 11.0 | x86_64 | xenkernel420-20260610.tgz |
| NetBSD 11.0 | x86_64 | xenkernel420-20260610.tgz |
| NetBSD 9.0 | x86_64 | xenkernel420-20260610.tgz |
| NetBSD 9.0 | x86_64 | xenkernel420-20260610.tgz |
Binary packages can be installed with the high-level tool pkgin (which can be installed with pkg_add) or pkg_add(1) (installed by default). The NetBSD packages collection is also designed to permit easy installation from source.
The pkg_admin audit command locates any installed package which has been mentioned in security advisories as having vulnerabilities.
Please note the vulnerabilities database might not be fully accurate, and not every bug is exploitable with every configuration.
Problem reports, updates or suggestions for this package should be reported with send-pr.