From 45f247979ec7ba01bb07926c4b3cfec946b63084 Mon Sep 17 00:00:00 2001 From: Nir Soffer Date: Sat, 5 Sep 2026 21:10:50 +0300 Subject: [PATCH 1/3] docs/podman: add timesync and guest agent config for vfkit Configure qemu-guest-agent to listen on vsock port 1234 and add --timesync vsockPort=1234 to the vfkit command. This syncs the guest clock after the host wakes from sleep. The default qemu-guest-agent.service on Fedora depends on a virtio-serial device that vfkit does not provide: [Unit] BindsTo=dev-virtio\x2dports-org.qemu.guest_agent.0.device [Install] WantedBy=dev-virtio\x2dports-org.qemu.guest_agent.0.device The service would never start since the device does not exist. We replace it with a unit file in /etc/systemd/system/ that uses vsock and starts via multi-user.target. The runcmd uses "disable" then "enable --now" to remove the stale symlinks from the original device target and create new ones for multi-user.target. The Fedora SELinux policy for virt_qemu_ga_t only allows virtio-serial communication. We install a CIL policy module to allow vsock socket operations, matching the policy used by podman-machine-os. When vfkit starts with --timesync vsockPort=1234, it monitors the host for sleep/resume events. After resume, vfkit connects to the guest agent over vsock port 1234 and sends the current host time to correct the guest clock, which stopped during host sleep. --- docs/podman.md | 20 ++++++++++++++++++++ 1 file changed, 20 insertions(+) diff --git a/docs/podman.md b/docs/podman.md index df75de4..b716372 100644 --- a/docs/podman.md +++ b/docs/podman.md @@ -95,7 +95,25 @@ users: packages: - avahi - podman +write_files: + - path: /etc/systemd/system/qemu-guest-agent.service + content: | + [Unit] + Description=QEMU Guest Agent + [Service] + ExecStart=/usr/bin/qemu-ga --method=vsock-listen --path=3:1234 + Restart=always + RestartSec=0 + [Install] + WantedBy=multi-user.target + - path: /root/qemu-ga-vsock.cil + content: | + (allow virt_qemu_ga_t self (vsock_socket (bind create getattr listen accept read write))) runcmd: + - semodule -i /root/qemu-ga-vsock.cil + - systemctl daemon-reload + - systemctl disable qemu-guest-agent + - systemctl enable --now qemu-guest-agent - systemctl enable --now avahi-daemon - systemctl enable --now podman.socket EOF @@ -156,6 +174,8 @@ cat > ~/Library/LaunchAgents/local.$VM_NAME.plist << EOF virtio-net,fd=4,mac=$MAC_ADDRESS --device virtio-rng + --timesync + vsockPort=1234 RunAtLoad From db3c1ddef78aa258e5ec57ac49f402fc62cfde6e Mon Sep 17 00:00:00 2001 From: Nir Soffer Date: Sat, 5 Sep 2026 23:11:22 +0300 Subject: [PATCH 2/3] docs/podman: add timesync and guest agent config for krunkit MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Same configuration as vfkit — krunkit supports the same --timesync vsockPort=1234 option. --- docs/podman.md | 22 ++++++++++++++++++++++ 1 file changed, 22 insertions(+) diff --git a/docs/podman.md b/docs/podman.md index b716372..bbbcbe5 100644 --- a/docs/podman.md +++ b/docs/podman.md @@ -338,7 +338,27 @@ users: packages: - avahi - podman +write_files: + - path: /etc/systemd/system/qemu-guest-agent.service + content: | + [Unit] + Description=QEMU Guest Agent + + [Service] + ExecStart=/usr/bin/qemu-ga --method=vsock-listen --path=3:1234 + Restart=always + RestartSec=0 + + [Install] + WantedBy=multi-user.target + - path: /root/qemu-ga-vsock.cil + content: | + (allow virt_qemu_ga_t self (vsock_socket (bind create getattr listen accept read write))) runcmd: + - semodule -i /root/qemu-ga-vsock.cil + - systemctl daemon-reload + - systemctl disable qemu-guest-agent + - systemctl enable --now qemu-guest-agent - systemctl enable --now avahi-daemon - systemctl enable --now podman.socket EOF @@ -400,6 +420,8 @@ cat > ~/Library/LaunchAgents/local.$VM_NAME.plist << EOF virtio-net,type=unixgram,fd=4,mac=$MAC_ADDRESS,offloading=on --device virtio-rng + --timesync + vsockPort=1234 RunAtLoad From 01e82e473b4e25cb3a893b1cf9b2d86f8bde15cc Mon Sep 17 00:00:00 2001 From: Nir Soffer Date: Sat, 5 Sep 2026 23:28:18 +0300 Subject: [PATCH 3/3] docs/docker: add timesync and guest agent config Same approach as the podman tutorial. Unlike Fedora, Ubuntu minimal does not ship qemu-guest-agent, so we add it to the cloud-init packages list. No SELinux policy is needed since Ubuntu uses AppArmor which does not restrict vsock access. --- docs/docker.md | 20 ++++++++++++++++++++ 1 file changed, 20 insertions(+) diff --git a/docs/docker.md b/docs/docker.md index 6520dcc..302f445 100644 --- a/docs/docker.md +++ b/docs/docker.md @@ -90,6 +90,24 @@ users: - "$(cat ~/.ssh/id_ed25519.pub)" packages: - avahi-daemon + - qemu-guest-agent +write_files: + - path: /etc/systemd/system/qemu-guest-agent.service + content: | + [Unit] + Description=QEMU Guest Agent + + [Service] + ExecStart=/usr/sbin/qemu-ga --method=vsock-listen --path=3:1234 + Restart=always + RestartSec=0 + + [Install] + WantedBy=multi-user.target +runcmd: + - systemctl daemon-reload + - systemctl disable qemu-guest-agent + - systemctl enable --now qemu-guest-agent bootcmd: - systemctl mask systemd-networkd-wait-online.service EOF @@ -151,6 +169,8 @@ cat > ~/Library/LaunchAgents/local.$VM_NAME.plist << EOF virtio-net,type=unixgram,fd=4,mac=$MAC_ADDRESS,offloading=on --device virtio-rng + --timesync + vsockPort=1234 RunAtLoad