The first release of mklinux for simultaneous execution of multiple Linux kernel instances

The first public release of the Multikernel Linux project (mklinux-v7.0-mk2) has been introduced, developing a variant of the Linux kernel enhanced with the capability to run multiple independent kernel instances on a single physical computer without the need for a hypervisor and virtualization. Each kernel instance has direct access to hardware resources and can be used to launch separate isolated system environments. The first release is based on Linux kernel 7.0 and includes the build configuration 'CONFIG_MULTIKERNEL', which, when disabled, makes the kernel behave exactly like the standard kernel 7.0. Currently, only x86_64 CPU architecture is supported.

Multikernel is presented as a new isolation mechanism occupying a niche between virtualization using a hypervisor and container-based isolation based on a shared kernel. Unlike virtualization, Multikernel does not require a hypervisor, simplifies the creation of environments for the isolated execution of individual applications, and allows for high performance without the overhead of virtualization. Unlike containers, Multikernel provides a high level of isolation and allows for the use of a separate kernel in each isolated environment, where crashes or exploits do not affect other environments.

The host kernel manages the distribution of available CPUs, memory, and PCI devices among concurrently running additional kernel instances. Each instance runs on a dedicated CPU core, operates with its assigned devices, and has access to a dedicated area of physical memory. The simultaneous execution of multiple kernels is accomplished without virtualization, using an SMP handler that distributes available CPUs. Dynamic resource allocation for the running environments is supported, ensuring predictable performance.

By eliminating the overhead typical of virtualization, performance when using Multikernel is rated as close to that of running on dedicated hardware. With Multikernel, there is no stage of control transfer between virtual machines (VM exit), second-level memory pages are not utilized, there is a separate device model, and IOMMU translation is not required. Compared to hypervisors, KVM using Multikernel leads to enhanced performance for various system calls and functions ranging from 1.07 to 2.5 times (fork + exit — 1.07x, write() — 1.39x, AF_UNIX — 1.55x, Pipe — 2.18x, context switching — 2.50x), with bandwidth and latency when working with memory remaining at the same level.



Source: opennet.ru
Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster