Multikernel has been introduced, a mechanism for simultaneously running multiple Linux kernels.

To discuss with Linux kernel developers, a series of patches has been proposed, developed by the Multikernel project, which has recently been transitioned to open-source status and will now be developed collaboratively with the community. Multikernel allows multiple independent instances of the Linux kernel to run on a single physical computer, granting them direct access to hardware resources and enabling the operation of several isolated system environments. The project was created by Multikernel Technologies, founded and led by Cong Wang, who oversees the traffic control subsystem (TC) within the Linux kernel.

An enhanced kexec call has been proposed for launching and managing kernels, which, unlike the classic kexec, is not limited to replacing the running kernel and allows for the concurrent execution of additional kernel instances. To monitor and debug the running kernel instances, the interface "/proc/multikernel" has been implemented, and a communication framework, Multikernel IPI, has been suggested for message passing between kernels and coordination of their operations.

Multikernel has been introduced, a mechanism for simultaneously running multiple Linux kernels.

Multikernel is presented as a new isolation architecture that occupies a niche between hypervisor-based virtualization and container-based isolation using a shared kernel. Unlike virtualization, Multikernel does not require the use of a hypervisor, simplifies the creation of environments for isolated execution of individual applications, and achieves high performance without the overhead associated with virtualization. In contrast to containers, Multikernel provides a high level of isolation and allows for the use of a separate kernel in each isolated environment.

Multikernel has been introduced, a mechanism for simultaneously running multiple Linux kernels.

Performance when using Multikernel is assessed as being close to that of execution on dedicated hardware. This has been achieved by eliminating the overhead typical of virtualization, which arises from control transfer handlers between virtual machines (VM exit), IOMMU translation, and hypervisor intervention in the execution of privileged operations. Dynamic resource allocation for the environments being launched is supported, ensuring predictable performance.

Simultaneous execution of multiple kernels occurs without virtualization, using an SMP handler that distributes available CPUs among instances of Linux kernels. Each Linux kernel instance is assigned one or more CPUs designated for its execution while sharing the remaining hardware resources.

Key advantages of Multikernel:

  • Improved isolation from failures in running environments.
  • Enhanced security through kernel-level separation.
  • More efficient resource utilization compared to traditional virtual machines based on hypervisors such as KVM and Xen.
  • Potential ability to update the kernel without stopping operations using the KHO (Kernel Hand Over) mechanism.
  • Support for integration with standard cloud infrastructures and the ability for seamless transition from traditional virtualization systems and container isolation.
  • Full compatibility with existing applications and Linux system interfaces. Multikernel only selectively modifies the kernel while maintaining complete API compatibility.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster