13 ms·
I've been wondering for a while as to why nobody was trying to run an entire VM at ring 0, the benefits would be significant. I was just not aware that's what S
by davidgrenier 8y ago
I've been wondering for a while as to why nobody was trying to run an entire VM at ring 0, the benefits would be significant. I was just not aware that's what Singularity/Midori were doing.
I'm glad more people are picking up on it.
- codetrotter 8y agoWhat are the benefits of doing so?
- naasking 8y agoThe cost of context switching is near zero. No need for expensive TLB flushes, for instance. No need for paged memory whose overhead sometimes accounts for up to 50% of program runtimes. Better isolation properties, since you can sandbox individual objects instead of whole processes.
- lkurusa 8y ago> expensive TLB flushes Note that modern CPUs store a tag of the current "address space ID" next to the TLB line, thus the cost of the flushing is heavily reduced. > No need for paged memory Unless you mean swapping, this doesn't apply as x86_64 long mode requires paging to be enabled.
- naasking 8y ago> Note that modern CPUs store a tag of the current "address space ID" next to the TLB line, thus the cost of the flushing is heavily reduced. Yes, tagged TLBs are much better, but the overhead is still not negligible. You can check the microkernel literature for all of the inefficiencies encountered in modern CPUs, and a language-based OS would eliminate most of them because protection is moved into the language itself. > Unless you mean swapping, this doesn't apply as x86_64 long mode requires paging to be enabled. a) This benefits from better caching since there's only one set of page tables, and b) CPUs are designed around the common uses, so if this OS design catches on, you'll start seeing CPUs that don't require page tables.
- monocasa 8y ago> Note that modern CPUs store a tag of the current "address space ID" next to the TLB line, thus the cost of the flushing is heavily reduced. Except you flush the TLBs as part of the meltdown mitigation.
- masklinn 8y agoDoesn't Ling/ErlangOnXen run in Ring0?
- qop 8y agoLing has the concept of hypercalls, as if you were running plain Linux on xen. So, it's less an actual unikernel and more like a skin that molds itself to xen, and looks like a unikernel. So yes. But no.
- monocasa 8y agoLinux and the BSDs have had a VM for decades in the form of BPF. Before that the exokernels absolutely loved VMs at ring 0.