[ANNOUNCE] mklinux v7.0-mk3 and kerf 0.3.0

From: Cong Wang

Date: Fri Sep 25 2026 - 17:08:33 EST


Hi all,

I am pleased to announce the third mklinux release, v7.0-mk3, together
with kerf 0.3.0, the user-space tool that manages it. The two are
released as a pair: v7.0-mk3 changes the device tree ABI between the
kernel and user space, so it needs kerf 0.3.0, and kerf 0.3.0 expects
a v7.0-mk3 kernel.

mklinux v7.0-mk3 is 58 patches on top of v7.0-mk2 (46 files changed,
3747 insertions, 1959 deletions).

The headline of this release is that a spawn kernel now boots from its
device tree, and PCI devices are identified by address and named
through standard /aliases, so the name you give a device when pooling
it is the name every later step uses.


Device tree
-----------

- A spawn boots from its device tree. The boot manifest is the
instance tree itself, with a /chosen node for the boot handoff, and
the OF core owns it.

- PCI devices are described under their host bridge in the devicetree
PCI bus binding, identified by PCI address and named through
/aliases. Host bridge nodes carry the ECAM window, so any PCI domain
and extended config space are reachable.

- A spawn creates its PCI root buses from those nodes, never probes
for PCI topology, gates device probing on the tree rather than a
private list, and keeps the tree as its record of PCI ownership.

- Network devices are named from their alias, including virtio and
USB netdevs, whose PCI function is found above them.

- The device-names list and the baseline snapshot it resolved against
are gone; devices are handed to an instance by PCI address. An
instance is named by the standard model property instead of its
root node name.

- New of_alias_from_node() helper in the OF core, and new
Documentation/multikernel/device-tree.rst describing the trees.


Takeover
--------

- A backup kernel can fence its parent with reboot(mk_id 0). This NMIs
every CPU the backup does not own, confirms each one by its presence
in the park loop, and wakes the fenced CPUs from the adopted host
wake slot.

- The host tree can come from user space through instance-create and
is emitted under the spawn's /chosen, so a backup enumerates every
CPU in the machine. A spawn created without one gets a tree the
kernel computes, so existing loaders keep working.

- CPU registers are saved on the way down for a backup that will take
a core.

- An overlay is now taken in one write, and the boot manifest grows
to 256 KB. Both were needed for instance-create to work on a 48-CPU
host with 267 PCI functions.


Pool and instances
------------------

- Pool state (CPU set, memory chunks, park area and its lock) is
gathered in struct mk_pool. root_instance becomes mk_self, and a
kernel's own park context is computed rather than stored.

- Instance records are built through one alloc/publish/free path.
Boot-restored instances show up in kernfs, the parent record is
named "host" and marked active, and the doorbell CPU is separated
from CPU ownership.

- CPUs surrendered to another kernel rest in the new CPUHP_DEPARTED
hotplug state.

- The manifest's pool-cpus list is sorted, so a spawn's CPU numbering
no longer depends on host history.


Spawn lifecycle
---------------

- A spawn without a ring can be force halted, and the force halt is
taken from the unknown-NMI chain. The NMI watchdog is back on in
spawn kernels.

- The spawn console registers before smp_init(), so an early panic
reaches the host.

- Spawn kernels inherit the host's timer calibration.


vsock
-----

- mk_transport answers unmatched packets with a reset, which doubles
as a liveness probe for the peer kernel.

- Its stream_allow callback now matches the core signature.


Build
-----

- CONFIG_MULTIKERNEL=n on x86 and CONFIG_KEXEC_FILE=n build again.

- MULTIKERNEL depends on the memory APIs the core needs.

- x86 details moved out of the generic core ahead of a second
architecture.


kerf 0.3.0
----------

kerf follows the kernel's new device model:

- Pool devices are keyed by PCI address and named through /aliases.
An NVMe keeps its controller name, a network device keeps its
interface name, and "=alias" overrides either. Pooling a partition
pools the whole controller.

- kerf create, kerf update and the validator accept an alias, a PCI
address or a node name. kerf create hands devices over by PCI
address against the live pool, so devices pooled after the first
kerf init work.

- kerf update can take devices back again, and "none" takes them all.

- kerf init resolves a block device to its own PCI function rather
than a bridge above it, and can be re-run with the same --devices
when devices are already pooled or lent to instances.

- The parser reads PCI devices from under their host bridge and takes
the instance name from the model property.

- kerf kill points at --force when a graceful halt times out.


Getting it
----------

Kernel:

https://github.com/multikernel/linux.git tag v7.0-mk3
https://github.com/multikernel/linux/tree/v7.0-mk3

kerf:

pip install kerf-multikernel==0.3.0
https://github.com/multikernel/kerf/releases/tag/v0.3.0

Previous release: v7.0-mk2 with kerf 0.2.0.

Feedback, bug reports and testing on more hardware are very welcome.

Thanks,
Cong Wang