基础设施 5.0 · 必读 2026-09-10 · 论文

AKTS: Sub-Microsecond Kernel Policy Switching for LM Agents (eBPF)

AKTS(mali-kh, 2026-09-10 提交,6 页附 1 图,代码与原始数据在 github.com/mali-kh/akts)针对 GPU 推理服务器把交互请求和后台批作业混跑在同一批 CPU 上的现实请求来时要保 TTFT,空闲时让批作业多吃吞吐,固定内核策略会牺牲一边;agent OS 要能在工作负载变化时切档难处在 eBPF 验证器不让在 110 s 调度事件里跑复杂代码:scalar 调控表达力不够动态生成 eBPF 策略把编译/验证/加载/可能的拒绝挂到运行时AKTS 把策略库在加载期一次性验证,运行时只写一个整数索引到内核里的已验证策略数组,内核内 tail call 解析索引,agent 发的是索引不是代码Linux 6.14 上策略切换 p50 920 ns;非法索引在 60,217 次调用里全部 inert...

打开原文回到归档

AKTS: Sub-Microsecond Kernel Policy Switching for LM Agents (eBPF)

Abstract (opencli arxiv paper)

arXiv 2609.12276 abstract (opencli arxiv paper 2609.12276 -f json): AKTS shifts policy switching from runtime eBPF synthesis to load-time one-shot verification of a policy library, then issues integer indices resolved by kernel tail calls. Linux 6.14: p50 920 ns; 60,217 calls with zero unsafe dispatches; vLLM retains 97% of batch activity at the throughput tier while matching latency-tier bursts.

论文要点 (中文)

mali-kh(Mohammadali Khodabandehlou、Mahdi Alizadeh)2026-09-10 提交,6 页附 1 图,代码与原始数据 github.com/mali-kh/akts。问题:GPU 推理服务器把交互请求与后台批作业混跑在同一批 CPU 上;请求来时保 TTFT,空闲时让批作业多吃吞吐。固定内核调度策略牺牲一边;agent OS 要按工作负载变化切档。难处在 eBPF 验证器不让在 1–10 μs 调度事件里跑复杂代码——scalar 调控表达力不够;动态生成 eBPF 策略把编译/验证/加载/可能的拒绝挂到运行时。AKTS 把策略库在加载期一次性验证;运行时只写整数索引到内核里「已验证策略数组」,内核内 tail call 解析索引,agent 发索引不发代码。Linux 6.14:策略切换 p50 920 ns;非法索引 60,217 次全部 inert;vLLM 工作负载捕到吞吐档 97% 批活,同时匹配延迟档的突发响应。范式「用预验证换运行时表达力」,可抄进自家沙箱/调度器控制面,Linux 6.14 基线要记下来。

Key claims (English)

AKTS (mali-kh; submitted 2026-09-10; 6 pages + 1 figure; github.com/mali-kh/akts) shifts agent-runtime kernel policy switching out of the hot path. The verifier-unfriendly 1–10 μs scheduling window forbids complex eBPF code; scalar knobs lack expressiveness; and dynamically generated policies push compile/verify/load (and possible rejection) into the runtime path. AKTS validates the policy library once at load time, then at runtime writes only an integer index into a kernel-resident verified-policy array, resolved by a tail call. Measured on Linux 6.14: policy-switch p50 920 ns; 60,217 calls with no unsafe dispatch; on vLLM workloads it preserves 97% of batch activity at the throughput tier while still matching latency-tier bursts. The paradigm is pre-validate to buy runtime expressiveness, with Linux 6.14 as the baseline to track.

Obsidian 证据摘录

「AKTS 把策略库在加载期一次性验证,agent 运行时只写一个整数索引到内核里的『已验证策略数组』,内核内 tail call 解析索引,agent 发的是索引不是代码,验证失败不再是运行时可能。Linux 6.14 上策略切换 p50 920 ns;非法索引在 60,217 次调用里全部 inert;vLLM 工作负载里跑批作业捕到吞吐档 97% 的批活、同时匹配延迟档的突发响应。」——OpenClaw定时任务/论文流水线/2026-09-15-论文流水线.md L19-21

链接