KRR: Efficient and Scalable Kernel Record Replay
Tianren Zhang, Sishuai Gong, Pedro Fonseca
Abstract
Modern kernels are large, complex, and plagued with bugs. Unfortunately, their large size and complexity make kernel failures very challenging for developers to diagnose since failures encountered in deployment are often notoriously difficult to reproduce. Although record-replay techniques provide the powerful ability to accurately record a failed execution and deterministically replay it, enabling advanced manual and automated analysis techniques, they are inefficient and do not scale with modern I/O-intensive, concurrent workloads.
This paper introduces KRR, a kernel record-replay framework that provides a highly efficient execution recording mechanism by narrowing the scope of the record and replay boundary to the kernel. Unlike previous record-replay wholestack approaches, KRR adopts a split-recorder design that employs the guest and the host to jointly record the kernel execution. Our evaluation demonstrates that KRR scales efficiently up to 8 cores, across a range of different workloads, including kernel compilation, RocksDB, and Nginx. When recording 8-core VMs that run RocksDB and kernel compilation, KRR incurs only a 1.52× ∼ 2.79× slowdown compared to native execution, while traditional whole-VM RR suffers from 8.97× ∼ 29.94× slowdown. We validate that KRR is practical and has a broad recording scope by reproducing 17 bugs across different Linux versions, including 6 non-deterministic bugs and 5 high-risk CVEs; KRR was able to record and reproduce all but one non-deterministic bug.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 583b4a0e-633d-4984-b3a3-38a0bce485a3Cited by top-tier papers2
- kSTEP: Characterization and Deterministic Testing of Linux CPU Scheduler BugsTingjia Cao, Shawn (Wanxiang) Zhong, Caeden Whitaker, Ke Han et al.OSDI 2026 · 1 citation
- kSFS: Repurposing a Microkernel-like Interface for Fast and Secure In-Kernel Linux File SystemsDinglan Peng, Pedro FonsecaUSENIX Security 2026
Builds on18
- Designing New Operating Primitives to Improve Fuzzing PerformanceWen Xu, Sanidhya Kashyap, Changwoo Min, Taesoo KimCCS 2017 · 139 citations
- Krace: Data Race Fuzzing for Kernel File SystemsMeng Xu, Sanidhya Kashyap, Hanqing Zhao, Taesoo KimS&P 2020 · 131 citations
- The Demikernel Datapath OS Architecture for Microsecond-scale Datacenter SystemsIrene Zhang, Amanda Raybuck, Pratyush Patel, Kirk Olynyk et al.SOSP 2021 · 83 citations
- Postmortem Program Analysis with Hardware-Enhanced Post-Crash ArtifactsJun Xu, Dongliang Mu, Xinyu Xing, Peng Liu et al.USENIX Security 2017 · 55 citations
- GREBE: Unveiling Exploitation Potential for Linux Kernel BugsZhenpeng Lin, Yueqi Chen, Yuhang Wu, Dongliang Mu et al.S&P 2022 · 47 citations
Related papers
- Reverse Debugging of Kernel Failures in Deployed SystemsXinyang Ge, Ben Niu, Weidong CuiUSENIX ATC 2020 · 29 citations
- Scalable Tuning of (OpenMP) GPU Applications via Kernel Record and ReplayKonstantinos Parasyris, Giorgis Georgakoudis, Esteban Rangel, Ignacio Laguna et al.SC 2023 · 15 citations
- Vidi: Record Replay for Reconfigurable HardwareGefei Zuo, Jiacheng Ma, Andrew Quinn, Baris KasikciASPLOS 2023 · 1 citation
- ReUSB: Replay-Guided USB Driver FuzzingJisoo Jang, Minsuk Kang, Dokyung SongUSENIX Security 2023
- Towards Better Linux Kernel Fault Localization: Leveraging Contrastive Reasoning and Hierarchical Context AnalysisHaichi Wang, Ruiguo Yu, Yesong Pang, Yingquan Zhao et al.ICSE 2026
