Atmosphere: Practical Verified Kernels with Rust and Verus
Xiangdong Chen, Zhaofeng Li, Jerry Zhang, Vikram Narayanan, Anton Burtsev
Abstract
Recent advances in programming languages and automated formal reasoning have changed the balance between the complexity and practicality of developing formally verified systems. Our work leverages Verus, a new verifier for Rust that combines ideas of linear types, permissioned reasoning, and automated verification based on satisfiability modulo theories (SMT), for the development of a formally verified microkernel, Atmosphere.
Atmosphere is a full-featured microkernel with support for strict isolation in mixed-criticality systems. We develop all code in Rust and prove its functional correctness, i.e., refinement of a high-level specification, with Verus. Development and verification of 6K lines of executable code required an effort of less than 2.5 person-years (only 1.5 years were spent on verification, another person-year was spent developing non-verified parts of the system). On average, our code has a proof-to-code ratio of 3.32:1 and completes verification in less than 20 seconds on a modern laptop, which we argue is practical for the development of verified systems.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext f892211c-9fe1-4698-9643-77660ef0b3ecCited by top-tier papers2
- Detecting Inconsistencies in Arm CCA's Formally Verified SpecificationChangho Choi, Xiang Cheng, Bokdeuk Jeong, Taesoo KimASPLOS 2026
- Rust’s Type Checker Implementation Is Unsound: An Empirical Study on Soundness Bugs in rustcYusung Sim, Sukyoung Ryu, Jaemin HongISSTA 2026
Builds on7
- RedLeaf: Isolation and Communication in a Safe Operating SystemVikram Narayanan, Tianjiao Huang, David Detweiler, Dan Appel et al.OSDI 2020 · 86 citations
- Verus: Verifying Rust Programs using Linear Ghost TypesAndrea Lattuada, Travis Hance, Chanhee Cho, Matthias Brun et al.OOPSLA 2023 · 86 citations
- Formally Verified Memory Protection for a Commodity Multiprocessor HypervisorShih-Wei Li, Xupeng Li, Ronghui Gu, Jason Nieh et al.USENIX Security 2021 · 48 citations
- VeriSMo: A Verified Security Module for Confidential VMsZiqiao Zhou, Anjali, Weiteng Chen, Sishuai Gong et al.OSDI 2024 · 27 citations
- Verus: A Practical Foundation for Systems VerificationAndrea Lattuada, Travis Hance, Jay Bosamiya, Matthias Brun et al.SOSP 2024 · 22 citations
Related papers
- TickTock: Verified Isolation in a Production Embedded OSVivien Rindisbacher, Evan Johnson, Nico Lehmann, Tyler Potyondy et al.SOSP 2025
- VerusBelt: A Semantic Foundation for Verus's Proof-Oriented Extensions to the Rust Type SystemTravis Hance, Laila Elbeheiry, Yusuke Matsushita, Derek DreyerPLDI 2026
- AutoVerus: Automated Proof Generation for Rust CodeChenyuan Yang, Xuheng Li, Md Rakib Hossain Misu, Jianan Yao et al.OOPSLA 2025 · 11 citations
- Compositional virtual timelines: verifying dynamic-priority partitions with algorithmic temporal isolationMengqi Liu, Zhong Shao, Hao Chen, Man-Ki Yoon et al.OOPSLA 2022 · 2 citations
- Bringing Foundational Verification to Real-World Rust CodeLennard Gäher, Vincent Lafeychine, Sascha Kehrli, Avraham Shinnar et al.OOPSLA 2026
