Virtual timeline: a formal abstraction for verifying preemptive schedulers with temporal isolation
Mengqi Liu, Lionel Rieg, Zhong Shao, Ronghui Gu, David Costanzo, Jung-Eun Kim, Man-Ki Yoon
摘要
The reliability and security of safety-critical real-time systems are of utmost importance because the failure of these systems could incur severe consequences (e.g., loss of lives or failure of a mission). Such properties require strong isolation between components and they rely on enforcement mechanisms provided by the underlying operating system (OS) kernel. In addition to spatial isolation which is commonly provided by OS kernels to various extents, it also requires temporal isolation, that is, properties on the schedule of one component (e.g., schedulability) are independent of behaviors of other components. The strict isolation between components relies critically on algorithmic properties of the concrete implementation of the scheduler, such as timely provision of time slots, obliviousness to preemption, etc. However, existing work either only reasons about an abstract model of the scheduler, or proves properties of the scheduler implementation that are not rich enough to establish the isolation between different components. In this paper, we present a novel compositional framework for reasoning about algorithmic properties of the concrete implementation of preemptive schedulers. In particular, we use virtual timeline , a variant of the supply bound function used in real-time scheduling analysis, to specify and reason about the scheduling of each component in isolation. We show that the properties proved on this abstraction carry down to the generated assembly code of the OS kernel. Using this framework, we successfully verify a real-time OS kernel, which extends mCertiKOS, a single-processor non-preemptive kernel, with user-level preemption, a verified timer interrupt handler, and a verified real-time scheduler. We prove that in the absence of microarchitectural-level timing channels, this new kernel enjoys temporal and spatial isolation on top of the functional correctness guarantee. All the proofs are implemented in the Coq proof assistant.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper11
- Design and Verification of the Arm Confidential Compute ArchitectureXupeng Li, Xuheng Li, Christoffer Dall, Ronghui Gu 等OSDI 2022 · 被引用 60 次
- Formal Verification of a Multiprocessor Hypervisor on Arm Relaxed Memory HardwareRunzhou Tao, Jianan Yao, Xupeng Li, Shih-Wei Li 等SOSP 2021 · 被引用 24 次
- Spoq: Scaling Machine-Checkable Systems Verification in CoqXupeng Li, Xuheng Li, Wei Qiang, Ronghui Gu 等OSDI 2023 · 被引用 10 次
- Layered and object-based game semanticsArthur Oliveira Vale, Paul-André Melliès, Zhong Shao, Jérémie Koenig 等POPL 2022 · 被引用 9 次
- Blinder: Partition-Oblivious Hierarchical SchedulingMan-Ki Yoon, Mengqi Liu, Hao Chen, Jung-Eun Kim 等USENIX Security 2021 · 被引用 7 次
相关 Paper
- Compositional virtual timelines: verifying dynamic-priority partitions with algorithmic temporal isolationMengqi Liu, Zhong Shao, Hao Chen, Man-Ki Yoon 等OOPSLA 2022 · 被引用 2 次
- RefinedProsa: Connecting Response-Time Analysis with C Verification for Interrupt-Free SchedulersKimaya Bedarkar, Laila Elbeheiry, Michael Sammler, Lennard Gäher 等PLDI 2025 · 被引用 2 次
- VeriRT: An End-to-End Verification Framework for Real-Time Distributed SystemsYoonseung Kim, Sung-Hwan Lee, Yonghyun Kim, Chung-Kil HurPOPL 2025 · 被引用 2 次
- TimeWall: Enabling Time Partitioning for Real-Time Multicore+Accelerator PlatformsTanya Amert, Zelin Tong, Sergey Voronov, Joshua Bakita 等RTSS 2021 · 被引用 23 次
- Formalising the Prevention of Microarchitectural Timing Channels by Operating SystemsRobert Sison, Scott Buckley, Toby Murray, Gerwin Klein 等FM 2023 · 被引用 2 次
