Score
Designs, builds, or analyzes operating system components and behaviors, including process and thread management, scheduling, memory management, file systems, concurrency and synchronization, device I/O, and kernel interfaces. Applies OS fundamentals to implement, configure, debug, and evaluate system-level software and resource-management policies.
研究分析了1500个来自Android、Linux和HarmonyOS的缺陷,通过多维度分类理解操作系统缺陷特征,为提高操作系统质量提供指导。
This study addresses the urgent need to enhance the security of information systems as critical societal infrastructure. Adopting the reference monitor architecture as a theoretical framework, this work systematically reviews three core technologies: virtualization, formal verification of operating systems, and fine-grained access control. It provides an in-depth analysis of their technical prospects and evolutionary challenges within security requirements analysis. Furthermore, this research constructs a comprehensive landscape of the operating system security domain, delineating integration pathways and future development directions for these technologies. By doing so, it establishes a solid theoretical foundation and a clear technical roadmap for overcoming existing bottlenecks in system security.
Traditional operating systems struggle to support goal-directed, dynamically tool-invoking agents with adaptive behaviors, exhibiting fundamental limitations in scheduling, state management, security, and observability. This work presents the first systematic design of an Agent Operating System (AOS) architecture, which introduces an agent control plane into conventional OS abstractions and rethinks core mechanisms—including scheduling, context management, capability registration, policy enforcement, and auditing. AOS clearly delineates responsibility boundaries and non-goals, establishing a multi-layered integration model spanning user-space runtimes to distributed control planes, thereby transcending the traditional OS assumption of deterministic program execution. The paper establishes novel system abstractions for agent-centric computing, proposes a security threat model and evaluation criteria, and makes significant advances in ensuring deterministic execution, auditability, and operational interpretability.
Conventional teaching operating systems often lack modern features and real-world application support, limiting students’ exposure to contemporary OS design principles and practical engineering challenges. Method: This work proposes a “reverse-engineering–driven” pedagogical paradigm: starting from a fully functional OS (e.g., VOS), it systematically decomposes the system into a sequence of incrementally implementable prototypes, guided by authentic use cases—including DOOM gaming, audio/video playback, and blockchain mining—to motivate and contextualize core mechanism design. VOS is implemented in Rust and C, featuring MMU-based virtual memory, a lightweight microkernel, SMP-aware scheduling, FAT32/USB protocol stacks, and a framebuffer-based GUI framework; it supports bare-metal booting on portable hardware and full graphical interactivity. Its modular architecture ensures prototype independence and composability. Contribution/Results: Deployed in undergraduate OS courses across multiple universities worldwide, VOS has demonstrably enhanced students’ engineering proficiency, systems-level intuition, and intrinsic motivation.
Formal verification of operating system kernel virtual memory management (VMM) code remains challenging due to hardware interface complexity and difficulties in semantically modeling dynamic multi-address-space switching. This paper addresses these challenges by introducing a modal-logic-based abstraction of address spaces. Our method features: (1) a novel modal assertion ([r]P) to express truth relative to an address space (r); (2) a precise virtual *points-to* relation that faithfully models hardware page-table translation semantics; and (3) the first fully mechanized formal verification—within the Iris separation logic framework and Coq—supporting instruction sequences spanning multiple address spaces. We verify critical VMM operations including address-space switching and page-table updates. All semantic definitions and proofs are entirely mechanized in Coq, achieving significantly stronger verification guarantees than prior approaches.
This work addresses the gap in current systems education, where learning resources often consist of superficial tutorials or AI-generated summaries that inadequately convey foundational design principles and thus fail to cultivate robust engineering capabilities. To remedy this, we propose a structured learning pathway centered on seminal research papers from distributed systems, operating systems, and big data domains. Integrating insights from leading academic curricula and industry practices, our approach emphasizes technical depth and problem-solving reasoning. By engaging learners in close reading of original literature, critical analysis of architectural trade-offs, and cross-domain synthesis, the framework fosters a deep understanding of underlying mechanisms and cultivates systems thinking—thereby equipping practitioners to effectively tackle complex engineering challenges and progress toward professional-level systems expertise.
This work addresses the inefficiency and security risks associated with manually crafting configuration code when operating systems are frequently adapted to emerging memory hardware. It presents the first application of domain-specific software synthesis to the generation of operating system memory management code. By leveraging high-level formal specifications that capture both the memory hardware’s mapping behavior and the OS execution environment, the approach automatically synthesizes verifiable low-level code along with corresponding hardware components. This methodology substantially improves development productivity and system security, enables seamless porting of operating systems to novel hardware platforms, and provides a robust and efficient implementation foundation for exploring new address translation mechanisms.
This work addresses the challenge of manual, expert-driven operating system tuning for application-specific performance, which is hindered by vast configuration spaces, high evaluation costs, and a prevalence of ineffective settings. The authors propose Wayfinder, a novel framework that enables fully automated, end-to-end OS configuration optimization for any quantifiable objective—such as performance, memory usage, or security. Wayfinder integrates automated benchmarking, a neural network–guided search algorithm, online learning, and cross-application transfer learning to dramatically improve tuning efficiency. Experimental results across two operating systems and four applications demonstrate that Wayfinder achieves up to a 24% performance gain and an 8.5% reduction in memory footprint, consistently outperforming baseline approaches including random search and Bayesian optimization.
本文系统化分析了Linux内核漏洞从发现到修复的全过程,指出现有自动化技术在漏洞处理后期阶段的不足,并提出了解决方案。
Identifying critical safety constraints from the vast number of Hardware Abstraction Layer (HAL) interfaces in embedded systems remains challenging, hindering effective fault prevention. Method: This paper proposes a fault-prevention-oriented requirement prioritization approach. Its core innovation is the formal definition of “indisputable relevance,” transforming hardware access constraint identification into a verifiable formal verification problem. The method models HAL interfaces, semantically analyzes real-world failure reports, and leverages model checkers (e.g., CBMC) to automatically generate mathematical proofs—thereby extracting and verifying constraints strongly correlated with system failures or hardware damage. Results: Evaluated on three industrial-grade failure cases involving the SPI bus spidev HAL, the approach successfully identified and formally verified critical requirements. Experimental results demonstrate its feasibility and effectiveness, establishing a novel, verifiable, and traceable paradigm for requirements engineering in high-reliability embedded systems.