Score
Designs, deploys, configures, operates, secures, and troubleshoots Linux-based servers and systems, covering OS installation, package and service management, user and access control, storage and networking, and system hardening. Builds automation and monitoring, performs backups, capacity planning and performance tuning, and analyzes logs and incidents to maintain reliability, availability, and security of Linux infrastructure.
To address poor reproducibility, low build efficiency, and insufficient deployment automation in embedded Linux system customization, this paper proposes a three-layer extensible architecture based on the Yocto Project. The architecture integrates GitLab CI and Docker to ensure environment isolation and enable continuous integration and deployment (CI/CD), while incorporating a local hash server (hashserv) and shared sstate cache server to significantly improve build artifact reuse. It supports automated real-time Linux kernel builds, QEMU-based simulation testing, and validation across six distinct boot scenarios. Experimental evaluation demonstrates substantial reduction in build time, markedly enhanced system stability and build reproducibility, and strong scalability and engineering deployability for industrial-grade applications.
Existing research is hindered by the lack of large-scale, Linux kernel configuration datasets that span multiple kernel versions and provide fine-grained, quantitative metrics. To address this, we introduce LinuxData—a curated dataset comprising over 240,000 automatically sampled configurations across 27 kernel versions (4.13–5.8), uniformly annotated with compilation outcomes and binary sizes. Our approach enables, for the first time, cross-version prediction of compilation success rate and binary size with high accuracy (mean absolute percentage error <3.2%). This supports advanced configurable-system analyses, including configuration-space modeling, evolutionary analysis, and transfer learning. The dataset is publicly released with a lightweight Python API, OpenML integration, and standardized machine learning benchmarking pipelines. By providing reproducible, version-aware ground truth and streamlined evaluation infrastructure, LinuxData significantly enhances both reproducibility and generalizability in configurable systems research.
本文系统化分析了Linux内核漏洞从发现到修复的全过程,指出现有自动化技术在漏洞处理后期阶段的不足,并提出了解决方案。
This study addresses the lack of systematic empirical analysis on the deployment of full Bitcoin nodes in Linux environments and the performance impact of configuration parameters. Building upon the Bitcoin Core source code, we fully deploy a full node on a Linux platform and employ system monitoring tools to quantitatively measure CPU, memory, and disk I/O consumption during the Initial Block Download (IBD) phase. For the first time, we systematically evaluate how key parameters—such as txindex, prune, and dbcache—affect synchronization performance and resource utilization. Our findings reveal the interaction patterns between configuration settings and system performance, leading to a reproducible, high-performance node deployment strategy that provides empirical foundations for blockchain data analysis tool development and node optimization.
This study addresses the non-uniform performance behavior of Linux's simple read interface, where complex interactions among workload characteristics, processing time, and critical-path waiting impede optimization. To tackle this, the work proposes an end-to-end decomposition of the buffered read path, constructing a cross-layer wait-chain model alongside a "first-completion, subsequent-capacity" abstraction. These models are quantitatively characterized through kernel prototyping, MQSim simulation, and empirical SSD measurements. The proposed approach achieves block-layer prediction errors below 6.9%, reveals opportunities for out-of-order copying and parallel submission, and establishes a closed-loop framework spanning observational modeling to control optimization. Ultimately, this research provides quantifiable theoretical foundations and practical guidelines for optimizing layered I/O stacks.
This study addresses the urgent need to enhance the security of information systems as critical societal infrastructure. Adopting the reference monitor architecture as a theoretical framework, this work systematically reviews three core technologies: virtualization, formal verification of operating systems, and fine-grained access control. It provides an in-depth analysis of their technical prospects and evolutionary challenges within security requirements analysis. Furthermore, this research constructs a comprehensive landscape of the operating system security domain, delineating integration pathways and future development directions for these technologies. By doing so, it establishes a solid theoretical foundation and a clear technical roadmap for overcoming existing bottlenecks in system security.
本文提出NACRE,一种RISC-V硬件-软件协同设计,通过分离主机管理资源与访问保护状态的权限,实现原生保密容器,解决了现有系统对Linux容器保护不足的问题。
This work presents the first systematic, source-level census of the Linux kernel’s ioctl attack surface, addressing its fragmented and inconsistent management that creates a broad local attack surface prone to out-of-bounds memory accesses due to insufficient input validation. Leveraging a deterministic static analysis framework built on libclang and an allmodconfig-enabled full-kernel build, the study extracts ioctl dispatch points, command codes, input sinks, and permission gates across 878 kernel modules. A formal threat model is encoded to distinguish between privileged and unprivileged reachable interfaces. The resulting structured open dataset encompasses 586 entry points, 1,289 command codes, 3,583 input sinks, and 1,298 permission gates, successfully retroactively validating 22 recent CVEs. The query architecture aligns with the Windows IOCTL Census, enabling cross-operating-system analysis.
Existing full-system firmware rehosting approaches struggle with custom devices due to their reliance on expert knowledge and inability to handle proprietary architectures and hardware configurations, leading to initialization and runtime failures. This work proposes the first fully automated, adaptive Linux firmware rehosting framework powered by large language models (LLMs), integrating static analysis, LLM-driven adaptive reasoning, reflective configuration synthesis, and autonomous runtime intervention to achieve end-to-end automation. Evaluated on 21 IoT firmware images spanning five distinct architectures, the approach attains a 100% network port activation rate and a 90.5% service interaction success rate, substantially outperforming current state-of-the-art methods. Furthermore, it successfully reproduces known vulnerabilities and uncovers previously unknown security flaws.
This study addresses cascading failures caused by shared firmware in commercial multi-host network interface cards (NICs) and the operational challenges of hyperscale deployments by proposing fbnic, a system-level solution. Architecturally, it introduces physical isolation and driver-priority mechanisms, combined with sub-sled-granularity firmware upgrade orchestration and slice-level fault containment. Operationally, it establishes a hardware-in-the-loop (HIL) continuous integration pipeline alongside cross-layer fault attribution monitoring and an automated remediation toolchain. Deployed across hundreds of thousands of hosts, fbnic reduces unplanned unavailability by 12×, shortens mean time to repair by 37%, and decreases hardware replacement rates by 2.3×, demonstrating robust stability at scale.