Score
Designs, implements, and debugs low‑level operating system software for Linux/Unix platforms, including kernel components (modules, drivers), system libraries, daemons, init and service management, and user‑space utilities. Analyzes and optimizes system behavior using operating‑system concepts such as process scheduling, memory management, concurrency and synchronization, system calls and ABI, filesystems, device I/O, kernel build/configuration, and system integration.
This study addresses the urgent need to enhance the security of information systems as critical societal infrastructure. Adopting the reference monitor architecture as a theoretical framework, this work systematically reviews three core technologies: virtualization, formal verification of operating systems, and fine-grained access control. It provides an in-depth analysis of their technical prospects and evolutionary challenges within security requirements analysis. Furthermore, this research constructs a comprehensive landscape of the operating system security domain, delineating integration pathways and future development directions for these technologies. By doing so, it establishes a solid theoretical foundation and a clear technical roadmap for overcoming existing bottlenecks in system security.
To address critical challenges in SoC design—including ambiguous system-level modeling semantics, poor interoperability across heterogeneous computational models (e.g., dataflow and neural networks), and the decoupling of design-space exploration from verification—this paper proposes a co-communication mechanism ensuring semantic consistency across multiple models. The approach establishes an integrated toolchain supporting system-level modeling, simulation-driven verification, hardware-software co-design space exploration, and joint power-performance analysis. Innovatively, it unifies dataflow modeling with system-level abstractions to enable functional correctness verification and quantitative energy-efficiency evaluation for representative applications such as video processing and AI acceleration. Experimental results demonstrate that the methodology significantly improves early-stage SoC design iteration efficiency and enhances the reliability of architectural decision-making.
To address poor reproducibility, low build efficiency, and insufficient deployment automation in embedded Linux system customization, this paper proposes a three-layer extensible architecture based on the Yocto Project. The architecture integrates GitLab CI and Docker to ensure environment isolation and enable continuous integration and deployment (CI/CD), while incorporating a local hash server (hashserv) and shared sstate cache server to significantly improve build artifact reuse. It supports automated real-time Linux kernel builds, QEMU-based simulation testing, and validation across six distinct boot scenarios. Experimental evaluation demonstrates substantial reduction in build time, markedly enhanced system stability and build reproducibility, and strong scalability and engineering deployability for industrial-grade applications.
研究分析了1500个来自Android、Linux和HarmonyOS的缺陷,通过多维度分类理解操作系统缺陷特征,为提高操作系统质量提供指导。
Formal verification of operating system kernel virtual memory management (VMM) code remains challenging due to hardware interface complexity and difficulties in semantically modeling dynamic multi-address-space switching. This paper addresses these challenges by introducing a modal-logic-based abstraction of address spaces. Our method features: (1) a novel modal assertion ([r]P) to express truth relative to an address space (r); (2) a precise virtual *points-to* relation that faithfully models hardware page-table translation semantics; and (3) the first fully mechanized formal verification—within the Iris separation logic framework and Coq—supporting instruction sequences spanning multiple address spaces. We verify critical VMM operations including address-space switching and page-table updates. All semantic definitions and proofs are entirely mechanized in Coq, achieving significantly stronger verification guarantees than prior approaches.
本文系统化分析了Linux内核漏洞从发现到修复的全过程,指出现有自动化技术在漏洞处理后期阶段的不足,并提出了解决方案。
This work addresses the inefficiencies and semantic inconsistencies arising from separately implementing driver and monitor programs in traditional hardware module testing. To overcome this, the authors propose a domain-specific language (DSL) tailored to hardware communication protocols, which enables the unified specification of both driver and monitor logic through an imperative syntax, thereby ensuring their semantic consistency for the first time. Building upon this DSL, they develop a prototype tool that leverages waveform parsing and transaction-level trace inference techniques to accurately reconstruct protocol-compliant transaction sequences from raw signal waveforms. Experimental results demonstrate that the approach significantly improves development efficiency, with further validation planned on real-world interconnect protocols such as Wishbone and AXI-Stream.
This study systematically evaluates whether Rust can compete with C in performance and resource efficiency for microcontroller firmware development and assesses its industrial viability. Two teams independently implemented identical industrial IoT firmware—one in Rust and the other in C—and key metrics including development effort, memory footprint, and execution speed were compared on real hardware. This work presents the first systematic comparison of the two languages in a genuine industrial context and introduces Ariel OS, a lightweight Rust-based runtime. Empirical results demonstrate that Rust matches or exceeds C in both resource utilization and execution performance, while Ariel OS exhibits a smaller binary footprint, collectively establishing Rust as a reliable and competitive choice for microcontroller firmware development.
Identifying critical safety constraints from the vast number of Hardware Abstraction Layer (HAL) interfaces in embedded systems remains challenging, hindering effective fault prevention. Method: This paper proposes a fault-prevention-oriented requirement prioritization approach. Its core innovation is the formal definition of “indisputable relevance,” transforming hardware access constraint identification into a verifiable formal verification problem. The method models HAL interfaces, semantically analyzes real-world failure reports, and leverages model checkers (e.g., CBMC) to automatically generate mathematical proofs—thereby extracting and verifying constraints strongly correlated with system failures or hardware damage. Results: Evaluated on three industrial-grade failure cases involving the SPI bus spidev HAL, the approach successfully identified and formally verified critical requirements. Experimental results demonstrate its feasibility and effectiveness, establishing a novel, verifiable, and traceable paradigm for requirements engineering in high-reliability embedded systems.
This study addresses the challenges of structural comprehension and evolution assessment arising from the massive scale of the Linux kernel codebase by proposing a 3D city metaphor visualization approach based on ExplorViz. Software metrics are mapped to building geometric dimensions and heatmaps, integrating Git commit parsing, custom metric computation, and Web-based frontend 3D rendering techniques to enable intuitive, interactive exploration of large-scale open-source projects. The proposed method successfully visualizes the complete file-level view of the kernel alongside the evolutionary trajectory of its Rust codebase. Consequently, this work provides efficient visual support for architectural analysis and historical evolution research in complex software systems.