Score
Designs, deploys, and administers systems and services built on the Unix/Linux family of operating systems, including kernel and system configuration, init/systemd and service management, filesystems, user and process management, networking, package management, and system security. Diagnoses and analyzes system performance, reliability and logs, and automates administration tasks and deployments using shell scripting and configuration management or orchestration tools.
本文系统化分析了Linux内核漏洞从发现到修复的全过程,指出现有自动化技术在漏洞处理后期阶段的不足,并提出了解决方案。
Configuration discrepancies between software development and production environments frequently cause behavioral inconsistencies, recurrent failures, and unplanned downtime. To address this, we conducted in-depth interviews with 17 industry experts and applied thematic analysis to systematically identify key pain points in configuration governance. Based on empirical evidence, we propose the first structured, practice-oriented taxonomy of mitigation strategies—comprising eight actionable categories: process design, automated deployment, Infrastructure-as-Code (IaC) adoption, Docker-based containerized validation, virtualization-based environment isolation, and closed-loop verification, among others. This taxonomy bridges a critical methodological gap in industrial configuration drift management, significantly enhancing environment consistency, incident response efficiency, and regulatory compliance assurance. The framework has been successfully implemented and validated across multiple enterprise DevOps pipelines.
File system configuration parameters exhibit complex, multi-level dependencies that frequently lead to misconfigurations and regression failures. This paper presents the first systematic characterization of deep configuration dependency patterns in Ext4, XFS, and ZFS. To address this challenge, we propose ConfD—a generic, scalable, automated dependency extraction framework integrating static configuration parsing, dependency graph modeling, and a cross-filesystem abstraction adaptation layer. ConfD employs a rule-driven, plugin-based diagnostic mechanism to detect misuses and localize regression-inducing configurations. Evaluated on three major filesystems, ConfD precisely extracts 160 configuration dependencies with low false-positive rates, successfully identifying both erroneous configurations and legitimate configurations that trigger regressions. Furthermore, we demonstrate ConfD’s extensibility by validating its applicability to storage engines beyond filesystems, including WiredTiger.
To address poor reproducibility, low build efficiency, and insufficient deployment automation in embedded Linux system customization, this paper proposes a three-layer extensible architecture based on the Yocto Project. The architecture integrates GitLab CI and Docker to ensure environment isolation and enable continuous integration and deployment (CI/CD), while incorporating a local hash server (hashserv) and shared sstate cache server to significantly improve build artifact reuse. It supports automated real-time Linux kernel builds, QEMU-based simulation testing, and validation across six distinct boot scenarios. Experimental evaluation demonstrates substantial reduction in build time, markedly enhanced system stability and build reproducibility, and strong scalability and engineering deployability for industrial-grade applications.
This study addresses the urgent need to enhance the security of information systems as critical societal infrastructure. Adopting the reference monitor architecture as a theoretical framework, this work systematically reviews three core technologies: virtualization, formal verification of operating systems, and fine-grained access control. It provides an in-depth analysis of their technical prospects and evolutionary challenges within security requirements analysis. Furthermore, this research constructs a comprehensive landscape of the operating system security domain, delineating integration pathways and future development directions for these technologies. By doing so, it establishes a solid theoretical foundation and a clear technical roadmap for overcoming existing bottlenecks in system security.
This paper presents a systematic review of core challenges in software deployment, including reproducibility, dependency resolution, trust mechanisms, and fine-grained incremental builds. It offers the first comprehensive evaluation of Nix’s pure functional approach across build systems, package management, system configuration, and development environments. Through dependency graph modeling and taxonomic analysis of related tools, the study clarifies Nix’s contributions to ensuring reproducible builds while exposing its limitations in trust establishment and incremental build support. The work further synthesizes cutting-edge community-driven solutions addressing these shortcomings and outlines promising directions for future research in reliable and efficient software deployment.
Traditional operating systems struggle to support goal-directed, dynamically tool-invoking agents with adaptive behaviors, exhibiting fundamental limitations in scheduling, state management, security, and observability. This work presents the first systematic design of an Agent Operating System (AOS) architecture, which introduces an agent control plane into conventional OS abstractions and rethinks core mechanisms—including scheduling, context management, capability registration, policy enforcement, and auditing. AOS clearly delineates responsibility boundaries and non-goals, establishing a multi-layered integration model spanning user-space runtimes to distributed control planes, thereby transcending the traditional OS assumption of deterministic program execution. The paper establishes novel system abstractions for agent-centric computing, proposes a security threat model and evaluation criteria, and makes significant advances in ensuring deterministic execution, auditability, and operational interpretability.
This work addresses the growing complexity of network management in cloud-native, heterogeneous, and distributed environments, where traditional manual operations struggle to efficiently handle configuration, troubleshooting, and security challenges. To overcome these limitations, we propose NetLLMeval, a novel framework that introduces the first fully automated evaluation mechanism for network management agents, eliminating the need for human intervention. By integrating large language models, network simulation, and an agent architecture encompassing both monolithic prompting and end-to-end pipeline designs, NetLLMeval enables multidimensional assessment of network agents in realistic settings. Extensive experiments—comprising 24,000 trials—demonstrate that specialized solver designs substantially enhance performance, boosting the accuracy of a 14B-parameter open-source model from 0.43 to 0.88, rivaling state-of-the-art systems with trillion-scale parameters.
While large language models (LLMs) can generate executable multi-service application environments, they often deviate from the architectural and security requirements essential for production deployment. This work proposes a method to automatically generate Dockerfiles and Docker Compose configurations solely from code repositories, evaluating deployment fidelity through end-to-end HTTP testing and structural comparison. It explicitly distinguishes between functional correctness and fidelity to deployment intent, deriving a minimal set of explicit deployment specifications that cannot be inferred automatically from source code alone. Experiments successfully reproduce the topology and dependencies of three heterogeneous multi-service systems, confirming functional feasibility; however, critical production-grade features—such as network isolation and multi-stage builds—are consistently absent, revealing fundamental limitations in current LLMs’ ability to model deployment intent.
This work addresses the challenge of highly manual and non-generalizable environment configuration in repository-level software engineering tasks by introducing RAT, the first language-agnostic framework for fully automated repository setup. RAT establishes an end-to-end pipeline comprising semantic initialization, task planning, invocation of specialized tools, and robust sandbox construction. To evaluate such systems realistically, the authors also release RATBench, the first benchmark reflecting the true distribution and heterogeneity of real-world code repositories. Experimental results demonstrate that RAT significantly outperforms strong existing baselines on RATBench, achieving an average 29.6% improvement in Environment Setup Success Rate (ESSR). This advance overcomes prior limitations that relied on predefined artifacts or were confined to specific programming languages.