Safe to the Last Instruction: Automated

Published  . 0 views
↓ Download
Safe to the Last Instruction: Automated
1 / 1
Safe to the Last Instruction: Automated - slide 1 of 19 Safe to the Last Instruction: Automated - slide 2 of 19 Safe to the Last Instruction: Automated - slide 3 of 19 Safe to the Last Instruction: Automated - slide 4 of 19 Safe to the Last Instruction: Automated - slide 5 of 19 Safe to the Last Instruction: Automated - slide 6 of 19 Safe to the Last Instruction: Automated - slide 7 of 19 Safe to the Last Instruction: Automated - slide 8 of 19 Safe to the Last Instruction: Automated - slide 9 of 19 Safe to the Last Instruction: Automated - slide 10 of 19 Safe to the Last Instruction: Automated - slide 11 of 19 Safe to the Last Instruction: Automated - slide 12 of 19 Safe to the Last Instruction: Automated - slide 13 of 19 Safe to the Last Instruction: Automated - slide 14 of 19 Safe to the Last Instruction: Automated - slide 15 of 19 Safe to the Last Instruction: Automated - slide 16 of 19 Safe to the Last Instruction: Automated - slide 17 of 19 Safe to the Last Instruction: Automated - slide 18 of 19 Safe to the Last Instruction: Automated - slide 19 of 19
Description: Safe to the Last Instruction: Automated Verification of a Type-Safe Operating System Jean Yang MIT CSAIL Chris Hawblitzel Microsoft Research Safe to the Last Instruction: Automated Verification of a Type-Safe Operating System Jean Yang MIT

Related Topics

Download Presentation

"Safe to the Last Instruction: Automated" is the property of its rightful owner. Permission is granted to download and print the materials on this website for personal, non-commercial use only, and to display it on your personal computer provided you do not modify the materials and that you retain all copyright notices contained in the materials. By downloading content from our website, you accept the terms of this agreement.

Presentation Transcript

slide1. Safe to the Last Instruction: Automated Verification of a Type-Safe Operating System Jean Yang
MIT CSAIL Chris Hawblitzel
Microsoft Research<br>
slide2. Safe to the Last Instruction: Automated Verification of a Type-Safe Operating System Jean Yang
MIT CSAIL Chris Hawblitzel
Microsoft Research<br>
slide3. 3 Safe to the Last Instruction / Jean Yang<br>
slide4. Safe to the Last Instruction / Jean Yang 4<br>
slide5. Safe to the Last Instruction / Jean Yang Memory Safety 5<br>
slide6. Type Safety 6 Safe to the Last Instruction / Jean Yang<br>
slide7. Safe to the Last Instruction / Jean Yang Untyped Unsafe code
(GC, stacks, drivers, …) Type-checked OS File System Drivers Applications Microkernel Hardware Previously: “Safe” Systems 7 What currently exists<br>
slide8. Safe to the Last Instruction / Jean Yang Untyped Unsafe code
(GC, stacks, drivers, …) Type-checked OS File System Drivers Applications Microkernel Hardware End-to-End Safe Systems 8 Verified code
(GC, stacks, drivers, …) What we want<br>
slide9. Verified Type-checked Verve, a Type-Safe OS Safe to the Last Instruction / Jean Yang Verify partial correctness of low-level Nucleus using Hoare logic based on a hardware spec.
Verify an interface to typed assembly for end-to-end safety. Nucleus File System Drivers Applications Microkernel Hardware specification Interface specification 9<br>
slide10. The Verve Nucleus Safe to the Last Instruction / Jean Yang 10 x86 instructions
Memory bounds Devices GC Heap Allocator and GC
[POPL 2009] Stacks Interrupt table Interrupt/error handling Interface specification<br>
slide11. Thread Context Invariant function StateInv
(s:StackID, state:StackState, …)
returns(bool) {
(!IsEmpty(state)  … && (IsInterrupted(state)  …
&& (IsYielded(state)  …
&& state == StackYielded(
StackEbp(s, tMems)
, StackEsp(s, tMems) + 4
, StackRA(s, tMems, fMems)) && …
} Safe to the Last Instruction / Jean Yang 11<br>
slide12. “Load” Specification procedure Load(ptr:int)
returns (val:int);
requires memAddr(ptr);
requires Aligned(ptr);
modifies Eip;
ensures word(val);
ensures val == Mem[ptr]; Safe to the Last Instruction / Jean Yang 12<br>
slide13. Assembling Verve Verified Safe to the Last Instruction / Jean Yang Boogie/Z3 Translator/
Assembler Source file Compilation tool Verification tool Nucleus.bpl (x86) 13<br>
slide14. Boogie to x86 implementation ReadKeyboard(){
call KeyboardStatusIn8();
call eax := And(eax, 1);
if (eax != 0) { goto proc; }
call eax := mov(256);
return;
proc:
call KeyboardDataIn8();
call eax := And(eax, 255);
return;
} Safe to the Last Instruction / Jean Yang ReadKeyboard proc
in al, 064h
and eax, 1
cmp eax, 0
jne ReadKeyboard$proc
mov eax, 256
ret
ReadKeyboard$skip:
in al, 060h
and eax, 255
ret 14<br>
slide15. Building Verve Verified Safe to the Last Instruction / Jean Yang C# compiler Kernel.cs Boogie/Z3 Translator/
Assembler TAL checker Linker/ISO generator Verve.iso Source file Compilation tool Verification tool Nucleus.bpl (x86) Kernel.obj (x86) 15<br>
slide16. Verve Performance Safe to the Last Instruction / Jean Yang 16<br>
slide17. Low Annotation Burden Safe to the Last Instruction / Jean Yang 17 9 person-months 3x code<br>
slide18. Verve vs. SeL4? Safe to the Last Instruction / Jean Yang SeL4 Verified microkernel
8,700 lines of C 200,000 lines of Isabelle ~600 lines ARM assembly 120-240 person-months 18 20x code Verve Verified Nucleus
~1500 lines of x86 C# kernel<br>
slide19. Contributions Safe to the Last Instruction / Jean Yang First automatically, mechanically verified OS for type safety.
Real system running on x86 with efficient code.
Approach for using automated techniques to verify safety. Verified Type-checked Verified nucleus File System Drivers Applications Microkernel Hardware specification Interface specification http://www.codeplex.com/singularity 19<br>