The Multics kernel design project

1977; Association for Computing Machinery; Volume: 11; Issue: 5 Linguagem: Inglês

10.1145/1067625.806546

ISSN

1943-586X

Autores

Michael Schroeder, David D. Clark, Jerome H. Saltzer,

Tópico(s)

Distributed systems and fault tolerance

Resumo

We describe a plan to create an auditable version of Multics. The engineering experiments of that plan are now complete. Type extension as a design discipline has been demonstrated feasible, even for the internal workings of an operating system, where many subtle intermodule dependencies were discovered and controlled. Insight was gained into several tradeoffs between kernel complexity and user semantics. The performance and size effects of this work are encouraging. We conclude that verifiable operating system kernels may someday be feasible.

Referência(s)