However, this could be built into ERA by using a simple, memory boundary
based memory management unit that would be by far simpler than the fully fledged
MMU which is required for the microkernel approach.
References
1. Green Hills Software. Integrity, the most advanced RTOS technology. Technical report, Green
Hills Software, 2008. 61, 191
2. Klein G et al (2009) sel4: formal verification of an os kernel. Technical report. 191
3. Dirk Vogt D, Döbel B, Lackorzynski A (2010) Stay strong, stay safe: enhancing reliability of a
secure operating system. In: Proceedings of the workshop on isolation and integration for
dependable systems (IIDS 2010), Paris, France, April 2010, New York, NY, USA. ACM. 192
4. Lackorzynski A, Warg A, (2009) Taming subsystems: capabilities as universal resource access
control in l4. In: Proceedings of the second workshop on isolation and integration in embedded
systems, IIES ’09, New York, NY, USA. ACM, pp 25–30. 192
5. Tanenbaum A (2006) Reorganizing Unix for reliability. In: Proceedings of 11th Asia-Pacific,
pp 81–94. 192
6. David F et al (2008) Curios: improving reliability through operating system structure. In:
OSDI’08, Berkeley, CA, USENIX Association, pp 59–72. 192
7. Shapiro J (1999) EROS: a capability system. PhD thesis, University of Pennsylvania. 192
Table 13.1 Comparison of existing FT approaches to ours
FT OS feature ERA Minix 3
CuriOS
Integrity
OS
L4ReAnimator
Error detection Yes
Yes
(component
failure)
Yes
(component
failure)
Yes, task
failure
Yes, capability and task
failure
Fault-type
determination
Yes
No
No
No
No
Hardware
reconfiguration
Yes
No
No
No
No
Location of
faulty software
states
Yes
No
No
No
No, last recovery point is
assumed to be correct, or
application restart
Automatic
software
reconfiguration
Yes
No
No
No
Semi-transparent,
application intervention
required
Software
recovery
Yes
Yes, restart
Yes, restart
Yes,
restart
Yes, restart or recovery
point
13.1 What Is Available?
195
Précédent

- 207/315

Suivant