The Multics kernel design project

Michael D. Schroeder, David D. Clark, Jerome H. Saltzer
1977 Proceedings of the sixth symposium on Operating systems principles - SOSP '77  
We describe a plan to create an auditable version of Multics. The engineering experiments of that plan are now complete. Type extension as a design discipline has been demonstrated feasible, even for the internal workings of an operating system, where many subtle intermodule dependencies were discovered and controlled. Insight was gained into several tradeoffs between kernel complexity and user semantics. The performance and size effects of this work are encouraging. We conclude that verifiable operating system kernels may someday be feasible.
doi:10.1145/800214.806546 dblp:conf/sosp/SchroederCS77 fatcat:2dwq3y5vqfgavlw3qxdnegbspi