3 ms·Safe to the Last Instruction: Automated Verification of a Type-Safe OS2 points by wkornewald 9y ago