5 ms·
Lot of superlative in there for a project I've never seen used anywhere. But competition is good and you never know so I'll keep an eye on it.
by sametmax 7y ago
Lot of superlative in there for a project I've never seen used anywhere.
But competition is good and you never know so I'll keep an eye on it.
- AnIdiotOnTheNet 7y agoIf you want to know why it isn't used anywhere, try using it somewhere. Like most (all?) microkernel projects it seems to exist purely for academic purposes.
- pjmlp 7y agoYet another one that didn't realize that most high integrity systems, where human lives are at stake, mobile radio stacks, factory automation, run real time OSes with microkernel design. Or that macOS, Windows and their derived implementations use an hybrid design. Pure UNIX clones are the surviving monoliths.
- AnIdiotOnTheNet 7y agoOk you got me there, I have literally no experience with such systems.
- nickpsecurity 7y agoCounterpoints: https://www.cs.vu.nl/%7East/reliable-os/ https://www.cs.vu.nl/%7East/reliable-os/ Especially QNX [1]. Green Hill's INTEGRITY, Sysgo's PikeOS, and Lynx's LynxOS-178B are other examples in safety-critical fields like aerospace. I think DDC-I's DEOS, which is in a bunch of aircraft systems, looked like a microkernel in its architectural diagrams. One of their main advantages, other than size, is that they let you evaluate systems piece by piece looking at components in isolation and then their specific, permitted interactions. Traditional monoliths might have control flow and state changes jumping all over the place. [1] Look up demos of the Blackberry Playbook vs iPad to see how usable, fast, and stutter free QNX-based system was.
- SomeOldThrow 7y agoI have no idea why you would consider popularity a proxy for quality.
- nickpsecurity 7y agoThey were actually objectively-true statements. That person just didn't give you evidence supporting them. Here's a few things these alternative designs do: 1. Tiny amount of code in kernel mode with privilege services run with as much untrusted code as possible. Linux is already miles away from this. Even starting with Linux makes you automatically lose against a minimalist, security-focused design. There's even vendors that pre-supply folks with money vulnerabilities to use against Linux. A steady stream. 2. Built-in support at the very foundation for both strong process isolation, decomposing a system into components, and making them communicate easily. The security is almost always better if it's baked in rather than bolted on. At the least, there's fewer bad interactions or escape hatches that can happen when combining insecure and security-focused code. 3. For many L4-related projects, Camkes as a way to handle IPC for you. They usually have some kind of middleware for automatically generating code for components to communicate. They focus on correctness and security more than feature support. I don't know how Docker compares there. https://ts.data61.csiro.au/software/TS/camkes/ https://ts.data61.csiro.au/software/TS/camkes/ 4. Now, like Docker, Genode has some kind of build tooling to put it all together. I haven't read as much about recent changes. So, I'll just say they both do this kind of thing now. I'll also note that separation kernels are typically designed to be integrated with an application, OS, or whatever into a deployable image that contains just what they need. In most, the resources and scheduling policy are also done statically in the code to reduce attack surface. If you're talking security and componentization, Genode-like designs have Docker beat with a foundation that has way less code, is actually designed for security, and makes achieving it easier by default. One still has to work on assuring anything they build on top. The GenodeOS might have vulnerabilities, too. Just by the numbers, Linux is going to have way more with higher impact on average. If you doubt that... https://events.linuxfoundation.org/wp-content/uploads/2017/11/Syzbot-and-the-Tale-of-Thousand-Kernel-Bugs-Dmitry-Vyukov-Google.pdf https://events.linuxfoundation.org/wp-content/uploads/2017/1...