Horst Schirmeier

dblp:54/667 · DBLP profile ↗
← Back
19ranked-venue papers
6as first author
7since 2021 · last 2026
0000-0002-1427-9343ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 7 · 2 first-author · 2 since 2021Security and privacy · 7 · 4 first-author · 1 since 2021Software engineering, systems software and programming languages · 7 · 3 first-author · 2 since 2021Artificial intelligence and machine learning · 2 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 BRUMM: A Case for Predictable Memory Reclamation
abstract
Edge data centers process latency-sensitive workloads of nearby Internet-of-Things devices. These security-critical, multi-tenant environments are equipped with comparatively limited compute resources. Consequently, resource management must be fast and predictable even in the presence of malicious tenants because there is no surplus of resources to compensate for performance attacks. In particular, there is a need to constrain the time it takes to reclaim memory from applications. Existing accounting mechanisms in operating systems focus on limiting memory or scheduling-time usage; they provide no guarantees about the latency of resource reclamation, which can vary greatly and is a potential vector for performance attacks. To solve this standing issue, we introduce BRUMM (Bounded Reclamation of User-space Memory Mappings): This accounting-driven mechanism predicts and tracks how long it will take to reclaim memory allocated to applications, enforcing an upper limit via a configurable latency budget. As a case study, we extended the L4Re microkernel to add a quota object for reclamation latency and enforce its limit. Our evaluation demonstrates that this implementation of BRUMM achieves a consistent overestimation of reclamation latency, staying within the same order of magnitude to real, measured latencies. The implementation only shows modest performance overhead on kernel operations, ranging from 2.4% overhead for simple system calls to 28% in synthetic worst-case scenarios. BRUMM makes reclamation latency a first-class resource that can be accounted for, thereby improving isolation and reliability in edge clouds.
Viktor Reusch, Michael Roitzsch, Horst Schirmeier
ECRTS3
2025 Path Expressions Revisited - Towards Compiler-enforced Reusable Synchronization Patterns
abstract
Path expressions (PEs) offer a declarative way to specify synchronization constraints in concurrent programs, but have largely fallen out of favor due to concerns over limited expressiveness, runtime overhead, and poor integration with contemporary languages. In this work, we revisit PEs and argue for their renewed relevance as reusable synchronization patterns. We present a compiler-assisted approach that integrates PEs into C++ using AspectC++, enabling non-invasive synchronization of existing code. Our prototype demonstrates practical integration on a ring buffer and evaluates performance in a real-world concurrency scenario using MySQL's myisamchk utility. Results show that PE-based synchronization can be both expressive and efficient, performing comparably to traditional mechanisms in many cases. While challenges remain particularly around runtime adaptability and scaling under contention, our findings suggest that PEs deserve reconsideration as a practical tool for building reliable, maintainable concurrent software.
Thomas Alexander Hövelmann, Olaf Spinczyk, Alexander Krause 0003, Horst Schirmeier, Peter Ulbrich
PLOS@SOSP4
2024 On-The-Fly Data Distribution to Accelerate Query Processing in Heterogeneous Memory Systems
André Berthold, Lennart Schmidt, Antonia Obersteiner, Dirk Habich, Wolfgang Lehner, Horst Schirmeier
ADBIS6
2023 Sleep Well: Pragmatic Analysis of the Idle States of Intel Processors
abstract
Rising energy consumption is of growing concern for cloud data center providers. Modern processors try to counteract this problem through low-power idle states that save energy in phases with little demand for compute resources. Making proper use of this feature, however, requires knowledge about the properties of these states for the very processors used in a specific setup; most importantly, the energy consumed in each idle state and the latency for resuming normal operation. Unfortunately, hardware vendors usually do not provide this critical information.
Till Smejkal, Jan Bierbaum, Thomas Oberhauser, Horst Schirmeier, Hermann Härtig
BDCAT4
2023 Compiler-Implemented Differential Checksums: Effective Detection and Correction of Transient and Permanent Memory Errors
abstract
The detection of memory errors is common practice in safety-critical software, for example in the automotive and avionics industry. International safety standards recommend using checksums for protecting critical data in computer memories. Typical implementations verify the checksum before data access and recompute it after modification using the same algorithm. However, we show that this approach can sometimes dramatically worsen the reliability of computer systems with regard to transient memory faults, and also permanent faults remain undetected. A solution with significant conceptual advantages is constituted by differential checksum algorithms, which update the respective checksum without full recomputation on data modification. We present a compiler-based solution that inserts differential checksums into C/C++ data structures automatically to cope with their increased complexity. An extensive fault-injection campaign with the TACLeBench benchmark collection shows that differential checksums reduce silent data corruptions by 95% on average whereas non-differential checksums turn out to be mostly ineffective because they introduce a window of vulnerability.
Christoph Borchert, Horst Schirmeier, Olaf Spinczyk
DSN2
2023 Process Composition with Typed Unix Pipes
abstract
Pipes are a standard inter-process communication mechanism in Unix-like operating systems, allowing to compose simple, single-purpose programs to solve complex problems. This powerful mechanism arguably contributed quite a lot to the success of Unix. However, the design decision to standardize unstructured, type-less byte streams as a basis for communication can be seen as disadvantageous: Incompatible programs can mistakenly be hooked together, conversions have to be added manually, and the structure of the communicated data has to be re-created by parsers and serialized again at every node in the pipeline.
Michael Sippel, Horst Schirmeier
PLOS@SOSP2
2022 Software-Managed Read and Write Wear-Leveling for Non-Volatile Main Memory
abstract
In-memory wear-leveling has become an important research field for emerging non-volatile main memories over the past years. Many approaches in the literature perform wear-leveling by making use of special hardware. Since most non-volatile memories only wear out from write accesses, the proposed approaches in the literature also usually try to spread write accesses widely over the entire memory space. Some non-volatile memories, however, also wear out from read accesses, because every read causes a consecutive write access. Software-based solutions only operate from the application or kernel level, where read and write accesses are realized with different instructions and semantics. Therefore different mechanisms are required to handle reads and writes on the software level. First, we design a method to approximate read and write accesses to the memory to allow aging aware coarse-grained wear-leveling in the absence of special hardware, providing the age information. Second, we provide specific solutions to resolve access hot-spots within the compiled program code (text segment) and on the application stack. In our evaluation, we estimate the cell age by counting the total amount of accesses per cell. The results show that employing all our methods improves the memory lifetime by up to a factor of 955×.
Christian Hakert, Kuan-Hsun Chen, Horst Schirmeier, Lars Bauer, Paul R. Genssler, Georg von der Brüggen, Hussam Amrouch, Jörg Henkel, Jian-Jia Chen
ACM Trans. Embed. Comput. Syst.3
2019 Design Optimization for Hardware-Based Message Filters in Broadcast Buses
abstract
In the field of automotive engineering, broadcast buses, e.g., Controller Area Network (CAN), are frequently used to connect multiple electronic control units (ECUs). Each message transmitted on such buses can be received by each single participant, but not all messages are relevant for every ECU. For this purpose, all incoming messages must be filtered in terms of relevance by either hardware or software techniques. We address the issue of designing hardware filter configurations for clients connected to a broadcast bus in order to reduce the cost, i.e., the computation overhead, provoked by undesired but accepted messages. More precisely, we propose an SMT formulation that can be applied to i) retrieve a (minimal) perfect filter configuration, i.e., no undesired messages are received, ii) optimize the filter quality under given hardware restrictions, or iii) minimize the hardware cost for a given type of filter component and a maximum cost threshold.
Lea Schönberger, Georg von der Brüggen, Horst Schirmeier, Jian-Jia Chen
DATE3
2019 LockDoc: Trace-Based Analysis of Locking in the Linux Kernel
abstract
For fine-grained synchronization of application and kernel threads, the Linux kernel provides a multitude of different locking mechanisms that are being used on various individually locked data structures. Understanding which locks are required in which order for a particular member variable of a kernel data structure has become truly difficult, even for Linux-kernel experts themselves.
Alexander Krause 0003, Horst Schirmeier, Hendrik Borghorst, Olaf Spinczyk
EuroSys2
2017 Generic Soft-Error Detection and Correction for Concurrent Data Structures
abstract
Recent studies indicate that transient memory errors (soft errors) have become a relevant source of system failures. This paper presents a generic software-based fault-tolerance mechanism that transparently recovers from memory errors in object-oriented program data structures. The main benefits are the flexibility to choose from an extensible toolbox of easily pluggable error detection and correction schemes, such as Hamming and CRC codes. This is achieved by a combination of aspect-oriented and generative programming techniques. Furthermore, we present a wait-free synchronization algorithm for error detection in data structures that are used concurrently by multiple threads of control. We give a formal correctness proof and show the excellent scalability of our approach in a multiprocessor environment. In a case study, we present our experiences with selectively hardening the eCos operating system and its benchmark suite. We explore the trade-off between resiliency and performance by choosing only the most vulnerable data structures for error recovery. Thereby, the total number of system failures, manifesting as silent data corruptions and crashes, is reduced by 69.14 percent at a negligible runtime overhead of 0.36 percent.
Christoph Borchert, Horst Schirmeier, Olaf Spinczyk
IEEE Trans. Dependable Secur. Comput.2
2016 Experiences with software-based soft-error mitigation using AN codes
Martin Hoffmann 0001, Peter Ulbrich, Christian Dietrich 0001, Horst Schirmeier, Daniel Lohmann, Wolfgang Schröder-Preikschat
Softw. Qual. J.4
2015 Avoiding Pitfalls in Fault-Injection Based Comparison of Program Susceptibility to Soft Errors
abstract
Since the first identification of physical causes for soft errors in memory circuits, fault injection (FI) has grown into a standard methodology to assess the fault resilience of computer systems. A variety of FI techniques trying to mimic these physical causes has been developed to measure and compare program susceptibility to soft errors. In this paper, we analyze the process of evaluating programs, which are hardened by software-based hardware fault-tolerance mechanisms, under a uniformly distributed soft-error model. We identify three pitfalls in FI result interpretation widespread in the literature, even published in renowned conference proceedings. Using a simple machine model and transient single-bit faults in memory, we find counterexamples that reveal the unfitness of common practices in the field, and substantiate our findings with real-world examples. In particular, we demonstrate that the fault coverage metric must be abolished for comparing programs. Instead, we propose to use extrapolated absolute failure counts as a valid comparison metric.
Horst Schirmeier, Christoph Borchert, Olaf Spinczyk
DSN1
2014 Smart-hopping: Highly efficient ISA-level fault injection on real hardware
abstract
Fault-injection experiments on the instruction-set architecture level are commonly used to analyze embedded software's susceptibility to hardware faults, typically involving a vast number of experiments with systematically varying fault locations and times. Determinism and high performance are the predominant requirements on fault-injection platforms. Injecting faults into a real embedded hardware platform instead of a simulator is favorable for both workload execution speed and result accuracy. The most performance-critical part of such a fault-injection platform is the “fast forward” operation, which executes the target machine code without faults until the exact dynamic instruction is reached at which the execution must be stopped to inject the next fault. Unfortunately, most embedded CPUs do not support this operation efficiently. In this paper we present an approach that speeds up fast-forwarding significantly for most workloads with minimal requirements on hardware support. Based on a previously recorded instruction trace — which is needed for systematic fault-injection experiment planning anyways — we use standard debugging hardware to advance to a chosen point in program execution with a minimal number of steps. We evaluate our FAIL∗ tool platform with two MiBench benchmark categories, and improve experiment throughput by up to several magnitudes compared to similar fault-injection tools in the field.
Horst Schirmeier, Lars Rademacher, Olaf Spinczyk
ETS1
2014 Effectiveness of Fault Detection Mechanisms in Static and Dynamic Operating System Designs
abstract
Developers of embedded (real-time) systems can choose from a variety of operating systems. While some embedded operating systems provide very flexible APIs, e.g., a POSIX-compliant interface for run-time management, others have a completely static structure, which is generated at compile time by utilizing detailed application knowledge. A prominent example for the latter class from the domain of automotive operating systems is OSEK/OS and its successor AUTOSAR/OS. As we have shown in previous work, the design of the operating system has a strong impact on its vulnerability for system failure caused by hardware faults. This observation is gaining importance, because there is an ongoing trend towards low-power and low-cost, yet less reliable, hardware. This work quantifies the difference in vulnerability for soft errors in main memory of a flexible (dynamic) operating systems (eCos) and a static system (CiAO), which has an OSEK-compliant structure. We also analyze the additional degree of robustness that is achieved by hardening an operating system with software-based and hardware-based fault-tolerance measures and the corresponding costs. Covering this design space gives developers a better chance for good design decisions with respect to the trade-off between fault tolerance, resource consumption, and interface convenience. Our results indicate that with a combination of hardware- and software-based fault-tolerance measures, silent data corruptions in both operating systems can be reduced to below one percent (compared to eCos). However, the analyzed fault-tolerance mechanisms are expensive for the dynamic system, whereas the statically designed operating system can be hardened at much lower price.
Martin Hoffmann 0001, Christoph Borchert, Christian Dietrich 0001, Horst Schirmeier, Rüdiger Kapitza, Olaf Spinczyk, Daniel Lohmann
ISORC4
2014 Rapid Fault-Space Exploration by Evolutionary Pruning
Horst Schirmeier, Christoph Borchert, Olaf Spinczyk
SAFECOMP1
2013 Generative software-based memory error detection and correction for operating system data structures
abstract
Recent studies indicate that the number of system failures caused by main memory errors is much higher than expected. In contrast to the commonly used hardware-based countermeasures, for example using ECC memory, software-based fault-tolerance measures are much more flexible and can exploit application knowledge, such as the criticality of specific data structures. This paper presents a software-based memory error protection approach, which we used to harden the eCos operating system in a case study. The main benefits of our approach are the flexibility to choose from an extensible toolbox of easily pluggable error detection and correction schemes as well as its very low runtime overhead, which totals in a range of 0.09-1.7 %. The implementation is based on aspect-oriented programming and exploits the object-oriented program structure of eCos to identify well-suited code locations for the insertion of generative fault-tolerance measures.
Christoph Borchert, Horst Schirmeier, Olaf Spinczyk
DSN2
2011 Revisiting Fault-Injection Experiment-Platform Architectures
abstract
Many years of research on dependable, fault-tolerant software systems yielded a myriad of tool implementations for vulnerability analysis and experimental validation of resilience measures. Trace recording and fault injection are among the core functionalities these tools provide for hardware debuggers or system simulators, partially including some means to automate larger experiment campaigns. We argue that current fault-injection tools are too highly specialized for specific hardware devices or simulators, and are developed in poorly modularized implementations impeding evolution and maintenance. In this article, we present a novel design approach for a fault-injection infrastructure that allows experimenting researchers to switch simulator or hardware back ends with little effort, fosters experiment code reuse, and retains a high level of maintainability.
Horst Schirmeier, Martin Hoffmann 0001, Rüdiger Kapitza, Daniel Lohmann, Olaf Spinczyk
PRDC1
2011 RAMpage: Graceful Degradation Management for Memory Errors in Commodity Linux Servers
abstract
Memory errors are a major source of reliability problems in current computers. Undetected errors may result in program termination, or, even worse, silent data corruption. Recent studies have shown that the frequency of permanent memory errors is an order of magnitude higher than previously assumed and regularly affects everyday operation. Often, neither additional circuitry to support hardware-based error detection nor downtime for performing hardware tests can be afforded. In the case of permanent memory errors, a system faces two challenges: detecting errors as early as possible and handling them while avoiding system downtime. To increase system reliability, we have developed RAMpage, an online memory testing infrastructure for commodity x86-64-based Linux servers, which is capable of efficiently detecting memory errors and which provides graceful degradation by withdrawing affected memory pages from further use. We describe the design and implementation of RAMpage and present results of an extensive qualitative as well as quantitative evaluation.
Horst Schirmeier, Jens Neuhalfen, Ingo Korb, Olaf Spinczyk, Michael Engel
PRDC1
2007 Tailoring Infrastructure Software Product Lines by Static Application Analysis
abstract
Besides ordinary applications, also infrastructure software such as operating systems or database management systems is being developed as a software product line. With proper tool support these systems can be configured easily by selecting features in a feature model. However, in the future multi-level architectures of layered product lines will be common practice. For humans the feature-based configuration will become increasingly complex, as the number of configurable features will be tremendous. Our goal is to reduce this complexity. The approach is based on the observation that many configuration decisions could be automated by statically analyzing the code of layers on top of an infrastructure product line. Motivated by use cases the paper presents the concepts behind our analysis tool, which is able to automate the configuration in many cases. First results in the context of a feature-oriented version of the Berkeley DB illustrate the potential of this novel approach.
Horst Schirmeier, Olaf Spinczyk
SPLC1