VLDB 2026 Research / reviewers in the wild / expert
Timothy Roscoe
dblp:r/TimothyRoscoe · also Mothy Roscoe
· DBLP profile ↗
73ranked-venue papers
3as first author
13since 2021 · last 2025
0000-0002-8298-1126ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 36 · 2 first-author · 9 since 2021Systems, architecture and hardware · 19 · 5 since 2021Databases, data management, data science and information retrieval · 12Computer networks · 9 · 1 first-author · 1 since 2021Theory of computation · 2 · 1 since 2021Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Efeu: generating efficient, verified, hybrid hardware/software drivers for I2C devicesabstractWriting device drivers is notoriously hard, and driver bugs are a major cause of system failures and vulnerabilities. The problem is particularly acute in bus-based protocols like I2C, where driver correctness is only half the story: correct functioning of the complete subsystem depends on all components on the bus interoperating correctly. Unfortunately, developers cannot control all aspects of a platform, and must interact with existing devices (peripherals and/or hardware bus controllers) which may misbehave. Failures in a protocol like I2C, often used in critical low-level system management, can result in permanent damage to the hardware, whether a server or a satellite. Daniel David Schwyn, Zikai Liu, Timothy Roscoe |
EuroSys | 3 |
| 2025 | The NIC should be part of the OSabstractThe network interface adapter (NIC) is a critical component of a cloud server occupying a unique position. Not only is network performance vital to efficient operation of the machine, but unlike compute accelerators like GPUs, the network subsystem must react to unpredictable events like the arrival of a network packet and communicate with the appropriate application end point with minimal latency. Pengcheng Xu 0005, Timothy Roscoe |
HotOS | 2 |
| 2025 | The Design and Implementation of a Virtual Firmware Monitor
Charly Castes, François Costa, Neelu S. Kalani, Timothy Roscoe, Nate Foster, Thomas Bourgeat, Edouard Bugnion |
SOSP | 4 |
| 2024 | High Throughput Hardware Accelerated CoreSight Trace DecodingabstractA single tracing component embedded into a high-frequency processor may produce up to 1 GB/s of trace data or more. These data are vital in debugging, monitoring, verification, and performance analysis in System-on-chip and heterogeneous system development. Hardware trace decoders and analyzers have emerged to support online processing of trace data for real-time applications. However, the existing hardware trace decoders designed for the Embedded Trace Macrocell version 4 (ETMv4), a standard feature in most modern ARM processors, can only process trace data at a maximum rate of 250 MB/s. This paper proposes an optimized and parallelized trace decoder for the ETMv4 specification implemented on a Xilinx Ultrascale+ processing up to 1 GB/s of trace data from a single ETM. Matthew Edwin Weingarten, Nora Hossle, Timothy Roscoe |
DATE | 3 |
| 2024 | Semi-Open-State Testing for in-Silicon Coherent Interconnects
Jasmin Schult, Ben Fiedler, David A. Cock, Timothy Roscoe |
FMCAD | 4 |
| 2023 | Function as a FunctionabstractFunction as a Service (FaaS) and the associated serverless computing paradigm alleviates users from resource management and allows cloud platforms to optimize system infrastructure under the hood. Despite significant advances, FaaS infrastructure still leaves much room to improve performance and resource efficiency. We argue that both higher performance and resource efficiency are possible --- while maintaining secure isolation --- if we are willing to revisit the FaaS programming model and system software design. We propose Dandelion, a clean-slate FaaS system that rethinks the programming model by treating serverless functions as pure functions, thereby explicitly separating computation and I/O. This new programming model enables a lightweight yet secure function execution system. It also makes functions more amenable to hardware acceleration and enables dataflow-aware function orchestration. Our initial prototype of Dandelion achieves 45× lower tail latency for cold starts compared to Firecracker. For 95% hot function invocations, Dandelion achieves 5× higher peak throughput. Tom Kuchler, Michael Giardino, Timothy Roscoe, Ana Klimovic |
SoCC | 3 |
| 2023 | Putting out the hardware dumpster fireabstractThe immense hardware complexity of modern computers, both mobile phones and datacenter servers, is a seemingly endless source of bugs and vulnerabilities in system software. Ben Fiedler, Daniel David Schwyn, Constantin Gierczak-Galle, David A. Cock, Timothy Roscoe |
HotOS | 5 |
| 2022 | Enzian: an open, general, CPU/FPGA platform for systems software researchabstractHybrid computing platforms, comprising CPU cores and FPGA logic, are increasingly used for accelerating data-intensive workloads in cloud deployments, and are a growing topic of interest in systems research. However, from a research perspective, existing hardware platforms are limited: they are often optimized for concrete, narrow use-cases and, therefore lack the flexibility needed to explore other applications and configurations. David A. Cock, Abishek Ramdas, Daniel David Schwyn, Michael Giardino, Adam Turowski, Zhenhao He, Nora Hossle, Dario Korolija, Melissa Licciardello, Kristina Martsenko, Reto Achermann, Gustavo Alonso, Timothy Roscoe |
ASPLOS | 13 |
| 2022 | How to diagnose nanosecond network latencies in rich end-host stacks
Roni Haecki, Radhika Niranjan Mysore, Lalith Suresh 0001, Gerd Zellweger, Bo Gan, Timothy Merrifield, Sujata Banerjee, Timothy Roscoe |
NSDI | 8 |
| 2021 | mmapx: uniform memory protection in a heterogeneous worldabstractModern Systems-on-Chip (SoCs) are networks of heterogeneous cores, intelligent devices, and memory, connected through multiple configurable address translation and protection units like IOMMUs and System MMUs. Reto Achermann, David A. Cock, Roni Haecki, Nora Hossle, Lukas Humbel, Timothy Roscoe, Daniel David Schwyn |
HotOS | 6 |
| 2021 | Generating correct initial page tables from formal hardware descriptionsabstractModern hardware platforms are increasingly complex and heterogeneous. System software uses a hodgepodge of different mechanisms and representations to express the memory topology of the target platform. Considerable maintenance effort is required to keep them in sync while often sharing is impossible due to hard-coded values. Incorrect platform-specific values in the hardware initialization sequence can lead to security critical and hard-to-find bugs because of misconfigured translation hardware, inaccessible devices, or the use of bad pointers. Reto Achermann, David A. Cock, Roni Haecki, Nora Hossle, Lukas Humbel, Timothy Roscoe, Daniel David Schwyn |
PLOS@SOSP | 6 |
| 2021 | A Model-Checked I2C Specification
Lukas Humbel, Daniel David Schwyn, Nora Hossle, Roni Haecki, Melissa Licciardello, Jan Schaer, David A. Cock, Michael Giardino, Timothy Roscoe |
SPIN | 9 |
| 2021 | Declarative Power SequencingabstractModern computer server systems are increasingly managed at a low level by baseboard management controllers (BMCs). BMCs are processors with access to the most critical parts of the platform, below the level of OS or hypervisor, including control over power delivery to every system component. Buggy or poorly designed BMC software not only poses a security threat to a machine, it can permanently render the hardware inoperative. Despite this, there is little published work on how to rigorously engineer the power management functionality of BMCs so as to prevent this happening. This article takes a first step toward putting BMC software on a sound footing by specifying the hardware environment and the constraints necessary for safe and correct operation. This is best accomplished through automation: correct-by-construction power control sequences can be efficiently generated from a simple, trustworthy model of the platform’s power tree that incorporates the sequencing requirements and safe voltage ranges of all components. We present both a modeling language for complex power-delivery networks and a tool to automatically generate safe, efficient power sequences for complex modern platforms. This not only increases the trustworthiness of a hitherto opaque yet critical element of platform firmware: regulator and chip power models are significantly simpler to produce than hand-written power sequences. This, combined with model reuse for common components, reduces both time and cost associated with platform bring-up for new hardware. We evaluate our tool using a new high-performance 2-socket server platform with >100W per socket TDP, tight voltage limits and 25 distinct power regulators needing configuration, showing both fast (<10s) tool runtime, and correct power sequencing of a live system. Jasmin Schult, Daniel David Schwyn, Michael Giardino, David A. Cock, Reto Achermann, Timothy Roscoe |
ACM Trans. Embed. Comput. Syst. | 6 |
| 2020 | Mitosis: Transparently Self-Replicating Page-Tables for Large-Memory MachinesabstractMulti-socket machines with 1-100 TBs of physical memory are becoming prevalent. Applications running on such multi-socket machines suffer non-uniform bandwidth and latency when accessing physical memory. Decades of research have focused on data allocation and placement policies in NUMA settings, but there have been no studies on the question of how to place page-tables amongst sockets. We make the case for explicit page-table allocation policies and show that page-table placement is becoming crucial to overall performance. We propose Mitosis to mitigate NUMA effects on page-table walks by transparently replicating and migrating page-tables across sockets without application changes. This reduces the frequency of accesses to remote NUMA nodes when performing page-table walks. Mitosis uses two components: (i) a mechanism to efficiently enable and (ii) policies to effectively control -- page-table replication and migration. We implement Mitosis in Linux and evaluate its benefits on real hardware. Mitosis improves performance for large-scale multi-socket workloads by up to 1.34x by replicating page-tables across sockets. Moreover, it improves performance by up to 3.24x in cases when the OS migrates a process across sockets by enabling cross-socket page-table migration. Reto Achermann, Ashish Panwar, Abhishek Bhattacharjee, Timothy Roscoe, Jayneel Gandhi |
ASPLOS | 4 |
| 2020 | Tackling Hardware/Software co-design from a database perspective
Gustavo Alonso, Timothy Roscoe, David A. Cock, Mohsen Ewaida, Kaan Kara, Dario Korolija, David Sidler, Zeke Wang |
CIDR | 2 |
| 2020 | Do OS abstractions make sense on FPGAs?
Dario Korolija, Timothy Roscoe, Gustavo Alonso |
OSDI | 2 |
| 2020 | Shared Arrangements: practical inter-query sharing for streaming dataflowsabstractCurrent systems for data-parallel, incremental processing and view maintenance over high-rate streams isolate the execution of independent queries. This creates unwanted redundancy and overhead in the presence of concurrent incrementally maintained queries: each query must independently maintain the same indexed state over the same input streams, and new queries must build this state from scratch before they can begin to emit their first results. This paper introduces shared arrangements : indexed views of maintained state that allow concurrent queries to reuse the same in-memory state without compromising data-parallel performance and scaling. We implement shared arrangements in a modern stream processor and show order-of-magnitude improvements in query response time and resource consumption for incremental, interactive queries against high-throughput streams, while also significantly improving performance in other domains including business analytics, graph processing, and program analysis. Frank McSherry, Andrea Lattuada 0001, Malte Schwarzkopf, Timothy Roscoe |
Proc. VLDB Endow. | 4 |
| 2019 | A fork() in the roadabstractThe received wisdom suggests that Unix's unusual combination of fork() and exec() for process creation was an inspired design. In this paper, we argue that fork was a clever hack for machines and programs of the 1970s that has long outlived its usefulness and is now a liability. We catalog the ways in which fork is a terrible abstraction for the modern programmer to use, describe how it compromises OS implementations, and propose alternatives. Andrew Baumann, Jonathan Appavoo, Orran Krieger, Timothy Roscoe |
HotOS | 4 |
| 2019 | Megaphone: Latency-conscious state migration for distributed streaming dataflowsabstractWe design and implement Megaphone, a data migration mechanism for stateful distributed dataflow engines with latency objectives. When compared to existing migration mechanisms, Megaphone has the following differentiating characteristics: (i) migrations can be subdivided to a configurable granularity to avoid latency spikes, and (ii) migrations can be prepared ahead of time to avoid runtime coordination. Megaphone is implemented as a library on an unmodified timely dataflow implementation, and provides an operator interface compatible with its existing APIs. We evaluate Megaphone on established benchmarks with varying amounts of state and observe that compared to naïve approaches Megaphone reduces service latencies during reconfiguration by orders of magnitude without significantly increasing steady-state overhead. Moritz Hoffmann 0001, Andrea Lattuada 0001, Frank McSherry, Vasiliki Kalavri, John Liagouris, Timothy Roscoe |
Proc. VLDB Endow. | 6 |
| 2019 | Memory-Side Protection With a Capability Enforcement Co-ProcessorabstractByte-addressable nonvolatile memory (NVM) blends the concepts of storage and memory and can radically improve data-centric applications, from in-memory databases to graph processing. By enabling large-capacity devices to be shared across multiple computing elements, fabric-attached NVM changes the nature of rack-scale systems and enables short-latency direct memory access while retaining data persistence properties and simplifying the software stack. An adequate protection scheme is paramount when addressing shared and persistent memory, but mechanisms that rely on virtual memory paging suffer from the tension between performance (pushing toward large pages) and protection granularity (pushing toward small pages). To address this tension, capabilities are worth revisiting as a more powerful protection mechanism, but the long time needed to introduce new CPU features hampers the adoption of schemes that rely on instruction-set architecture support. This article proposes the Capability Enforcement Co-Processor (CEP), a programmable memory controller that implements fine-grain protection through the capability model without requiring instruction-set support in the application CPU. CEP decouples capabilities from the application CPU instruction-set architecture, shortens time to adoption, and can rapidly evolve to embrace new persistent memory technologies, from NVDIMMs to native NVM devices, either locally connected or fabric attached in rack-scale configurations. CEP exposes an application interface based on memory handles that get internally converted to extended-pointer capabilities. This article presents a proof of concept implementation of a distributed object store (Redis) with CEP. It also demonstrates a capability-enhanced file system (FUSE) implementation using CEP. Our proof of concept shows that CEP provides fine-grain protection while enabling direct memory access from application clients to the NVM, and that by doing so opens up important performance optimization opportunities (up to 4× reduction in latency in comparison to software-based security enforcement) without compromising security. Finally, we also sketch how a future hybrid model could improve the initial implementation by delegating some CEP functionality to a CHERI-enabled processor. Leonid Azriel, Lukas Humbel, Reto Achermann, Alex Richardson 0001, Moritz Hoffmann 0001, Avi Mendelson, Timothy Roscoe, Robert N. M. Watson, Paolo Faraboschi, Dejan S. Milojicic |
ACM Trans. Archit. Code Optim. | 7 |
| 2018 | Physical Addressing on Real Hardware in Isabelle/HOL
Reto Achermann, Lukas Humbel, David A. Cock, Timothy Roscoe |
ITP | 4 |
| 2018 | SnailTrail: Generalizing Critical Paths for Online Analysis of Distributed Dataflows
Moritz Hoffmann 0001, Andrea Lattuada 0001, John Liagouris, Vasiliki Kalavri, Desislava C. Dimitrova, Sebastian Wicki, Zaheer Chothia, Timothy Roscoe |
NSDI | 8 |
| 2018 | Three steps is all you need: fast, accurate, automatic scaling decisions for distributed streaming dataflows
Vasiliki Kalavri, John Liagouris, Moritz Hoffmann 0001, Desislava C. Dimitrova, Matthew Forshaw, Timothy Roscoe |
OSDI | 6 |
| 2017 | Online Reconstruction of Structural Information from Datacenter LogsabstractWell-run datacenter application architectures are heavily instrumented to provide detailed traces of messages and remote invocations. Reconstructing user sessions, call graphs, transaction trees, and other structural information from these messages, a process known as sessionization, is the foundation for a variety of diagnostic, profiling, and monitoring tasks essential to the operation of the datacenter. Zaheer Chothia, John Liagouris, Desislava C. Dimitrova, Timothy Roscoe |
EuroSys | 4 |
| 2017 | Separating Translation from Protection in Address Spaces with Dynamic RemappingabstractIt is time to reconsider memory protection. The emergence of large non-volatile main memories, scalable interconnects, and rack-scale computers running large numbers of small "micro services" creates significant challenges for memory protection based solely on MMU mechanisms. Central to this is a tension between protection and translation: optimizing for translation performance often comes with a cost in protection flexibility. Reto Achermann, Chris I. Dalton, Paolo Faraboschi, Moritz Hoffmann 0001, Dejan S. Milojicic, Geoffrey Ndu, Alex Richardson 0001, Timothy Roscoe, Adrian L. Shaw, Robert N. M. Watson |
HotOS | 8 |
| 2017 | Towards Correct-by-Construction Interrupt Routing on Real HardwareabstractIn this paper we address the problem of correctly configuring interrupts. The interrupt subsystem of a computer is increasingly complex: a zoo of different controllers with varying constraints and capabilities form a network with limited connectivity. An OS which aspires to provable correctness must manage a limited set of interrupt vectors, delegate interrupts to device drivers and configure the controllers correctly. No well-specified approach exists. Lukas Humbel, Reto Achermann, David A. Cock, Timothy Roscoe |
PLOS@SOSP | 4 |
| 2016 | SpaceJMP: Programming with Multiple Virtual Address SpacesabstractMemory-centric computing demands careful organization of the virtual address space, but traditional methods for doing so are inflexible and inefficient. If an application wishes to address larger physical memory than virtual address bits allow, if it wishes to maintain pointer-based data structures beyond process lifetimes, or if it wishes to share large amounts of memory across simultaneously executing processes, legacy interfaces for managing the address space are cumbersome and often incur excessive overheads. We propose a new operating system design that promotes virtual address spaces to first-class citizens, enabling process threads to attach to, detach from, and switch between multiple virtual address spaces. Our work enables data-centric applications to utilize vast physical memory beyond the virtual range, represent persistent pointer-rich data structures without special pointer representations, and share large amounts of memory between processes efficiently. Izzat El Hajj, Alex Merritt, Gerd Zellweger, Dejan S. Milojicic, Reto Achermann, Paolo Faraboschi, Wen-Mei W. Hwu, Timothy Roscoe, Karsten Schwan |
ASPLOS | 8 |
| 2016 | Customized OS support for data-processingabstractFor decades, database engines have found the generic interfaces offered by the operating systems at odds with the need for efficient utilization of hardware resources. As a result, most engines circumvent the OS and manage hardware directly. With the growing complexity and heterogeneity of modern hardware, database engines are now facing a steep increase in the complexity they must absorb to achieve good performance. Taking advantage of recent proposals in operating system design, such as multi-kernels, in this paper we explore the development of a light weight OS kernel tailored for data processing and discuss its benefits for simplifying the design and improving the performance of data management systems. Jana Giceva, Gerd Zellweger, Gustavo Alonso, Timothy Roscoe |
DaMoN | 4 |
| 2016 | Machine-Aware Atomic Broadcast Trees for Multicores
Stefan Kaestle, Reto Achermann, Roni Haecki, Moritz Hoffmann 0001, Sabela Ramos, Timothy Roscoe |
OSDI | 6 |
| 2016 | Explaining Outputs in Modern Data AnalyticsabstractWe report on the design and implementation of a general framework for interactively explaining the outputs of modern data-parallel computations, including iterative data analytics. To produce explanations, existing works adopt a naive backward tracing approach which runs into known issues; naive backward tracing may identify: (i) too much information that is difficult to process, and (ii) not enough information to reproduce the output, which hinders the logical debugging of the program. The contribution of this work is twofold. First, we provide methods to effectively reduce the size of explanations based on the first occurrence of a record in an iterative computation. Second, we provide a general method for identifying explanations that are sufficient to reproduce the target output in arbitrary computations -- a problem for which no viable solution existed until now. We implement our approach on differential dataflow , a modern high-throughput, low-latency dataflow platform. We add a small (but extensible) set of rules to explain each of its data-parallel operators, and we implement these rules as differential dataflow operators themselves. This choice allows our implementation to inherit the performance characteristics of differential dataflow, and results in a system that efficiently computes and updates explanatory inputs even as the inputs of the reference computation change. We evaluate our system with various analytic tasks on real datasets, and we show that it produces concise explanations in tens of milliseconds, while remaining faster -- up to two orders of magnitude -- than even the best implementations that do not support explanations. Zaheer Chothia, John Liagouris, Frank McSherry, Timothy Roscoe |
Proc. VLDB Endow. | 4 |
| 2016 | Arrakis: The Operating System Is the Control PlaneabstractRecent device hardware trends enable a new approach to the design of network server operating systems. In a traditional operating system, the kernel mediates access to device hardware by server applications to enforce process isolation as well as network and disk security. We have designed and implemented a new operating system, Arrakis, that splits the traditional role of the kernel in two. Applications have direct access to virtualized I/O devices, allowing most I/O operations to skip the kernel entirely, while the kernel is re-engineered to provide network and disk protection without kernel mediation of every operation. We describe the hardware and software changes needed to take advantage of this new abstraction, and we illustrate its power by showing improvements of 2 to 5 × in latency and 9 × throughput for a popular persistent NoSQL store relative to a well-tuned Linux implementation. Simon Peter 0001, Jialin Li 0001, Irene Zhang, Dan R. K. Ports, Doug Woos, Arvind Krishnamurthy, Thomas E. Anderson, Timothy Roscoe |
ACM Trans. Comput. Syst. | 8 |
| 2015 | Not Your Parents' Physical Address Space
Simon Gerber, Gerd Zellweger, Reto Achermann, Kornilios Kourtis, Timothy Roscoe, Dejan S. Milojicic |
HotOS | 5 |
| 2015 | Distributing the Data Plane for Remote Storage Access
Torsten Hoefler, Robert B. Ross, Timothy Roscoe |
HotOS | 3 |
| 2015 | Shoal: Smart Allocation and Replication of Memory For Parallel Programs
Stefan Kaestle, Reto Achermann, Timothy Roscoe, Tim Harris 0001 |
USENIX ATC | 3 |
| 2014 | Arrakis: The Operating System is the Control Plane
Simon Peter 0001, Jialin Li 0001, Irene Zhang, Dan R. K. Ports, Doug Woos, Arvind Krishnamurthy, Thomas E. Anderson, Timothy Roscoe |
OSDI | 8 |
| 2014 | Decoupling Cores, Kernels, and Operating Systems
Gerd Zellweger, Simon Gerber, Kornilios Kourtis, Timothy Roscoe |
OSDI | 4 |
| 2014 | Deployment of Query Plans on MulticoresabstractEfficient resource scheduling of multithreaded software on multicore hardware is difficult given the many parameters involved and the hardware heterogeneity of existing systems. In this paper we explore the efficient deployment of query plans over a multicore machine. We focus on shared query systems, and implement the proposed ideas using SharedDB. The goal of the paper is to explore how to deliver maximum performance and predictability, while minimizing resource utilization when deploying query plans on multicore machines. We propose to use resource activity vectors to characterize the behavior of individual database operators. We then present a novel deployment algorithm which uses these vectors together with dataflow information from the query plan to optimally assign relational operators to physical cores. Experiments demonstrate that this approach significantly reduces resource requirements while preserving performance and is robust across different server architectures. Jana Giceva, Gustavo Alonso, Timothy Roscoe, Tim Harris 0001 |
Proc. VLDB Endow. | 3 |
| 2013 | COD: Database / Operating System Co-Design
Jana Giceva, Tudor-Ioan Salomie, Adrian Schüpbach, Gustavo Alonso, Timothy Roscoe |
CIDR | 5 |
| 2013 | Application level ballooning for efficient server consolidationabstractSystems software like databases and language runtimes typically manage memory themselves to exploit application knowledge unavailable to the OS. Traditionally deployed on dedicated machines, they are designed to be statically configured with memory sufficient for peak load. In virtualization scenarios (cloud computing, server consolidation), however, static peak provisioning of RAM to applications dramatically reduces the efficiency and cost-saving benefits of virtualization. Unfortunately, existing memory "ballooning" techniques used to dynamically reallocate physical memory between VMs badly impact the performance of applications which manage their own memory. We address this problem by extending ballooning to applications (here, a database engine and Java runtime) so that memory can be efficiently and effectively moved between virtualized instances as the demands of each change over time. The results are significantly lower memory requirements to provide the same performance guarantees to a collocated set of VM running such applications, with minimal overhead or intrusive changes to application code. Tudor-Ioan Salomie, Gustavo Alonso, Timothy Roscoe, Kevin Elphinstone |
EuroSys | 3 |
| 2013 | We Need to Talk About NICs
Pravin Shinde, Antoine Kaufmann, Timothy Roscoe, Stefan Kaestle |
HotOS | 3 |
| 2013 | Modeling NICs with UnicornabstractNICs are increasingly complex and diverse, offering a wide range of hardware functionality to aid network protocol processing. Harnessing the power of NIC hardware requires the ability to control and reason about a variety of different feature sets in the network stack. Towards this goal, we propose Unicorn, a language for describing modern NICs. Unicorn offers a simple set of abstractions for modeling both NIC functionality and the state of a protocol stack. To evaluate its expressivity and potential, we present a non-trivial model for the Intel i82599 10GbE NIC, and an algorithm that uses graph embedding to optimize the use of NIC hardware in the network stack. Pravin Shinde, Antoine Kaufmann, Kornilios Kourtis, Timothy Roscoe |
PLOS@SOSP | 4 |
| 2012 | A Declarative Language Approach to Device ConfigurationabstractC remains the language of choice for hardware programming (device drivers, bus configuration, etc.): it is fast, allows low-level access, and is trusted by OS developers. However, the algorithms required to configure and reconfigure hardware devices and interconnects are becoming more complex and diverse, with the added burden of legacy support, “quirks,” and hardware bugs to work around. Even programming PCI bridges in a modern PC is a surprisingly complex problem, and is getting worse as new functionality such as hotplug appears. Existing approaches use relatively simple algorithms, hard-coded in C and closely coupled with low-level register access code, generally leading to suboptimal configurations. We investigate the merits and drawbacks of a new approach: separating hardware configuration logic (algorithms to determine configuration parameter values) from mechanism (programming device registers). The latter we keep in C, and the former we encode in a declarative programming language with constraint-satisfaction extensions. As a test case, we have implemented full PCI configuration, resource allocation, and interrupt assignment in the Barrelfish research operating system, using a concise expression of efficient algorithms in constraint logic programming. We show that the approach is tractable, and can successfully configure a wide range of PCs with competitive runtime cost. Moreover, it requires about half the code of the C-based approach in Linux while offering considerably more functionality. Additionally it easily accommodates adaptations such as hotplug, fixed regions, and “quirks.” Adrian Schüpbach, Andrew Baumann, Timothy Roscoe, Simon Peter 0001 |
ACM Trans. Comput. Syst. | 3 |
| 2011 | A declarative language approach to device configurationabstractC remains the language of choice for hardware programming (device drivers, bus configuration, etc.): it is fast, allows low-level access, and is trusted by OS developers. However, the algorithms required to configure and reconfigure hardware devices and interconnects are becoming more complex and diverse, with the added burden of legacy support, quirks, and hardware bugs to work around. Even programming PCI bridges in a modern PC is a surprisingly complex problem, and is getting worse as new functionality such as hotplug appears. Existing approaches use relatively simple algorithms, hard-coded in C and closely coupled with low-level register access code, generally leading to suboptimal configurations. Adrian Schüpbach, Andrew Baumann, Timothy Roscoe, Simon Peter 0001 |
ASPLOS | 3 |
| 2011 | SWissBox: An Architecture for Data Processing Appliances
Gustavo Alonso, Donald Kossmann, Timothy Roscoe |
CIDR | 3 |
| 2011 | Policy expressivity in the Anzere personal cloudabstractWe present a technique for partially replicating data items at scale according to expressive policy specifications. Recent projects have addressed the challenge of policy-based replication of personal data (photos, music, etc.) within a network of devices, as an alternative to centralized online services. To date, the policies supported by such systems have been relatively simple, in order to facilitate scaling the policy calculation to large numbers of items. Oriana Riva, Qin Yin, Dejan Juric, Ercan Ucan, Timothy Roscoe |
SoCC | 5 |
| 2011 | Mind the Gap: Reconnecting Architecture and OS Research
Jeffrey C. Mogul, Andrew Baumann, Timothy Roscoe, Livio B. Soares |
HotOS | 3 |
| 2011 | Dexferizer: A service for data transfer optimizationabstractWe present an approach to optimizing the transfer of data objects within a user's collection of computers and personal devices, subject to a variety of user-defined quality metrics such as cost, power consumption, and latency. By abstracting object transfer as a high-level service, and employing declarative networking techniques to cast object transfer as a constrained optimization problem, we show how to transparently exploit techniques as diverse as swarming and multi-hop transfer through virtual machines. Using a data replication system as a driving application, we demonstrate that our approach can easily accommodate flexible policies not easily implemented with existing solutions, and can thereby result in savings in time, power, bandwidth, or other costs. Ercan Ucan, Timothy Roscoe |
IWQoS | 2 |
| 2009 | Your computer is already a distributed system. Why isn't your OS?
Andrew Baumann, Simon Peter 0001, Adrian Schüpbach, Akhilesh Singhania, Timothy Roscoe, Paul Barham 0001, Rebecca Isaacs |
HotOS | 5 |
| 2009 | Rhizoma: A Runtime for Self-deploying, Self-managing Overlays
Qin Yin, Adrian Schüpbach, Justin Cappos, Andrew Baumann, Timothy Roscoe |
Middleware | 5 |
| 2009 | The multikernel: a new OS architecture for scalable multicore systemsabstractCommodity computer systems contain more and more processor cores and exhibit increasingly diverse architectural tradeoffs, including memory hierarchies, interconnects, instruction sets and variants, and IO configurations. Previous high-performance computing systems have scaled in specific cases, but the dynamic nature of modern client and server workloads, coupled with the impossibility of statically optimizing an OS for all workloads and hardware variants pose serious challenges for operating system structures. Andrew Baumann, Paul Barham 0001, Pierre-Évariste Dagand, Tim Harris 0001, Rebecca Isaacs, Simon Peter 0001, Timothy Roscoe, Adrian Schüpbach, Akhilesh Singhania |
SOSP | 7 |
| 2009 | Filet-o-Fish: practical and dependable domain-specific languages for OS developmentabstractWe address a persistent problem with using domain-specific languages to write operating systems: the effort of implementing, checking, and debugging the DSL usually outweighs any of its benefits. Because these DSLs generate C by templated string concatenation, they are tedious to write, fragile, and incompatible with automated verification tools. Pierre-Évariste Dagand, Andrew Baumann, Timothy Roscoe |
PLOS@SOSP | 3 |
| 2009 | Resource overbooking and application profiling in a shared Internet hosting platformabstractIn this article, we present techniques for provisioning CPU and network resources in shared Internet hosting platforms running potentially antagonistic third-party applications. The primary contribution of our work is to demonstrate the feasibility and benefits of overbooking resources in shared Internet platforms. Since an accurate estimate of an application's resource needs is necessary when overbooking resources, we present techniques to profile applications on dedicated nodes, possibly while in service, and use these profiles to guide the placement of application components onto shared nodes. We then propose techniques to overbook cluster resources in a controlled fashion. We outline an empirical appraoch to determine the degree of overbooking that allows a platform to achieve improvements in revenue while providing performance guarantees to Internet applications. We show how our techniques can be combined with commonly used QoS resource allocation mechanisms to provide application isolation and performance guarantees at run-time. We implement our techniques in a Linux cluster and evaluate them using common server applications. We find that the efficiency (and consequently revenue) benefits from controlled overbooking of resources can be dramatic. Specifically, we find that overbooking resources by as little as 1% we can increase the utilization of the cluster by a factor of two, and a 5% overbooking yields a 300--500% improvement, while still providing useful resource guarantees to applications. Bhuvan Urgaonkar, Prashant J. Shenoy, Timothy Roscoe |
ACM Trans. Internet Techn. | 3 |
| 2008 | Controlled, systematic, and efficient code replacement for running java programsabstractIn this paper we present PROSE, a system that performs reversible and systematic changes to running Java applications without requiring them to be shut down. PROSE is motivated by scenarios such as hotfixes, online program instrumentation and debugging, and evolution of critical legacy applications. In PROSE, changes to running applications are performed by replacing method bodies. To select which code to replace, PROSE supports matching based on both type information and regular expressions. New code can invoke the method it replaces, facilitating code evolution. Changes are composable, and may be reordered or selectively withdrawn at any time. Furthermore, the dynamic changes are expressed as Java classes rather than through an additional programming language. We describe the architecture of PROSE, the challenges of using aggressive inlining to achieve performance, and use standard benchmarks to demonstrate code performance comparable with, or better than, compile-time systems from the Aspect-Oriented Programming community. Angela Nicoara, Gustavo Alonso, Timothy Roscoe |
EuroSys | 3 |
| 2008 | 30 seconds is not enough!: a study of operating system timer usageabstractThe basic system timer facilities used by applications and OS kernels for scheduling timeouts and periodic activities have remained largely unchanged for decades, while hardware architectures and application loads have changed radically. This raises concerns with CPU overhead power management and application responsiveness. Simon Peter 0001, Andrew Baumann, Timothy Roscoe, Paul Barham 0001, Rebecca Isaacs |
EuroSys | 3 |
| 2008 | BFT Protocols Under Fire
Atul Singh, Tathagata Das, Petros Maniatis, Peter Druschel, Timothy Roscoe |
NSDI | 5 |
| 2007 | Public Health for the Internet (PHI)
Joseph M. Hellerstein, Tyson Condie, Minos N. Garofalakis, Boon Thau Loo, Petros Maniatis, Timothy Roscoe, Nina Taft |
CIDR | 6 |
| 2007 | Towards a Practical, Verified Kernel
Kevin Elphinstone, Gerwin Klein, Philip Derrin, Timothy Roscoe, Gernot Heiser |
HotOS | 4 |
| 2007 | Hype and Virtue
Timothy Roscoe, Kevin Elphinstone, Gernot Heiser |
HotOS | 1 |
| 2007 | R-OSGi: Distributed Applications Through Software Modularization
Jan S. Rellermeyer, Gustavo Alonso, Timothy Roscoe |
Middleware | 3 |
| 2007 | Friday: Global Comprehension for Distributed Replay
Dennis Geels, Gautam Altekar, Petros Maniatis, Timothy Roscoe, Ion Stoica |
NSDI | 4 |
| 2006 | Using queries for distributed monitoring and forensicsabstractDistributed systems are hard to build, profile, debug, and test. Monitoring a distributed system - to detect and analyze bugs, test for regressions, identify fault-tolerance problems or security compromises - can be difficult and error-prone. In this paper we argue that declarative development of distributed systems is well suited to tackle these tasks. We present an application logging, monitoring, and debugging facility that we have built on top of the P2 system, comprising an introspection model, an execution tracing component, and a distributed query processor. We use this facility to demonstrate a range of on-line distributed diagnosis tools that range from simple, local state assertions to sophisticated global property detectors on consistent snapshots. These tools are small, simple, and can be deployed piecemeal on-line at any point during a system's life cycle. Our evaluation suggests that the overhead of our approach to improving and monitoring running distributed systems continuously is well in tune with its benefits. Atul Singh, Petros Maniatis, Timothy Roscoe, Peter Druschel |
EuroSys | 3 |
| 2006 | The End of Internet Architecture
Timothy Roscoe |
HotNets | 1 |
| 2006 | Declarative networking: language, execution and optimizationabstractThe networking and distributed systems communities have recently explored a variety of new network architectures, both for application-level overlay networks, and as prototypes for a next-generation Internet architecture. In this context, we have investigated declarative networking: the use of a distributed recursive query engine as a powerful vehicle for accelerating innovation in network architectures [23, 24, 33]. Declarative networking represents a significant new application area for database research on recursive query processing. In this paper, we address fundamental database issues in this domain. First, we motivate and formally define the Network Datalog (NDlog) language for declarative network specifications. Second, we introduce and prove correct relaxed versions of the traditional semi-naïve query evaluation technique, to overcome fundamental problems of the traditional technique in an asynchronous distributed setting. Third, we consider the dynamics of network state, and formalize the iheventual consistencyl. of our programs even when bursts of updates can arrive in the midst of query execution. Fourth, we present a number of query optimization opportunities that arise in the declarative networking context, including applications of traditional techniques as well as new optimizations. Last, we present evaluation results of the above ideas implemented in our P2 declarative networking system, running on 100 machines over the Emulab network testbed. Boon Thau Loo, Tyson Condie, Minos N. Garofalakis, David E. Gay, Joseph M. Hellerstein, Petros Maniatis, Raghu Ramakrishnan 0001, Timothy Roscoe, Ion Stoica |
SIGMOD Conference | 8 |
| 2005 | The Architecture of PIER: an Internet-Scale Query Processor
Ryan Huebsch, Brent N. Chun, Joseph M. Hellerstein, Boon Thau Loo, Petros Maniatis, Timothy Roscoe, Scott Shenker, Ion Stoica, Aydan R. Yumerefendi |
CIDR | 6 |
| 2005 | A need for componentized transport protocolsabstractThere has been a steady stream of research over the years into componentized network protocols: protocol implementations assembled from a variety of building blocks. A promise of such frameworks has generally been flexibility: a protocol stack tailored for a particular application can be easily assembled, usually without writing any new code, by binding protocol objects together. Tyson Condie, Joseph M. Hellerstein, Petros Maniatis, Sean C. Rhea, Timothy Roscoe |
SOSP | 5 |
| 2005 | Implementing declarative overlaysabstractOverlay networks are used today in a variety of distributed systems ranging from file-sharing and storage systems to communication infrastructures. However, designing, building and adapting these overlays to the intended application and the target environment is a difficult and time consuming process.To ease the development and the deployment of such overlay networks we have implemented P2, a system that uses a declarative logic language to express overlay networks in a highly compact and reusable form. P2 can express a Narada-style mesh network in 16 rules, and the Chord structured overlay in only 47 rules. P2 directly parses and executes such specifications using a dataflow architecture to construct and maintain overlay networks. We describe the P2 approach, how our implementation works, and show by experiment its promising trade-off point between specification complexity and performance. Boon Thau Loo, Tyson Condie, Joseph M. Hellerstein, Petros Maniatis, Timothy Roscoe, Ion Stoica |
SOSP | 5 |
| 2004 | Operating Systems Support for Planetary-Scale Network Services
Andy C. Bavier, Mic Bowman, Brent N. Chun, David E. Culler, Scott Karlin, Steve Muir, Larry L. Peterson, Timothy Roscoe, Tammo Spalink, Michal Wawrzoniak |
NSDI | 8 |
| 2004 | Querying at Internet-ScaleabstractWe are developing a distributed query processor called PIER, which is designed to run on the scale of the entire Internet. PIER utilizes a Distributed Hash Table (DHT) as its communication substrate in order to achieve scalability, reliability, decentralized control, and load balancing. PIER enhances DHTs with declarative and algebraic query interfaces, and underneath those interfaces implements multihop, in-network versions of joins, aggregation, recursion, and query/result dissemination. PIER is currently being used for diverse applications, including network monitoring, keyword-based filesharing search, and network topology mapping. We will demonstrate PIER's functionality by showing system monitoring queries running on PlanetLab, a testbed of over 300 machines distributed across the globe. Brent N. Chun, Joseph M. Hellerstein, Ryan Huebsch, Shawn R. Jeffery, Boon Thau Loo, Sam Mardanbeigi, Timothy Roscoe, Sean C. Rhea, Scott Shenker, Ion Stoica |
SIGMOD Conference | 7 |
| 2004 | Handling Churn in a DHT (Awarded Best Paper!)
Sean C. Rhea, Dennis Geels, Timothy Roscoe, John Kubiatowicz |
USENIX ATC, General Track | 3 |
| 2003 | Palimpsest: Soft-Capacity Storage for Planetary-Scale Services
Timothy Roscoe, Steven Hand 0001 |
HotOS | 1 |
| 2002 | Resource Overbooking and Application Profiling in Shared Hosting Platforms
Bhuvan Urgaonkar, Prashant J. Shenoy, Timothy Roscoe |
OSDI | 3 |
| 1998 | Artefact: A Framework for Low-Overhead Web-Based Collaborative SystemsabstractThe Artefact framework is a tool for building collaborative applications that deliver = representations of art objectoriented appXcation space to standard browsers.We present some aspects of Artefact's implementation, including_ enhancements to support synchronous collaboration, the de-coup~ng of input and output in the interaction protocol, a lighhveight gened-purpose Java appleqand tie Wera~en~ that bridge the gap behveen a browser and an appficahon.We describe some of the characteristics that m&e it easy to create multi-user applications witi ArtefacL and illustrate WISwith a simple example application.Finally, we compare Artefact to some existing distributed application platforms. Jeffrey Lynn Brandenburg, Boyce Byerly, Tom Dobridge, Jinkun Lin, Dharmaraja Rajan, Timothy Roscoe |
CSCW | 6 |
| 1996 | The Design and Implementation of an Operating System to Support Distributed Multimedia ApplicationsabstractSupport for multimedia applications by general purpose computing platforms has been the subject of considerable research. Much of this work is based on an evolutionary strategy in which small changes to existing systems are made. The approach adopted is to start ab initio with no backward compatibility constraints. This leads to a novel structure for an operating system. The structure aims to decouple applications from one another and to provide multiplexing of all resources, not just the CPU, at a low level. The motivation for this structure, a design based on the structure, and its implementation on a number of hardware platforms is described. Ian M. Leslie, Derek McAuley, Richard Black, Timothy Roscoe, Paul Barham 0001, David Martin Evers, Robin Fairbairns, Eoin Hyden |
IEEE J. Sel. Areas Commun. | 4 |