Olaf Spinczyk

dblp:s/OlafSpinczyk · DBLP profile ↗
← Back
47ranked-venue papers
3as first author
5since 2021 · last 2026
0000-0001-9469-2367ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 21 · 2 first-author · 3 since 2021Systems, architecture and hardware · 13 · 2 since 2021Security and privacy · 10 · 1 since 2021Artificial intelligence and machine learning · 6 · 2 first-author · 1 since 2021Computer networks · 4Applied, interdisciplinary, general and emerging computing · 3 · 1 first-author
YearPublicationVenuePosition
2026 MxGPU: Efficient and safe communication between GPGPU applications in an OS-controlled GPGPU multiplexing environment
abstract
With the growing demand for artificial intelligence and other data-intensive applications, the demand for graphics processing units (GPUs) has also increased. Even though there are many approaches on multiplexing GPUs, none of the approaches known to us enable the operating system to coherently integrate GPU resources alongside CPU resources into a holistic resource management. Due to the history of GPUs, GPU drivers are still a large, isolated part within the driver stack of operating systems. This paper aims to conduct a case study on how a multiplexing solution for GPGPUs could look like, where the OS is able to define scheduling policies for GPGPU tasks and manage GPU memory. OS-controlled GPU memory management can especially be helpful for efficient and safe communication between GPGPU applications. We will discuss and evaluate the architecture of MxGPU , which offers software-based multiplexing of integrated Intel GPUs. MxGPU has a tiny code base, which is a precondition for formal verification approaches and usage in safety-critical environments. Experiments with our prototype show that MxGPU can grant the operating system control over GPU resources while allowing more GPU sessions. Furthermore, MxGPU allows for execution of GPGPU tasks with less latency compared to Linux and enables efficient and safe communication between GPU applications. • MxGPU has a source code complexity much lower compared to existing solutions. • MxGPU supports any number of GPU sessions as long as enough memory is available. • MxGPU allows the operating system manage GPU resources by defining scheduling policies and managing GPU memory. • MxGPU has less overhead than Linux.
Marcel Lütke Dreimann, Olaf Spinczyk
J. Syst. Archit.2
2025 Path Expressions Revisited - Towards Compiler-enforced Reusable Synchronization Patterns
abstract
Path expressions (PEs) offer a declarative way to specify synchronization constraints in concurrent programs, but have largely fallen out of favor due to concerns over limited expressiveness, runtime overhead, and poor integration with contemporary languages. In this work, we revisit PEs and argue for their renewed relevance as reusable synchronization patterns. We present a compiler-assisted approach that integrates PEs into C++ using AspectC++, enabling non-invasive synchronization of existing code. Our prototype demonstrates practical integration on a ring buffer and evaluates performance in a real-world concurrency scenario using MySQL's myisamchk utility. Results show that PE-based synchronization can be both expressive and efficient, performing comparably to traditional mechanisms in many cases. While challenges remain particularly around runtime adaptability and scaling under contention, our findings suggest that PEs deserve reconsideration as a practical tool for building reliable, maintainable concurrent software.
Thomas Alexander Hövelmann, Olaf Spinczyk, Alexander Krause 0003, Horst Schirmeier, Peter Ulbrich
PLOS@SOSP2
2023 Compiler-Implemented Differential Checksums: Effective Detection and Correction of Transient and Permanent Memory Errors
abstract
The detection of memory errors is common practice in safety-critical software, for example in the automotive and avionics industry. International safety standards recommend using checksums for protecting critical data in computer memories. Typical implementations verify the checksum before data access and recompute it after modification using the same algorithm. However, we show that this approach can sometimes dramatically worsen the reliability of computer systems with regard to transient memory faults, and also permanent faults remain undetected. A solution with significant conceptual advantages is constituted by differential checksum algorithms, which update the respective checksum without full recomputation on data modification. We present a compiler-based solution that inserts differential checksums into C/C++ data structures automatically to cope with their increased complexity. An extensive fault-injection campaign with the TACLeBench benchmark collection shows that differential checksums reduce silent data corruptions by 95% on average whereas non-differential checksums turn out to be mostly ineffective because they introduce a window of vulnerability.
Christoph Borchert, Horst Schirmeier, Olaf Spinczyk
DSN3
2022 Black-box models for non-functional properties of AI software systems
abstract
Non-functional properties (NFPs) such as latency, memory requirements, or hardware cost are an important characteristic of AI software systems, especially in the domain of resource-constrained embedded devices. Embedded AI products require sufficient resources for satisfactory latency and accuracy, but should also be cost-efficient and therefore not use more powerful hardware than strictly necessary. Traditionally, modeling and optimization efforts focus on the AI architecture, utilizing methods such as neural architecture search (NAS). However, before developers can start optimizing, they need to know which architectures are suitable candidates for their use case. To this end, architectures must be viewed in context: model post-processing (e.g. quantization), hardware platform, and run-time configuration such as batching all have significant effects on NFPs and therefore on AI architecture performance. Moreover, scalar parameters such as batch size cannot be benchmarked exhaustively. We argue that it is worthwhile to address this issue by means of black-box models before deciding on AI architectures for optimization and hardware/software platforms for inference. To support our claim, we present an AI product line with variable hardware and software components, perform benchmarks, and present notable results. Additionally, we evaluate both compactness and generalization capabilities of regression tree-based modeling approaches from the machine learning and product line engineering communities. We find that linear model trees perform best: they can capture NFPs of known AI configurations with a mean error of up to 13 %, and can predict unseen configurations with a mean error of 10 to 26 %. We find linear model trees to be more compact and interpretable than other tree-based approaches.
Birte Friesel, Olaf Spinczyk
CAIN2
2021 Decoupling Application Logic from Persistent Memory Frameworks with AspectC++
abstract
Over the past decade, various systems and software libraries have been developed that provide crash consistency on byte-addressable persistent memory. They often require programmers to adapt their code significantly or to use special compiler plugins. Constant innovation in this evolving field makes it desirable to be able to easily switch to more recent systems without massive code refactoring, and without changing compilers.
Marcel Köppen, Birte Friesel, Christoph Borchert, Olaf Spinczyk
PLOS@SOSP4
2020 Transformation- and Pattern-based State Machine Mining from Embedded C Code
Andreas Grosche, Burkhard Igel, Olaf Spinczyk
ICSOFT3
2020 From Global to Local Quiescence: Wait-Free Code Patching of Multi-Threaded Processes
Florian Rommel, Christian Dietrich 0001, Birte Friesel, Marcel Köppen, Christoph Borchert, Michael Müller 0009, Olaf Spinczyk, Daniel Lohmann
OSDI7
2019 LockDoc: Trace-Based Analysis of Locking in the Linux Kernel
abstract
For fine-grained synchronization of application and kernel threads, the Linux kernel provides a multitude of different locking mechanisms that are being used on various individually locked data structures. Understanding which locks are required in which order for a particular member variable of a kernel data structure has become truly difficult, even for Linux-kernel experts themselves.
Alexander Krause 0003, Horst Schirmeier, Hendrik Borghorst, Olaf Spinczyk
EuroSys4
2019 I2C considered wasteful: saving energy with host-controlled pull-up resistors: poster abstract
abstract
The Inter-Integrated Circuit (I2C) bus is frequently used to connect sensors and actuators to cyber-physical systems. It is designed around always-on pull-up resistors, which transform valuable electric energy into heat whenever a 0-signal is sent or received. Using a software I2C implementation which disables pull-ups when possible, we decrease the energy demand of I2C transmissions at the cost of additional CPU time. On a low-power MSP430FR5969 microcontroller, we observe 10 to 50 % lower whole-system energy usage per transmission compared to conventional software I2C. An advantage over hardware I2C modules is only apparent at bus clocks below 10 kHz.
Birte Friesel, Olaf Spinczyk
IPSN2
2019 High-Accuracy Software Fault Injection in Source Code with Clang
abstract
We present a novel method to inject software faults into source code, which is capable of operating on unpreprocessed C/C++ source code and can inject faults into source files, with as little modifications as possible. Tools that inject faults on lower levels, i.e. assembly or intermediate representation, suffer from limited accuracy regarding the emulated fault model. In contrast, our approach operates on source code and utilizes Clang AST Matchers to emulate faults as close to the model as possible. Additionally, we show how macros and other compile-time constructs, additional image modifications by other tools, and compiler optimization settings can have a negative impact on the validity of performed injection campaigns. Furthermore, we highlight some weaknesses in the description of the currently used fault models, which are based on the different injection levels and progress in the software development processes.
Ulrich Thomas Gabor, Daniel Ferdinand Siegert, Olaf Spinczyk
PRDC3
2019 Spectrum-Based Fault Localization in Deployed Embedded Systems with Driver Interaction Models
Ulrich Thomas Gabor, Simon Dierl, Olaf Spinczyk
SAFECOMP3
2019 Cache-Line Transactions: Building Blocks for Persistent Kernel Data Structures Enabled by AspectC++
abstract
With the availability of systems that contain large amounts of byte-addressable non-volatile memory (NVRAM), there is a growing need for data structures that can be mapped into a process's address space and be used without data (de-)serialization. While NVRAM is able to retain memory contents during system failure and power loss, data consistency has to be preserved by using transactional operations for data manipulation.
Marcel Köppen, Jana Traue, Christoph Borchert, Jörg Nolte, Olaf Spinczyk
PLOS@SOSP5
2017 On reducing busy waiting in autosar via task-release-delta-based runnable reordering
abstract
The increasing amount of innovative software technologies in the automotive domain comes with challenges regarding inevitable distributed multi-core and many-core methodologies. Approaches for general purpose solutions have been studied over decades but do not completely meet the specific constraints (e. g. timing, safety, reliability, affinity, etc.) for Autosar compliant applications. Autosar utilizes a spinlock mechanism in combination with the priority ceiling protocol in order to provide mutually exclusive access to shared resources. The essential disadvantages of spinlocks are unpredictable task response times on the one hand and wasted computation time caused by busy waiting periods on the other hand. In this paper, we propose a concept of task-release-delta-based runnable reordering for the purpose of sequentializing parallel accesses to shared resources, resulting in reduced task response times, improved timing predictability, and increased parallel efficiency respectively. To achieve this, runnables that represent smallest executable program parts in Autosar are reordered based on precedence constraints. Our experiments among industrial use cases show that task response times can be reduced by up to 18,2%.
Robert Hoettger, Burkhard Igel, Olaf Spinczyk
DATE3
2017 PhyNetLab: An IoT-Based Warehouse Testbed
abstract
Future warehouses will be made of modular embedded entities with communication ability and energy aware operation attached to the traditional materials handling and warehousing objects.This advancement is mainly to fulfill the flexibility and scalability needs of the emerging warehouses.However, it leads to a new layer of complexity during development and evaluation of such systems due to the multidisciplinarity in logistics, embedded systems, and wireless communications.Although each discipline provides theoretical approaches and simulations for these tasks, many issues are often discovered in a real deployment of the full system.In this paper we introduce PhyNetLab as a real scale warehouse testbed made of cyber physical objects (PhyNodes) developed for this type of application.The presented platform provides a possibility to check the industrial requirement of an IoT-based warehouse in addition to the typical wireless sensor networks tests.We describe the hardware and software components of the nodes in addition to the overall structure of the testbed.Finally, we will demonstrate the advantages of the testbed by evaluating the performance of the ETSI compliant radio channel access procedure for an IoT warehouse.
Robert Falkenberg, Mojtaba Masoudinejad, Markus Buschhoff, Aswin Karthik Ramachandran Venkatapathy, Birte Friesel, Michael ten Hompel, Olaf Spinczyk, Christian Wietfeld
FedCSIS7
2017 Annotations in Operating Systems with Custom AspectC++ Attributes
abstract
Aspect Oriented Programming (AOP) supports the modular implementation of crosscutting concerns, which are woven into program parts designated by pointcuts, e.g. calls to specific functions. The release of AspectC++ 2.2 introduces the ability to express pointcuts based on C++11-style attributes as well as the definition of custom attributes for annotation purposes. In this paper, we propose the use of such attributes for operating system development. We cover three examples: Replacing non-portable compiler attributes and extending portable ones with domain-specific knowledge, providing implementation-independent joinpoint APIs to core operating system functions, and compile-time support for co-development of source code and corresponding models. We discuss the implementation effort and code size overhead of our ideas on the operating systems CocoOS and RIOT and show that annotations with custom attributes are a helpful addition for system development.
Birte Friesel, Markus Buschhoff, Olaf Spinczyk
PLOS@SOSP3
2017 Evolutionary planning of virtualized cyber-physical compute and control clusters
Boguslaw Jablkowski, Ulrich Thomas Gabor, Olaf Spinczyk
J. Syst. Archit.3
2017 Generic Soft-Error Detection and Correction for Concurrent Data Structures
abstract
Recent studies indicate that transient memory errors (soft errors) have become a relevant source of system failures. This paper presents a generic software-based fault-tolerance mechanism that transparently recovers from memory errors in object-oriented program data structures. The main benefits are the flexibility to choose from an extensible toolbox of easily pluggable error detection and correction schemes, such as Hamming and CRC codes. This is achieved by a combination of aspect-oriented and generative programming techniques. Furthermore, we present a wait-free synchronization algorithm for error detection in data structures that are used concurrently by multiple threads of control. We give a formal correctness proof and show the excellent scalability of our approach in a multiprocessor environment. In a case study, we present our experiences with selectively hardening the eCos operating system and its benchmark suite. We explore the trade-off between resiliency and performance by choosing only the most vulnerable data structures for error recovery. Thereby, the total number of system failures, manifesting as silent data corruptions and crashes, is reduced by 69.14 percent at a negligible runtime overhead of 0.36 percent.
Christoph Borchert, Horst Schirmeier, Olaf Spinczyk
IEEE Trans. Dependable Secur. Comput.3
2015 Avoiding Pitfalls in Fault-Injection Based Comparison of Program Susceptibility to Soft Errors
abstract
Since the first identification of physical causes for soft errors in memory circuits, fault injection (FI) has grown into a standard methodology to assess the fault resilience of computer systems. A variety of FI techniques trying to mimic these physical causes has been developed to measure and compare program susceptibility to soft errors. In this paper, we analyze the process of evaluating programs, which are hardened by software-based hardware fault-tolerance mechanisms, under a uniformly distributed soft-error model. We identify three pitfalls in FI result interpretation widespread in the literature, even published in renowned conference proceedings. Using a simple machine model and transient single-bit faults in memory, we find counterexamples that reveal the unfitness of common practices in the field, and substantiate our findings with real-world examples. In particular, we demonstrate that the fault coverage metric must be abolished for comparing programs. Instead, we propose to use extrapolated absolute failure counts as a valid comparison metric.
Horst Schirmeier, Christoph Borchert, Olaf Spinczyk
DSN3
2015 Hardening an L4 microkernel against soft errors by aspect-oriented programming and whole-program analysis
abstract
Transient hardware faults in computer systems have become widespread as shrinking structures and low supply voltages reduce the amount of energy needed to trigger a fault. This paper describes the latest improvements of a software-based fault-tolerance mechanism called Generic Object Protection (GOP). It is based on Aspect-Orientied Programming in AspectC++ and has been used in a case study to harden the L4/Fiasco.OC microkernel. As a result, the improved GOP avoids 60% of kernel failures at an acceptable overhead of 19% code size and less than 1% runtime. The GOP improvements use static whole-program analysis and have been implemented in a prototypical manner. As an outlook, the paper presents envisioned language extensions providing whole-program control-flow and data-flow analyses in future AspectC++ versions.
Christoph Borchert, Olaf Spinczyk
PLOS@SOSP2
2015 Interfacing the hardware API with a feature-based operating system family
Matthias Meier, Mark Breddemann, Olaf Spinczyk
J. Syst. Archit.3
2014 A context-aware battery lifetime model for carrier aggregation enabled LTE-A systems
abstract
A Quality of Experience (QoE) parameter of increasing importance is the time that a battery powered communication device (e.g. smartphone) can be operated before it needs to be recharged. However, due to the fact that battery capacity is not evolving as fast as the power requirement, the battery lifetime of modern user equipment is stagnating or even decreasing from one device generation to another. In parallel, a major challenge for the design of next generation wireless systems such as LTE-Advanced (LTE-A) is that the required high portion of spectrum is not available in a consecutive portion. For this reason, a procedure called interband non-continuous Carrier Aggregation (CA) will be introduced in LTE-A which allows for the combination of multiple spectrum pieces from different frequency bands. This procedure however requires the parallel operation of multiple power amplifiers that are characterized by a high energy demand. In this paper, we quantify the impact of CA on the power consumption of LTE-A enabled communication by means of a Markovian based power consumption model that incorporates system parameters as well as context parameters. The results show that the suitability of CA does from a battery lifetime perspective strongly depend upon the actual device characteristics as well as the resource availability is the various frequency bands. Furthermore, the application of the sophisticated Kinetic Battery Model (KiBaM) shows that the charge recovery effect during idle periods does significantly affect the battery lifetime.
Bjoern Dusza, Peter Marwedel, Olaf Spinczyk, Christian Wietfeld
CCNC3
2014 Crosscheck: Hardening Replicated Multithreaded Services
abstract
State-machine replication has received widespread attention for the provisioning of highly available services in data centers. However, current production systems focus on tolerating crash faults only and prominent service outages caused by state corruptions have indicated that this is a risky strategy. In the future, state corruptions due to transient faults (such as bit flips) become even more likely, caused by ongoing hardware trends regarding the shrinking of structure sizes and reduction of operating voltages. In this paper we present Crosscheck, an approach to tolerate arbitrary state corruption (ASC) in the context of fault-tolerant replication of multithreaded services. Crosscheck is able to detect silent data corruptions ahead of execution, and by crosschecking state changes with co-executing replicas, even ASCs can be detected. Finally, fault tolerance is achieved by a fine-grained recovery using fault-free replicas. Our implementation is transparent to the application by utilizing fine-grained software-hardening mechanisms using aspect-oriented programming. To validate Crosscheck we present a replicated multithreaded key-value store that is resilient to state corruptions.
Arthur Martens, Christoph Borchert, Tobias Oliver Geissler, Daniel Lohmann, Olaf Spinczyk, Rüdiger Kapitza
DSN5
2014 Smart-hopping: Highly efficient ISA-level fault injection on real hardware
abstract
Fault-injection experiments on the instruction-set architecture level are commonly used to analyze embedded software's susceptibility to hardware faults, typically involving a vast number of experiments with systematically varying fault locations and times. Determinism and high performance are the predominant requirements on fault-injection platforms. Injecting faults into a real embedded hardware platform instead of a simulator is favorable for both workload execution speed and result accuracy. The most performance-critical part of such a fault-injection platform is the “fast forward” operation, which executes the target machine code without faults until the exact dynamic instruction is reached at which the execution must be stopped to inject the next fault. Unfortunately, most embedded CPUs do not support this operation efficiently. In this paper we present an approach that speeds up fast-forwarding significantly for most workloads with minimal requirements on hardware support. Based on a previously recorded instruction trace — which is needed for systematic fault-injection experiment planning anyways — we use standard debugging hardware to advance to a chosen point in program execution with a minimal number of steps. We evaluate our FAIL∗ tool platform with two MiBench benchmark categories, and improve experiment throughput by up to several magnitudes compared to similar fault-injection tools in the field.
Horst Schirmeier, Lars Rademacher, Olaf Spinczyk
ETS3
2014 Analysis of communication networks for smart substations using a virtualized execution platform
abstract
The current development of the power grid towards a Smart Grid advances the complexity of the system, involving active control, new software components and large amounts of data. This, in turn, requires new approaches for the ICT infrastructure to guarantee real-time capability and reliability. In this work, we present our design of a novel infrastructure for smart substations in the transmission grid, applying the concept of virtualization to substation devices. Since virtualization has already been successfully applied for fault-tolerant and dependable computer systems, it promises to be a valuable concept for substation automation. However, virtualization poses additional challenges to the real-time capability of the substation infrastructure in terms of additional traffic and resource allocation. For analysing the impact on substation communication, we apply simulations and the analytical technique Network Calculus to provide guarantees on the performance of the proposed communication infrastructure. In addition, the performance of the execution platform is studied empirically, measuring occurring delays in a test-bed set-up. Finally, we combine the results from both evaluations to derive an end-to-end delay bound for a power grid related example. Our results show that, other than Fast Ethernet, Gigabit Ethernet networks can guarantee the secure operation of virtualized, fault-tolerant substation infrastructures.
Nils Dorsch, Boguslaw Jablkowski, Hanno Georg, Olaf Spinczyk, Christian Wietfeld
ICC4
2014 Effectiveness of Fault Detection Mechanisms in Static and Dynamic Operating System Designs
abstract
Developers of embedded (real-time) systems can choose from a variety of operating systems. While some embedded operating systems provide very flexible APIs, e.g., a POSIX-compliant interface for run-time management, others have a completely static structure, which is generated at compile time by utilizing detailed application knowledge. A prominent example for the latter class from the domain of automotive operating systems is OSEK/OS and its successor AUTOSAR/OS. As we have shown in previous work, the design of the operating system has a strong impact on its vulnerability for system failure caused by hardware faults. This observation is gaining importance, because there is an ongoing trend towards low-power and low-cost, yet less reliable, hardware. This work quantifies the difference in vulnerability for soft errors in main memory of a flexible (dynamic) operating systems (eCos) and a static system (CiAO), which has an OSEK-compliant structure. We also analyze the additional degree of robustness that is achieved by hardening an operating system with software-based and hardware-based fault-tolerance measures and the corresponding costs. Covering this design space gives developers a better chance for good design decisions with respect to the trade-off between fault tolerance, resource consumption, and interface convenience. Our results indicate that with a combination of hardware- and software-based fault-tolerance measures, silent data corruptions in both operating systems can be reduced to below one percent (compared to eCos). However, the analyzed fault-tolerance mechanisms are expensive for the dynamic system, whereas the statically designed operating system can be hardened at much lower price.
Martin Hoffmann 0001, Christoph Borchert, Christian Dietrich 0001, Horst Schirmeier, Rüdiger Kapitza, Olaf Spinczyk, Daniel Lohmann
ISORC6
2014 Rapid Fault-Space Exploration by Evolutionary Pruning
Horst Schirmeier, Christoph Borchert, Olaf Spinczyk
SAFECOMP3
2013 Generative software-based memory error detection and correction for operating system data structures
abstract
Recent studies indicate that the number of system failures caused by main memory errors is much higher than expected. In contrast to the commonly used hardware-based countermeasures, for example using ECC memory, software-based fault-tolerance measures are much more flexible and can exploit application knowledge, such as the criticality of specific data structures. This paper presents a software-based memory error protection approach, which we used to harden the eCos operating system in a case study. The main benefits of our approach are the flexibility to choose from an extensible toolbox of easily pluggable error detection and correction schemes as well as its very low runtime overhead, which totals in a range of 0.09-1.7 %. The implementation is based on aspect-oriented programming and exploits the object-oriented program structure of eCos to identify well-suited code locations for the insertion of generative fault-tolerance measures.
Christoph Borchert, Horst Schirmeier, Olaf Spinczyk
DSN3
2012 A unified approach for online and offline estimation of sensor platform energy consumption
abstract
To minimize the power consumption of energy-constrained systems, energy-models are used to make design decisions and to optimize program code. Usually, energy models for design- or compile-time decisions, which we call offline models, can become very complex. In this article we describe a method to create offline models, which can be simplified in a way that allows the models to be used even at run-time. This allows dynamic resource management, by postponing decisions about resource utilization to the running system. The simplified models remain exact for the pre-defined usage and software scenarios. This makes it possible to create components that are self-describing in their resource consumption for different environmental situations, while the complex offline models stay reusable.
Markus Buschhoff, Christian Günter, Olaf Spinczyk
IWCMC3
2012 CiAO/IP: a highly configurable aspect-oriented IP stack
abstract
Internet protocols are constantly gaining relevance for the domain of mobile and embedded systems. However, building complex network protocol stacks for small resource-constrained devices is more than just porting a reference implementation. Due to the cost pressure in this area especially the memory footprint has to be minimized. Therefore, embedded TCP/IP implementations tend to be statically configurable with respect to the concrete application scenario. This paper describes our software engineering approach for building CiAO/IP - a tailorable TCP/IP stack for small embedded systems, which pushes the limits of static configurability while retaining source code maintainability. Our evaluation results show that CiAO/IP thereby outperforms both lwIP and uIP in terms of code size (up to 90% less than uIP), throughput (up to 20% higher than lwIP), energy consumption (at least 40% lower than uIP) and, most importantly, tailorability.
Christoph Borchert, Daniel Lohmann, Olaf Spinczyk
MobiSys3
2011 Revisiting Fault-Injection Experiment-Platform Architectures
abstract
Many years of research on dependable, fault-tolerant software systems yielded a myriad of tool implementations for vulnerability analysis and experimental validation of resilience measures. Trace recording and fault injection are among the core functionalities these tools provide for hardware debuggers or system simulators, partially including some means to automate larger experiment campaigns. We argue that current fault-injection tools are too highly specialized for specific hardware devices or simulators, and are developed in poorly modularized implementations impeding evolution and maintenance. In this article, we present a novel design approach for a fault-injection infrastructure that allows experimenting researchers to switch simulator or hardware back ends with little effort, fosters experiment code reuse, and retains a high level of maintainability.
Horst Schirmeier, Martin Hoffmann 0001, Rüdiger Kapitza, Daniel Lohmann, Olaf Spinczyk
PRDC5
2011 RAMpage: Graceful Degradation Management for Memory Errors in Commodity Linux Servers
abstract
Memory errors are a major source of reliability problems in current computers. Undetected errors may result in program termination, or, even worse, silent data corruption. Recent studies have shown that the frequency of permanent memory errors is an order of magnitude higher than previously assumed and regularly affects everyday operation. Often, neither additional circuitry to support hardware-based error detection nor downtime for performing hardware tests can be afforded. In the case of permanent memory errors, a system faces two challenges: detecting errors as early as possible and handling them while avoiding system downtime. To increase system reliability, we have developed RAMpage, an online memory testing infrastructure for commodity x86-64-based Linux servers, which is capable of efficiently detecting memory errors and which provides graceful degradation by withdrawing affected memory pages from further use. We describe the design and implementation of RAMpage and present results of an extensive qualitative as well as quantitative evaluation.
Horst Schirmeier, Jens Neuhalfen, Ingo Korb, Olaf Spinczyk, Michael Engel
PRDC4
2010 Approaching Non-functional Properties of Software Product Lines: Learning from Products
abstract
Approaching the configuration of non-functional properties (NFPs) in traditional software systems is not an easy task, addressing the configuration of these properties in software product lines (SPLs) imposes even further challenges. Therefore, we have devised the Feedback Approach, which extends the traditional SPL development techniques in order to improve the configuration of NFPs. In this work we present the general guidelines of our approach and also we show the feasibility of the idea by presenting a case study using the Linux Kernel.
Julio Sincero, Wolfgang Schröder-Preikschat, Olaf Spinczyk
APSEC3
2010 LavA: An Open Platform for Rapid Prototyping of MPSoCs
abstract
Configurable hardware is becoming increasingly powerful and less expensive. This allows embedded system developers to exploit hardware parallelism in order to improve real time properties and energy efficiency. However, hardware design, even if performed using high-level hardware description languages, is error-prone and time consuming, especially when designing complex heterogeneous multiprocessor systems. To reduce the time to market for such systems, it is necessary to support the designer with a flexible workflow and methods for efficient reuse of existing components. In software engineering, this is enabled by using model-driven design flows and tools for configuration. In this paper, we describe LavA, a system which adapts these concepts to hardware design. By providing a streamlined toolchain and workflow to rapidly prototype complex, heterogeneous multiprocessor systems-on-chip based on a model-driven approach, developers can reduce turnaround times in design as well as design space exploration.
Matthias Meier, Michael Engel, Matthias Steinkamp, Olaf Spinczyk
FPL4
2010 AspectC++: An integrated approach for static and dynamic adaptation of system software
Reinhard Tartler, Daniel Lohmann, Fabian Scheler, Olaf Spinczyk
Knowl. Based Syst.4
2009 Dynamic AspectC++: Generic Advice at Any Time
abstract
In theory, the expressive power of an aspect language should be independent of the aspect deployment approach, whether it is static or dynamic weaving. However, in the area of strictly statically typed and compiled languages, such as C or C++, there seems to be a feedback from the weaver implementation to the language level: dynamic aspect languages offer noticeable fewer features than their static counterparts. Especially means for generic aspect implementations are missing, as they are very difficult to implement in dynamic weavers. This hinders reusability of aspects and the application of AOP to scenarios where both, runtime and compile-time adaptation is required. Our solution to overcome these limitations is based on a novel combination of static and dynamic weaving techniques, which facilitates the support of typical static language features, such as generic advice, in dynamic weavers for compiled languages. In our implementation, the same AspectC++ aspect code can now be woven statically or dynamically into the Squid web proxy, providing flexibility and best of bread for many AOP-based adaptation scenarios.
Reinhard Tartler, Daniel Lohmann, Wolfgang Schröder-Preikschat, Olaf Spinczyk
SoMeT4
2009 CiAO: An Aspect-Oriented Operating-System Family for Resource-Constrained Embedded Systems
Daniel Lohmann, Wanja Hofer, Wolfgang Schröder-Preikschat, Jochen Streicher, Olaf Spinczyk
USENIX ATC5
2007 Aspectizing a Web Server for Adaptation
abstract
Web servers are exposed to extremely changing runtime requirements. Going offline to adjust policies and configuration parameters in order to cope with such requirements is not an available choice for long running Web servers. Many of the policies that need to be adapted are crosscutting in nature. Aspect-oriented programming (AOP) provides mechanisms to encapsulate the crosscutting policies as aspects. This paper describes the integration of a statically configurable Web server with our dynamic aspect weaving infrastructure. This integration transformed the server to a dynamically adaptable one that could adjust its policies and configuration parameters at runtime according to the changing requirements. This paper further provides a comprehensive analysis of the memory and runtime costs associated with this transformation, and explains how our dynamic aspect weaving infrastructure via its tailored support facilitates to minimise these costs.
Wasif Gilani, Julio Sincero, Olaf Spinczyk, Wolfgang Schröder-Preikschat
ISCC3
2007 Configurable memory protection by aspects
abstract
We describe the implementation of memory protection by means of aspect-oriented programming (AOP) in CiAO, an AUTOSAR-like family of embedded operating systems. The use of AOP was originally motivated by the fact that memory protection is a cross-cutting policy, which, furthermore, has to be configurable at build-time in AUTOSAR. We learned, however, that besides switching between full protection and no protection, an AOP-based approach also makes it easy to apply completely different models of protection. For the domain of statically configured embedded systems, where certain failure scenarios can often be excluded by means of code analysis or even probability, this facilitates tailored and light-weight "pay-as-you-use" protection strategies.
Daniel Lohmann, Jochen Streicher, Wanja Hofer, Olaf Spinczyk, Wolfgang Schröder-Preikschat
PLOS@SOSP4
2007 Tailoring Infrastructure Software Product Lines by Static Application Analysis
abstract
Besides ordinary applications, also infrastructure software such as operating systems or database management systems is being developed as a software product line. With proper tool support these systems can be configured easily by selecting features in a feature model. However, in the future multi-level architectures of layered product lines will be common practice. For humans the feature-based configuration will become increasingly complex, as the number of configurable features will be tremendous. Our goal is to reduce this complexity. The approach is based on the observation that many configuration decisions could be automated by statically analyzing the code of layers on top of an infrastructure product line. Motivated by use cases the paper presents the concepts behind our analysis tool, which is able to automate the configuration in many cases. First results in the context of a feature-oriented version of the Berkeley DB illustrate the potential of this novel approach.
Horst Schirmeier, Olaf Spinczyk
SPLC2
2007 The design and implementation of AspectC++
Olaf Spinczyk, Daniel Lohmann
Knowl. Based Syst.1
2006 Linguistic support for modern operating systems workshop on programming languages and operating systems 2006 (PLOS 2006)
abstract
This report gives an overview over the Workshop on Programming Languages and Operating Systems (PLOS 2006), which was colocated with ASPLOS XII. It introduces the motivation for the work-shop and gives a summary of the workshop contributions.
Christian W. Probst, Andreas Gal, Robert Grimm 0001, Olaf Spinczyk
PLOS4
2006 A quantitative analysis of aspects in the eCos kernel
abstract
Nearly ten years after its first presentation and five years after its first application to operating systems, the suitability of Aspect-Oriented Programming (AOP) for the development of operating system kernels is still highly in dispute. While the AOP advocacy emphasizes the benefits of AOP towards better configurability and maintainability of system software, most kernel developers express a sound skepticism regarding the thereby induced runtime and memory costs: Operating system kernels have to be lean and efficient.We have analyzed the runtime and memory costs of aspects in general, on the level of μ-benchmarks, and by refactoring and extending the eCos operating system kernel using AspectC++, an AOP extension to the C++ language. Our results show that most AOP features do not induce a intrinsic overhead and that the actual overhead induced by AspectC++ is very low. We have also analyzed a test case with significant aspect-related costs. This example shows how the structure of the underlying kernel can have a negative impact on aspect implementations and how these costs can be avoided by an aspect-aware design.Based on this analysis, our conclusion is that AOP is suitable for the development of operating system kernels and other kinds of highly efficient infrastructure software.
Daniel Lohmann, Fabian Scheler, Reinhard Tartler, Olaf Spinczyk, Wolfgang Schröder-Preikschat
EuroSys4
2006 Using Feature Models for Product Derivation
abstract
In general the implementation of a software product line leads to a high degree of variability within the software architecture. For an effective development and deployment it is necessary to resolve variation points within the architecture and source code automatically during product/variant derivation. Given the complexity of most software systems tool support is necessary for these tasks.
Olaf Spinczyk, Holger Papajewski
SPLC1
2005 Advances in AOP with AspectC++
Olaf Spinczyk, Daniel Lohmann
SoMeT1
2004 Generic Advice: On the Combination of AOP with Generative Programming in AspectC++
Daniel Lohmann, Georg Blaschke, Olaf Spinczyk
GPCE3
2000 On Interrupt-Transparent Synchronization in an Embedded Object-Oriented Operating System
abstract
A crucial aspect in the design of (embedded real-time) operating systems concerns interrupt handling. This paper presents the concept of a modularized interrupt-handling subsystem that enables the synchronization of interrupt-driven, non-sequential code without the need to disabling hardware interrupts. The basic idea is to use nonblocking/optimistic concurrency sequences for synchronization inside an operating-system kernel. Originally designed for the PURE embedded operating system, the presented object-oriented implementation is highly portable not only regarding the CPU but also operating systems and yet efficient.
Friedrich Schön, Wolfgang Schröder-Preikschat, Olaf Spinczyk, Ute Spinczyk
ISORC3
1999 The PURE Family of Object-Oriented Operating Systems for Deeply Embedded Systems
abstract
Deeply embedded systems are forced to operate under extreme resource constraints in terms of memory, CPU, time and power consumption. Automotive systems are a typical example: today's limousines can be considered as (large-scale) distributed systems on wheels. There are cars in daily operation consisting of over 60 networked processors (i.e. microcontrollers). Conservative estimations suggest that, in the near future, every car will be equipped with about 20 networked microcontrollers, on average. The complexity of these "decentralized computer architectures" can no longer be managed by the application alone. Dedicated embedded operating systems are required to ensure the manageability, adaptability, portability and efficiency of the software. Resource-sparing operations under (hard) real-time constraints must be the maxim. This paper discusses the design and implementation of PURE (Portable Universal Runtime Executive) for these classes of deeply embedded systems.
Danilo Beuche, Abdelaziz Guerrouat, Holger Papajewski, Wolfgang Schröder-Preikschat, Olaf Spinczyk, Ute Spinczyk
ISORC5