Adding operating system structure to language-based protection

Thorsten von Eicken, Chris Hawblitzel · 2000

Extensible Internet applications increasingly rely on language safety for protection, rather than using protection mechanisms based on virtual memory. For example, the Java language now provides protection for applets, servlets, agents and active networks. Unfortunately, typical safe language systems do not have the support for resource control, revocation, and on-demand program termination present in traditional operating systems. Naive attempts to add these features to a language can easily backfire: Sun recently deprecated Java's thread termination methods because of subtle interactions with Java's synchronization and abstraction mechanisms. In this thesis, I argue that these problems arise from a lack of clear structure in safe language systems. Often, these systems allow objects, threads, and code to pass freely from one program to another, blurring the boundaries between programs. To restore the boundaries, I introduce the idea of a safe language task that encapsulates a program's objects, threads, and code, and I argue that a system based on the task model can provide strong and simple guarantees about resource control, thread management, termination, revocation, and whole-program optimization. I present two implementations of the task model: the J-Kernel, which uses Java remote method invocation for inter-task communication, and Luna, which extends Java's type system to express the task model directly.

Read the paper · More papers on PaperTik