We report on the formal, machine-checked verification of microkernel from an abstract specification down to its C implementation. We assume correctness of compiler, assembly code,...
Gerwin Klein, June Andronick, Kevin Elphinstone, G...
with a full abstract specification of the data-types involved and a multi-level architecture similar to that of a DBMS. A related question is the kind of model that is most suitabl...