Ksplice: Automatic Rebootless Kernel Updates
Name
2E677D25d01.pdf
Size
392.9 KB
Format
Adobe PDF
Checksum (MD5)
7435061ce5c705d37f28f6d88ecca4e7
Author(s) •
Kaashoek, M. Frans
Arnold, Jeffrey B.
Date Issued
2009
Journal
Proceedings of the 4th ACM European conference on Computer systems
Publisher
Association for Computing Machinery
Citation
Arnold, Jeff, and M. Frans Kaashoek. “Ksplice: automatic rebootless kernel updates.” Proceedings of the 4th ACM European conference on Computer systems. Nuremberg, Germany: ACM, 2009. 187-198.
Version
Author's final manuscript
Abstract
Ksplice allows system administrators to apply patches to their operating system kernels without rebooting. Unlike previous hot update systems, Ksplice operates at the object code layer, which allows Ksplice to transform many traditional source code patches into hot updates with little or no programmer involvement. In the common case that a patch does not change the semantics of persistent data structures, Ksplice can create a hot update without a programmer writing any new code.
Security patches are one compelling application of hot updates. An evaluation involving all significant x86-32 Linux security patches from May 2005 to May 2008 finds that most security patches-56 of 64-require no new code to be performed as a Ksplice update. In other words, Ksplice can correct 88% of the Linux kernel vulnerabilities from this interval without the need for rebooting and without writing any new code.
If a programmer writes a small amount of new code to assist with the remaining patches (about 17 lines per patch, on average), then Ksplice can apply all 64 of the security patches from this interval without rebooting.
MIT Department
Massachusetts Institute of Technology. Computer Science and Artificial Intelligence Laboratory
Massachusetts Institute of Technology. Department of Electrical Engineering and Computer Science
Terms of Use
Article is made available in accordance with the publisher's policy and may be subject to US copyright law. Please refer to the publisher's site for terms of use.
Persistent DSpace Link
DOI of Published Version
http://dx.doi.org/10.1145/1519065.1519085