skip to main content
10.1145/1926385.1926398acmconferencesArticle/Chapter ViewAbstractPublication PagespoplConference Proceedingsconference-collections

Static analysis of interrupt-driven programs synchronized via the priority ceiling protocol

Published: 26 January 2011 Publication History


We consider programs for embedded real-time systems which use priority-driven preemptive scheduling with task priorities adjusted dynamically according to the immediate ceiling priority protocol. For these programs, we provide static analyses for detecting data races between tasks running at different priorities as well as methods to guarantee transactional execution of procedures. Beyond that, we demonstrate how general techniques for value analyses can be adapted to this setting by developing a precise analysis of affine equalities.

Supplementary Material

MP4 File (10-mpeg-4.mp4)


C. Artho, K. Havelund, and A. Biere. Using block-local atomicity to detect stale-value concurrency errors. In ATVA'04, vol. 3299 of LNCS, pp. 150--164. Springer, 2004.
M. F. Atig, A. Bouajjani, and T. Touili. Analyzing asynchronous programs with preemption. In FSTTCS'08, vol. 2 of LIPIcs, pp. 37--48. Schloss Dagstuhl, 2008.
Autosar consortium. Autosar Architecture Specification, Release 4.0, 2009. URL
T. P. Baker. Stack-based scheduling of realtime processes. Real-Time Systems, 3(1):67--99, 1991.
A. Bouajjani, M. Müller-Olm, and T. Touili. Regular symbolic analysis of dynamic networks of pushdown systems. In CONCUR'05, vol. 3653 of LNCS, pp. 473--487. Springer, 2005.
P. Cousot and R. Cousot. Comparing the Galois connection and widening/narrowing approaches to abstract interpretation, invited paper. In PLILP'92, pp. 269--295. Springer, 1992.
B. Dutertre. Formal analysis of the priority ceiling protocol. In RTSS'00, pp. 151--160. IEEE Press, 2000.
J. Esparza and A. Podelski. Efficient algorithms for pre* and post* on interprocedural parallel flow graphs. In POPL'00, pp. 1--11. ACM Press, 2000.
C. Fecht and H. Seidl. A Faster Solver for General Systems of Equations. Sci. Comput. Programming, 35(2):137--161, 1999.
C. Flanagan, S. N. Freund, S. Qadeer, and S. A. Seshia. Modular verification of multithreaded programs. Theoretical Comput. Sci., 338 (1--3):153--183, 2005.
C. Flanagan, S. N. Freund, M. Lifshin, and S. Qadeer. Types for atomicity: Static checking and inference for java. ACM Trans. Prog. Lang. Syst., 30(4):1--53, 2008.
M. S. Hecht. Flow Analysis of Computer Programs. Elsevier, 1977.
T. Henties, J. J. Hunt, D. Locke, K. Nilsen,M. Schoeberl, and J. Vitek. Java for safety-critical applications. In SafeCert'09, ENTCS. Elsevier, 2010.
V. Kahlon and A. Gupta. On the analysis of interacting pushdown systems. In POPL'07, pp. 303--314. ACM Press, 2007.
V. Kahlon, F. Ivančić, and A. Gupta. Reasoning about threads communicating via locks. In CAV'05, vol. 3576 of LNCS, pp. 505--518. Springer, 2005.
V. Kahlon, Y. Yang, S. Sankaranarayanan, and A. Gupta. Fast and accurate static data-race detection for concurrent programs. In CAV'07, vol. 4590 of LNCS, pp. 226--239. Springer, 2007.
N. Kidd, P. Lammich, T. Touili, and T. Reps. A decision procedure for detecting atomicity violations for communicating processes with locks. In SPIN'09, vol. 5578 of LNCS, pp. 125--142. Springer, 2009.
N. Kidd, S. Jagannathan, and J. Vitek. One stack to run them all reducing concurrent analysis to sequential analysis under priority scheduling. In SPIN'10, vol. 6349 of LNCS, pp. 245--261. Springer, 2010.
P. Lammich and M. Müller-Olm. Conflict analysis of programs with procedures, dynamic thread creation, and monitors. In SAS'08, vol. 5079 of LNCS, pp. 205--220. Springer, 2008.
P. Lammich, M. Müller-Olm, and A. Wenner. Predecessor sets of dynamic pushdown networks with Tree-Regular constraints. In CAV'09, vol. 5643 of LNCS, pp. 525--539. Springer, 2009.
M. Müller-Olm and H. Seidl. Precise interprocedural analysis through linear algebra. In POPL'04, pp. 330--341. ACM Press, 2004.
OSEK/VDX Group. OSEK/VDX Operating System Specification, Version 2.2.3, 2005. URL
M. Pilling, A. Burns, and K. Raymond. Formal specifications and proofs of inheritance protocols for real-time scheduling. Softw. Eng. J., 5(5):263--279, 1990.
G. Ramalingam. Context-sensitive synchronization-sensitive analysis is undecidable. ACM Trans. Prog. Lang. Syst., 22(2):416--430, 2000.
J. Regehr and N. Cooprider. Interrupt verification via thread verification. ENTCS, 174(9):139--150, 2007.
J. Regehr, A. Reid, and K. Webb. Eliminating stack overflow by abstract interpretation. ACM Trans. Embedded Comput. Syst., 4(4): 751--778, 2005.
L. Sha, R. Rajkumar, and J. P. Lehoczky. Priority inheritance protocols: an approach to real-time synchronization. IEEE Trans. Comput., 39(9):1175--1185, Sept. 1990.
M. Sharir and A. Pnueli. Two approaches to interprocedural data flow analysis. Program Flow Analysis: Theory and Applications, pp. 189--234, 1981.
Takashi Chikamasa et al. OSEK platform for LEGO MINDSTORMS 2010. URL
M. Vaziri, F. Tip, and J. Dolby. Associating synchronization constraints with data in an object-oriented language. In POPL'06, pp. 334--345. ACM Press, 2006.
V. Vojdani and V. Vene. Goblint: Path-sensitive data race analysis. Annales Univ. Sci. Budapest., Sect. Comp., 30:141--155, 2009.

Cited By

View all
  • (2023)Static Data Race Detection in Multi-task Programs for Industrial RobotsDistributed Computing and Intelligent Technology10.1007/978-3-031-24848-1_4(51-66)Online publication date: 18-Jan-2023
  • (2022)Static Race Detection for Periodic ProgramsProgramming Languages and Systems10.1007/978-3-030-99336-8_11(290-316)Online publication date: 29-Mar-2022
  • (2021)Program Verification Enhanced Precise Analysis of Interrupt-Driven Program Vulnerabilities2021 28th Asia-Pacific Software Engineering Conference (APSEC)10.1109/APSEC53868.2021.00033(253-263)Online publication date: Dec-2021
  • Show More Cited By



Information & Contributors


Published In

cover image ACM Conferences
POPL '11: Proceedings of the 38th annual ACM SIGPLAN-SIGACT symposium on Principles of programming languages
January 2011
652 pages
  • cover image ACM SIGPLAN Notices
    ACM SIGPLAN Notices  Volume 46, Issue 1
    POPL '11
    January 2011
    624 pages
    Issue’s Table of Contents
Permission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for components of this work owned by others than ACM must be honored. Abstracting with credit is permitted. To copy otherwise, or republish, to post on servers or to redistribute to lists, requires prior specific permission and/or a fee. Request permissions from [email protected]




Association for Computing Machinery

New York, NY, United States

Publication History

Published: 26 January 2011


Request permissions for this article.

Check for updates

Author Tags

  1. abstract domains
  2. interprocedural analysis
  3. interrupt-driven concurrency


  • Research-article


POPL '11

Acceptance Rates

Overall Acceptance Rate 860 of 4,328 submissions, 20%

Upcoming Conference

POPL '26


Other Metrics

Bibliometrics & Citations


Article Metrics

  • Downloads (Last 12 months)10
  • Downloads (Last 6 weeks)0
Reflects downloads up to 05 Mar 2025

Other Metrics


Cited By

View all
  • (2023)Static Data Race Detection in Multi-task Programs for Industrial RobotsDistributed Computing and Intelligent Technology10.1007/978-3-031-24848-1_4(51-66)Online publication date: 18-Jan-2023
  • (2022)Static Race Detection for Periodic ProgramsProgramming Languages and Systems10.1007/978-3-030-99336-8_11(290-316)Online publication date: 29-Mar-2022
  • (2021)Program Verification Enhanced Precise Analysis of Interrupt-Driven Program Vulnerabilities2021 28th Asia-Pacific Software Engineering Conference (APSEC)10.1109/APSEC53868.2021.00033(253-263)Online publication date: Dec-2021
  • (2021)Static analysis for detecting high-level races in RTOS kernelsFormal Methods in System Design10.1007/s10703-020-00354-058:1-2(294-321)Online publication date: 8-Jan-2021
  • (2019)Easy modelling and verification of unpredictable and preemptive interrupt-driven systemsProceedings of the 41st International Conference on Software Engineering10.1109/ICSE.2019.00037(212-222)Online publication date: 25-May-2019
  • (2017)Static analysis of deterministic negotiationsProceedings of the 32nd Annual ACM/IEEE Symposium on Logic in Computer Science10.5555/3329995.3330079(1-12)Online publication date: 20-Jun-2017
  • (2017)Modular verification of interrupt-driven softwareProceedings of the 32nd IEEE/ACM International Conference on Automated Software Engineering10.5555/3155562.3155592(206-216)Online publication date: 30-Oct-2017
  • (2017)Static analysis of deterministic negotiations2017 32nd Annual ACM/IEEE Symposium on Logic in Computer Science (LICS)10.1109/LICS.2017.8005144(1-12)Online publication date: Jun-2017
  • (2017)Modular verification of interrupt-driven software2017 32nd IEEE/ACM International Conference on Automated Software Engineering (ASE)10.1109/ASE.2017.8115634(206-216)Online publication date: Oct-2017
  • (2017)Proving Absence of Starvation by Means of Abstract Interpretation and Model CheckingAutomated Technology for Verification and Analysis10.1007/978-3-319-68167-2_1(3-22)Online publication date: 27-Sep-2017
  • Show More Cited By

View Options

Login options

View options


View or Download as a PDF file.



View online with eReader.







Share this Publication link

Share on social media