ParentFull threadsanxiyn·The primary paper to read is "Comprehensive formal verification of an OS microkernel" (2014).http://dl.acm.org/citation.cfm?id=2560537View on HN