proving that the implementation of any particular general-purpose kernel enforces this
property is yet to be achieved. In this paper we take a significant step towards this vision by
presenting a machine-checked formulation of intransitive noninterference for OS kernels,
and its associated sound and complete unwinding conditions, as well as a scalable proof
calculus over nondeterministic state monads for discharging these unwinding conditions …