THE 1960S

Multics

In 1962, Joseph Carl Robnett Licklider, then director of DARPA, launched the idea for the Multics operating system. The contract was awarded in August 1964. Multics extended the work of the Compatible Time-Sharing System, developed at MIT under Fernando Corbató. Computers still operated as batch processing machines, with programs executing one after another, and users sometimes waiting entire days for their results. The first time-sharing systems struggled to manage more than a few simultaneous programs, forced to offload inactive ones onto magnetic tape.

The project brought together an unusual alliance consisting of MIT for research, General Electric for hardware, and Bell Labs for software development. GE secured the contract after IBM rejected the proposed paging and segmentation concepts. This convergence of academic and industrial talent assembled some of the greatest minds in computing of that era.

The technical ambition exceeded anything previously attempted. Multics integrated virtual memory, segmentation-based protection, hierarchical file system, shared-memory multiprocessing, security, and online reconfiguration. The system was among the first to be developed primarily in a high-level language and to support multiple programming languages. MacLisp and troff found their origins in Multics, as did much of the modern UNIX command line.

Implementation proved challenging. The GE 645 hardware arrived late, and Multics only achieved self-hosting in 1968. In 1969, DARPA threatened to pull the plug, pushing Bell Labs toward the exit. This withdrawal would give birth to UNIX, created by former Multics developers: Kenneth Lane Thompson, Dennis MacAlistair Ritchie, Douglas McIlroy, and Joseph Francis Ossanna.

Honeywell, which acquired General Electric’s computer business in 1970, commercialized Multics from 1973 until 1985 at an initial price of $7 million. The customer base consisted of the US Air Force, universities such as the University of Southwestern Louisiana and the French university system, and major corporations like General Motors and Ford. In total, approximately 80 licenses were sold. The last Multics system, operated by the Canadian Department of National Defence, was shut down in 2000.

The system architecture rested on two pillars: processes and segments. Processes provided execution contexts, while segments stored code, data, and I/O devices. These segments were organized in a directory hierarchy, ancestors of current file systems. A process’s protection domain delimited accessible segments and authorized operations.

Regarding security, Multics introduced protection rings, a hierarchical structure ranging from ring 0, the most privileged, to higher, less powerful rings. The GE 645 provided for 64 rings, but only 8 were actually implemented. The Multics supervisor, confined to rings 0 and 1, could only be modified by code executing in these privileged rings. This approach still influences modern processors, which typically use two levels: supervisor (kernel) and user.

In 1974, Paul Karger and Roger Schell of the US Air Force conducted a vulnerability analysis that revealed several flaws. A hardware vulnerability bypassed access checks in certain indirect addressing cases. Software flaws appeared, particularly related to the master mode of execution in user rings, a modification introduced to improve performance. These discoveries illustrated the difficulty of maintaining security in a complex system under performance optimization pressures.

Several factors explain Multics’s relative commercial failure. Integrated circuits evolved at an exponential rate, transforming the computing landscape. When Multics reached the market in 1973, it perfectly addressed the problems of 1964, but the world had changed. The system cost too much, depended too heavily on proprietary architecture, and was too focused on centralized shared computing while decentralized departmental computing was taking off. Meanwhile, Digital Equipment Corporation was marketing entry-level versions of the PDP-11, and the 8080 microprocessor was running the first versions of CP/M as early as 1974.