Building high-integrity distributed systems with Ravenscar restrictions