AI 中文总结
研究针对C/C++内存安全问题,提出PTSan这一LLVM检查器,通过在指针高位存对象标识符及边界到运行时表,实现低开销指针检查,在普通硬件上运行速度与现有最佳相当,将实用指针内存安全引入仅重新编译的部署模型。
AI 中文摘要
内存安全错误仍是C和C++中严重漏洞的主要来源。基于指针的检查器比基于位置的工具(如LLVM的ASan)能提供更强的保证,但开销和兼容性限制阻碍了其在生产中的应用。我们提出了PTSan,一种LLVM检查器,通过在每个指针的高位存储对象标识符及其边界到固定大小的运行时表中,使基于指针的检查变得实用。这种表示方式用有限的活动对象预算换取了低开销、优化器可见性和对商用硬件的支持。由于标识随指针值传播,普通的LLVM数据流无需显式的逐指针元数据指令就能传播它。将元数据查找与检查执行分离,使两者都作为LLVM IR公开,从而实现检查提升、省略和合并,以及兼容标签条的全函数最小割放置。英特尔线性地址掩码在可用时在硬件中消除剩余的标签条。在普通硬件上,PTSan的运行速度与已发布的最快基于位置的检查器相当:在x86-64上的SPEC CPU 2017上几何平均开销为57.2%(使用英特尔LAM时为46.4%),在ARM64上为54.7%,在应用形状的LLVM多源套件上为31.5%(x86-64)。这大约是具有类似指针-对象权限保证的先前系统已发布开销百分比的三分之一,同时保留了由独立内存安全测试套件测量的对象间、非对象和时间检测覆盖率。其物理内存开销实际上是原生的,这对于生产部署来说是一个关键属性,因为内存成本已成为首要约束。我们还展示了在实际服务器和安全工作负载上的实际开销。这些结果表明,PTSan将基于指针的实用内存安全引入了仅需重新编译的检查器部署模型。
英文摘要
Memory safety errors remain the dominant source of severe vulnerabilities in C and C++. Pointer-based sanitizers provide stronger guarantees than location-based tools such as LLVM's ASan, but their overhead and compatibility limitations have constrained production use. We present PTSan, an LLVM sanitizer that makes pointer-based checking practical by storing an object identifier in each pointer's high bits and its bounds in a fixed-size runtime table. This representation trades a finite live-object budget for low overhead, optimizer visibility, and commodity-hardware support. Because identity travels with the pointer value, ordinary LLVM dataflow propagates it without explicit per-pointer metadata instructions. Separating metadata lookup from check enforcement exposes both as LLVM IR, enabling check hoisting, elision, and merging, plus whole-function min-cut placement of compatibility tag strips. Intel Linear Address Masking eliminates the remaining strips in hardware when available. On stock hardware PTSan runs at parity with the fastest published location-based sanitizer: 57.2% geomean overhead on SPEC CPU 2017 on x86-64 (46.4% with Intel LAM), 54.7% on ARM64, and 31.5% (x86-64) on the application-shaped LLVM MultiSource suite. This is roughly a third of the published overhead percentage of prior systems with similar pointer-object authority guarantees, while preserving the inter-object, non-object, and temporal detection coverage measured by an independent memory safety test suite. Its physical-memory overhead is effectively native, a critical property for production deployment as memory costs become a first-order constraint. We also demonstrate practical overhead on real-world server and security workloads. These results show that PTSan brings practical pointer-based memory safety into a recompile-only sanitizer deployment model.