发表机构
KAIST; UNIST; Yale University(韩国科学技术院; 蔚山科学技术院; 耶鲁大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本研究通过分析2022-2025年GitHub上30个rustc健全性缺陷问题,发现其存在多种类型的不健全问题,现有工具部分可检测相关缺陷,文档语义解释存在不足。
AI 中文摘要
Rust被宣称是一种类型健全的语言,能够防止包括内存缺陷在内的各种不良行为。然而,官方Rust编译器rustc并非完美无缺,它包含健全性缺陷,即编译器会接受那些本应在类型检查阶段被拒绝的程序。在本研究中,我们对2022年1月1日至2025年9月1日期间从GitHub问题跟踪器收集的30个报告rustc潜在健全性缺陷的问题展开实证研究。我们对每个问题进行深入分析,重点关注其受影响的特性、症状(该特性的处理失误方式)、后果(产生的不良行为)、触发特性、关于其是否为缺陷的社区共识,以及生命周期,包括引入、发现和修复过程。此外,我们还研究了现有工具,如AddressSanitizer、Miri、Chalk和a-mir-formality等实现,以及Rust Reference、FLS和Rust RFCs等文档,以评估它们作为rustc类型健全性测试的预言机的潜力。我们的主要发现如下:(1) 某些健全性缺陷通常由隐含边界或trait对象触发,会损害内存安全;(2) 与关联类型以及生命周期与trait的交互相关的边缘情况会对健全的类型检查构成挑战;(3) 大多数缺陷从相关特性首次引入时就已存在,需要很长时间才能被发现;(4) 虽然AddressSanitizer和Miri能够检测导致内存缺陷的健全性缺陷,但a-mir-formality和Chalk目前尚不成熟,尽管它们有潜力识别其他类别的缺陷;(5) 现有文档常常无法对语言语义提供精确的解释。
英文摘要
Rust is claimed to be a type-sound language capable of preventing various undesirable behaviors, including memory bugs. However, rustc, the official Rust compiler, is not immune to defects; it contains soundness bugs, where the compiler accepts programs that should be rejected during type checking. In this work, we present an empirical study of 30 issues that report potential soundness bugs in rustc, collected from the GitHub issue tracker between January 1, 2022 and September 1, 2025. We analyze each issue in depth, focusing on its affected feature, symptom (how the feature is mishandled), consequence (the resulting undesirable behavior), triggering features, community consensus regarding whether it is a bug, and lifecycle, including introduction, discovery, and fix. Furthermore, we investigate existing artifacts, including implementations such as AddressSanitizer, Miri, Chalk, and a-mir-formality, alongside documentation such as the Rust Reference, the FLS, and Rust RFCs to assess their potential as oracles for testing the type soundness of rustc. Our key findings indicate that: (1) Certain soundness bugs, typically triggered by implied bounds or trait objects, compromise memory safety. (2) Sound type checking is challenged by edge cases involving associated types and the interaction between lifetimes and traits. (3) Most bugs persist from the initial introduction of the relevant features and require significant time to be discovered. (4) While AddressSanitizer and Miri can detect soundness bugs that lead to memory bugs, a-mir-formality and Chalk are currently immature despite their potential to identify other bug categories. (5) Existing documentation frequently fails to provide precise explanations of the language semantics.
Comments25 pages, 1 figure. To appear in Proceedings of the ACM on Software Engineering (PACMSE), ISSTA 2026
Journal refProc. ACM Softw. Eng. 3, ISSTA, Article ISSTA129 (2026)
DOI:10.1145/3832220