arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

UnsafeChecker:在 Rust 安全抽象中发现健全性缺陷

UnsafeChecker: Finding Soundness Bugs in Rust Safe Abstractions

Xizhe Yin, Yaokun Zhang, Yang Feng, Baowen Xu

arXiv 2609.09641首次发表:更新:

发表机构

Nanjing University(南京大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

针对 Rust 安全抽象中的健全性缺陷,提出编译器集成的静态分析框架 UnsafeChecker,通过流敏感抽象解释分析 MIR,检测未定义行为和契约违规,在基准上召回率 67.9%,并发现大量真实缺陷。

AI 中文摘要

Rust 通过严格的所有权和借用系统,在没有垃圾回收的情况下保证内存安全。然而,对于底层系统编程,许多广泛使用的库依赖于 unsafe 关键字。这些库将裸指针操作封装在安全 API 之后,形成安全抽象。内部 unsafe 代码中的单个错误可能破坏其安全契约,导致抽象不健全,并允许安全客户端触发未定义行为。检测这些潜在的安全违规具有挑战性。现有的针对 C/C++ 的静态分析工具忽略了 Rust 特有的安全契约,而当前的 Rust 工具缺乏跟踪裸指针擦除上下文所需的深层语义建模。为解决这一差距,我们提出了 UnsafeChecker,一个编译器集成的静态分析框架,用于检测 Rust 安全抽象中潜在的安全违规。UnsafeChecker 使用流敏感的抽象解释分析 Rust MIR,该解释维护一个包含三个组件的共享状态:所有权、对象有效性和布局。每条警告规则消耗相应 Rust 安全义务所需的事实子集。UnsafeChecker 报告指令级未定义行为和可能通过安全 API 逃逸的边界级契约违规。我们在包含 53 个真实缺陷的 46 个 RustSec 漏洞基准上评估了 UnsafeChecker。UnsafeChecker 优于几种最先进的工具,检测到 32 个 CVE,覆盖 36 个缺陷(召回率 67.9%),警报级精确率为 51.6%。此外,在对 http://this 上的真实世界 crate 的大规模扫描中,UnsafeChecker 在 83 个 crate 中发现了 114 个先前未知的缺陷,其中 45 个已确认,27 个已被维护者修复。

英文摘要

Rust guarantees memory safety without garbage collection through a strict ownership and borrowing system. However, for low-level systems programming, many widely used libraries rely on the unsafe keyword. These libraries encapsulate raw-pointer operations behind safe APIs to form safe abstractions. A single mistake in this internal unsafe code can break its safety contract, rendering the abstraction unsound and allowing safe clients to trigger undefined behavior. Detecting these potential soundness violations is challenging. Existing static analysis tools for C/C++ ignore Rust-specific safety contracts, while current Rust tools lack the deep semantic modeling required to track the contexts that raw pointers erase. To address this gap, we present UnsafeChecker, a compiler-integrated static analysis framework for detecting potential soundness violations in Rust safe abstractions. UnsafeChecker analyzes Rust MIR using a flow-sensitive abstract interpretation that maintains a shared state with three components: ownership, object validity, and layout. Each warning rule consumes the subset of facts needed for the corresponding Rust safety obligation. UnsafeChecker reports both instruction-level undefined behavior and boundary-level contract violations that may escape through safe APIs. We evaluate UnsafeChecker on a benchmark of 46 RustSec vulnerabilities, which contain 53 ground-truth bugs. UnsafeChecker outperforms several state-of-the-art tools, detecting 32 CVEs and covering 36 bugs (67.9% recall) with 51.6% alert-level precision. Furthermore, in a large-scale scan of real-world crates on crates.io, UnsafeChecker uncovered 114 previously unknown bugs across 83 crates, with 45 confirmed and 27 already fixed by maintainers.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑