arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

CPyGraph:面向原生 CPython 字节码的版本感知静态分析框架

CPyGraph: A Version-Aware Static Analysis Framework for Native CPython Bytecode

Baihong Chen, Wen Li

arXiv 2609.25083首次发表:更新:

发表机构

Utah State University(犹他州立大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

CPyGraph 是一个 C++ 框架,通过版本适配器支持 CPython 字节码的包级静态分析,实现高精确率的指向分析和调用图,并在多版本上保持一致。

AI 中文摘要

对 Python 包的静态分析必须恢复程序结构和对象流,涵盖一等函数、动态分派、隐式协议调用、异常、闭包和模块执行。原生 CPython 字节码提供了这些行为的可执行低级表示,但其指令、调用、栈和异常表示在不同版本间会发生变化。这产生了对版本感知分析基础的需求,其图产物共享相同的字节码标识和语义。我们提出了 CPyGraph,一个用于包级分析原生 CPython 字节码的 C++ 框架。版本特定适配器通过共享接口暴露栈、控制、调用、词法、协议和异常语义,同时保留代码对象标识和原生字节码偏移。一个操作数栈感知的 Andersen 指向分析和调用图共同增长到不动点。它们的共享状态支持异常感知的控制流图(CFG)、块级控制依赖图(CDG)和过程间数据依赖图(DDG),并可选函数级流、上下文和有界路径敏感性。该框架还通过类型化覆盖摘要记录未解决的动态行为。我们使用 PYGBench 评估 CPyGraph,包括 201 个包级程序和 1,733 个固定候选。在 CPython 3.10 上,默认分析达到 91.40% 的候选精确率和 100% 的召回率;完整敏感性达到 94.97% 的精确率,召回率相同。在 CPython 3.10-3.14 上,1,334 个版本不变查询中有 1,328 个一致,且 CPyGraph 在其 112 程序调用图基准上与 PyCG 匹配。

英文摘要

Static analysis of Python packages must recover both program structure and object flow across first-class functions, dynamic dispatch, implicit protocol calls, exceptions, closures, and module execution. Native CPython bytecode provides the executable lowering of these behaviors, but its instruction, call, stack, and exception representations change across releases. This creates a need for a version-aware analysis foundation whose graph products share the same bytecode identities and semantics. We present CPyGraph, a C++ framework for package-level analysis of native CPython bytecode. Version- specific adapters expose stack, control, call, lexical, protocol, and exception semantics through a shared interface while preserving code-object identities and native bytecode offsets. An operand-stack-aware Andersen points- to analysis and call graph grow together to a fixed point. Their shared state supports exception-aware CFGs, block-level CDGs, and interprocedural DDGs, with optional function-level flow, context, and bounded path sensitivity. The framework also records unresolved dynamic behavior through typed coverage summaries. We evaluate CPyGraph with PYGBench, 201 package-level programs and 1,733 fixed candidates. On CPython 3.10, the default analysis reaches 91.40% candidate precision and 100% recall; complete sensitivity reaches 94.97% precision with the same recall. Across CPython 3.10-3.14, 1,328 of 1,334 version-invariant queries agree, and CPyGraph matches PyCG on its 112-program call-graph benchmark.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑