CLIR: Liveness-Driven and Structure-Aware Fuzzing for the Cranelift Compiler
Shangtong Cao, Tianlei Song, Qiuping Yi, Tianyu Chen, Guoai Xu, Ningyu He, Haoyu Wang
Abstract
Modern compilers are complex software systems that must correctly translate high-level programming languages into machine code across multiple architectures. Cranelift, a fast and modern compiler backend originally developed for WebAssembly and recently adopted as an experimental backend for Rust, has gained increasing importance due to its superior compilation speed compared to LLVM and comprehensive multiarchitecture support, including x86-64, AArch64, s390x, and RISCV64. However, despite decades of development in compiler testing, testing Cranelift still presents unique challenges, including (1) constructing valid IR under the strict enforcement of SSA form, (2) generating sequences with sufficient computational density to stress backend components, and (3) balancing broad backend coverage with efficient root cause analysis across heterogeneous architectures.
To address these challenges, we propose CLIR, a differential testing framework that integrates a syntaxpreserving hierarchical generation strategy to guarantee SSA validity, a liveness-guided instruction refinement mechanism to maximize computational density, and a diagnosis-guided cross-architecture adaptation scheme to facilitate efficient root cause analysis across heterogeneous backends. Our comprehensive evaluation demonstrates that CLIR significantly outperforms existing state-of-the-art baselines, detecting 8×, 24×, and 8× more unique bugs than cranelift-fuzzgen, wasm-smith, and WASMaker, respectively, while RustSmith uncovered no bugs. Consequently, within 72 hours of testing, CLIR discovered 24 bugs spanning all target architectures, with 21 confirmed and 9 fixed.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 1c949ecb-5bdc-419b-84b9-5385c35918d1Builds on10
- RedLeaf: Isolation and Communication in a Safe Operating SystemVikram Narayanan, Tianjiao Huang, David Detweiler, Dan Appel et al.OSDI 2020 · 86 citations
- Theseus: an Experiment in Operating System Structure and State ManagementKevin Boos, Namitha Liyanage, Ramla Ijaz, Lin ZhongOSDI 2020 · 67 citations
- Enriching Compiler Testing with Real Program from Bug ReportHao ZhongASE 2022 · 24 citations
- Copy-and-patch compilation: a fast compilation algorithm for high-level languages and bytecodeHaoran Xu, Fredrik KjolstadOOPSLA 2021 · 24 citations
- Boosting Compiler Testing by Injecting Real-World CodeShaohua Li, Theodoros Theodoridis, Zhendong SuPLDI 2024 · 24 citations
Related papers
- Rustlantis: Randomized Differential Testing of the Rust CompilerQian Wang, Ralf JungOOPSLA 2024 · 14 citations
- IRFuzzer: Specialized Fuzzing for LLVM Backend Code GenerationYuyang Rong, Zhanghan Yu, Zhenkai Weng, Stephen Neuendorffer et al.ICSE 2025 · 1 citation
- MLIRSmith: Random Program Generation for Fuzzing MLIR Compiler InfrastructureHaoyu Wang, Junjie Chen, Chuyue Xie, Shuang Liu et al.ASE 2023 · 16 citations
- Clozemaster: Fuzzing Rust Compiler by Harnessing Llms for Infilling Masked Real ProgramsHongyan Gao, Yibiao Yang, Maolin Sun, Jiangchang Wu et al.ICSE 2025 · 6 citations
- BackSmith: A Systematic Approach to Testing Compiler BackendsHongyu Chen, Yu Wang, Jianhua Zhao, Ke WangOOPSLA 2026
