End-to-End Mechanized Proof of a JIT-Accelerated eBPF Virtual Machine for IoT
Shenghao Yuan, Frédéric Besson, Jean-Pierre Talpin
Abstract
Abstract Modern operating systems have adopted Berkeley Packet Filters (BPF) as a mechanism to extend kernel functionalities dynamically, e.g., Linux’s eBPF or RIOT’s rBPF. The just-in-time (JIT) compilation of eBPF introduced in Linux eBPF for performance has however led to numerous critical issues. Instead, RIOT’s rBPF uses a slower but memory-isolating interpreter (a virtual machine) which implements a defensive semantics of BPF; and therefore trades performance for security. To increase performance without sacrificing security, this paper presents a fully verified JIT implementation for RIOT’s rBPF, consisting of: i/ an end-to-end refinement workflow to both proving the JIT correct from an abstract specification and by deriving a verified concrete C implementation; ii/ a symbolic CompCert interpreter for executing binary code; iii/ a verified JIT compiler for rBPF; iv/ a verified hybrid rBPF virtual machine. Our core contribution is, to the best of our knowledge, the first and fully verified rBPF JIT compiler with correctness guarantees from high-level specification to low-level implementation. Benchmarks on microcontrollers hosting the RIOT operating system demonstrate significant performance improvements over the existing implementations of rBPF, even in worst-case application scenarios.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 3f80e394-7fd1-400b-a4e9-eb9507e283d4Builds on6
- Specification and verification in the field: Applying formal methods to BPF just-in-time compilers in the Linux kernelLuke Nelson, Jacob Van Geffen, Emina Torlak, Xi WangOSDI 2020 · 72 citations
- Coq Coq correct! verification of type checking and erasure for Coq, in CoqMatthieu Sozeau, Simon Boulier, Yannick Forster, Nicolas Tabareau et al.POPL 2020 · 67 citations
- Formally verified speculation and deoptimization in a JIT compilerAurèle Barrière, Sandrine Blazy, Olivier Flückiger, David Pichardie et al.POPL 2021 · 38 citations
- Formally Verified Native Code Generation in an Effectful JIT: Turning the CompCert Backend into a Formally Verified JIT CompilerAurèle Barrière, Sandrine Blazy, David PichardiePOPL 2023 · 27 citations
- Synthesizing JIT Compilers for In-Kernel DSLsJacob Van Geffen, Luke Nelson, Isil Dillig, Xi Wang et al.CAV 2020 · 27 citations
Related papers
- End-to-End Mechanized Proof of an eBPF Virtual Machine for Micro-controllersShenghao Yuan, Frédéric Besson, Jean-Pierre Talpin, Samuel Hym et al.CAV 2022 · 13 citations
- MOAT: Towards Safe BPF Kernel ExtensionHongyi Lu, Shuai Wang, Yechang Wu, Wanning He et al.USENIX Security 2024 · 18 citations
- Formalizing the Linux eBPF Core ISA: A Mechanized Operational Semantics and Its Real-World ApplicationsShenghao Yuan, Yazhou Tang, Tianci Cao, Frédéric Besson et al.OOPSLA 2026
- Synthesizing safe and efficient kernel extensions for packet processingQiongwen Xu, Michael D. Wong, Tanvi Wagle, Srinivas Narayana et al.SIGCOMM 2021 · 30 citations
- A Flow-Sensitive Refinement Type System for Verifying eBPF ProgramsAmeer Hamza, Lucas Zavalía, Arie Gurfinkel, Jorge A. Navas et al.OOPSLA 2025 · 1 citation
