Tree Borrows
Neven Villani, Johannes Hostert, Derek Dreyer, Ralf Jung
Abstract
The Rust programming language is well known for its ownership-based type system, which offers strong guarantees like memory safety and data race freedom. However, Rust also provides unsafe escape hatches, for which safety is not guaranteed automatically and must instead be manually upheld by the programmer. This creates a tension. On the one hand, compilers would like to exploit the strong guarantees of the type system—particularly those pertaining to aliasing of pointers—in order to unlock powerful intraprocedural optimizations. On the other hand, those optimizations are easily invalidated by “badly behaved” unsafe code. To ensure correctness of such optimizations, it thus becomes necessary to clearly define what unsafe code is “badly behaved.” In prior work, Stacked Borrows defined a set of rules achieving this goal. However, Stacked Borrows rules out several patterns that turn out to be common in real-world unsafe Rust code, and it does not account for advanced features of the Rust borrow checker that were introduced more recently. To resolve these issues, we present Tree Borrows . As the name suggests, Tree Borrows is defined by replacing the stack at the heart of Stacked Borrows with a tree. This overcomes the aforementioned limitations: our evaluation on the 30 000 most widely used Rust crates shows that Tree Borrows rejects 54% fewer test cases than Stacked Borrows does. Additionally, we prove (in Rocq) that it retains most of the Stacked Borrows optimizations and also enables important new ones, notably read-read reorderings.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 6e8bf3d3-de4c-4eb5-9bc6-846c9c864cd3Cited by top-tier papers6
- Miri: Practical Undefined Behavior Detection for RustRalf Jung, Benjamin Kimock, Christian Poveda, Eduardo Sánchez Muñoz et al.POPL 2026 · 8 citations
- From Linearity to BorrowingAndrew Wagner, Olek Gierczak, Brianna Marshall, John M. Li et al.OOPSLA 2025 · 1 citation
- Place Capability Graphs: A General-Purpose Model of Rust's Ownership and Borrowing GuaranteesZachary Grannan, Aurel Bílý, Jonás Fiala, Jasper Geer et al.OOPSLA 2025 · 1 citation
- Tracking Borrows with Regular ExpressionsTodd Nowacki, Sam Blackshear, John Mitchell, Shaz Qadeer et al.OOPSLA 2026
- Soteria: Efficient Symbolic Execution as a Functional Library: Perhaps You Should Write Your Own Symbolic Execution Engine!Sacha-Élie Ayoun, Opale Sjöstedt, Azalea RaadPLDI 2026
Builds on4
- Alive2: bounded translation validation for LLVMNuno P. Lopes, Juneyoung Lee, Chung-Kil Hur, Zhengyang Liu et al.PLDI 2021 · 109 citations
- Stacked borrows: an aliasing model for RustRalf Jung, Hoang-Hai Dang, Jeehoon Kang, Derek DreyerPOPL 2020 · 67 citations
- Simuliris: a separation logic framework for verifying concurrent program optimizationsLennard Gäher, Michael Sammler, Simon Spies, Ralf Jung et al.POPL 2022 · 33 citations
- A Study of Undefined Behavior Across Foreign Function Boundaries in Rust LibrariesIan McCormack, Joshua Sunshine, Jonathan AldrichICSE 2025 · 5 citations
Related papers
- How do programmers use unsafe rust?Vytautas Astrauskas, Christoph Matheja, Federico Poli, Peter Müller et al.OOPSLA 2020 · 78 citations
- Is rust used safely by software developers?Ana Nora Evans, Bradford Campbell, Mary Lou SoffaICSE 2020 · 57 citations
- Automatic Linear Resource Bound Analysis for Rust via Prophecy PotentialsQihao Lian, Di WangOOPSLA 2025 · 1 citation
- Aliasing Limits on Translating C to Safe RustMehmet Emre, Peter Boyland, Aesha Parekh, Ryan Schroeder et al.OOPSLA 2023 · 32 citations
- Flux: Liquid Types for RustNico Lehmann, Adam T. Geller, Niki Vazou, Ranjit JhalaPLDI 2023 · 29 citations
