Canary: practical static detection of inter-thread value-flow bugs
Yuandao Cai, Peisen Yao, Charles Zhang
Abstract
Concurrent programs are still prone to bugs arising from the subtle interleavings of threads. Traditional static analysis for concurrent programs, such as data-flow analysis and symbolic execution, has to explicitly explore redundant control states, leading to prohibitive computational complexity.
This paper presents a value-flow analysis framework for concurrent programs called Canary that is practical to statically find diversified inter-thread value-flow bugs. Our work is the first to convert the concurrency bug detection to a source-sink reachability problem, effectively reducing redundant thread interleavings. Specifically, we propose a scalable thread-modular algorithm to capture data and interference dependence in a value-flow graph. The relevant edges of value flows are annotated with execution constraints as guards to describe the conditions of value flows. Canary then traverses the graph to detect concurrency defects via tracking the source-sink properties and solving the aggregated guards of value flows with an SMT solver to decide the realizability of interleaving executions. Experiments show that Canary is precise, scalable, and practical, detecting over eighteen previously unknown concurrency bugs in large, widely-used software systems with low false positives.
• Software and its engineering → Software verification and validation.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers13
- Context Sensitivity without Contexts: A Cut-Shortcut Approach to Fast and Precise Pointer AnalysisWenjie Ma, Shengyuan Yang, Tian Tan, Xiaoxing Ma et al.PLDI 2023 · 29 citations
- Controlled Concurrency Testing via Periodical SchedulingCheng Wen, Mengda He, Bohao Wu, Zhiwu Xu et al.ICSE 2022 · 25 citations
- Unleashing the Power of Type-Based Call Graph Construction by Using Regional Pointer InformationYuandao Cai, Yibo Jin, Charles ZhangUSENIX Security 2024 · 16 citations
- Peahen: fast and precise static deadlock detection via context reductionYuandao Cai, Chengfeng Ye, Qingkai Shi, Charles ZhangFSE 2022 · 16 citations
- Plankton: Reconciling Binary Code and Debug InformationAnshunkang Zhou, Chengfeng Ye, Heqing Huang, Yuandao Cai et al.ASPLOS 2024 · 11 citations
Builds on5
- Razzer: Finding Kernel Race Bugs through FuzzingDae R. Jeong, Kyungtae Kim, Basavesh Shivakumar, Byoungyoung Lee et al.S&P 2019 · 202 citations
- Krace: Data Race Fuzzing for Kernel File SystemsMeng Xu, Sanidhya Kashyap, Hanqing Zhao, Taesoo KimS&P 2020 · 131 citations
- Fast, sound, and effectively complete dynamic race predictionAndreas PavlogiannisPOPL 2020 · 46 citations
- SmartTrack: efficient predictive race detectionJake Roemer, Kaan Genç, Michael D. BondPLDI 2020 · 28 citations
- MUZZ: Thread-aware Grey-box Fuzzing for Effective Bug Hunting in Multithreaded ProgramsHongxu Chen, Shengjian Guo, Yinxing Xue, Yulei Sui et al.USENIX Security 2020
Related papers
- Conquering the extensional scalability problem for value-flow analysis frameworksQingkai Shi, Rongxin Wu, Gang Fan, Charles ZhangICSE 2020 · 15 citations
- Interference relation-guided SMT solving for multi-threaded program verificationHongyu Fan, Weiting Liu, Fei HePPoPP 2022 · 9 citations
- Precise and efficient atomicity violation detection for interrupt-driven programs via staged path pruningChao Li, Rui Chen, Boxiang Wang, Tingting Yu et al.ISSTA 2022 · 9 citations
- Detecting Blocking Errors in Go Programs using Localized Abstract InterpretationOskar Haarklou Veileborg, Georgian-Vlad Saioc, Anders MøllerASE 2022 · 12 citations
- Reorder Pointer Flow in Sound Concurrency Bug PredictionYuqi Guo, Shihao Zhu, Yan Cai, Liang He et al.ICSE 2024 · 1 citation
