Crabtree: Rust API Test Synthesis Guided by Coverage and Type
Yoshiki Takashima, Chanhee Cho, Ruben Martins, Limin Jia, Corina S. Pasareanu
Abstract
Rust type system constrains pointer operations, preventing bugs such as use-after-free. However, these constraints may be too strict for programming tasks such as implementing cyclic data structures. For such tasks, programmers can temporarily suspend checks using the unsafe keyword. Rust libraries wrap unsafe code blocks and expose higher-level APIs. They need to be extensively tested to uncover memory-safety bugs that can only be triggered by unexpected API call sequences or inputs. While prior works have attempted to automatically test Rust library APIs, they fail to test APIs with common Rust features, such as polymorphism, traits, and higher-order functions, or they have scalability issues and can only generate tests for a small number of combined APIs. We propose Crabtree, a testing tool for Rust library APIs that can automatically synthesize test cases with native support for Rust traits and higher-order functions. Our tool improves upon the test synthesis algorithms of prior works by combining synthesis and fuzzing through a coverage- and type-guided search algorithm that intelligently grows test programs and input corpus towards testing more code. To the best of our knowledge, our tool is the first to generate well-typed tests for libraries that make use of higher-order trait functions. Evaluation of Crabtree on 30 libraries found four previously unreported memory-safety bugs, all of which were accepted by the respective authors.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 99f1c789-db23-4da7-a80e-4d1431aa765eCited by top-tier papers4
- Miri: Practical Undefined Behavior Detection for RustRalf Jung, Benjamin Kimock, Christian Poveda, Eduardo Sánchez Muñoz et al.POPL 2026 · 8 citations
- deepSURF: Detecting Memory Safety Vulnerabilities in Rust Through Fuzzing LLM-Augmented HarnessesGeorgios C. Androutsopoulos, Antonio BianchiS&P 2026 · 5 citations
- Automated Exploit Generation for Node.js PackagesFilipe Marques, Mafalda Ferreira, André Nascimento, Miguel E. Coimbra et al.PLDI 2025 · 5 citations
- RustGo: Fairly Directed Greybox Fuzzing for Enforcing Rust Memory SafetyDongyeon Yu, Jiun Min, Yewan Na, Mijung Kim et al.CCS 2026
Builds on14
- Driller: Augmenting Fuzzing Through Selective Symbolic ExecutionNick Stephens, John Grosen, Christopher Salls, Andrew Dutcher et al.NDSS 2016 · 1,021 citations
- Understanding memory and thread safety practices and issues in real-world Rust programsBoqin Qin, Yilun Chen, Zeming Yu, Linhai Song et al.PLDI 2020 · 112 citations
- Verus: Verifying Rust Programs using Linear Ghost TypesAndrea Lattuada, Travis Hance, Chanhee Cho, Matthias Brun et al.OOPSLA 2023 · 86 citations
- Stacked borrows: an aliasing model for RustRalf Jung, Hoang-Hai Dang, Jeehoon Kang, Derek DreyerPOPL 2020 · 67 citations
- RULF: Rust Library Fuzzing via API Dependency Graph TraversalJianfeng Jiang, Hui Xu, Yangfan ZhouASE 2021 · 44 citations
Related papers
- RPG: Rust Library Fuzzing with Pool-based Fuzz Target Generation and Generic SupportZhiwu Xu, Bohao Wu, Cheng Wen, Bin Zhang et al.ICSE 2024 · 9 citations
- FRIES: Fuzzing Rust Library Interactions via Efficient Ecosystem-Guided Target GenerationXizhe Yin, Yang Feng, Qingkai Shi, Zixi Liu et al.ISSTA 2024 · 6 citations
- SyRust: automatic testing of Rust libraries with semantic-aware program synthesisYoshiki Takashima, Ruben Martins, Limin Jia, Corina S. PasareanuPLDI 2021 · 32 citations
- Validating Rust Compilers with Trait-Type Constraint GraphXin Lai, Ming Wen, Xiaofei Liao, Hai JinSOSP 2026
- CULPA: Universal Detection of Memory-Safety Bugs in Unsafe Rust Through the Lens of Safety RequirementsHung-Mao Chen, Bo Lu, Xu He, Xiaokuan Zhang et al.USENIX Security 2026
