C to checked C by 3c
Aravind Machiry, John H. Kastner, Matt McCutchen, Aaron Eline, Kyle Headley, Michael Hicks
Abstract
Owing to the continued use of C (and C++), spatial safety violations (e.g., buffer overflows) still constitute one of today's most dangerous and prevalent security vulnerabilities. To combat these violations, Checked C extends C with bounds-enforced checked pointer types. Checked C is essentially a gradually typed spatially safe C - checked pointers are backwards-binary compatible with legacy pointers, and the language allows them to be added piecemeal, rather than necessarily all at once, so that safety retrofitting can be incremental. This paper presents a semi-automated process for porting a legacy C program to Checked C. The process centers on 3C, a static analysis-based annotation tool. 3C employs two novel static analysis algorithms - typ3c and boun3c - to annotate legacy pointers as checked pointers, and to infer array bounds annotations for pointers that need them. 3C performs a root cause analysis to direct a human developer to code that should be refactored; once done, 3C can be re-run to infer further annotations (and updated root causes). Experiments on 11 programs totaling 319KLoC show 3C to be effective at inferring checked pointer types, and experience with previously and newly ported code finds 3C works well when combined with human-driven refactoring.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext a71d9e00-4b5e-4a74-acf9-076fa7f048f0Cited by top-tier papers7
- Ownership Guided C to Rust TranslationHanliang Zhang, Cristina David, Yijun Yu, Meng WangCAV 2023 · 37 citations
- Aliasing Limits on Translating C to Safe RustMehmet Emre, Peter Boyland, Aesha Parekh, Ryan Schroeder et al.OOPSLA 2023 · 32 citations
- LLM Assistance for Memory SafetyJ. Nausheen Mohammed, Akash Lal, Aseem Rastogi, Rahul Sharma et al.ICSE 2025 · 4 citations
- &inator: Correct, Precise C-to-Rust Interface TranslationVictor Chen, Ayden Coughlin, Michael D. BondPLDI 2026 · 1 citation
- Cpp2Rust: Automatic Translation of C++ to Safe RustLucian Popescu, Francisco Gouveia, Henrique Preto, João Silveira et al.PLDI 2026 · 1 citation
Builds on4
- SoK: Sanitizing for SecurityDokyung Song, Julian Lettner, Prabhu Rajasekaran, Yeoul Na et al.S&P 2019 · 196 citations
- Translating C to safer RustMehmet Emre, Ryan Schroeder, Kyle Dewey, Ben HardekopfOOPSLA 2021 · 60 citations
- Solver-based gradual type migrationLuna Phipps-Costin, Carolyn Jane Anderson, Michael Greenberg, Arjun GuhaOOPSLA 2021 · 16 citations
- What is decidable about gradual types?Zeina Migeed, Jens PalsbergPOPL 2020 · 12 citations
Related papers
- Adding Spatial Memory Safety to EDK II through Checked C (Experience Paper)Sourag Cherupattamoolayil, Arunkumar Bhattar, Connor Glosner, Aravind MachiryISSTA 2025
- Fat Pointers for Temporal Memory Safety of CJie Zhou, John Criswell, Michael HicksOOPSLA 2023 · 17 citations
- A Dependent Nominal Physical Type System for Static Analysis of Memory in Low Level CodeJulien Simonnet, Matthieu Lemerre, Mihaela SighireanuOOPSLA 2024 · 4 citations
- Scylla: Translating an Applicative Subset of C to Safe RustAymeric Fromherz, Jonathan ProtzenkoOOPSLA 2026 · 6 citations
- Towards Reliable Spatial Memory Safety for Embedded Software by Combining Checked C with Concolic TestingSören Tempel, Vladimir Herdt, Rolf DrechslerDAC 2021 · 2 citations
