ProveNFix: Temporal Property-Guided Program Repair
Yahui Song, Xiang Gao, Wenhua Li, Wei-Ngan Chin, Abhik Roychoudhury
Abstract
Model checking has been used traditionally for finding violations of temporal properties. Recently, testing or fuzzing approaches have also been applied to software systems to find temporal property violations. However, model checking suffers from state explosion, while fuzzing can only partially cover program paths. Moreover, once a violation is found, the fix for the temporal error is usually manual. In this work, we develop the first compositional static analyzer for temporal properties, and the analyzer supports a proof-based repair strategy to fix temporal bugs automatically. To enable a more flexible specification style for temporal properties, on top of the classic pre/post-conditions, we allow users to write a future -condition to modularly express the expected behaviors after the function call. Instead of requiring users to write specifications for each procedure, our approach automatically infers the procedure’s specification according to user-supplied specifications for a small number of primitive APIs. We further devise a term rewriting system to check the actual behaviors against its inferred specification. Our method supports the analysis of 1) memory usage bugs, 2) unchecked return values, 3) resource leaks, etc., with annotated specifications for 17 primitive APIs, and detects 515 vulnerabilities from over 1 million lines of code ranging from ten real-world C projects. Intuitively, the benefit of our approach is that a small set of properties can be specified once and used to analyze/repair a large number of programs. Experimental results show that our tool, P rove NF ix , detects <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" display="inline"> mml:mrow mml:mn72.2</mml:mn> mml:mi%</mml:mi> </mml:mrow> </mml:math> more true alarms than the latest release of the Infer static analyzer. Moreover, we show the effectiveness of our repair strategy when compared to other state-of-the-art systems — fixing <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" display="inline"> mml:mrow mml:mn5</mml:mn> mml:mi%</mml:mi> </mml:mrow> </mml:math> more memory leaks than SAVER, <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" display="inline"> mml:mrow mml:mn40</mml:mn> mml:mi%</mml:mi> </mml:mrow> </mml:math> more resource leaks than FootPatch, and with a <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" display="inline"> mml:mrow mml:mn90</mml:mn> mml:mi%</mml:mi> </mml:mrow> </mml:math> fix rate for null pointer dereferences.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext ba8c69af-1258-41fa-a7d4-e1892c07ca5fCited by top-tier papers4
- Robustifying Debug Information Updates in LLVM via Control-Flow Conformance AnalysisShan Huang, Jingjing Liang, Ting Su, Qirun ZhangPLDI 2025 · 3 citations
- NESA: Relational Neuro-Symbolic Static Program AnalysisChengpeng Wang, Yifei Gao, Wuqi Zhang, Xuwei Liu et al.FSE 2026 · 1 citation
- TLR: Codebase-Level C Memory Management Error Repair with Large Language ModelsXiao Cheng, Zhihao Guo, Huan Huo, Yulei SuiFSE 2026 · 1 citation
- Translating C To Rust: Lessons from a User StudyRuishi Li, Bo Wang, Tianyu Li, Prateek Saxena et al.NDSS 2025
Builds on5
- Using Safety Properties to Generate Vulnerability PatchesZhen Huang, David Lie, Gang Tan, Trent JaegerS&P 2019 · 91 citations
- Finding real bugs in big programs with incorrectness logicQuang Loc Le, Azalea Raad, Jules Villard, Josh Berdine et al.OOPSLA 2022 · 52 citations
- Linear-time Temporal Logic guided Greybox FuzzingRuijie Meng, Zhen Dong, Jialin Li, Ivan Beschastnikh et al.ICSE 2022 · 29 citations
- SAVER: scalable, precise, and safe memory-error repairSeongjoon Hong, Junhee Lee, Jeongsoo Lee, Hakjoo OhICSE 2020 · 28 citations
- Bounded Exhaustive Search of Alloy Specification RepairsSimón Gutiérrez Brida, Germán Regis, Guolong Zheng, Hamid Bagheri et al.ICSE 2021 · 6 citations
Related papers
- Statically Discover Cross-Entry Use-After-Free Vulnerabilities in the Linux KernelHang Zhang, Jangha Kim, Chuhong Yuan, Zhiyun Qian et al.NDSS 2025
- Detecting API Post-Handling Bugs Using Code and Description in PatchesMiaoqian Lin, Kai Chen, Yang XiaoUSENIX Security 2023
- Program vulnerability repair via inductive inferenceYuntong Zhang, Xiang Gao, Gregory J. Duck, Abhik RoychoudhuryISSTA 2022 · 29 citations
- CULPA: Universal Detection of Memory-Safety Bugs in Unsafe Rust Through the Lens of Safety RequirementsHung-Mao Chen, Bo Lu, Xu He, Xiaokuan Zhang et al.USENIX Security 2026
- Boosting Static Resource Leak Detection via LLM-based Resource-Oriented Intention InferenceChong Wang, Jianan Liu, Xin Peng, Yang Liu et al.ICSE 2025 · 5 citations
