Icarus: Trustworthy Just-In-Time Compilers with Symbolic Meta-Execution
Naomi Smith, Abhishek Sharma, John Renner, David Thien, Fraser Brown, Hovav Shacham, Ranjit Jhala, Deian Stefan
Abstract
Just-in-time (JIT) compilers make JavaScript run efficiently by replacing slow JavaScript interpreter code with fast machine code. However, this efficiency comes at a cost: bugs in JIT compilers can completely subvert all language-based (memory) safety guarantees, and thereby introduce catastrophic exploitable vulnerabilities. We present Icarus: a new framework for implementing JIT compilers that are automatically, formally verified to be safe, and which can then be converted to C++ that can be linked into browser runtimes. Crucially, we show how to build a JIT with Icarus such that verifying the JIT implementation statically ensures the security of all possible programs that the JIT could ever generate at run-time, via a novel technique called symbolic meta-execution that encodes the behaviors of all possible JIT-generated programs as a single Boogie meta-program which can be efficiently verified by SMT solvers. We evaluate Icarus by using it to re-implement components of Firefox's JavaScript JIT. We show that Icarus can scale up to expressing complex JITs, quickly detects real-world JIT bugs and verifies fixed versions, and yields C++ code that is as fast as hand-written code.
- Work done while at UCSD.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext ca5658f6-d69e-434a-a3a9-5e6dd8a7493cCited by top-tier papers3
- Mohabi: Disaggregating and Sandboxing the Firefox JavaScript EngineAbhishek Sharma, Anand Balaji, Zachary Yedidia, Anthony Du et al.OSDI 2026 · 1 citation
- Understanding and Finding JIT Compiler Performance BugsZijian Yi, Cheng Ding, August Shi, Milos GligoricOOPSLA 2026
- Scaling Instruction-Selection Verification against Authoritative ISA SemanticsMichael McLoughlin, Ashley Sheng, Chris Fallin, Bryan Parno et al.OOPSLA 2025
Builds on11
- CodeAlchemist: Semantics-Aware Code Generation to Find Vulnerabilities in JavaScript EnginesHyungSeok Han, DongHyeon Oh, Sang Kil ChaNDSS 2019 · 178 citations
- Fuzzing JavaScript Engines with Aspect-preserving MutationSoyeon Park, Wen Xu, Insu Yun, Daehee Jang et al.S&P 2020 · 126 citations
- JIT-Picking: Differential Fuzzing of JavaScript EnginesLukas Bernhard, Tobias Scharnowski, Moritz Schloegel, Tim Blazytko et al.CCS 2022 · 42 citations
- Formally verified speculation and deoptimization in a JIT compilerAurèle Barrière, Sandrine Blazy, Olivier Flückiger, David Pichardie et al.POPL 2021 · 38 citations
- JITGuard: Hardening Just-in-time Compilers with SGXTommaso Frassetto, David Gens, Christopher Liebchen, Ahmad-Reza SadeghiCCS 2017 · 37 citations
Related papers
- Towards a verified range analysis for JavaScript JITsFraser Brown, John Renner, Andres Nötzli, Sorin Lerner et al.PLDI 2020 · 28 citations
- Specification and verification in the field: Applying formal methods to BPF just-in-time compilers in the Linux kernelLuke Nelson, Jacob Van Geffen, Emina Torlak, Xi WangOSDI 2020 · 72 citations
- FuzzJIT: Oracle-Enhanced Fuzzing for JavaScript Engine JIT CompilerJunjie Wang, Zhiyi Zhang, Shuang Liu, Xiaoning Du et al.USENIX Security 2023
- FUZZILLI: Fuzzing for JavaScript JIT Compiler VulnerabilitiesSamuel Groß, Simon Koch, Lukas Bernhard, Thorsten Holz et al.NDSS 2023
- Synthesizing JIT Compilers for In-Kernel DSLsJacob Van Geffen, Luke Nelson, Isil Dillig, Xi Wang et al.CAV 2020 · 27 citations
