TransForm: Formally Specifying Transistency Models and Synthesizing Enhanced Litmus Tests
Naorin Hossain, Caroline Trippel, Margaret Martonosi
Abstract
Memory consistency models (MCMs) specify the legal ordering and visibility of shared memory accesses in a parallel program. Traditionally, instruction set architecture (ISA) MCMs assume that relevant program-visible memory ordering behaviors only result from shared memory interactions that take place between user-level program instructions. This assumption fails to account for virtual memory (VM) implementations that may result in additional shared memory interactions between user-level program instructions and both 1) system-level operations (e.g., address remappings and translation lookaside buffer invalidations initiated by system calls) and 2) hardware-level operations (e.g., hardware page table walks and dirty bit updates) during a user-level program's execution. These additional shared memory interactions can impact the observable memory ordering behaviors of user-level programs. Thus, memory transistency models (MTMs) have been coined as a superset of MCMs to additionally articulate VM-aware consistency rules. However, no prior work has enabled formal MTM specifications, nor methods to support their automated analysis.
To fill the above gap, this paper presents the TransForm framework. First, TransForm features an axiomatic vocabulary for formally specifying MTMs. Second, TransForm includes a synthesis engine to support the automated generation of litmus tests enhanced with MTM features (i.e., enhanced litmus tests, or ELTs) when supplied with a TransForm MTM specification. As a case study, we formally define an estimated MTM for Intel x86 processors, called x86t elt, that is based on observations made by an ELT-based evaluation of an Intel x86 MTM implementation from prior work and available public documentation [23,29]. Given x86t elt and a synthesis bound (on program size) as input, TransForm's synthesis engine successfully produces a complete set of ELTs (for synthesis bounds that complete within one week) including relevant hand-curated ELTs from prior work, plus over 100 more.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext f1cfdcd6-0a81-481c-add0-715b0c838133Cited by top-tier papers2
- Synthesizing Formal Models of Hardware from RTL for Efficient Verification of Memory Model ImplementationsYao Hsiao, Dominic P. Mulligan, Nikos Nikoleris, Gustavo Petri et al.MICRO 2021 · 20 citations
- CounterPoint: Using Hardware Event Counters to Refute and Refine Microarchitectural AssumptionsNick Lindsay, Caroline Trippel, Anurag Khandelwal, Abhishek BhattacharjeeASPLOS 2026
Builds on1
Related papers
- Extending Intel-x86 consistency and persistency: formalising the semantics of Intel-x86 memory types and non-temporal storesAzalea Raad, Luc Maranget, Viktor VafeiadisPOPL 2022 · 24 citations
- Taming x86-TSO persistencyArtem Khyzha, Ori LahavPOPL 2021 · 26 citations
- Persistency semantics of the Intel-x86 architectureAzalea Raad, John Wickerson, Gil Neiger, Viktor VafeiadisPOPL 2020 · 61 citations
- Foundations of empirical memory consistency testingJake Kirkham, Tyler Sorensen, Esin Tureci, Margaret MartonosiOOPSLA 2020 · 7 citations
- Extending the C/C++ Memory Model with Inline AssemblyPaulo Emílio de Vilhena, Ori Lahav, Viktor Vafeiadis, Azalea RaadOOPSLA 2024 · 1 citation
