CLIR: Liveness-Driven and Structure-Aware Fuzzing for the Cranelift Compiler
Shangtong Cao, Tianlei Song, Qiuping Yi, Tianyu Chen, Guoai Xu, Ningyu He, Haoyu Wang
摘要
Modern compilers are complex software systems that must correctly translate high-level programming languages into machine code across multiple architectures. Cranelift, a fast and modern compiler backend originally developed for WebAssembly and recently adopted as an experimental backend for Rust, has gained increasing importance due to its superior compilation speed compared to LLVM and comprehensive multiarchitecture support, including x86-64, AArch64, s390x, and RISCV64. However, despite decades of development in compiler testing, testing Cranelift still presents unique challenges, including (1) constructing valid IR under the strict enforcement of SSA form, (2) generating sequences with sufficient computational density to stress backend components, and (3) balancing broad backend coverage with efficient root cause analysis across heterogeneous architectures.
To address these challenges, we propose CLIR, a differential testing framework that integrates a syntaxpreserving hierarchical generation strategy to guarantee SSA validity, a liveness-guided instruction refinement mechanism to maximize computational density, and a diagnosis-guided cross-architecture adaptation scheme to facilitate efficient root cause analysis across heterogeneous backends. Our comprehensive evaluation demonstrates that CLIR significantly outperforms existing state-of-the-art baselines, detecting 8×, 24×, and 8× more unique bugs than cranelift-fuzzgen, wasm-smith, and WASMaker, respectively, while RustSmith uncovered no bugs. Consequently, within 72 hours of testing, CLIR discovered 24 bugs spanning all target architectures, with 21 confirmed and 9 fixed.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper10
- RedLeaf: Isolation and Communication in a Safe Operating SystemVikram Narayanan, Tianjiao Huang, David Detweiler, Dan Appel 等OSDI 2020 · 被引用 86 次
- Theseus: an Experiment in Operating System Structure and State ManagementKevin Boos, Namitha Liyanage, Ramla Ijaz, Lin ZhongOSDI 2020 · 被引用 67 次
- Enriching Compiler Testing with Real Program from Bug ReportHao ZhongASE 2022 · 被引用 24 次
- Copy-and-patch compilation: a fast compilation algorithm for high-level languages and bytecodeHaoran Xu, Fredrik KjolstadOOPSLA 2021 · 被引用 24 次
- Boosting Compiler Testing by Injecting Real-World CodeShaohua Li, Theodoros Theodoridis, Zhendong SuPLDI 2024 · 被引用 24 次
相关 Paper
- Rustlantis: Randomized Differential Testing of the Rust CompilerQian Wang, Ralf JungOOPSLA 2024 · 被引用 14 次
- IRFuzzer: Specialized Fuzzing for LLVM Backend Code GenerationYuyang Rong, Zhanghan Yu, Zhenkai Weng, Stephen Neuendorffer 等ICSE 2025 · 被引用 1 次
- MLIRSmith: Random Program Generation for Fuzzing MLIR Compiler InfrastructureHaoyu Wang, Junjie Chen, Chuyue Xie, Shuang Liu 等ASE 2023 · 被引用 16 次
- Clozemaster: Fuzzing Rust Compiler by Harnessing Llms for Infilling Masked Real ProgramsHongyan Gao, Yibiao Yang, Maolin Sun, Jiangchang Wu 等ICSE 2025 · 被引用 6 次
- BackSmith: A Systematic Approach to Testing Compiler BackendsHongyu Chen, Yu Wang, Jianhua Zhao, Ke WangOOPSLA 2026
