Semantic Reification: A New Paradigm for Random Program Generation
Kavya Chopra, Cong Li, Thodoris Sotiropoulos, Zhendong Su
摘要
We introduce semantic reification, a novel paradigm for random program generation that centers on program semantics rather than syntax. Our key insight is to reformulate random program generation to capture two types of program semantics: (1) compile-time semantics (what a program can do), represented by the control flow graph (CFG), and (2) runtime semantics (what a program actually does), represented by execution paths within the CFG. For any CFG and any execution path on it, semantic reification constructs a program guaranteed to be well-behaved with respect to a specific input and output. This means that when executed with this input, the program deterministically follows the designated execution path to produce the expected output. This paradigm differs from existing work by supporting arbitrary control flow such as unbounded loops and irreducible regions, while still ensuring that the generated programs are semantically correct and terminating. We develop a practical realization of this paradigm. First, we introduce symbolic function reification that integrates a lightweight form of symbolic execution into the generation process to generate an individual, leaf function (i.e., a function that is free of function calls). Each leaf function satisfies the constraints of a given CFG and a selected execution path. Second, we compose multiple leaf functions into a larger, more complex program via semantics-preserving peephole rewriting, guided by an arbitrary call graph. Over five months, our implementation for C compilers, Reify, has uncovered 59 bugs in GCC and LLVM (57 confirmed, 27 fixed), 24 of which are long-latent. Among them, 36 are wrong-code bugs, many are high-priority issues, and most of them involve semantic characteristics overlooked by existing tools. We believe semantic reification opens new directions for research beyond compilers, such as validating debuggers, analyzers, and verifiers.
CCS Concepts: • Software and its engineering → Compilers; Software testing and debugging.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper14
- Random testing for C and C++ compilers with YARPGenVsevolod Livinskii, Dmitry Babokin, John RegehrOOPSLA 2020 · 被引用 140 次
- GrayC: Greybox Fuzzing of Compilers and Analysers for CKarine Even-Mendoza, Arindam Sharma, Alastair F. Donaldson, Cristian CadarISSTA 2023 · 被引用 52 次
- Coverage-guided tensor compiler fuzzing with joint IR-pass mutationJiawei Liu, Yuxiang Wei, Sen Yang, Yinlin Deng 等OOPSLA 2022 · 被引用 50 次
- Fuzzing Loop Optimizations in Compilers for C++ and Data-Parallel LanguagesVsevolod Livinskii, Dmitry Babokin, John RegehrPLDI 2023 · 被引用 42 次
- Finding typing compiler bugsStefanos Chaliasos, Thodoris Sotiropoulos, Diomidis Spinellis, Arthur Gervais 等PLDI 2022 · 被引用 36 次
相关 Paper
- Boosting Compiler Testing by Injecting Real-World CodeShaohua Li, Theodoros Theodoridis, Zhendong SuPLDI 2024 · 被引用 24 次
- Rustlantis: Randomized Differential Testing of the Rust CompilerQian Wang, Ralf JungOOPSLA 2024 · 被引用 14 次
- Enriching Compiler Testing with Real Program from Bug ReportHao ZhongASE 2022 · 被引用 24 次
- Enhanced Compiler Bug Isolation via Memoized SearchJunjie Chen, Haoyang Ma, Lingming ZhangASE 2020 · 被引用 36 次
- IRFuzzer: Specialized Fuzzing for LLVM Backend Code GenerationYuyang Rong, Zhanghan Yu, Zhenkai Weng, Stephen Neuendorffer 等ICSE 2025 · 被引用 1 次
