Verifying object construction
Martin Kellogg, Manli Ran, Manu Sridharan, Martin Schäf, Michael D. Ernst
摘要
In object-oriented languages, constructors often have a combination of required and optional formal parameters. It is tedious and inconvenient for programmers to write a constructor by hand for each combination. The multitude of constructors is error-prone for clients, and client code is difficult to read due to the large number of constructor arguments. Therefore, programmers often use design patterns that enable more flexible object construction-the builder pattern, dependency injection, or factory methods. However, these design patterns can be too flexible: not all combinations of logical parameters lead to the construction of wellformed objects. When a client uses the builder pattern to construct an object, the compiler does not check that a valid set of values was provided. Incorrect use of builders can lead to security vulnerabilities, run-time crashes, and other problems. This work shows how to statically verify uses of object construction, such as the builder pattern. Using a simple specification language, programmers specify which combinations of logical arguments are permitted. Our compile-time analysis detects client code that may construct objects unsafely. Our analysis is based on a novel special case of typestate checking, accumulation analysis, that modularly reasons about accumulations of method calls. Because accumulation analysis does not require precise aliasing information for soundness, our analysis scales to industrial programs. We evaluated it on over 9 million lines of code, discovering defects which included previously-unknown security vulnerabilities and potential null-pointer violations in heavily-used open-source codebases. Our analysis has a low false positive rate and low annotation burden. Our implementation and experimental data are publicly available. CCS Concepts: • Software and its engineering → Software verification; Automated static analysis; Data types and structures.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- Continuous ComplianceMartin Kellogg, Martin Schäf, Serdar Tasiran, Michael D. ErnstASE 2020 · 被引用 16 次
- Lightweight and modular resource leak verificationMartin Kellogg, Narges Shadab, Manu Sridharan, Michael D. ErnstFSE 2021 · 被引用 14 次
- Pluggable Type Inference for FreeMartin Kellogg, Daniel Daskiewicz, Loi Ngo Duc Nguyen, Muyeed Ahmed 等ASE 2023 · 被引用 4 次
- On the Relationship between Code Verifiability and UnderstandabilityKobi Feldman, Martin Kellogg, Oscar ChaparroFSE 2023 · 被引用 2 次
- Verifying the Option Type with Rely-Guarantee ReasoningJames Yoo, Michael D. Ernst, René JustASE 2024
它引用的顶会 Paper1
相关 Paper
- A type-and-effect system for object initializationFengyun Liu, Ondrej Lhoták, Aggelos Biboudis, Paolo G. Giarrusso 等OOPSLA 2020 · 被引用 8 次
- An empirical study on the effectiveness of static C code analyzers for vulnerability detectionStephan Lipp, Sebastian Banescu, Alexander PretschnerISSTA 2022 · 被引用 99 次
- Memory-Safety Verification of Open Programs with Angelic AssumptionsGourav Takhar, Baldip Bijlani, Prantik Chatterjee, Akash Lal 等OOPSLA 2025 · 被引用 2 次
- Validating Soundness and Completeness in Pattern-Match Coverage AnalyzersCyril Moser, Thodoris Sotiropoulos, Chengyu Zhang, Zhendong SuOOPSLA 2025 · 被引用 1 次
- CULPA: Universal Detection of Memory-Safety Bugs in Unsafe Rust Through the Lens of Safety RequirementsHung-Mao Chen, Bo Lu, Xu He, Xiaokuan Zhang 等USENIX Security 2026
