Translation Validation for JIT Compiler in the V8 JavaScript Engine
Seungwan Kwon, Jaeseong Kwon, Wooseok Kang, Juneyoung Lee, Kihong Heo
摘要
We present TurboTV, a translation validator for the JavaScript (JS) just-in-time (JIT) compiler of V8. While JS engines have become a crucial part of various software systems, their emerging adaption of JIT compilation makes it increasingly challenging to ensure their correctness. We tackle this problem with an SMT-based translation validation (TV) that checks whether a specific compilation is semantically correct. We formally define the semantics of IR of TurboFan (JIT compiler of V8) as SMT encoding. For efficient validation, we design a staged strategy for JS JIT compilers. This allows us to decompose the whole correctness checking into simpler ones. Furthermore, we utilize fuzzing to achieve practical TV. We generate a large number of JS functions using a fuzzer to trigger various optimization passes of TurboFan and validate their compilation using TurboTV. Lastly, we demonstrate that TurboTV can also be used for cross-language TV. We show that TurboTV can validate the translation chain from LLVM IR to TurboFan IR, collaborating with an off-the-shelf TV tool for LLVM. We evaluated TurboTV on various sets of JS and LLVM programs. TurboTV effectively validated a large number of compilations of TurboFan with a low false positive rate and discovered a new miscompilation in LLVM.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper6
- Optimization-Directed Compiler Fuzzing for Continuous Translation ValidationJaeseong Kwon, Bongjun Jang, Juneyoung Lee, Kihong HeoPLDI 2025 · 被引用 5 次
- Extraction and Mutation at a High Level: Template-Based Fuzzing for JavaScript EnginesWai Kin Wong, Dongwei Xiao, Anthony Cheuk Tung Lai, Yiteng Peng 等OOPSLA 2025 · 被引用 4 次
- Translation Validation for LLVM's AArch64 BackendRyan Berger, Mitch Briles, Nader Boushehrinejad Moradi, Nicholas Coughlin 等OOPSLA 2025 · 被引用 3 次
- Semantic Reification: A New Paradigm for Random Program GenerationKavya Chopra, Cong Li, Thodoris Sotiropoulos, Zhendong SuPLDI 2026
- State-Aware Fuzzing of JavaScript Engines with LLM-Guided InstrumentationWai Kin Wong, Dongwei Xiao, Anthony Cheuk Tung Lai, Ping Fan Ke 等SOSP 2026
它引用的顶会 Paper10
- CodeAlchemist: Semantics-Aware Code Generation to Find Vulnerabilities in JavaScript EnginesHyungSeok Han, DongHyeon Oh, Sang Kil ChaNDSS 2019 · 被引用 178 次
- Fuzzing JavaScript Engines with Aspect-preserving MutationSoyeon Park, Wen Xu, Insu Yun, Daehee Jang 等S&P 2020 · 被引用 126 次
- Alive2: bounded translation validation for LLVMNuno P. Lopes, Juneyoung Lee, Chung-Kil Hur, Zhengyang Liu 等PLDI 2021 · 被引用 109 次
- JIT-Picking: Differential Fuzzing of JavaScript EnginesLukas Bernhard, Tobias Scharnowski, Moritz Schloegel, Tim Blazytko 等CCS 2022 · 被引用 42 次
- Formally verified speculation and deoptimization in a JIT compilerAurèle Barrière, Sandrine Blazy, Olivier Flückiger, David Pichardie 等POPL 2021 · 被引用 38 次
相关 Paper
- FuzzJIT: Oracle-Enhanced Fuzzing for JavaScript Engine JIT CompilerJunjie Wang, Zhiyi Zhang, Shuang Liu, Xiaoning Du 等USENIX Security 2023
- Validating JIT Compilers via Compilation Space ExplorationCong Li, Yanyan Jiang, Chang Xu, Zhendong SuSOSP 2023 · 被引用 22 次
- FUZZILLI: Fuzzing for JavaScript JIT Compiler VulnerabilitiesSamuel Groß, Simon Koch, Lukas Bernhard, Thorsten Holz 等NDSS 2023
- OptFuzz: Optimization Path Guided Fuzzing for JavaScript JIT CompilersJiming Wang, Yan Kang, Chenggang Wu, Yuhao Hu 等USENIX Security 2024 · 被引用 7 次
- Language-parametric compiler validation with application to LLVMTheodoros Kasampalis, Daejun Park, Zhengyao Lin, Vikram S. Adve 等ASPLOS 2021 · 被引用 18 次
