Automated bug localization in JIT compilers

Automated bug localization in JIT compilers
复制标题

DOI:
10.1145/3453933.3454021
复制
发表时间:
2021-04
期刊:
Proceedings of the 17th ACM SIGPLAN/SIGOPS International Conference on Virtual Execution Environments
影响因子:
--
通讯作者:
HeuiChan Lim;S. Debray
HeuiChan Lim;S. Debray
中科院分区:
其他
文献类型:
--
作者:
HeuiChan Lim;S. Debray

文献摘要

相似文献

许多广泛部署的现代编程系统使用即时(JIT)编译器来提高性能。基于JIT的系统的规模和复杂性,再加上JIT编译器优化的动态特性,使得快速定位和修复JIT编译器错误具有挑战性。与此同时,JIT编译器错误可能会导致可利用的安全漏洞,因此快速错误定位非常重要。现有的自动bug定位工作集中在静态代码上,即,不是在运行时生成的代码,因此无法处理JIT编译器中在优化期间生成不正确代码的错误。本文描述了一种在JIT编译器中自动化错误定位的方法,下到不同的优化阶段,从一个初始的概念证明(Proof-of-Concept,简称PROF)输入开始,演示错误。在Google的V8 JavaScript解释器和TurboFan JIT编译器上使用我们的想法的原型实现的实验表明,它可以成功地识别错误的优化阶段。
Many widely-deployed modern programming systems use just-in-time (JIT) compilers to improve performance. The size and complexity of JIT-based systems, combined with the dynamic nature of JIT-compiler optimizations, make it challenging to locate and fix JIT compiler bugs quickly. At the same time, JIT compiler bugs can result in exploitable security vulnerabilities, making rapid bug localization important. Existing work on automated bug localization focuses on static code, i.e., code that is not generated at runtime, and so cannot handle bugs in JIT compilers that generate incorrect code during optimization. This paper describes an approach to automated bug localization in JIT compilers, down to the level of distinct optimization phases, starting with a single initial Proof-of-Concept (PoC) input that demonstrates the bug. Experiments using a prototype implementation of our ideas on Google’s V8 JavaScript interpreter and TurboFan JIT compiler demonstrates that it can successfully identify buggy optimization phases.