A Multilanguage Static Analysis of Python Programs with Native C Extensions

A Multilanguage Static Analysis of Python Programs with Native C Extensions
复制标题

DOI:
10.1007/978-3-030-88806-0_16
复制
发表时间:
2021
期刊:
--
影响因子:
--
通讯作者:
Raphaël Monat;Abdelraouf Ouadjaout;A. Miné
Raphaël Monat;Abdelraouf Ouadjaout;A. Miné
中科院分区:
其他
文献类型:
--
作者:
Raphaël Monat;Abdelraouf Ouadjaout;A. Miné

文献摘要

被引文献

相似文献

现代程序越来越多地使用多种语言,以便从每种编程语言的优点中受益并重用库。例如,开发人员可能希望将联合收割机高级Python代码与面向性能的低级C代码结合起来。事实上,GitHub上下载量最大的200个Python库中,有五分之一包含C代码。静态分析器倾向于关注单一语言,并可能使用存根来模拟外部函数调用的行为。然而,存根的实现成本很高,并且会破坏分析器的可靠性。在这项工作中,我们设计了一个静态分析器的抽象解释,可以处理Python程序调用C扩展。它直接和全自动地分析Python和C源代码。它报告可能在Python、C和接口中发生的运行时错误。我们以模块化的方式实现了我们的分析:它重用了在同一个分析器中编写的现成的C和Python分析。这种方法允许在不同语言的抽象域之间共享。我们的分析器可以在几分钟内处理数千行C和Python的真实库的测试。
Modern programs are increasingly multilanguage, to benefit from each programming language’s advantages and to reuse libraries. For example, developers may want to combine high-level Python code with low-level, performance-oriented C code. In fact, one in five of the 200 most downloaded Python libraries available on GitHub contains C code. Static analyzers tend to focus on a single language and may use stubs to model the behavior of foreign function calls. However, stubs are costly to implement and undermine the soundness of analyzers. In this work, we design a static analyzer by abstract interpretation that can handle Python programs calling C extensions. It analyses directly and fully automatically both the Python and the C source codes. It reports runtime errors that may happen in Python, in C, and at the interface. We implemented our analysis in a modular fashion: it reuses off-the-shelf C and Python analyses written in the same analyzer. This approach allows sharing between abstract domains of different languages. Our analyzer can tackle tests of real-world libraries a few thousand lines of C and Python long in a few minutes.