Fuzzing the Rust Typechecker Using CLP
Fuzzing the Rust Typechecker Using CLP
复制标题
使用 CLP 模糊 Rust 类型检查器
DOI:
--
复制
发表时间:
2015
期刊:
影响因子:
--
通讯作者:
B. Hardekopf
中科院分区:
文献类型:
--
作者:
Kyle Dewey;Jared Roesch;B. Hardekopf
Language fuzzing is a bug-finding technique for testing compilers and interpreters; its effectiveness depends upon the ability to automatically generate valid programs in the language under test. Despite the proven success of language fuzzing, there is a severe lack of tool support for fuzzing statically-typed languages with advanced type systems because existing fuzzing techniques cannot effectively and automatically generate well-typed programs that use sophisticated types. In this work we describe how to automatically generate well-typed programs that use sophisticated type systems by phrasing the problem of well-typed program generation in terms of Constraint Logic Programming (CLP). In addition, we describe how to specifically target the typechecker implementation for testing, unlike all existing work which ignores the typechecker. We focus on typechecker precision bugs, soundness bugs, and consistency bugs. We apply our techniques to Rust, a complex, industrialstrength language with a sophisticated type system.