End-to-end Compositional Verification of Program Safety through Verified and Verifying Compilation

📅 2025-10-11
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
End-to-end security verification remains challenging in modern safe languages (e.g., Rust) due to the coexistence of safe and unsafe modules, which undermines compositional reasoning and hinders holistic assurance. Method: We propose the “Open Safety” theoretical framework, formalizing composable security via open-labeled transition systems; it enables modular, heterogeneous verification—separately verifying safe and unsafe components—and target-level composition. The framework unifies verified compilation and verification-aware compilation, integrating separation logic, ownership types, and verified compilation techniques to support progressive derivation from partial to full safety. Contribution/Results: We implement a verified compiler for Owlang—a custom Rust-like language—and evaluate it on an Owlang/C hybrid hash table case study. Our approach demonstrates both effectiveness—achieving end-to-end security guarantees—and scalability—supporting cross-language, mixed-safety module composition—thereby advancing practical, compositional security verification for systems programming languages.

Technology Category

Natural Language Processing: Safety and RobustnessConstraint Satisfaction and Optimization: Satisfiability Modulo TheoriesComputer Vision: Language and Vision

Application Category

Security and Privacy: Data transparency and provenanceSystems and Infrastructure for Web, Mobile and WoT: Experiences and lessons learnt from Web-based algorithms and system deploymentsSemantics and Knowledge: Provenance, trust, security and privacy, and ethical issues in managing semantic data
📝 Abstract
Program safety (i.e., absence of undefined behaviors) is critical for correct operation of computer systems. It is usually verified at the source level (e.g., by separation logics) and preserved to the target by verified compilers (e.g., CompCert), thereby achieving end-to-end verification of safety. However, modern safe programming languages like Rust pose new problems in achieving end-to-end safety. Because not all functionalities can be implemented in the safe language, mixing safe and unsafe modules is needed. Therefore, verified compilation must preserve a modular notion of safety which can be composed at the target level. Furthermore, certain classes of errors (e.g., memory errors) are automatically excluded by verifying compilation (e.g., borrow checking) for modules written in safe languages. As a result, verified compilation needs to cooperate with verifying compilation to ensure end-to-end safety. To address the above problems, we propose a modular and generic definition of safety called open safety based on program semantics described as open labeled transition systems (LTS). Open safety is composable at the boundary of modules and can be modularly preserved by verified compositional compilation. Those properties enable separate verification of safety for heterogeneous modules and composition of the safety results at the target level. Open safety can be generalized to partial safety (i.e., only a certain class of errors can occur). By this we formalized the correctness of verifying compilation as derivation of total safety from partial safety. We demonstrate how our framework can combine verified and verifying compilation by developing a verified compiler for an ownership language (called Owlang) inspired by Rust. We evaluate our approach on the compositional safety verification using a hash map implemented by Owlang and C.
Problem

Research questions and friction points this paper is trying to address.

Ensuring end-to-end program safety with mixed safe and unsafe modules
Preserving modular safety through verified compositional compilation
Combining verified and verifying compilation for heterogeneous language verification
Innovation

Methods, ideas, or system contributions that make the work stand out.

Open safety definition based on program semantics
Verified compositional compilation preserves modular safety
Combining verified and verifying compilation for end-to-end safety
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
J
Jinhua Wu
Shanghai Jiao Tong University, China
Y
Yuting Wang
Shanghai Jiao Tong University, China
L
Liukun Yu
Shanghai Jiao Tong University, China
L
Linglong Meng
University of Minnesota, USA