🤖 AI Summary
This study addresses the absence of rigorous formal semantics for Rust’s concurrent and asynchronous programming, which has hindered the deductive verification of such programs. We propose a modular, source-level formal semantics for Rust that adopts a “locally abstract, globally concrete” framework to decouple local evaluation from global traces. This semantics is further extended to model the Tokio runtime, providing the first complete formalization of Rust’s asynchronous features and scheduler fairness. Building upon this semantic foundation, we develop a program logic and prove its soundness, thereby enabling efficient source-level verification of asynchronous Rust programs. Ultimately, this work establishes both the theoretical foundations and methodological support necessary for the formal assurance of safety-critical system-level software.
📝 Abstract
Formally reasoning about Rust programs requires a rigorous formal semantics, especially in the context of deductive verification and concurrent programming. We present a modular, flexible semantics for a significant subset of (close to) source code level Rust, based on the recent locally abstract, globally concrete semantics framework, separating local evaluation of expressions from their composition into concrete traces. The semantics is extended to model Rust's asynchronous programming features and Rust's most popular async runtime, Tokio. Based on our more abstract formalization, we establish the fairness of Tokio's scheduler. Further, we show the applicability of our semantics to deductive verification of Rust by providing soundness proofs for a Rust program logic.