Score
Designs, implements, and analyzes low-level, performance-critical system components in Rust—such as protocol handlers, drivers, or runtime services—focusing on explicit ownership and memory safety. Implements concurrency and synchronization patterns, and measures and optimizes implementations for throughput and latency through benchmarking and profiling.
Rust guarantees memory safety for safe code, yet unsafe code blocks remain susceptible to undefined behavior (UB), undermining system reliability. This paper introduces the first systematic analysis framework targeting Rust’s unsafe code, leveraging concrete execution traces to dynamically detect UB risks and formally delineate correctness boundaries. We propose a trace-based safety judgment criterion and a novel encapsulation soundness evaluation model, integrating static feature extraction with empirical analysis across 12 widely used crates. Our study systematically classifies root causes, recurring patterns, and misuse scenarios of unsafe code, and derives a verifiable set of secure coding guidelines. The framework advances formal verification of Rust programs, enhances toolchain capabilities for UB detection, and informs evidence-based safety standards for industrial Rust development.
Rust lacks a general-purpose dynamic analysis framework capable of supporting diverse runtime analyses. This work proposes DMIR, the first natively Rust-based, event-driven dynamic analysis infrastructure, which captures MIR-level semantics through compiler instrumentation and, for the first time, integrates high-level language features—such as ownership, types, and the memory model—into dynamic analysis. Runtime behaviors are exposed as structured event streams, enabling rich semantic introspection. Leveraging DMIR, we implement three classes of analysis tools: concolic execution, Rust-specific checkers, and control-flow tracing, demonstrating its expressiveness and practicality while maintaining acceptable runtime overhead.
This study systematically evaluates whether Rust can compete with C in performance and resource efficiency for microcontroller firmware development and assesses its industrial viability. Two teams independently implemented identical industrial IoT firmware—one in Rust and the other in C—and key metrics including development effort, memory footprint, and execution speed were compared on real hardware. This work presents the first systematic comparison of the two languages in a genuine industrial context and introduces Ariel OS, a lightweight Rust-based runtime. Empirical results demonstrate that Rust matches or exceeds C in both resource utilization and execution performance, while Ariel OS exhibits a smaller binary footprint, collectively establishing Rust as a reliable and competitive choice for microcontroller firmware development.
Rust’s unsafe code may introduce memory-safety vulnerabilities that compromise the entire program. To address this, we propose an in-process, fine-grained isolation mechanism leveraging Memory Protection Keys (MPK), the first to dynamically isolate safe and unsafe code regions in Rust—thereby preventing cross-region propagation of violations such as heap/stack buffer overflows. Our approach integrates lightweight context switching, cross-isolation secure serialization and communication protocols, and application-level fault detection with automatic rollback of safe code segments. Evaluation shows that our mechanism effectively intercepts diverse heap and stack memory violations; incurs low overhead (<5% on average), substantially outperforming process-level isolation; and supports highly automated integration, validated across multiple real-world Rust projects. Our core contributions are: (1) the first MPK-based isolation framework targeting the Rust safe/unsafe boundary, and (2) integrated rollback guarantees for safe code upon unsafe-region failures.
Rust’s static memory safety guarantees can be violated during foreign function interface (FFI) interactions due to aliasing model incompatibilities—particularly with Tree Borrows—leading to undefined behavior (UB) that existing dynamic analysis tools like Miri cannot detect, creating a critical correctness gap in cross-language interoperability. Method: We conduct the first large-scale empirical study across 37 widely used Rust crates, combining Miri with the LLVM interpreter to enable cross-language cooperative analysis and systematically verify FFI call compliance under the Tree Borrows model. Contribution/Results: Our analysis uncovers 46 instances of UB or unexpected behavior—including in three high-download crates and one officially maintained Rust library—demonstrating that while Tree Borrows relaxes aliasing constraints, it exposes severe blind spots in current tooling for FFI contexts. This work establishes a novel methodology and an empirically grounded benchmark for verifying Rust’s cross-language memory safety.
This study addresses the challenge of verifying liveness properties in Rust asynchronous runtimes by proposing a lightweight, modular proof technique. Methodologically, it constructs a formal verification framework grounded in a model of the Rust language, integrating static analysis with a modular proof architecture. This approach pioneers a liveness verification paradigm for highly concurrent and heavily optimized libraries, overcoming traditional verification bottlenecks. Experimental results demonstrate that the proposed technique successfully verifies the eventual progress of multiple critical components, ensuring the reliable advancement of asynchronous tasks. Ultimately, this work provides a scalable pathway for formally guaranteeing low-level system infrastructure, significantly enhancing the reliability of the Rust asynchronous ecosystem.
This work addresses the challenge posed by unsafe code in Rust, which bypasses the type system and may violate pointer aliasing rules, thereby compromising memory safety and the correctness of compiler optimizations. The paper presents the first modular program logic for unsafe Rust, formally capturing ownership and borrowing semantics to enable static, compositional verification of pointer aliasing constraints. By doing so, it bridges the verification gap left by Rust’s type system within unsafe regions, supporting modular reasoning while ensuring that programs containing unsafe code still adhere to Rust’s memory safety guarantees.
This work addresses the limitations of existing large language models in generating concurrent, stateful Rust API tests—namely, frequent violations of preconditions, insufficient depth, and degeneration into sequential execution—as well as the heavy manual modeling burden of traditional model-driven testing. The authors propose a Petri net–guided test generation framework that employs colored Petri nets to formally model API resources, lifecycles, and causal dependencies. This formalism yields valid, near-valid, and partially ordered concurrent scenarios as constrained intermediate representations. Guided by local fidelity contracts, structural repair loops, and schedule shaping mechanisms, large language models synthesize executable tests exhibiting high conflict and coverage. The approach enables low-cost translation from formal scenarios to test code, significantly improving the legality, depth, and concurrency coverage of generated tests.
This study addresses the lack of mature coding guidelines for Rust that align with functional safety standards such as ISO 26262, which hinders its adoption in safety-critical systems. The work presents the first systematic mapping framework from MISRA C++ 2023—comprising 179 rules—to Rust, evaluating the applicability of each rule within both safe and unsafe subsets of the language through semantic analysis, comparative language feature assessment, and Rust’s memory safety model. The analysis reveals that 47.75% of the rules are inherently enforced by Rust, with 36 already satisfied when using only safe Rust. Furthermore, 69 rules are identified as requiring retention or adaptation, leading to the proposal of a Rust-specific coding guideline. All mapping results have been made publicly available as open-source artifacts.
This study addresses the absence of rigorous formal semantics for Rust’s concurrent and asynchronous programming, which has hindered the deductive verification of such programs. We propose a modular, source-level formal semantics for Rust that adopts a “locally abstract, globally concrete” framework to decouple local evaluation from global traces. This semantics is further extended to model the Tokio runtime, providing the first complete formalization of Rust’s asynchronous features and scheduler fairness. Building upon this semantic foundation, we develop a program logic and prove its soundness, thereby enabling efficient source-level verification of asynchronous Rust programs. Ultimately, this work establishes both the theoretical foundations and methodological support necessary for the formal assurance of safety-critical system-level software.