Understanding memory and thread safety practices and issues in real-world Rust programs
- 11 June 2020
- conference paper
- conference paper
- Published by Association for Computing Machinery (ACM) in Proceedings of the 41st ACM SIGPLAN Conference on Programming Language Design and Implementation
Abstract
Rust is a young programming language designed for systems software development. It aims to provide safety guarantees like high-level languages and performance efficiency like low-level languages. The core design of Rust is a set of strict safety rules enforced by compile-time checking. To support more low-level controls, Rust allows programmers to bypass these compiler checks to write unsafe code. It is important to understand what safety issues exist in real Rust programs and how Rust safety mechanisms impact programming practices. We performed the first empirical study of Rust by close, manual inspection of 850 unsafe code usages and 170 bugs in five open-source Rust projects, five widely-used Rust libraries, two online security databases, and the Rust standard library. Our study answers three important questions: how and why do programmers write unsafe code, what memory-safety issues real Rust programs have, and what concurrency bugs Rust programmers make. Our study reveals interesting real-world Rust program behaviors and new issues Rust programmers make. Based on our study results, we propose several directions of building Rust bug detectors and built two static bug detectors, both of which revealed previously unknown bugs.Keywords
This publication has 30 references indexed in Scilit:
- Understanding and generating high quality patches for concurrency bugsPublished by Association for Computing Machinery (ACM) ,2016
- CREDALPublished by Association for Computing Machinery (ACM) ,2016
- Driller: Augmenting Fuzzing Through Selective Symbolic ExecutionPublished by Internet Society ,2016
- Fuzzing the Rust Typechecker Using CLP (T)Published by Institute of Electrical and Electronics Engineers (IEEE) ,2015
- What change history tells us about thread synchronizationPublished by Association for Computing Machinery (ACM) ,2015
- Understanding and detecting real-world performance bugsPublished by Association for Computing Machinery (ACM) ,2012
- Learning from mistakesPublished by Association for Computing Machinery (ACM) ,2008
- RaceTrackPublished by Association for Computing Machinery (ACM) ,2005
- An empirical study of operating systems errorsPublished by Association for Computing Machinery (ACM) ,2001
- EraserACM Transactions on Computer Systems, 1997