Abstract Domains of Affine Relations

被引:8
|
作者
Elder, Matt [1 ]
Lim, Junghee [2 ]
Sharma, Tushar [3 ]
Andersen, Tycho [4 ]
Reps, Thomas [5 ,6 ]
机构
[1] Quixey, Mountain View, CA 94041 USA
[2] GrammaTech Inc, Ithaca, NY 14850 USA
[3] Univ Wisconsin, Dept Comp Sci, Madison, WI 53706 USA
[4] Canon Grp Ltd, London SE1 0SU, England
[5] Univ Wisconsin, Dept Comp Sci, Madison, WI 53703 USA
[6] GrammaTech Inc, Madison, WI 53705 USA
基金
美国国家科学基金会;
关键词
Algorithms; Theory; Verification; Experimentation; Performance; Abstract domain; abstract interpretation; affine relation; static analysis; modular arithmetic; Howell form; symbolic abstraction; PRECISE INTERPROCEDURAL ANALYSIS; STATIC ANALYSIS; PROGRAMS; SYSTEM;
D O I
10.1145/2651361
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
This article considers some known abstract domains for affine-relation analysis (ARA), along with several variants, and studies how they relate to each other. The various domains represent sets of points that satisfy Aline relations over variables that hold machine integers and are based on an extension of linear algebra to modules over a ring (in particular, arithmetic performed modulo 2(w), for some machine-integer width w). We show that the abstract domains of Muller-Olm/Seidl (MOS) and King,/Sondergaard (KS) are, in general, incomparable. However, we give sound interconversion methods. In other words, we give an algorithm to convert a KS element v(KS) to an overapproximating MOS element v(mos) that is, y(v(Ks)) subset of gamma(v(mos)) as well as an algorithm to convert an MOS element w(mos) to an overapproximating KS element w(KS)-that is, Y(w(mos)) subset of y(w(KS)) The article provides insight on the range of options that one has for performing ARA in a program analyzer: We describe how to perform a greedy, operator-by-operator abstraction method to obtain KS abstract transtbrmers. We also describe a more global approach to obtaining KS abstract transformers that considers the semantics of an entire instruction, basic block, or other loop-free program fragment. The latter method can yield best abstract transformers, and hence can be more precise than the former method. However, the latter method is more expensive. We also explain how to use the KS domain for interprocedural program analysis using a bit-precise concrete semantics, but without bit blasting. Categories and Subject Descriptors: D.2.4 [Software Engineering]: Software/Program Verification Assertion checkers; Formal methods; Validation; F.3.1 [Logics and Meanings of Programs]: Specifying and Verifying and Reasoning about Programs Invariants; Mechanical verification
引用
收藏
页码:1 / 73
页数:73
相关论文
共 50 条
  • [1] Abstract Domains of Affine Relations
    Elder, Matt
    Lim, Junghee
    Sharma, Tushar
    Andersen, Tycho
    Reps, Thomas
    STATIC ANALYSIS, 2011, 6887 : 198 - 215
  • [2] AFFINE COORDINATIZATION OF ABSTRACT GEMETRIES
    WILLE, R
    CANADIAN MATHEMATICAL BULLETIN, 1967, 10 (02): : 302 - &
  • [3] Sum of Abstract Domains
    Amato, Gianluca
    Di Maio, Simone Di Nardo
    Scozzari, Francesca
    NASA FORMAL METHODS (NFM 2015), 2015, 9058 : 35 - 49
  • [5] Temporal Abstract Domains
    Bertrane, Julien
    2011 16TH IEEE INTERNATIONAL CONFERENCE ON ENGINEERING OF COMPLEX COMPUTER SYSTEMS (ICECCS), 2011, : 3 - 12
  • [6] ON ABSTRACT AFFINE NEAR-RINGS
    GONSHOR, H
    PACIFIC JOURNAL OF MATHEMATICS, 1964, 14 (04) : 1237 - &
  • [7] A uniform property of affine domains
    Wang, HJ
    JOURNAL OF ALGEBRA, 1999, 215 (02) : 500 - 508
  • [8] ABSTRACT FAMILIES OF RELATIONS
    SANTOS, ES
    INFORMATION SCIENCES, 1979, 19 (02) : 155 - 177
  • [9] String Abstract Domains and Their Combination
    Sondergaard, Harald
    LOGIC-BASED PROGRAM SYNTHESIS AND TRANSFORMATION (LOPSTR 2021), 2022, 13290 : 1 - 15
  • [10] Abstract Domains for Type Juggling
    Arceri V.
    Maffeis S.
    Electronic Notes in Theoretical Computer Science, 2017, 331 : 41 - 55