CLower: Detecting Compiler Pessimization Bugs through Redundant Memory Accesses
This program is tentative and subject to change.
Compilers are expected to generate optimized code, but they sometimes introduce
pessimizations, quality-degrading redundant instructions. These bugs not only incur
performance overhead but also, critically, expand the attack surface by introducing
unexpected side effects (e.g., redundant memory accesses) without breaking compilation
correctness. Existing bug-finding methods are neither designed for nor effective
at identifying such security-sensitive pessimizations.
This paper presents CLower, a novel, black-box approach for automatically detecting
compiler pessimizations via redundant memory accesses.
CLower's core insight is that any extra global memory accesses in a fully optimized
binary, compared to the source, indicate a pessimization. To reliably distinguish
compiler-introduced redundancy from source-level redundancy, we generate random
C programs in which each global variable has a predetermined, controlled number of memory accesses.
CLower then executes the instrumented binary and verifies whether superfluous accesses
have been introduced during compilation.
We applied CLower to GCC and LLVM, reporting 23 unique bugs (21 in GCC, 2 in Clang),
with 16 confirmed as new pessimization bugs.
Our evaluation shows that CLower accurately detects diverse, impactful pessimization
bugs, the majority of which (75%) also manifest for heap-allocated objects,
demonstrating that the underlying compiler flaws are general and not limited to global memory.
Furthermore, we identify a systematic conflict between
compiler optimizations and pessimization bugs, which causes many such bugs to remain hidden
in compiler versions. This study sheds light on the under-explored area of compiler
pessimization and provides a practical tool for improving compiler quality.
This program is tentative and subject to change.
Mon 5 OctDisplayed time zone: Pacific Time (US & Canada) change
13:30 - 15:00 | Testing Compilers and SolversOOPSLA at Junior Ballroom 3&4 Chair(s): Harrison Goldstein University at Buffalo | ||
13:30 18mTalk | BackSmith: A Systematic Approach to Testing Compiler Backends OOPSLA Hongyu Chen Nanjing University, Yu Wang Nanjing University, Jianhua Zhao Nanjing University, Ke Wang Nanjing University DOI | ||
13:48 18mTalk | CLower: Detecting Compiler Pessimization Bugs through Redundant Memory Accesses OOPSLA Jianhao Xu Southeast University, Kunbo Zhang State Key Laboratory for Novel Software Technology at Nanjing University, Mathias Payer EPFL, Kangjie Lu University of Minnesota, Bing Mao State Key Laboratory for Novel Software Technology at Nanjing University DOI | ||
14:06 18mTalk | Seeking Evidence of Further Optimization: Detecting Missed Optimizations through Compiler’s Native Analyses OOPSLA Yi Zhang Nanjing University, Yu Wang Nanjing University, Ke Wang Nanjing University, Linzhang Wang Nanjing University DOI | ||
14:24 18mTalk | Validating Optimizing SMT Solvers via Cross-Theory Approximation OOPSLA Maolin Sun Nanjing University, Fuqi Jia Institute of Software at Chinese Academy of Sciences; University of Chinese Academy of Sciences, Yibiao Yang Nanjing University, Yuming Zhou Nanjing University DOI | ||