Iris-Wasm: Robust and Modular Verification of WebAssembly Programs

Author:

Rao Xiaojia1ORCID,Georges Aïna Linn2ORCID,Legoupil Maxime2ORCID,Watt Conrad3ORCID,Pichon-Pharabod Jean2ORCID,Gardner Philippa1ORCID,Birkedal Lars2ORCID

Affiliation:

1. Imperial College London, UK

2. Aarhus University, Denmark

3. University of Cambridge, UK

Abstract

WebAssembly makes it possible to run C/C++ applications on the web with near-native performance. A WebAssembly program is expressed as a collection of higher-order ML-like modules, which are composed together through a system of explicit imports and exports using a host language, enabling a form of higher- order modular programming. We present Iris-Wasm, a mechanized higher-order separation logic building on a specification of Wasm 1.0 mechanized in Coq and the Iris framework. Using Iris-Wasm, we are able to specify and verify individual modules separately, and then compose them modularly in a simple host language featuring the core operations of the WebAssembly JavaScript Interface. Building on Iris-Wasm, we develop a logical relation that enforces robust safety: unknown, adversarial code can only affect other modules through the functions that they explicitly export. Together, the program logic and the logical relation allow us to formally verify functional correctness of WebAssembly programs, even when they invoke and are invoked by unknown code, thereby demonstrating that WebAssembly enforces strong isolation between modules.

Funder

villum investigator grant

EPSRC fellowship

Publisher

Association for Computing Machinery (ACM)

Subject

Safety, Risk, Reliability and Quality,Software

Reference35 articles.

1. Lars Birkedal and Aleš Bizjak . 2017. Lecture Notes on Iris: Higher-Order Concurrent Separation Logic . Aarhus University . Lars Birkedal and Aleš Bizjak. 2017. Lecture Notes on Iris: Higher-Order Concurrent Separation Logic. Aarhus University.

2. Position Paper

3. Daniel Ehrenberg. 2019. WebAssembly JavaScript Interface W3C Recommendation. W3C. https://www.w3.org/TR/wasm-js-api-1/ Daniel Ehrenberg. 2019. WebAssembly JavaScript Interface W3C Recommendation. W3C. https://www.w3.org/TR/wasm-js-api-1/

4. Modular verification of concurrent assembly code with dynamic thread creation and termination

5. Michael Fitzgibbons. 2022. CapableWasm: Bringing Better Interop Down to WebAssembly. https://www.youtube.com/watch?v=E44lTaa2qHk POPL’22 student research competition presentation Michael Fitzgibbons. 2022. CapableWasm: Bringing Better Interop Down to WebAssembly. https://www.youtube.com/watch?v=E44lTaa2qHk POPL’22 student research competition presentation

Cited by 6 articles. 订阅此论文施引文献 订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献

1. A Logical Approach to Type Soundness;Journal of the ACM;2024-07-10

2. RichWasm: Bringing Safe, Fine-Grained, Shared-Memory Interoperability Down to WebAssembly;Proceedings of the ACM on Programming Languages;2024-06-20

3. Bringing the WebAssembly Standard up to Speed with SpecTec;Proceedings of the ACM on Programming Languages;2024-06-20

4. Securing Verified IO Programs Against Unverified Code in F*;Proceedings of the ACM on Programming Languages;2024-01-05

5. An Iris Instance for Verifying CompCert C Programs;Proceedings of the ACM on Programming Languages;2024-01-05

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3