Affiliation:
1. Tel Aviv University, Israel
2. VMware, USA
3. Stanford University, USA
4. Tel Aviv University, Israel / VMware, USA
Abstract
Callbacks are essential in many programming environments, but drastically complicate program understanding and reasoning because they allow to mutate object's local states by external objects in unexpected fashions, thus breaking modularity. The famous DAO bug in the cryptocurrency framework Ethereum, employed callbacks to steal $150M. We define the notion of Effectively Callback Free (ECF) objects in order to allow callbacks without preventing modular reasoning.
An object is ECF in a given execution trace if there exists an equivalent execution trace without callbacks to this object. An object is ECF if it is ECF in every possible execution trace. We study the decidability of dynamically checking ECF in a given execution trace and statically checking if an object is ECF. We also show that dynamically checking ECF in Ethereum is feasible and can be done online. By running the history of all execution traces in Ethereum, we were able to verify that virtually all existing contract executions, excluding these of the DAO or of contracts with similar known vulnerabilities, are ECF. Finally, we show that ECF, whether it is verified dynamically or statically, enables modular reasoning about objects with encapsulated state.
Funder
European Research Council
United States-Israel Binational Science Foundation
The Pazy Foundation
Publisher
Association for Computing Machinery (ACM)
Subject
Safety, Risk, Reliability and Quality,Software
Reference40 articles.
1. 2017. Validity Labs. https://validitylabs.org . [Online]. 2017. Validity Labs. https://validitylabs.org . [Online].
2. Averroes: Whole-Program Analysis without the Whole Program
3. B9Lab. 2017. ING hack challenge. [Online]. B9Lab. 2017. ING hack challenge. [Online].
4. Ownership confinement ensures representation independence for object-oriented programs
Cited by
124 articles.
订阅此论文施引文献
订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献