Reference. Code-Specify-Test-Debug-Prove: Flexibly Integrating Separation Logic Specification into Conventional Workflows
We seek to enable more flexible use of rich specifications in a variety of ways that smoothly extend conventional software development practice. We show how a single specification language, based on separation logic to capture the subtle ownership disciplines of systems code, can be used for runtime assertion checking, for property-based testing, and for formal machine-checked proof—and how each of these complements and supports the others. We demonstrate all this on a challenging example: a component of a production hypervisor, running both stand-alone at user level and in situ in the hypervisor.
Cite
Cites 78 works (4 here)
With notes (4)
Fulminate: Testing CN Separation-Logic Specifications in C banerjee-2025-fulminate
Separation logic has become an important tool for formally capturing and reasoning about the ownership patterns of imperative programs, originally for paper proof, and now the foundation for industrial static analyses and multiple proof tools. However, there has been very little work on program testing of separationlogic specifications in concrete execution. At first sight, separation-logic formulas are hard to evaluate in reasonable time, with their implicit quantification over heap splittings, and other explicit existentials. In this paper we observe that a restricted fragment of separation logic, adopted in the CN proof tool to enable predictable proof automation, also has a natural and readable computational interpretation, that makes it practically usable in runtime testing. We discuss various design issues and develop this as a C + CN source to C source translation, Fulminate. This adds checks – including ownership checks and ownership transfer – for C code annotated with CN pre- and post-conditions; we demonstrate this on nontrivial examples, including the allocator from a production hypervisor. We formalise our runtime ownership testing scheme, showing (and proving) how its reified ghost state correctly captures ownership passing, in a semantics for a small C-like language.
CN: Verifying Systems C Code with Separation-Logic Refinement Types pulte-2023-cn
Despite significant progress in the verification of hypervisors, operating systems, and compilers, and in verification tooling, there exists a wide gap between the approaches used in verification projects and conventional development of systems software. We see two main challenges in bringing these closer together: verification handling the complexity of code and semantics of conventional systems software, and verification usability. We describe an experiment in verification tool design aimed at addressing some aspects of both: we design and implement CN, a separation-logic refinement type system for C systems software, aimed at predictable proof automation, based on a realistic semantics of ISO C. CN reduces refinement typing to decidable propositional logic reasoning, uses first-class resources to support pointer aliasing and pointer arithmetic, features resource inference for iterated separating conjunction, and uses a novel syntactic restriction of ghost variables in specifications to guarantee their successful inference. We implement CN and formalise key aspects of the type system, including a soundness proof of type checking. To demonstrate the usability of CN we use it to verify a substantial component of Google’s pKVM hypervisor for Android.
Iris from the ground up: A modular foundation for higher-order concurrent separation logic jung_etal_iris_ground_up_2018
Iris is a framework for higher-order concurrent separation logic, which has been implemented in the Coq proof assistant and deployed very effectively in a wide variety of verification projects. Iris was designed with the express goal of simplifying and consolidating the foundations of modern separation logics, but it has evolved over time, and the design and semantic foundations of Iris itself have yet to be fully written down and explained together properly in one place. Here, we attempt to fill this gap, presenting a reasonably complete picture of the latest version of Iris (version 3.1), from first principles and in one coherent narrative.
IronFleet: proving practical distributed systems correct hawblitzel-2015-ironfleet
External (74)
- Artifact: Code-Specify-Test-Debug-Prove: Flexibly Integrating Separation Logic Specification into Conventional Workflows (2026)
- Bennet: Randomized Specification Testing for Heap-Manipulating Programs (2025)
- Ghost in the Android Shell: Pragmatic Test-oracle Specification of a Production Hypervisor (2025)
- Statements and Declarations in Expressions (GCC documentation) (2025)
- Contracts: primitive ownership assertions: owned and block #942 (Rust-lang proposal) (2025)
- Systems Correctness Practices at AWS (2024)
- Cedar: A New Language for Expressive, Fast, Safe, and Analyzable Authorization (2024)
- VST-A: A Foundationally Sound Annotation Verifier (2024)
- Abstract Interpretation of Recursive Logic Definitions for Efficient Runtime Assertion Checking (2023)
- ASN1*: Provably Correct, Non-malleable Parsing for ASN.1 DER (2023)
- Etna: An Evaluation Platform for Property-Based Testing (Experience Report) (2023)
- The Prusti Project: Formal Verification for Rust (2022)
- Developing With Formal Methods at BedRock Systems, Inc (2022)
- Using Lightweight Formal Methods to Validate a Key-Value Storage Node in Amazon S3 (2021)
- Formally Verified Memory Protection for a Commodity Multiprocessor Hypervisor (2021)
- A Secure and Formally Verified Linux KVM Hypervisor (2021)
- Gillian, Part II: Real-World Verification for JavaScript and C (2021)
- The e-ACSL perspective on runtime assertion checking (2021)
- Formal Verification of a Multiprocessor Hypervisor on Arm Relaxed Memory Hardware (2021)
- Symbolic execution with SymCC: Don't interpret, compile! (2020)
- Gillian, part i: a multi-language platform for symbolic execution (2020)
- Concolic Testing Heap-Manipulating Programs (2019)
- Enhancing Symbolic Execution of Heap-Based Programs with Separation Logic for Test Input Generation (2019)
- VST-Floyd: A Separation Logic Tool to Verify Correctness of C Programs (2018)
- SMTSampler: Efficient Stimulus Generation from Complex SMT Constraints (2018)
- Runtime Verification - 17 Years Later (2018)
- Testing heap-based programs with Java StarFinder (2018)
- E-ACSL, a Runtime Verification Tool for Safety and Security of C Programs (tool paper) (2018)
- From Static Analysis to Runtime Verification with Frama-C and E-ACSL (habilitation) (2018)
- Generating good generators for inductive relations (2017)
- A Decidable Fragment in Separation Logic with Inductive Predicates and Arithmetic (2017)
- Viper: A Verification Infrastructure for Permission-Based Reasoning (2017)
- Refinement reflection: complete verification with SMT (2017)
- Beginner's luck: a language for property-based generators (2016)
- Dependent types and multi-monadic effects in F* (2016)
- CertiKOS: An Extensible Architecture for Building Certified Concurrent OS Kernels (2016)
- Generating constrained random data with uniform distribution (2015)
- Type Targeted Testing (2015)
- Mechanized verification of fine-grained concurrent programs (2015)
- Generating Constrained Random Data with Uniform Distribution (FLOPS 2014) (2014)
- Deep Specifications and Certified Abstraction Layers (2014)
- Comprehensive formal verification of an OS microkernel (2014)
- FocalTest: A Constraint Programming Approach for Property-Based Testing (2013)
- SAGE: whitebox fuzzing for security testing (2012)
- AddressSanitizer: A Fast Address Sanity Checker (2012)
- Infer: An Automatic Program Verifier for Memory Safety of C Programs (2011)
- VeriFast: A Powerful, Sound, Predictable, Fast Verifier for C and Java (2011)
- First Steps towards the Certification of an ARM Simulator Using Compcert (2011)
- Test generation through programming in UDITA (2010)
- seL4: formal verification of an operating-system kernel (2010)
- Constraint Reasoning in FocalTest (2010)
- Mechanized Semantics for the Clight Subset of the C Language (2009)
- Verifying the Microsoft Hyper-V Hypervisor with VCC (2009)
- A Formally Verified Compiler Back-end (2009)
- Z3: An Efficient SMT Solver (2008)
- KLEE: Unassisted and Automatic Generation of High-Coverage Tests for Complex Systems Programs (2008)
- Property Directed Generation of First-Order Test Data (2007)
- Valgrind: a framework for heavyweight dynamic binary instrumentation (2007)
- DART: directed automated random testing (2005)
- CUTE: a concolic unit testing engine for C (2005)
- The Spec# Programming System: An Overview (2004)
- A Tool for Checking ANSI-C Programs (2004)
- How the Design of JML Accommodates Both Runtime Assertion Checking and Formal Verification (2003)
- A needed narrowing strategy (2000)
- QuickCheck: a lightweight tool for random testing of Haskell programs (2000)
- Testing from a Z Specification (1997)
- Formal Methods Light (1996)
- A rigorous approach to formal methods (in 'Formal Methods Light', IEEE Computer) (1996)
- Hints for writing specifications (1995)
- Larch: Languages and Tools for Formal Specification (1993)
- Applying 'design by contract' (1992)
- The Z Notation: A Reference Manual (1989)
- Report on the programming language Euclid (1977)
- Software Engineering: Report of a conference sponsored by the NATO Science Committee, Garmisch, Germany, 7-11 Oct (1969)