Léo Andrès1 , Filipe Marques2 , Arthur Carcano3 , Pierre Chambart4 , José Fragoso Santos5 , and Jean-Christophe Filliâtre6
The Art, Science, and Engineering of Programming, 2025, Vol. 9, Issue 1, Article 3
Submission date: 2024-06-02
Publication date: 2024-10-15
DOI: https://doi.org/10.22152/programming-journal.org/2025/9/3
Full text: PDF
In this paper, we present the design of Owi, a symbolic interpreter for WebAssembly written in OCaml, and how we used it to create a state-of-the-art tool to find bugs in programs combining C and Rust code. WebAssembly (Wasm) is a binary format for executable programs. Originally intended for web applications, Wasm is also considered a serious alternative for server-side runtimes and embedded systems due to its performance and security benefits. Despite its security guarantees and sandboxing capabilities, Wasm code is still vulnerable to buffer overflows and memory leaks, which can lead to exploits on production software. To help prevent those, different techniques can be used, including symbolic execution.
Owi is built around a modular, monadic interpreter capable of both normal and symbolic execution of Wasm programs. Monads have been identified as a way to write modular interpreters since 1995 and this strategy has allowed us to build a robust and performant symbolic execution tool which our evaluation shows to be the best currently available for Wasm. Moreover, because WebAssembly is a compilation target for multiple languages (such as Rust and C), Owi can be used to find bugs in C and Rust code, as well as in codebases mixing the two. We demonstrate this flexibility through illustrative examples and evaluate its scalability via comprehensive experiments using the 2024 Test-Comp benchmarks. Results show that Owi achieves comparable performance to state-of-the-art tools like KLEE and Symbiotic, and exhibits advantages in specific scenarios where KLEE’s approximations could lead to false negatives.
OCamlPro, France / Université Paris-Saclay - CNRS - ENS Paris-Saclay - Inria - LMF, France
https://orcid.org/0000-0003-2940-6605
INESC-ID, Portugal / University of Lisbon, Portugal
https://orcid.org/0000-0002-2555-5382
OCamlPro, France
https://orcid.org/0000-0002-9946-1645
OCamlPro, France
https://orcid.org/0009-0008-9163-9091
INESC-ID, Portugal / University of Lisbon, Portugal
https://orcid.org/0000-0001-5077-300X
Université Paris-Saclay - CNRS - ENS Paris-Saclay - Inria - LMF, France
https://orcid.org/0000-0003-2359-975X