Checking Type Safety of Foreign Function Calls ∗ Michael Furr Jeffrey S. Foster University of Maryland, College Park University of Maryland, College Park
[email protected] [email protected] Abstract guages. Such interfaces are important for accessing system-wide We present a multi-lingual type inference system for checking type libraries and legacy components, but they are difficult to use cor- safety across a foreign function interface. The goal of our system is rectly, especially when there are mismatches between native and to prevent foreign function calls from introducing type and mem- foreign type systems, data representations, and run-time environ- ory safety violations into an otherwise safe language. Our system ments. In all of the FFIs we are aware of, there is little or no consis- targets OCaml’s FFI to C, which is relatively lightweight and illus- tency checking between foreign and native code [4, 8, 15, 16, 17]. trates some interesting challenges in multi-lingual type inference. As a consequence, adding an FFI to a safe language potentially The type language in our system embeds OCaml types in C types provides a rich source of operations that can violate safety in subtle and vice-versa, which allows us to track type information accu- and difficult-to-find ways. rately even through the foreign language, where the original types This paper presents a multi-lingual type inference system to are lost. Our system uses representational types that can model check type and garbage collection safety across foreign function multiple OCaml types, because C programs can observe that many calls.