Verifying a Compiler for Java Threads? Andreas Lochbihler Karlsruher Institut f¨urTechnologie (KIT), Karlsruhe, Germany
[email protected] Abstract. A verified compiler is an integral part of every security infra- structure. Previous work has come up with formal semantics for sequen- tial and concurrent variants of Java and has proven the correctness of compilers for the sequential part. This paper presents a rigorous formal- isation (in the proof assistant Isabelle/HOL) of concurrent Java source and byte code together with an executable compiler and its correctness proof. It guarantees that the generated byte code shows exactly the same observable behaviour as the semantics for the multithreaded source code. 1 Introduction In a recent \research highlights" article in CACM [14], the CompCert C compiler [13] by Leroy was praised as follows: \I think we are on the verge of a new paradigm for safety-critical systems, where we rely upon formal, machine checked verification, instead of human audits. Leroy's compiler is an impressive step toward this goal." And indeed, Leroy's work can be seen as a door opener, in particular because his verification includes various optimisations and generates assembler code for a real machine. However, concurrent programs call for formal methods even louder, because many bugs show up only in some interleavings of the threads' executions, which makes the bugs nearly impossible to find and reproduce. But so far, nobody has ever never included the compilation of thread primitives and multithreaded (imperative) programs. In this paper, we present a compiler from a substantial subset of multi- threaded Java source code to byte code and show semantic preservation w.r.t.