FFIProbe: Effectively Detecting Multilingual Rust Memory Bugs with FFI Sanitization
Abstract
Rust has emerged as a promising systems programming language for security-critical domains, offering effective protection against memory safety issues through its strong type system and ownership model. However, practical multilingual Rust applications that interact with unsafe languages such as C/C++ via the Foreign Function Interface (FFI) can undermine Rust’s security guarantees because the integration of disparate memory management mechanisms often circumvents Rust’s compiler safety checks, rendering the interaction boundaries highly error-prone.In this paper, we propose FFIProbe, a technique that enables dynamic analysis for effectively detecting memory safety bugs in multilingual Rust programs. Specifically, we utilize Rust’s mid-level intermediate representation (MIR) as the instrumentation target, statically instrument probe functions for raw pointer operations at multilingual interaction boundaries, and identify memory safety bugs arising from memory objects in illegal states during program execution. To facilitate accurate tracking of memory object states, we also design a custom heap allocator that proxies memory allocation requests from both Rust and foreign languages, while maintaining metadata for allocated memory objects to support probe functions in identifying bugs at runtime. We implement a prototype of FFIProbe and conduct extensive experiments to evaluate its practical effectiveness and performance on 2,635 real-world multilingual Rust packages. Our evaluation detects 43 memory safety bugs across 29 packages, while introducing an average runtime overhead of 25.6% and a memory overhead of 33.2%.