Skip to content
Open access

Rust’s Type Checker Implementation Is Unsound: An Empirical Study on Soundness Bugs in rustc

Aug 2026 · Proceedings of the ACM on Software Engineering · Vol 3, pp. 2952 - 2975 · 0 citations · 69 references
Computer Science

TL;DR

An empirical study of 30 issues that report potential soundness bugs in rustc, collected from the GitHub issue tracker between January 1, 2022 and September 1, 2025, indicates that certain soundness bugs, typically triggered by implied bounds or trait objects, compromise memory safety.

Abstract

Rust is claimed to be a type-sound language capable of preventing various undesirable behaviors, including memory bugs. However, rustc, the official Rust compiler, is not immune to defects; it contains soundness bugs, where the compiler accepts programs that should be rejected during type checking. In this work, we present an empirical study of 30 issues that report potential soundness bugs in rustc, collected from the GitHub issue tracker between January 1, 2022 and September 1, 2025. We analyze each issue in depth, focusing on its affected feature, symptom (how the feature is mishandled), consequence (the resulting undesirable behavior), triggering features, community consensus regarding whether it is a bug, and lifecycle, including introduction, discovery, and fix. Furthermore, we investigate existing artifacts, including implementations such as AddressSanitizer, Miri, Chalk, and a-mir-formality, alongside documentation such as the Rust Reference, the FLS, and Rust RFCs to assess their potential as oracles for testing the type soundness of rustc. Our key findings indicate that: (1) Certain soundness bugs, typically triggered by implied bounds or trait objects, compromise memory safety. (2) Sound type checking is challenged by edge cases involving associated types and the interaction between lifetimes and traits. (3) Most bugs persist from the initial introduction of the relevant features and require significant time to be discovered. (4) While AddressSanitizer and Miri can detect soundness bugs that lead to memory bugs, a-mir-formality and Chalk are currently immature despite their potential to identify other bug categories. (5) Existing documentation frequently fails to provide precise explanations of the language semantics.

Read PDF

Similar papers

Open access Oct 2026

RICE: Harnessing LLMs and Historical Issues to Discover Internal Rust Compiler Errors

Rust is a modern system-level programming language that emphasizes safety, concurrency, and performance. Ensuring the reliability of the Rust compiler is critical, as undetected compiler defects, particularly internal compiler errors (ICEs), can lead to runtime crashes or undefined behavior in system software. Existing...

Lang-Yi Lu, Wei You, Bin Liang et al. · 0 citations
Preprint Sep 2026

C-to-Rust Fallacy: Automatic Refactoring != Memory Security

Rust has emerged as the leading system programming language, offering strong memory and type safety guarantees without compromising performance. This positions it as a compelling alternative to traditional languages like C and C++, which are susceptible to memory security bugs. However, manually transforming C to Rust...

Hung-Mao Chen, Xu He, Bo Lu et al. · 0 citations
Open access Aug 2026

Improving Bug Detection in LLM-Generated Unit Tests: Revisiting Test-Oracle Reliability Across Modern Large Language Models

This paper presents a formal mathematical model for categorizing the outcome of generated-tests into four classes, a couple of basic metrics: Bug-Revealing Rate (BRR) and Bug-Validating Rate (BVR); and two basic statistical tests to ensure that the results are rigorous.

Zeyad Farooq Lutfi · 0 citations
Open access Oct 2026

Bringing Foundational Verification to Real-World Rust Code

How to extend RefinedRust with several of the high-level abstractions that Rust provides, including traits, closures, and iterators, and in a manner such that they can be used in conjunction with unsafe code.

Lennard Gäher, Vincent Lafeychine, Sascha Kehrli et al. · 0 citations
Preprint Sep 2026

VSpector: Specification-Driven Bug Detection for RISC-V CPUs

VSpector is presented, a specification-driven bug detection pipeline that directly checks whether CPU register-transfer level (RTL) implementations adhere to official specification rules, without requiring specialized construction of reference models, formal properties, or custom bug patterns.

Tian-Yu Jia, Zhao-Yang Yu, Yuan-Liang Chen et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.