Safe Dynamic Memory Management in Ada and SPARK

  • Maroua Maalej
  • Tucker Taft
  • Yannick Moy
Conference paper
Part of the Lecture Notes in Computer Science book series (LNCS, volume 10873)


Handling memory in a correct and efficient way is a step toward safer, less complex, and higher performing software-intensive systems. However, languages used for critical software development such as Ada, which supports formal verification with its SPARK subset, face challenges regarding any use of pointers due to potential pointer aliasing. In this work, we introduce an extension to the Ada language, and to its SPARK subset, to provide pointer types (“access types” in Ada) that provide provably safe, automatic storage management without any asynchronous garbage collection, and without explicit deallocation by the user. Because the mechanism for these safe pointers relies on strict control of aliasing, it can be used in the SPARK subset for formal verification, including both information flow analysis and proof of safety and correctness properties. In this paper, we present this proposal (which has been submitted for inclusion in the next version of Ada), and explain how we are able to incorporate these pointers into formal analyses.


Compilation Safe pointers Formal verification Memory management 



We thank the anonymous reviewers for their remarks, and Georges-Axel Jaloyan for his initial work on the design, formalization and implementation of these ownership rules for Ada and SPARK.


  1. 1.
    AdaCore: Access value ownership and parameter aliasing (2018).
  2. 2.
    AdaCore, Thales: Implementation guidance for the adoption of SPARK (2017).
  3. 3.
    Balasubramanian, A., Baranowski, M.S., Burtsev, A., Panda, A., Rakamaric, Z., Ryzhyk, L.: System programming in rust: Beyond safety. In: Proceedings of the 16th Workshop on Hot Topics in Operating Systems, HotOS 2017, Whistler, BC, Canada, 8–10 May 2017, pp. 156–161 (2017)Google Scholar
  4. 4.
    Barnett, M., Chang, B.-Y.E., DeLine, R., Jacobs, B., Leino, K.R.M.: Boogie: a modular reusable verifier for object-oriented programs. In: de Boer, F.S., Bonsangue, M.M., Graf, S., de Roever, W.-P. (eds.) FMCO 2005. LNCS, vol. 4111, pp. 364–387. Springer, Heidelberg (2006). Scholar
  5. 5.
    Grossman, D., Morrisett, J.G., Jim, T., Hicks, M.W., Wang, Y., Cheney, J.: Region-based memory management in cyclone. In: Proceedings of the 2002 ACM SIGPLAN Conference on Programming Language Design and Implementation (PLDI), Berlin, Germany, 17–19 June 2002, pp. 282–293 (2002)Google Scholar
  6. 6.
    Jaloyan, G.A., Moy, Y., Paskevich, A.: Borrowing safe pointers from rust in spark. In: International Conference on Computer-Aided Verification - 29th International Conference, Heidelberg, Germany (2018, in submission)Google Scholar
  7. 7.
    Leino, K.R.M.: Dafny: an automatic program verifier for functional correctness. In: Clarke, E.M., Voronkov, A. (eds.) LPAR 2010. LNCS (LNAI), vol. 6355, pp. 348–370. Springer, Heidelberg (2010). Scholar
  8. 8.
    McCormick, J.W., Chapin, P.C.: Building High Integrity Applications with SPARK. Cambridge University Press, Cambridge (2015)CrossRefGoogle Scholar
  9. 9.
    O’Neill, I.: SPARK - a language and tool-set for high-integrity software development. In: Industrial Use of Formal Methods: Formal Verification (2012)Google Scholar
  10. 10.
    Reynolds, J.C.: Separation logic: a logic for shared mutable data structures. In: Proceedings of th 17th IEEE Symposium on Logic in Computer Science (LICS 2002), 22–25 July 2002, Copenhagen, Denmark, pp. 55–74 (2002)Google Scholar
  11. 11.
    Sant, P.M.: Concurrent read, exclusive write. In: Pieterse, V., Black, P.E. (eds.) Dictionary of Algorithms and Darta Structures (2004).
  12. 12.
    Svoboda, D., Wrage, L.: Pointer ownership model. In: Proceedings of the 47th Hawaii International Conference on System Sciences (HICSS 2014), 6–9 Jan 2014, Waikoloa, Hawaii, pp. 5090–5099 (2014)Google Scholar
  13. 13.
    Taft, S.T.: Multicore programming in ParaSail. In: Romanovsky, A., Vardanega, T. (eds.) Ada-Europe 2011. LNCS, vol. 6652, pp. 196–200. Springer, Heidelberg (2011). Scholar

Copyright information

© Springer International Publishing AG, part of Springer Nature 2018

Authors and Affiliations

  1. 1.AdaCoreParisFrance
  2. 2.AdaCoreNew YorkUSA

Personalised recommendations