NSF Safe-OSE: Scalably Detecting Inconsistencies Between Git Commit Messages and Code in Open-source Projects

NSF Award Search · 01002526DB NSF RESEARCH & RELATED ACTIVIT · $1,469,443 · view on nsf.gov ↗

Abstract

Computer systems research relies on software simulation to perform early-stage design-space exploration, quickly iterate on new hardware-software changes, and explore the viability of new ideas before committing to expensive hardware prototyping and fabrication. In computer architecture, gem5 is the most widely used open-source simulation tool, heavily employed by academia, industry, and national laboratories. Like many other open-source projects, gem5 relies on a small number of volunteer maintainers to manage the ever-growing numbers of users and proposed changes. These maintainers typically have no formal training in identifying potential security vulnerabilities. Moreover, computer architecture designs prototyped in gem5 are often incorporated directly into real hardware. Vulnerabilities in gem5 could thus cause practitioners to inadvertently introduce security vulnerabilities into hardware that cannot easily be patched, impacting future commercial hardware and threatening national infrastructure. This project provides a novel framework to strengthen the security of the gem5 codebase and any future hardware designed with it. This project will also increase the impact of results generated with gem5 for U.S. industry and national lab practitioners by allowing them to more safely use the cutting-edge, top-secret designs they prototype in gem5. This project combines expertise across simulator design, computer architecture, programming languages, security, and language mode

Key facts

NSF award ID
2533192
Awardee
University of Wisconsin-Madison (WI)
SAM.gov UEI
LCLSJAGTNZQ7
PI
Matthew D Sinclair
Primary program
01002526DB NSF RESEARCH & RELATED ACTIVIT
All programs
—
Estimated total
$1,469,443
Funds obligated
$1,469,443
Transaction type
Cooperative Agreement
Period
10/01/2025 → 09/30/2027