ECSTATIC: An Extensible Framework for Testing and Debugging Configurable Static Analysis
Austin Mordahl, Zenong Zhang, Dakota Soles, Shiyi Wei
Abstract
Testing and debugging the implementation of static analysis is a challenging task, often involving significant manual effort from domain experts in a tedious and unprincipled process. In this work, we propose an approach that greatly improves the automation of this process for static analyzers with configuration options. At the core of our approach is the novel adaptation of the theoretical partial order relations that exist between these options to reason about the correctness of actual results from running the static analyzer with different configurations. This allows for automated testing of static analyzers with clearly defined oracles, followed by automated delta debugging, even in cases where ground truths are not defined over the input programs. To apply this approach to many static analysis tools, we design and implement ECSTATIC, an easy-to-extend, open-source framework. We have integrated four popular static analysis tools, SOOT, WALA, DOOP, and FlowDroid, into ECSTATIC. Our evaluation shows running ECSTATIC detects 74 partial order bugs in the four tools and produces reduced bug-inducing programs to assist debugging. We reported 42 bugs; in all cases where we received responses, the tool developers confirmed the reported tool behavior was unintended. So far, three bugs have been fixed and there are ongoing discussions to fix more.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 08b5846f-59ab-479a-9102-48f2d33c7f27Cited by top-tier papers11
- Understanding and Detecting Annotation-Induced Faults of Static AnalyzersHuaien Zhang, Yu Pei, Shuyun Liang, Shin Hwei TanFSE 2024 · 4 citations
- The Same Only Different: On Information Modality for Configuration Performance AnalysisHongyuan Liang, Yue Huang, Tao ChenICSE 2025 · 3 citations
- Interrogation Testing of Program Analyzers for Soundness and Precision IssuesDavid Kaindlstorfer, Anastasia Isychev, Valentin Wüstholz, Maria ChristakisASE 2024 · 2 citations
- Constraint-Based Test Oracles for Program AnalyzersMarkus Fleischmann, David Kaindlstorfer, Anastasia Isychev, Valentin Wüstholz et al.ASE 2024 · 2 citations
- Arguzz: Testing zkVMs for Soundness and Completeness BugsChristoph Hochrainer, Valentin Wüstholz, Maria ChristakisUSENIX Security 2026 · 2 citations
Builds on1
Related papers
- Statfier: Automated Testing of Static Analyzers via Semantic-Preserving Program TransformationsHuaien Zhang, Yu Pei, Junjie Chen, Shin Hwei TanFSE 2023 · 15 citations
- An Extensive Empirical Study of Nondeterministic Behavior in Static Analysis ToolsMiao Miao, Austin Mordahl, Dakota Soles, Alice Beideck et al.ICSE 2025 · 1 citation
- Finding and Understanding Defects in Static Analyzers by Constructing Automated OraclesWeigang He, Peng Di, Mengli Ming, Chengyu Zhang et al.FSE 2024 · 6 citations
- On the Real-World Effectiveness of Static Bug Detectors at Finding Null Pointer ExceptionsDavid A. Tomassi, Cindy Rubio-GonzálezASE 2021 · 24 citations
- Metha: Network Verifiers Need To Be Correct Too!Rüdiger Birkner, Tobias Brodmann, Petar Tsankov, Laurent Vanbever et al.NSDI 2021 · 20 citations
