Ahead-of-Time Analysis of Shell Program Effects
Lukas Lazarek, Evangelos Lamprou, George Kapetanakis, Anirudh Narsipur, Eric Zhao, Zhiwen Zheng, Michael Greenberg, Konstantinos Kallas, Nikos Vasilakis
Abstract
The Unix shell remains a core system substrate across system administration, automation, and software development. Shell programs, however, are prone to subtle, severe, and often irreversible effects that are difficult to predict. The challenge stems from the shell's unique execution model, its reliance on external computation and state, its highly dynamic expansion semantics, and the complex interactions among these features. This paper presents SaSh, a system that statically analyzes shell programs to identify errors in their execution before they occur. SaSh introduces an optimistic symbolic execution engine for shell programs that limits path explosion and focuses on high-impact failures. It tracks the effects of external commands over a filesystem model, and approximates shell word expansion using a tailored abstract domain. SaSh quickly identifies bugs even in large programs with a risk-directed exploration strategy, steering its analysis to program fragments likely to exhibit dangerous behavior. Applied to 61 buggy programs, including several high-profile disasters, SaSh identifies all but one instance of unwanted behavior with no false positives, going far beyond the current state-of-the-art. Furthermore, SaSh has already yielded 104 new bug reports in 50 open-source projects such as PyTorch, the P4 compiler, Kubernetes, and vLLM, including bugs that can lead to irreversible data loss.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Related papers
- A Compilation-Based Under-Constrained Execution EngineMingjun Yin, Zhaorui Li, Ju Chen, Haochen Zeng et al.OSDI 2026
- Sys: A Static/Symbolic Tool for Finding Good Bugs in Good (Browser) CodeFraser Brown, Deian Stefan, Dawson R. EnglerUSENIX Security 2020
- DiSh: Dynamic Shell-Script DistributionTammam Mustafa, Konstantinos Kallas, Pratyush Das, Nikos VasilakisNSDI 2023 · 11 citations
- PaSh: light-touch data-parallel shell processingNikos Vasilakis, Konstantinos Kallas, Konstantinos Mamouras, Achilles Benetopoulos et al.EuroSys 2021 · 12 citations
- Holistic Concolic Execution for Dynamic Web Applications via Symbolic Interpreter AnalysisPenghui Li, Wei Meng, Mingxue Zhang, Chenlin Wang et al.S&P 2024 · 6 citations
