Lune

NSDI2026Top-tier venue

UpFuzz: Detecting Data Format Incompatibility Bugs during Distributed Storage System Upgrade

Ke Han, P. C. Sruthi, Yayu Wang, Yaoxu Song, Bishal Basak Papan, Junwen Yang, Pedro Fonseca, Yongle Zhang

2026Year
3Citations
1Top-tier citations

Abstract

Data format incompatibility is a significant cause of cloud incidents during distributed system upgrades, often resulting in severe consequences such as data corruption and service unavailability. A majority of such bugs are only discovered post-release, largely due to the lack of automated testing techniques tailored specifically for the upgrade process. Traditional automated test generation methods face a unique challenge when applied to upgrade testing: the high cost associated with upgrading distributed storage systems due to system initialization. Therefore, the accurate selection of potential failure-inducing tests from the extensive pool of automatically generated tests becomes critical.

In this work, we address this problem by proposing a novel approach to prioritize upgrade tests through analyzing data format properties over transitively persisted states: program states that are persisted to disk, directly or indirectly, through chains of memory copies by the old version, and eventually read by the new version after upgrade. Because data format incompatibility bugs happen due to translation errors of such states across versions, transitively persisted states satisfying unique data format properties related to changed data formats are particularly essential for testing.

We build a likely invariant analysis engine that captures such properties as feedback for seed test selection in UPFUZZ, the automated testing engine for the distributed storage system upgrade procedure. UPFUZZ has detected 15 previously unknown upgrade failures caused by data format incompatibilities in the latest stable versions of Cassandra, HBase, and HDFS; developers have confirmed 8 of them. 7 are triggered exclusively with UPFUZZ's data format analysis. The detected bugs have severe consequences, with 6 crashing the cluster and 4 causing data loss or corruption.

1 To ensure a fair comparison, we implemented UPFUZZ baseline version (with traditional feedback) using state-of-the-art fuzzing techniques, including grammar-aware input mutation [11,82], configuration mutation [85], and stateful fuzzing [23,86]. UPFUZZ has uncovered a total of 38 previously unknown bugs, 18 of which have been confirmed. 1 /* Create a table with a composite key. */ 2 CREATE TABLE t (k1 INT, k2 INT, v1 TEXT, v2 TEXT, 3

Ask about this paper

Your agent reads all of it.

Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.

Questions to start from

Your agent calls

Luneget_paper_fulltext

Ask in Lune

Free to start. No credit card required.

lune papers fulltext 0c2cdcc4-6eaa-4c11-97c5-d1d85998521f

Cited by top-tier papers1

Ask how each one uses it

Builds on27

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines