ARG: Testing Query Rewriters via Abstract Rule Guided Fuzzing
Dawei Li, Yuxiao Guo, Qifan Liu, Jie Liang, Zhiyong Wu, Jingzhou Fu, Chi Zhang, Yu Jiang
Abstract
Query rewriters transform a query into a more efficient yet semantically equivalent form, which is vital for optimizing query execution. Despite its importance, query rewriting is inherently complex, influenced by factors including rewrite rule design, rule interactions, and semantic preservation. Consequently, its implementation struggles to prevent problems, which may result in system crashes or incorrect query results. Existing DBMS testing approaches are generally designed for broad bug detection. However, due to the diversity of rewrite rules, they cover only a limited subset of rewrite scenarios, potentially overlooking critical bugs. In this paper, we propose Abstract Rule Guided (ARG) fuzzing to detect bugs in query rewrites. The key idea is to use feedback from abstract rules to guide query generation, thereby activating more rewriting logic and enhancing bug detection. Abstract rules provide a unified representation of the patterns (e.g., AST structures and related constraints) that trigger rewrites, as well as the resulting transformations. We track abstract rules to identify which patterns have been covered. This feedback is then used to dynamically adjust query generation, prioritizing unexplored patterns to avoid redundancy and expose more rewriting logic. We implemented ARG to test four popular query rewrites, namely Apache Calcite, WeTune, SQLSolver, and LearnedRewrite. ARG discovered 38 previously unknown bugs, consisting of 4 crashes, 13 invalid SQL outputs, and 21 semantic deviations. Among them, 19 have been confirmed, while the remaining cases are still under investigation. We also compared ARG against popular DBMS testing tools. In 24 hours, ARG triggered 76% and 1017% more written rules, triggered 13 and 15 more bugs than SQLsmith and SQLancer, respectively. Index Terms-Query Rewriter, Rule Feedback, Bug Detection --Cast operation leads to unequal results CREATE TABLE t1 (c1 float NOT NULL, PRIMARY KEY(c1)); INSERT INTO t1 VALUES (0), (0.0963786); --Original query SELECT t0.c1 AS c0, t2.c1 AS c1 FROM t1 AS t0 RIGHT JOIN t1 AS t2 ON TRUE WHERE t0.c1 IS NOT NULL;
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 22fce8ef-8d89-461d-9d2b-849eceb5d033Builds on9
- Finding bugs in database systems via query partitioningManuel Rigger, Zhendong SuOOPSLA 2020 · 116 citations
- Detecting optimization bugs in database engines via non-optimizing reference engine constructionManuel Rigger, Zhendong SuFSE 2020 · 104 citations
- A Learned Query Rewrite System using Monte Carlo Tree SearchXuanhe Zhou, Guoliang Li, Chengliang Chai, Jianhua FengVLDB 2022 · 85 citations
- Automatic Detection of Performance Bugs in Database Systems using Equivalent QueriesXinyu Liu, Qi Zhou, Joy Arulraj, Alessandro OrsoICSE 2022 · 42 citations
- Detecting Logic Bugs of Join Optimizations in DBMSXiu Tang, Sai Wu, Dongxiang Zhang, Feifei Li et al.SIGMOD 2023 · 34 citations
Related papers
- WeTune: Automatic Discovery and Verification of Query Rewrite RulesZhaoguo Wang, Zhou Zhou, Yicun Yang, Haoran Ding et al.SIGMOD 2022 · 35 citations
- Testing Graph Database Systems via Equivalent Query RewritingQiuyang Mang, Aoyang Fang, Boxi Yu, Hanfei Chen et al.ICSE 2024 · 12 citations
- QueryBooster: Improving SQL Performance Using Middleware Services for Human-Centered Query RewritingQiushi Bai, Sadeem Alsudais, Chen LiVLDB 2023 · 14 citations
- Detecting Logical Bugs of DBMS with Coverage-based GuidanceYu Liang, Song Liu, Hong HuUSENIX Security 2022
- Testing Database Engines via Query Plan GuidanceJinsheng Ba, Manuel RiggerICSE 2023 · 39 citations
