Constraint-Based Test Oracles for Program Analyzers
Markus Fleischmann, David Kaindlstorfer, Anastasia Isychev, Valentin Wüstholz, Maria Christakis
Abstract
Program analyzers implement complex algorithms and, as any software, can contain bugs. Bugs in their implementation may lead to analyzers being imprecise and failing to verify safe programs, i.e., programs with no reachable error locations; or worse, analyzer bugs may lead to reporting unsound results by verifying unsafe programs, i.e., programs with reachable error locations. In this paper, we propose a method to detect such bugs by generating constraint-based test oracles for analyzers. We re-purpose and extend Fuzzle, a tool for benchmarking fuzzers, in a tool called Minotaur. Minotaur generates C programs from SMT constraints, and based on the satisfiability of the constraints, derives whether the generated programs are safe or unsafe. For instance, for an unsafe program, an analyzer under test contains a soundness issue if it proves it safe. Using Minotaur, we found 30 unique soundness and precision issues in 11 well-known analyzers that reason about reachability properties. CCS Concepts • Software and its engineering → Software testing and debugging.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 27e366ef-aa17-4ad6-82b3-13c6d40b3dbcCited by top-tier papers3
- Fuzzing Processing Pipelines for Zero-Knowledge CircuitsChristoph Hochrainer, Anastasia Isychev, Valentin Wüstholz, Maria ChristakisCCS 2025 · 1 citation
- Cost-Effective Testing of MPC CompilersSebastian Watzinger, Valentin Wüstholz, Deepak Garg, Maria ChristakisFSE 2026
- Testing Static Taint Analyzers with Equivalence Modulo TaintMaria Christakis, Anastasia Isychev, Samuel Pilz, Florian Tesarek et al.ISSTA 2026
Builds on13
- Validating SMT solvers via semantic fusionDominik Winterer, Chengyu Zhang, Zhendong SuPLDI 2020 · 80 citations
- On the unusual effectiveness of type-aware operator mutations for testing SMT solversDominik Winterer, Chengyu Zhang, Zhendong SuOOPSLA 2020 · 55 citations
- GrayC: Greybox Fuzzing of Compilers and Analysers for CKarine Even-Mendoza, Arindam Sharma, Alastair F. Donaldson, Cristian CadarISSTA 2023 · 52 citations
- Detecting critical bugs in SMT solvers using blackbox mutational fuzzingMuhammad Numair Mansur, Maria Christakis, Valentin Wüstholz, Fuyuan ZhangFSE 2020 · 51 citations
- Generative type-aware mutation for testing SMT solversJiwon Park, Dominik Winterer, Chengyu Zhang, Zhendong SuOOPSLA 2021 · 31 citations
Related papers
- Interrogation Testing of Program Analyzers for Soundness and Precision IssuesDavid Kaindlstorfer, Anastasia Isychev, Valentin Wüstholz, Maria ChristakisASE 2024 · 2 citations
- Fuzzle: Making a Puzzle for FuzzersHaeun Lee, Soomin Kim, Sang Kil ChaASE 2022 · 13 citations
- Finding and Understanding Defects in Static Analyzers by Constructing Automated OraclesWeigang He, Peng Di, Mengli Ming, Chengyu Zhang et al.FSE 2024 · 6 citations
- Interrogation Testing of CHC SolversDavid Kaindlstorfer, Anastasia Isychev, Valentin Wüstholz, Maria ChristakisFSE 2026 · 1 citation
- Automatically testing string solversAlexandra Bugariu, Peter MüllerICSE 2020 · 28 citations
