ValScope: Value-Semantics-Aware Metamorphic Testing for Detecting Logical Bugs in DBMSs
Li Lin, Liehang Chen, Rongxin Wu
Abstract
Database Management Systems (DBMSs) are crucial for data processing in many large-scale applications. However, detecting logical bugs in DBMSs remains challenging, as defining what constitutes a correct query result is inherently difficult. Metamorphic testing (MT) addresses this issue by checking relations between systematically transformed queries. However, existing MT approaches mainly rely on equivalent or set-semantic relations, and thus fail to detect subtle bugs that preserve the result set while corrupting value semantics, such as faulty aggregation, ordering, or numeric computation.
In this paper, we propose a unified SQL query approximation model that integrates set-semantic and value-semantic reasoning. Beyond result set inclusion or equivalence, our model captures how value-level changes affect query correctness. Based on this model, we develop VALSCOPE, which generates and mutates SQL queries using predefined mutators and performs approximation propagation analysis to reason about global semantic effects. We evaluate VALSCOPE on 6 widely used DBMSs and uncover 67 unique logical bugs, many of which were missed by prior approaches. The results show that VALSCOPE substantially broadens the spectrum of detectable logical bugs beyond existing MT techniques.
• We propose a unified model, SQL query approximation, that combines set-semantic and value-semantic reasoning to detect logical bugs in DBMSs.
• We implement a novel MT framework, VALSCOPE, which systematically generates, mutates, and verifies SQL queries based on the proposed approximation relations, effectively identifying logical bugs in DBMSs.
• We evaluate VALSCOPE on 6 real-world DBMSs. In total, we found 67 logical bugs. To further facilitate research on DBMS testing, we open-source the tool at https://github.com/linli1724647576/ValScope
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 419c3852-cb58-4cd4-8406-cb04d340c219Builds on20
- Testing Database Engines via Pivoted Query SynthesisManuel Rigger, Zhendong SuOSDI 2020 · 150 citations
- Finding bugs in database systems via query partitioningManuel Rigger, Zhendong SuOOPSLA 2020 · 116 citations
- Detecting optimization bugs in database engines via non-optimizing reference engine constructionManuel Rigger, Zhendong SuFSE 2020 · 104 citations
- Griffin : Grammar-Free DBMS FuzzingJingzhou Fu, Jie Liang, Zhiyong Wu, Mingzhe Wang et al.ASE 2022 · 44 citations
- Testing Database Engines via Query Plan GuidanceJinsheng Ba, Manuel RiggerICSE 2023 · 39 citations
Related papers
- Pinolo: Detecting Logical Bugs in Database Management Systems with Approximate Query SynthesisZongyin Hao, Quanfeng Huang, Chengpeng Wang, Jianfeng Wang et al.USENIX ATC 2023 · 26 citations
- Detecting Logical Bugs of DBMS with Coverage-based GuidanceYu Liang, Song Liu, Hong HuUSENIX Security 2022
- Testing Database Systems via Differential Query ExecutionJiansen Song, Wensheng Dou, Ziyu Cui, Qianwang Dai et al.ICSE 2023 · 26 citations
- Detecting Schema-Related Logic Bugs in Relational DBMSs via Equivalent Database ConstructionJiansen Song, Wensheng Dou, Yingying Zheng, Yu Gao et al.VLDB 2025 · 6 citations
- Detecting Metadata-Related Logic Bugs in Database Systems via Raw Database ConstructionJiansen Song, Wensheng Dou, Yu Gao, Ziyu Cui et al.VLDB 2024 · 13 citations
