Differential regression testing for REST APIs
Patrice Godefroid, Daniel Lehmann, Marina Polishchuk
Abstract
Cloud services are programmatically accessed through REST APIs. Since REST APIs are constantly evolving, an important problem is how to prevent breaking changes of APIs, while supporting several different versions. To find such breaking changes in an automated way, we introduce differential regression testing for REST APIs. Our approach is based on two observations. First, breaking changes in REST APIs involve two software components, namely the client and the service. As such, there are also two types of regressions: regressions in the API specification, i.e., in the contract between the client and the service, and regressions in the service itself, i.e., previously working requests are "broken" in later versions of the service. Finding both kinds of regressions involves testing along two dimensions: when the service changes and when the specification changes. Second, to detect such bugs automatically, we employ differential testing. That is, we compare the behavior of different versions on the same inputs against each other, and find regressions in the observed differences. For generating inputs (sequences of HTTP requests) to services, we use RESTler, a stateful fuzzer for REST APIs. Comparing the outputs (HTTP responses) of a cloud service involves several challenges, like abstracting over minor differences, handling out-of-order requests, and non-determinism. Differential regression testing across 17 different versions of the widely-used Azure networking APIs deployed between 2016 and 2019 detected 14 regressions in total, 5 of those in the official API specifications and 9 regressions in the services themselves. CCS CONCEPTS • Software and its engineering → Software testing and debugging; Correctness; • Networks → Cloud computing.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers12
- Automated test generation for REST APIs: no time to rest yetMyeongsoo Kim, Qi Xin, Saurabh Sinha, Alessandro OrsoISSTA 2022 · 67 citations
- Are Machine Learning Cloud APIs Used Correctly?Chengcheng Wan, Shicheng Liu, Henry Hoffmann, Michael Maire et al.ICSE 2021 · 37 citations
- Data-Oriented Differential Testing of Object-Relational Mapping SystemsThodoris Sotiropoulos, Stefanos Chaliasos, Vaggelis Atlidakis, Dimitris Mitropoulos et al.ICSE 2021 · 21 citations
- Finding Unstable Code via Compiler-Driven Differential TestingShaohua Li, Zhendong SuASPLOS 2023 · 19 citations
- Vulnerability-oriented Testing for RESTful APIsWenlong Du, Jian Li, Yanhao Wang, Libo Chen et al.USENIX Security 2024 · 17 citations
Related papers
- Intelligent REST API data fuzzingPatrice Godefroid, Bo-Yuan Huang, Marina PolishchukFSE 2020 · 57 citations
- R2Z2: Detecting Rendering Regressions in Web Browsers through Differential Fuzz TestingSuhwan Song, Jaewon Hur, Sunwoo Kim, Philip Rogers et al.ICSE 2022 · 12 citations
- MINER: A Hybrid Data-Driven Approach for REST API FuzzingChenyang Lyu, Jiacheng Xu, Shouling Ji, Xuhong Zhang et al.USENIX Security 2023
- Fidelity of Cloud Emulators: The Imitation Game of Testing Cloud-Based SoftwareAnna Mazhar, Saad Sher Alam, William X. Zheng, Yinfang Chen et al.ICSE 2025 · 2 citations
- Regression Fuzzing for Deep Learning SystemsHanmo You, Zan Wang, Junjie Chen, Shuang Liu et al.ICSE 2023 · 28 citations
