Understanding and Detecting SQL Function Bugs: Using Simple Boundary Arguments to Trigger Hundreds of DBMS Bugs
Jingzhou Fu, Jie Liang, Zhiyong Wu, Yanyang Zhao, Shanshan Li, Yu Jiang
Abstract
Built-in SQL functions are crucial in Database Management Systems (DBMSs), supporting various operations and computations across multiple data types. They are essential for querying, data transformation, and aggregation. Despite their importance, the bugs in SQL functions have caused widespread problems in the real world, from system failures to arbitrary code execution. However, the understanding of the bug characteristics is limited. More importantly, conventional function testing methods struggle to generate semantically correct SQL test cases, while DBMS testing efforts are hard to measure built-in SQL functions.
This paper presents a comprehensive study of 318 built-in SQL function bugs, shedding light on their characteristics and root causes. Our investigation reveals that 87.4% of these bugs were caused by improper handling of boundary values of arguments. The boundary values of arguments come from three sources: literal values, type castings, and nested functions. By studying the bugs from three sources, we summarized 10 SQL patterns of bug-inducing queries. Moreover, we designed Soft, a testing tool based on the patterns to test seven widely used DBMSs, including PostgreSQL, MySQL, and ClickHouse. Soft discovered and confirmed 132 previously unknown SQL function bugs. The DBMS vendors took these bugs seriously and fixed 97 bugs in three days. For example, the CTO of ClickHouse commented on one bug: "We must fix it immediately or get rid of this function."
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 55f482ae-81dc-4f71-8a9b-e9c0238638f9Cited by top-tier papers2
- Fawkes: Finding Data Durability Bugs in DBMSs via Recovered Data State VerificationZhiyong Wu, Jie Liang, Jingzhou Fu, Wenqian Deng et al.SOSP 2025 · 1 citation
- VDBFuzz: Understanding and Detecting Crash Bugs in Vector Database Management SystemsShenao Wang, Zhao Liu, Yanjie Zhao, Quanchen Zou et al.ICSE 2026
Builds on20
- Angora: Efficient Fuzzing by Principled SearchPeng Chen, Hao ChenS&P 2018 · 616 citations
- QSYM : A Practical Concolic Execution Engine Tailored for Hybrid FuzzingInsu Yun, Sangho Lee, Meng Xu, Yeongjin Jang et al.USENIX Security 2018 · 537 citations
- Testing Database Engines via Pivoted Query SynthesisManuel Rigger, Zhendong SuOSDI 2020 · 150 citations
- Finding bugs in database systems via query partitioningManuel Rigger, Zhendong SuOOPSLA 2020 · 116 citations
- Detecting optimization bugs in database engines via non-optimizing reference engine constructionManuel Rigger, Zhendong SuFSE 2020 · 104 citations
Related papers
- Mozi: Discovering DBMS Bugs via Configuration-Based Equivalent TransformationJie Liang, Zhiyong Wu, Jingzhou Fu, Mingzhe Wang et al.ICSE 2024 · 18 citations
- ValScope: Value-Semantics-Aware Metamorphic Testing for Detecting Logical Bugs in DBMSsLi Lin, Liehang Chen, Rongxin WuOSDI 2026
- DynSQL: Stateful Fuzzing for Database Management Systems with Complex and Valid SQL Query GenerationZu-Ming Jiang, Jia-Ju Bai, Zhendong SuUSENIX Security 2023
- Scaling Automated Database System TestingSuyang Zhong, Manuel RiggerASPLOS 2026 · 4 citations
- Efficiently Detecting DBMS Bugs through Bottom-up Syntax-based SQL GenerationYu Liang, Peng LiuNDSS 2026
