Detecting Metadata-Related Bugs in Enterprise Applications
Md Mahir Asef Kabir, Xiaoyin Wang, Na Meng
Abstract
When building enterprise applications (EAs) on Java frameworks (e.g., Spring), developers often configure application components via metadata (i.e., Java annotations and XML files). It is challenging for developers to correctly use metadata, because the usage rules can be complex and existing tools provide limited assistance. When developers misuse metadata, EAs become misconfigured, which can trigger erroneous runtime behaviors or introduce security vulnerabilities. To help developers correctly use metadata, this paper presents (1) RSL — a domain-specific language that domain experts can adopt to prescribe metadata checking rules, and (2) MeCheck — a tool that takes in RSL rules and EAs to check for rule violations. With RSL, domain experts (e.g., owner developers of a Java framework) can specify metadata checking rules by defining content consistency among XML files, annotations, and Java code. Given such RSL rules and a program to scan, MeCheck interprets rules as cross-file static analyzers that scan Java and/or XML files to gather information and look for consistency violations. For evaluation, we studied the Spring and JUnit documentation to manually define 15 rules, and created 2 datasets with 115 open-source EAs. The first dataset includes 45 EAs, and the ground truth of 45 manually injected bugs. The second dataset includes multiple versions of 70 EAs. We observed that MeCheck identified bugs in the first dataset with 100% precision, 96% recall, and 98% F-score. It reported 152 bugs in the second dataset, 49 of which were already fixed by developers. Our evaluation shows that MeCheck helps ensure the correct usage of metadata.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on3
- Finding broken Linux configuration specifications by statically analyzing the Kconfig languageJeho Oh, Necip Fazil Yildiran, Julian Braha, Paul GazzilloFSE 2021 · 46 citations
- Understanding and Detecting Annotation-Induced Faults of Static AnalyzersHuaien Zhang, Yu Pei, Shuyun Liang, Shin Hwei TanFSE 2024 · 4 citations
- Inferring and Applying Def-Use Like Configuration Couplings in Deployment DescriptorsChengyuan Wen, Yaxuan Zhang, Xiao He, Na MengASE 2020 · 3 citations
Related papers
- JavaDL: automatically incrementalizing Java bug pattern detectionAlexandru Dura, Christoph Reichenbach, Emma SöderbergOOPSLA 2021 · 13 citations
- API-Misuse Detection Driven by Fine-Grained API-Constraint Knowledge GraphXiaoxue Ren, Xinyuan Ye, Zhenchang Xing, Xin Xia et al.ASE 2020 · 62 citations
- A Comprehensive Study on Quality Assurance Tools for JavaHan Liu, Sen Chen, Ruitao Feng, Chengwei Liu et al.ISSTA 2023 · 12 citations
- Jasmine: A Static Analysis Framework for Spring Core TechnologiesMiao Chen, Tengfei Tu, Hua Zhang, Qiaoyan Wen et al.ASE 2022 · 9 citations
- An empirical study on API parameter rulesHao Zhong, Na Meng, Zexuan Li, Li JiaICSE 2020 · 16 citations
