WAFFLE: Exposing Memory Ordering Bugs Efficiently with Active Delay Injection
Bogdan Alexandru Stoica, Shan Lu, Madanlal Musuvathi, Suman Nath
Abstract
Concurrency bugs are difficult to detect, reproduce, and diagnose, as they manifest under rare timing conditions. Recently, active delay injection has proven efficient for exposing one such type of bug -thread-safety violations -with low overhead, high coverage, and minimal code analysis. However, how to efficiently apply active delay injection to broader classes of concurrency bugs is still an open question.
We aim to answer this question by focusing on MemOrder bugs -a type of concurrency bug caused by incorrect timing between a memory access to a particular object and the object's initialization or deallocation. We first show experimentally that the current state-of-the-art delay injection technique leads to high overhead and low detection coverage since MemOrder bugs exhibit particular characteristics that cause high delay density and interference. Based on these insights, we propose Waffle -a delay injection tool that tailors key design points to better match the nature of MemOrder bugs. Evaluating our tool on 11 popular opensource multi-threaded C# applications shows that Waffle can expose more bugs with less overhead than state-of-theart techniques.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 7da72682-933f-46d8-a7c7-b1e95e90a7f9Cited by top-tier papers4
- OZZ: Identifying Kernel Out-of-Order Concurrency Bugs with In-Vivo Memory Access ReorderingDae R. Jeong, Yewon Choi, Byoungyoung Lee, Insik Shin et al.SOSP 2024 · 4 citations
- Paralegal: Practical Static Analysis for Privacy BugsJustus Adam, Carolyn Zech, Livia Zhu, Sreshtaa Rajesh et al.OSDI 2025 · 2 citations
- Themis: Detecting Distributed Concurrency Bugs through RPC-Driven Race-Directed Test Generation and FuzzingHongchen Cao, Jingzhu He, Ting Dai, Guoliang JinNSDI 2026 · 1 citation
- State-Aware Fuzzing of JavaScript Engines with LLM-Guided InstrumentationWai Kin Wong, Dongwei Xiao, Anthony Cheuk Tung Lai, Ping Fan Ke et al.SOSP 2026
Builds on5
- Razzer: Finding Kernel Race Bugs through FuzzingDae R. Jeong, Kyungtae Kim, Basavesh Shivakumar, Byoungyoung Lee et al.S&P 2019 · 202 citations
- SoK: Sanitizing for SecurityDokyung Song, Julian Lettner, Prabhu Rajasekaran, Yeoul Na et al.S&P 2019 · 196 citations
- Preventing Use-After-Free Attacks with Fast Forward AllocationBrian Wickman, Hong Hu, Insu Yun, Daehee Jang et al.USENIX Security 2021 · 53 citations
- Snowboard: Finding Kernel Concurrency Bugs through Systematic Inter-thread Communication AnalysisSishuai Gong, Deniz Altinbüken, Pedro Fonseca, Petros ManiatisSOSP 2021 · 26 citations
- UAFSan: an object-identifier-based dynamic approach for detecting use-after-free vulnerabilitiesBinfa Gui, Wei Song, Jeff HuangISSTA 2021 · 9 citations
Related papers
- Reorder Pointer Flow in Sound Concurrency Bug PredictionYuqi Guo, Shihao Zhu, Yan Cai, Liang He et al.ICSE 2024 · 1 citation
- Efficiently detecting concurrency bugs in persistent memory programsZhangyu Chen, Yu Hua, Yongle Zhang, Luochangqi DingASPLOS 2022 · 11 citations
- Controlled Concurrency Testing via Periodical SchedulingCheng Wen, Mengda He, Bohao Wu, Zhiwu Xu et al.ICSE 2022 · 25 citations
- Fast, flexible, and comprehensive bug detection for persistent memory programsBang Di, Jiawen Liu, Hao Chen, Dong LiASPLOS 2021 · 37 citations
- Soundness of Predictive Concurrency AnalysesShuyang Liu, Doug Lea, Jens PalsbergOOPSLA 2025
