JavaDL: automatically incrementalizing Java bug pattern detection
Alexandru Dura, Christoph Reichenbach, Emma Söderberg
Abstract
Static checker frameworks support software developers by automatically discovering bugs that fit generalpurpose bug patterns. These frameworks ship with hundreds of detectors for such patterns and allow developers to add custom detectors for their own projects. However, existing frameworks generally encode detectors in imperative specifications, with extensive details of not only what to detect but also how. These details complicate detector maintenance and evolution, and also interfere with the framework's ability to change how detection is done, for instance, to make the detectors incremental.
In this paper, we present JavaDL, a Datalog-based declarative specification language for bug pattern detection in Java code. JavaDL seamlessly supports both exhaustive and incremental evaluation from the same detector specification. This specification allows developers to describe local detector components via syntactic pattern matching, and nonlocal (e.g., interprocedural) reasoning via Datalog-style logical rules. We compare our approach against the well-established SpotBugs and Error Prone tools by re-implementing several of their detectors in JavaDL. We find that our implementations are substantially smaller and similarly effective at detecting bugs on the Defects4J benchmark suite, and run with competitive runtime performance. In our experiments, neither incremental nor exhaustive analysis can consistently outperform the other, which highlights the value of our ability to transparently switch execution modes. We argue that our approach showcases the potential of clear-box static checker frameworks that constrain the bug detector specification language to enable the framework to adapt and enhance the detectors. CCS Concepts: • Software and its engineering → Automated static analysis; Constraint and logic languages; Domain specific languages; • Theory of computation → Pattern matching.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers1
Ask how each one uses itBuilds on1
Related papers
- Detecting Metadata-Related Bugs in Enterprise ApplicationsMd Mahir Asef Kabir, Xiaoyin Wang, Na MengFSE 2025 · 1 citation
- On the Real-World Effectiveness of Static Bug Detectors at Finding Null Pointer ExceptionsDavid A. Tomassi, Cindy Rubio-GonzálezASE 2021 · 24 citations
- Tai-e: A Developer-Friendly Static Analysis Framework for Java by Harnessing the Good Designs of ClassicsTian Tan, Yue LiISSTA 2023 · 26 citations
- Pattern-Based Peephole Optimizations with Java JIT TestsZhiqiang Zang, Aditya Thimmaiah, Milos GligoricISSTA 2023 · 2 citations
- Validating Soundness and Completeness in Pattern-Match Coverage AnalyzersCyril Moser, Thodoris Sotiropoulos, Chengyu Zhang, Zhendong SuOOPSLA 2025 · 1 citation
