Detecting Logic Bugs in Database Engines via Equivalent Expression Transformation
Zu-Ming Jiang, Zhendong Su
Abstract
Database management systems (DBMSs) are crucial for storing and fetching data. To improve the reliability of such systems, approaches have been proposed to detect logic bugs that cause DBMSs to process data incorrectly. These approaches manipulate queries and check whether the query results produced by DBMSs follow the expectations. However, such query-level manipulation cannot handle complex query semantics and thus needs to limit the patterns of generated queries, degrading testing effectiveness.
In this paper, we tackle the problem using a fine-grained methodology-expression-level manipulation-which empowers the proposed approach to be applicable to arbitrary queries. To find logic bugs in DBMSs, we design a novel and general approach, equivalent expression transformation (EET). Our core idea is that manipulating expressions of a query in a semantic-preserving manner also preserves the semantics of the entire query and is independent of query patterns. EET validates DBMSs by checking whether the transformed queries still produce the same results as the corresponding original queries. We realize our approach and evaluate it on 5 widely used and extensively tested DBMSs: MySQL, PostgreSQL, SQLite, ClickHouse, and TiDB. In total, EET found 66 unique bugs, 35 of which are logic bugs. We expect the generality and effectiveness of EET to inspire follow-up research and benefit the reliability of many DBMSs.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext d0b60e5c-1506-44e2-896a-ff0597529530Cited by top-tier papers12
- Constant Optimization Driven Database System TestingChi Zhang, Manuel RiggerSIGMOD 2025 · 8 citations
- Scaling Automated Database System TestingSuyang Zhong, Manuel RiggerASPLOS 2026 · 4 citations
- DDLumos: Understanding and Detecting Atomic DDL Bugs in DBMSsZhiyong Wu, Jie Liang, Jingzhou Fu, Wenqian Deng et al.USENIX ATC 2025 · 2 citations
- Testing Graph Databases with Synthesized QueriesZijing Yin, Si Liu, David A. BasinSIGMOD 2026 · 2 citations
- QTRAN: Extending Metamorphic-Oracle Based Logical Bug Detection Techniques for Multiple-DBMS Dialect SupportLi Lin, Qinglin Zhu, Hongqiao Chen, Zhuangda Wang et al.ISSTA 2025 · 2 citations
Builds on13
- Testing Database Engines via Pivoted Query SynthesisManuel Rigger, Zhendong SuOSDI 2020 · 150 citations
- Finding bugs in database systems via query partitioningManuel Rigger, Zhendong SuOOPSLA 2020 · 116 citations
- Detecting optimization bugs in database engines via non-optimizing reference engine constructionManuel Rigger, Zhendong SuFSE 2020 · 104 citations
- APOLLO: Automatic Detection and Diagnosis of Performance Regressions in Database SystemsJinho Jung, Hong Hu, Joy Arulraj, Taesoo Kim et al.VLDB 2020 · 77 citations
- Testing Database Engines via Query Plan GuidanceJinsheng Ba, Manuel RiggerICSE 2023 · 39 citations
Related papers
- Testing Database Systems via Differential Query ExecutionJiansen Song, Wensheng Dou, Ziyu Cui, Qianwang Dai et al.ICSE 2023 · 26 citations
- Detecting Logic Bugs in DBMSs via Equivalent Data ConstructionWenqian Deng, Jie Liang, Zhiyong Wu, Jingzhou Fu et al.SIGMOD 2026 · 1 citation
- Mozi: Discovering DBMS Bugs via Configuration-Based Equivalent TransformationJie Liang, Zhiyong Wu, Jingzhou Fu, Mingzhe Wang et al.ICSE 2024 · 18 citations
- EPSC: Testing Database Management Systems via Equivalent Prepared Statement ConstructionChi Zhang, Jie Liang, Zhiyong Wu, Dalong Shi et al.SIGMOD 2026 · 2 citations
- Detecting Schema-Related Logic Bugs in Relational DBMSs via Equivalent Database ConstructionJiansen Song, Wensheng Dou, Yingying Zheng, Yu Gao et al.VLDB 2025 · 6 citations
