Fast and Precise Application Code Analysis using a Partial Library
Akshay Utture, Jens Palsberg
Abstract
Long analysis times are a key bottleneck for the widespread adoption of whole-program static analysis tools. Fortunately, however, a user is often only interested in finding errors in the application code, which constitutes a small fraction of the whole program. Current application-focused analysis tools overapproximate the effect of the library and hence reduce the precision of the analysis results. However, empirical studies have shown that users have high expectations on precision and will ignore tool results that don't meet these expectations. In this paper, we introduce the first tool QueryMax that significantly speeds up an application code analysis without dropping any precision. QueryMax acts as a pre-processor to an existing analysis tool to select a partial library that is most relevant to the analysis queries in the application code. The selected partial library plus the application is given as input to the existing static analysis tool, with the remaining library pointers treated as the bottom element in the abstract domain. This achieves a significant speedup over a whole-program analysis, at the cost of a few lost errors, and with no loss in precision. We instantiate and run experiments on QueryMax for a cast-check analysis and a null-pointer analysis. For a particular configuration, QueryMax enables these two analyses to achieve, relative to a whole-program analysis, an average recall of 87%, a precision of 100% and a geometric mean speedup of 10x.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext da9b22e7-67c1-467a-b152-97c4266e2704Cited by top-tier papers2
- From Leaks to Fixes: Automated Repairs for Resource Leak WarningsAkshay Utture, Jens PalsbergFSE 2023 · 5 citations
- Automatic Generation and Reuse of Precise Library Summaries for Object-Sensitive Pointer AnalysisJingbo Lu, Dongjie He, Wei Li, Yaoqing Gao et al.ASE 2023 · 1 citation
Builds on3
- Conquering the extensional scalability problem for value-flow analysis frameworksQingkai Shi, Rongxin Wu, Gang Fan, Charles ZhangICSE 2020 · 15 citations
- Pipelining bottom-up data flow analysisQingkai Shi, Charles ZhangICSE 2020 · 14 citations
- Heaps'n leaks: how heap snapshots improve Android taint analysisManuel Benz, Erik Krogh Kristensen, Linghui Luo, Nataniel P. Borges et al.ICSE 2020 · 9 citations
Related papers
- A Container-Usage-Pattern-Based Context Debloating Approach for Object-Sensitive Pointer AnalysisDongjie He, Yujiang Gui, Wei Li, Yonggang Tao et al.OOPSLA 2023 · 9 citations
- PUS: A Fast and Highly Efficient Solver for Inclusion-based Pointer AnalysisPeiming Liu, Yanze Li, Bradley Swain, Jeff HuangICSE 2022 · 3 citations
- Hybrid Inlining: A Framework for Compositional and Context-Sensitive Static AnalysisJiangchao Liu, Jierui Liu, Peng Di, Diyu Wu et al.ISSTA 2023 · 3 citations
- Striking a Balance: Pruning False-Positives from Static Call GraphsAkshay Utture, Shuyang Liu, Christian Gram Kalhauge, Jens PalsbergICSE 2022 · 18 citations
- Program analysis via efficient symbolic abstractionPeisen Yao, Qingkai Shi, Heqing Huang, Charles ZhangOOPSLA 2021 · 12 citations
