Has My Release Disobeyed Semantic Versioning? Static Detection Based on Semantic Differencing
Lyuye Zhang, Chengwei Liu, Zhengzi Xu, Sen Chen, Lingling Fan, Bihuan Chen, Yang Liu
Abstract
To enhance the compatibility in the version control of Java Thirdparty Libraries (TPLs), Maven adopts Semantic Versioning (SemVer) to standardize the underlying meaning of versions, but users could still confront abnormal execution and crash after upgrades even if compilation and linkage succeed. It is caused by semantic breaking (SemB) issues, such that APIs directly used by users have identical signatures but inconsistent semantics across upgrades. To strengthen compliance with SemVer rules, developers and users should be alerted of such issues. Unfortunately, it is challenging to detect them statically, because semantic changes in the internal methods of APIs are difficult to capture. Dynamic testing can confirmingly uncover some, but it is limited by inadequate coverage. To detect SemB issues over compatible upgrades (Patch and Minor) by SemVer rules, we conduct an empirical study on 180 SemB issues to understand the root causes, inspired by which, we propose Sembid (Semantic Breaking Issue Detector) to statically detect such issues of TPLs for developers and users. Since APIs are directly used by users, Sembid detects and reports SemB issues based on APIs.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext e3484936-6ad4-4678-a0bb-c53522590915Cited by top-tier papers15
- Mitigating Persistence of Open-Source Vulnerabilities in Maven EcosystemLyuye Zhang, Chengwei Liu, Sen Chen, Zhengzi Xu et al.ASE 2023 · 25 citations
- Understanding Breaking Changes in the WildDhanushka Jayasuriya, Valerio Terragni, Jens Dietrich, Samuel Ou et al.ISSTA 2023 · 19 citations
- Compatible Remediation on Vulnerabilities from Third-Party Libraries for Java ProjectsLyuye Zhang, Chengwei Liu, Zhengzi Xu, Sen Chen et al.ICSE 2023 · 19 citations
- Empirical Analysis of Vulnerabilities Life Cycle in Golang EcosystemJinchang Hu, Lyuye Zhang, Chengwei Liu, Sen Yang et al.ICSE 2024 · 10 citations
- Understanding the Impact of APIs Behavioral Breaking Changes on Client ApplicationsDhanushka Jayasuriya, Valerio Terragni, Jens Dietrich, Kelly BlincoeFSE 2024 · 8 citations
Builds on5
- Demystifying the Vulnerability Propagation and Its Evolution via Dependency Trees in the NPM EcosystemChengwei Liu, Sen Chen, Lingling Fan, Bihuan Chen et al.ICSE 2022 · 94 citations
- ATVHUNTER: Reliable Version Detection of Third-Party Libraries for Vulnerability Identification in Android ApplicationsXian Zhan, Lingling Fan, Sen Chen, Feng Wu et al.ICSE 2021 · 85 citations
- CCGraph: a PDG-based code clone detector with approximate graph matchingYue Zou, Bihuan Ban, Yinxing Xue, Yun XuASE 2020 · 46 citations
- How Android developers handle evolution-induced API compatibility issues: a large-scale studyHao Xia, Yuan Zhang, Yingtian Zhou, Xiaoting Chen et al.ICSE 2020 · 38 citations
- Taming behavioral backward incompatibilities via cross-project testing and analysisLingchao Chen, Foyzul Hassan, Xiaoyin Wang, Lingming ZhangICSE 2020 · 30 citations
Related papers
- A Large-Scale Empirical Study on Semantic Versioning in Golang EcosystemWenke Li, Feng Wu, Cai Fu, Fan ZhouASE 2023 · 7 citations
- Interactive, effort-aware library version harmonizationKaifeng Huang, Bihuan Chen, Bowen Shi, Ying Wang et al.FSE 2020 · 32 citations
- Compatibility Issue Detection for Android Apps Based on Path-Sensitive Semantic AnalysisSen Yang, Sen Chen, Lingling Fan, Sihan Xu et al.ICSE 2023 · 12 citations
- Keep me Updated: An Empirical Study of Third-Party Library Updatability on AndroidErik Derr, Sven Bugiel, Sascha Fahl, Yasemin Acar et al.CCS 2017 · 196 citations
- Detecting locations in JavaScript programs affected by breaking library changesAnders Møller, Benjamin Barslev Nielsen, Martin Toldam TorpOOPSLA 2020 · 32 citations
