ZendDiff: Differential Testing of PHP Interpreter
Yuancheng Jiang, Jianing Wang, Qiange Liu, Yeqi Fu, Jian Mao, Roland H. C. Yap, Zhenkai Liang
Abstract
The PHP interpreter, powering over 70% of websites on the internet, plays a crucial role in web development. Existing approaches to finding bugs in PHP primarily focus on detecting explicit security issues through crashes or sanitizerbased oracles, but fail to identify logic bugs that can silently lead to incorrect results. We observe that the introduction of Just-In-Time (JIT) compilation mode in PHP presents an opportunity for differential testing, as it provides an alternative implementation of the same language specification. We propose, ZendDiff, an automatic differential testing framework that effectively detects logic bugs in the PHP interpreter by comparing JIT and non-JIT execution results. Our differential testing incorporates three techniques: program state probing for fine-grained execution state comparison, JIT-aware program mutation to sufficiently exercise JIT functionality, and dual verification to handle nondeterministic behaviors in PHP programs. Our experimental results demonstrate that ZendDiff outperforms the official test suite used in PHP's continuous integration, achieving higher code coverage and executing more Zend opcodes. Through ablation studies, we validate the effectiveness of these techniques. To date, ZendDiff has identified 51 previously unknown logic bugs in the PHP interpreter, with 37 already fixed and 3 confirmed by the PHP maintainers. ZendDiff has been acknowledged by the PHP community and offers a practical tool for automatically discovering logic bugs in the PHP interpreter. Index Terms-differential testing, just-in-time compilation, logic bug detection, PHP interpreter, software testing Zend Virtual Machine PHP Code Opcache JIT Buffer JIT Compiler Machine Code
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext f69f6068-120c-4dc6-b49c-ef1419414374Cited by top-tier papers1
Ask how each one uses itBuilds on20
- Evaluating Fuzz TestingGeorge Klees, Andrew Ruef, Benji Cooper, Shiyi Wei et al.CCS 2018 · 753 citations
- NAUTILUS: Fishing for Deep Bugs with GrammarsCornelius Aschermann, Tommaso Frassetto, Thorsten Holz, Patrick Jauernig et al.NDSS 2019 · 291 citations
- Testing Database Engines via Pivoted Query SynthesisManuel Rigger, Zhendong SuOSDI 2020 · 150 citations
- Finding bugs in database systems via query partitioningManuel Rigger, Zhendong SuOOPSLA 2020 · 116 citations
- Automated conformance testing for JavaScript engines via deep compiler fuzzingGuixin Ye, Zhanyong Tang, Shin Hwei Tan, Songfang Huang et al.PLDI 2021 · 75 citations
Related papers
- Interpreter-guided differential JIT compiler unit testingGuillermo Polito, Stéphane Ducasse, Pablo TesonePLDI 2022 · 9 citations
- JEST: N+1 -version Differential Testing of Both JavaScript Engines and SpecificationJihyeok Park, Seungmin An, Dongjun Youn, Gyeongwon Kim et al.ICSE 2021 · 24 citations
- LWDIFF: an LLM-Assisted Differential Testing Framework for Webassembly RuntimesShiyao Zhou, Jincheng Wang, He Ye, Hao Zhou et al.ICSE 2025 · 2 citations
- Holistic Concolic Execution for Dynamic Web Applications via Symbolic Interpreter AnalysisPenghui Li, Wei Meng, Mingxue Zhang, Chenlin Wang et al.S&P 2024 · 6 citations
- Fuzzing the PHP Interpreter via Dataflow FusionYuancheng Jiang, Chuqi Zhang, Bonan Ruan, Jiahao Liu et al.USENIX Security 2025
