Detecting Logical Bugs of DBMS with Coverage-based Guidance
Yu Liang, Song Liu, Hong Hu
摘要
Database management systems (DBMSs) are critical components of modern data-intensive applications. Developers have adopted many testing techniques to detect DBMS bugs such as crashes and assertion failures. However, most previous efforts cannot detect logical bugs that make the DBMS return incorrect results. Recent work proposed several oracles to identify incorrect results, but they rely on rule-based expression generation to synthesize queries without any guidance. In this paper, we propose to combine coverage-based guidance, validity-oriented mutations and oracles to detect logical bugs in DBMS systems. Specifically, we first design a set of general APIs to decouple the logic of fuzzers and oracles, so that developers can easily port fuzzing tools to test DBMSs and write new oracles for existing fuzzers. Then, we provide validity-oriented mutations to generate high-quality query statements in order to find more logical bugs. Our prototype, SQLRight, outperforms existing tools that only rely on oracles or code coverage. In total, SQLRight detects 18 logical bugs from two well-tested DBMSs, SQLite and MySQL. All bugs have been confirmed and 14 of them have been fixed. 01 CREATE TABLE person (pid INT ); 02 INSERT INTO person VALUES (1) , (10) , (10); 03 CREATE UNIQUE INDEX idx ON person (pid) WHERE pid =1; 04 SELECT DISTINCT pid FROM person WHERE pid =10; 05 --output : 10 n10 06 --expect : 10 CREATE TABLE person (pid INT ); INSERT INTO person VALUES (1) , (10) , (10); SELECT DISTINCT pid FROM person WHERE pid =10; Listing 2: A functional-equivalent query of Listing 1 query by deleting the CREATE UNIQUE INDEX statement. 01 CREATE TABLE v0 (v1 TEXT ); 02 INSERT INTO v0 VALUES ('text '); 03 SELECT v1 FROM 'v0 ';
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper32
- Testing Database Engines via Query Plan GuidanceJinsheng Ba, Manuel RiggerICSE 2023 · 被引用 39 次
- Testing Database Systems via Differential Query ExecutionJiansen Song, Wensheng Dou, Ziyu Cui, Qianwang Dai 等ICSE 2023 · 被引用 26 次
- Keep It Simple: Testing Databases via Differential Query PlansJinsheng Ba, Manuel RiggerSIGMOD 2024 · 被引用 23 次
- Detecting Logic Bugs in Database Engines via Equivalent Expression TransformationZu-Ming Jiang, Zhendong SuOSDI 2024 · 被引用 22 次
- Detecting Isolation Bugs via Transaction Oracle ConstructionWensheng Dou, Ziyu Cui, Qianwang Dai, Jiansen Song 等ICSE 2023 · 被引用 21 次
它引用的顶会 Paper23
- Driller: Augmenting Fuzzing Through Selective Symbolic ExecutionNick Stephens, John Grosen, Christopher Salls, Andrew Dutcher 等NDSS 2016 · 被引用 1,021 次
- Angora: Efficient Fuzzing by Principled SearchPeng Chen, Hao ChenS&P 2018 · 被引用 616 次
- QSYM : A Practical Concolic Execution Engine Tailored for Hybrid FuzzingInsu Yun, Sangho Lee, Meng Xu, Yeongjin Jang 等USENIX Security 2018 · 被引用 537 次
- CollAFL: Path Sensitive FuzzingShuitao Gan, Chao Zhang, Xiaojun Qin, Xuwen Tu 等S&P 2018 · 被引用 426 次
- REDQUEEN: Fuzzing with Input-to-State CorrespondenceCornelius Aschermann, Sergej Schumilo, Tim Blazytko, Robert Gawlik 等NDSS 2019 · 被引用 413 次
相关 Paper
- Pinolo: Detecting Logical Bugs in Database Management Systems with Approximate Query SynthesisZongyin Hao, Quanfeng Huang, Chengpeng Wang, Jianfeng Wang 等USENIX ATC 2023 · 被引用 26 次
- SQUIRREL: Testing Database Management Systems with Language Validity and Coverage FeedbackRui Zhong, Yongheng Chen, Hong Hu, Hangfan Zhang 等CCS 2020 · 被引用 5 次
- ValScope: Value-Semantics-Aware Metamorphic Testing for Detecting Logical Bugs in DBMSsLi Lin, Liehang Chen, Rongxin WuOSDI 2026
- Detecting Metadata-Related Logic Bugs in Database Systems via Raw Database ConstructionJiansen Song, Wensheng Dou, Yu Gao, Ziyu Cui 等VLDB 2024 · 被引用 13 次
- Constant Optimization Driven Database System TestingChi Zhang, Manuel RiggerSIGMOD 2025 · 被引用 8 次
