Finding broken Linux configuration specifications by statically analyzing the Kconfig language
Jeho Oh, Necip Fazil Yildiran, Julian Braha, Paul Gazzillo
摘要
Highly-configurable software underpins much of our computing infrastructure. It enables extensive reuse, but opens the door to broken configuration specifications. The configuration specification language, Kconfig, is designed to prevent invalid configurations of the Linux kernel from being built. However, the astronomical size of the configuration space for Linux makes finding specification bugs difficult by hand or with random testing. In this paper, we introduce a software model checking framework for building Kconfig static analysis tools. We develop a formal semantics of the Kconfig language and implement the semantics in a symbolic evaluator called kclause that models Kconfig behavior as logical formulas. We then design and implement a bug finder, called kismet, that takes kclause models and leverages automated theorem proving to find unmet dependency bugs. kismet is evaluated for its precision, performance, and impact on kernel development for a recent version of Linux, which has over 140,000 lines of Kconfig across 28 architecture-specific specifications. Our evaluation finds 781 bugs (151 when considering sharing among Kconfig specifications) with 100% precision, spending between 37 and 90 minutes for each Kconfig specification, although it misses some bugs due to underapproximation. Compared to random testing, kismet finds substantially more true positive bugs in a fraction of the time.
• Software and its engineering → Software configuration management and version control systems; Automated static analysis; Software testing and debugging.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper7
- AutoOS: Make Your OS More Powerful by Exploiting Large Language ModelsHuilai Chen, Yuanbo Wen, Limin Cheng, Shouxu Kuang 等ICML 2024 · 被引用 8 次
- Maximizing Patch Coverage for Testing of Highly-Configurable Software without Exploding Build TimesNecip Fazil Yildiran, Jeho Oh, Julia Lawall, Paul GazzilloFSE 2024 · 被引用 7 次
- Hacksaw: Hardware-Centric Kernel Debloating via Device Inventory and Dependency AnalysisZhenghao Hu, Sangho Lee, Marcus PeinadoCCS 2023 · 被引用 3 次
- Detecting Metadata-Related Bugs in Enterprise ApplicationsMd Mahir Asef Kabir, Xiaoyin Wang, Na MengFSE 2025 · 被引用 1 次
- On the Expressive Power of Languages for Static VariabilityPaul Maximilian Bittner, Alexander Schultheiß, Benjamin Moosherr, Jeffrey M. Young 等OOPSLA 2024 · 被引用 1 次
它引用的顶会 Paper3
- Block public access: trust safety verification of access control policiesMalik Bouchet, Byron Cook, Bryant Cutler, Anna Druzkina 等FSE 2020 · 被引用 25 次
- Practical fault detection in puppet programsThodoris Sotiropoulos, Dimitris Mitropoulos, Diomidis SpinellisICSE 2020 · 被引用 22 次
- Inferring and Applying Def-Use Like Configuration Couplings in Deployment DescriptorsChengyuan Wen, Yaxuan Zhang, Xiao He, Na MengASE 2020 · 被引用 3 次
相关 Paper
- Can SAT Solvers Keep Up With the Linux Kernel's Feature Model?Elias Kuiter, Urs-Benedict Braun, Thomas Thüm, Sebastian Krieter 等ICSE 2026
- Balancing Analysis Time and Bug Detection: Daily Development-friendly Bug Detection in LinuxKeita Suzuki, Kenta Ishiguro, Kenji KonoUSENIX ATC 2024 · 被引用 6 次
- Metha: Network Verifiers Need To Be Correct Too!Rüdiger Birkner, Tobias Brodmann, Petar Tsankov, Laurent Vanbever 等NSDI 2021 · 被引用 20 次
- KNighter: Transforming Static Analysis with LLM-Synthesized CheckersChenyuan Yang, Zijie Zhao, Zichen Xie, Haoyu Li 等SOSP 2025 · 被引用 1 次
- Metis: File System Model Checking via Versatile Input and State ExplorationYifei Liu, Manish Adkar, Gerard J. Holzmann, Geoff Kuenning 等FAST 2024 · 被引用 6 次
