Understanding and Detecting SQL Function Bugs: Using Simple Boundary Arguments to Trigger Hundreds of DBMS Bugs
Jingzhou Fu, Jie Liang, Zhiyong Wu, Yanyang Zhao, Shanshan Li, Yu Jiang
摘要
Built-in SQL functions are crucial in Database Management Systems (DBMSs), supporting various operations and computations across multiple data types. They are essential for querying, data transformation, and aggregation. Despite their importance, the bugs in SQL functions have caused widespread problems in the real world, from system failures to arbitrary code execution. However, the understanding of the bug characteristics is limited. More importantly, conventional function testing methods struggle to generate semantically correct SQL test cases, while DBMS testing efforts are hard to measure built-in SQL functions.
This paper presents a comprehensive study of 318 built-in SQL function bugs, shedding light on their characteristics and root causes. Our investigation reveals that 87.4% of these bugs were caused by improper handling of boundary values of arguments. The boundary values of arguments come from three sources: literal values, type castings, and nested functions. By studying the bugs from three sources, we summarized 10 SQL patterns of bug-inducing queries. Moreover, we designed Soft, a testing tool based on the patterns to test seven widely used DBMSs, including PostgreSQL, MySQL, and ClickHouse. Soft discovered and confirmed 132 previously unknown SQL function bugs. The DBMS vendors took these bugs seriously and fixed 97 bugs in three days. For example, the CTO of ClickHouse commented on one bug: "We must fix it immediately or get rid of this function."
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- Fawkes: Finding Data Durability Bugs in DBMSs via Recovered Data State VerificationZhiyong Wu, Jie Liang, Jingzhou Fu, Wenqian Deng 等SOSP 2025 · 被引用 1 次
- VDBFuzz: Understanding and Detecting Crash Bugs in Vector Database Management SystemsShenao Wang, Zhao Liu, Yanjie Zhao, Quanchen Zou 等ICSE 2026
它引用的顶会 Paper20
- Angora: Efficient Fuzzing by Principled SearchPeng Chen, Hao ChenS&P 2018 · 被引用 616 次
- QSYM : A Practical Concolic Execution Engine Tailored for Hybrid FuzzingInsu Yun, Sangho Lee, Meng Xu, Yeongjin Jang 等USENIX Security 2018 · 被引用 537 次
- Testing Database Engines via Pivoted Query SynthesisManuel Rigger, Zhendong SuOSDI 2020 · 被引用 150 次
- Finding bugs in database systems via query partitioningManuel Rigger, Zhendong SuOOPSLA 2020 · 被引用 116 次
- Detecting optimization bugs in database engines via non-optimizing reference engine constructionManuel Rigger, Zhendong SuFSE 2020 · 被引用 104 次
相关 Paper
- Mozi: Discovering DBMS Bugs via Configuration-Based Equivalent TransformationJie Liang, Zhiyong Wu, Jingzhou Fu, Mingzhe Wang 等ICSE 2024 · 被引用 18 次
- ValScope: Value-Semantics-Aware Metamorphic Testing for Detecting Logical Bugs in DBMSsLi Lin, Liehang Chen, Rongxin WuOSDI 2026
- DynSQL: Stateful Fuzzing for Database Management Systems with Complex and Valid SQL Query GenerationZu-Ming Jiang, Jia-Ju Bai, Zhendong SuUSENIX Security 2023
- Scaling Automated Database System TestingSuyang Zhong, Manuel RiggerASPLOS 2026 · 被引用 4 次
- Efficiently Detecting DBMS Bugs through Bottom-up Syntax-based SQL GenerationYu Liang, Peng LiuNDSS 2026
