Guarding the Lifeline: A First Look and Automated Defect Diagnosis for ROS Central Index
Weijie Sun, Huiyan Wang, Ying Wang, Chang Xu
摘要
The Robot Operating System (ROS) relies on a centralized dependency index, the rosdistro central index, to manage packages across its heterogeneous software ecosystem, which integrates independently evolving Operating System (OS) repositories for system libraries, ROS repositories for domain-specific support, and Programming Language (PL) repositories for functional modules. While this design enables portability, it introduces a critical source of fragility since ROS dependency management depends entirely on this manually curated, static index that must map packages across independently evolving, multi-source repositories. This leads to persistent defects in the central index, such as missing, incorrect, or outdated installation rules, which undermine the reliability of ROS dependency management. To address this problem, we conducted the first in-depth empirical study of 863 real-world maintenance cases involving the ROS central index. We categorize defects as either coverage or correctness defects, identify their underlying structural causes, and demonstrate that the primary bottleneck in manual maintenance is the difficulty of identifying equivalent packages across repositories. Motivated by these findings, we propose RosdepAuditor, an automated auditing framework that introduces a cross-repository mapping mechanism with hybrid scoring to infer package equivalence and detect defects. Evaluated on a ground-truth dataset, RosdepAuditor achieves 94.7% mapping accuracy without recommending non-existent packages, outperforming existing pattern-based and upstream-based approaches as well as leading large language models (LLMs). When applied to the live index, it uncovered 3,249 potential defects across 2,233 entries, 46 of which have been confirmed and fixed, demonstrating its practical usefulness in strengthening ROS dependency management.
CCS Concepts: • Software and its engineering → Software libraries and repositories; Software evolution.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper17
- Identifying Open-Source License Violation and 1-day Security Risk at Large ScaleRuian Duan, Ashish Bijlani, Meng Xu, Taesoo Kim 等CCS 2017 · 被引用 126 次
- Watchman: monitoring dependency conflicts for Python library ecosystemYing Wang, Ming Wen, Yepang Liu, Yibo Wang 等ICSE 2020 · 被引用 65 次
- Fixing dependency errors for Python build reproducibilitySuchita Mukherjee, Abigail Almanza, Cindy Rubio-GonzálezISSTA 2021 · 被引用 55 次
- A longitudinal analysis of bloated Java dependenciesCésar Soto-Valero, Thomas Durieux, Benoit BaudryFSE 2021 · 被引用 47 次
- BinaryAI: Binary Software Composition Analysis via Intelligent Binary Source Code MatchingLing Jiang, Junwen An, Huihui Huang, Qiyi Tang 等ICSE 2024 · 被引用 43 次
相关 Paper
- RoboFuzz: fuzzing robotic systems over robot operating system (ROS) for finding correctness bugsSeulbae Kim, Taesoo KimFSE 2022 · 被引用 32 次
- Enhancing ROS System Fuzzing through Callback TracingYuheng Shen, Jianzhong Liu, Yiru Xu, Hao Sun 等ISSTA 2024 · 被引用 7 次
- How to Pet a Two-Headed Snake? Solving Cross-Repository Compatibility Issues with HeraYifan Xie, Zhouyang Jia, Shanshan Li, Ying Wang 等ASE 2024 · 被引用 2 次
- BTreeFuzz: Enhanced Feedback Mechanism for ROS Program Fuzzer Based on Behavior TreeHee Yeon Kim, Gyunghoon Kim, Dong Hoon Lee, Wonsuk ChoiICSE 2026
- PHYSFRAME: type checking physical frames of reference for robotic systemsSayali Kate, Michael Chinn, Hongjun Choi, Xiangyu Zhang 等FSE 2021 · 被引用 5 次
