State Reconciliation Defects in Infrastructure as Code
Md. Mahadi Hassan, John Salvador, Shubhra Kanti Karmaker Santu, Akond Rahman
摘要
In infrastructure as code (IaC), state reconciliation is the process of querying and comparing the infrastructure state prior to changing the infrastructure. As state reconciliation is pivotal to manage IaC-based computing infrastructure at scale, defects related to state reconciliation can create large-scale consequences. A categorization of state reconciliation defects, i.e., defects related to state reconciliation, can aid in understanding the nature of state reconciliation defects. We conduct an empirical study with 5,110 state reconciliation defects where we apply qualitative analysis to categorize state reconciliation defects. From the identified defect categories, we derive heuristics to design prompts for a large language model (LLM), which in turn are used for validation of state reconciliation. From our empirical study, we identify 8 categories of state reconciliation defects, amongst which 3 have not been reported for previously-studied software systems. The most frequently occurring defect category is inventory, i.e., the category of defects that occur when managing infrastructure inventory. Using an LLM with heuristics-based paragraph style prompts, we identify 9 previously unknown state reconciliation defects of which 7 have been accepted as valid defects, and 4 have already been fixed. Based on our findings, we conclude the paper by providing a set of recommendations for researchers and practitioners. CCS Concepts: • Software and its engineering → Software defect analysis ; Empirical software validation
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- When Your Infrastructure Is a Buggy Program: Understanding Faults in Infrastructure as Code EcosystemsGeorgios-Petros Drosos, Thodoris Sotiropoulos, Georgios Alexopoulos, Dimitris Mitropoulos 等OOPSLA 2024 · 被引用 14 次
- An Empirical Study on Kubernetes Operator BugsQingxin Xu, Yu Gao, Jun WeiISSTA 2024 · 被引用 7 次
- Who Watches the Watchers? On the Reliability of Softwarizing Cloud Application ManagementJiawei Tyler Gu, Zhen Tang, Yiming Su, Bogdan Alexandru Stoica 等NSDI 2026 · 被引用 3 次
- LLM4Perf: Large Language Models Are Effective Samplers for Multi-Objective Performance ModelingXin Wang, Zhenhao Li, Zishuo DingICSE 2026
- Unfulfilled Promises: LLM-Based Detection of OS Compatibility Issues in Infrastructure as CodeGeorgios-Petros Drosos, Georgios Alexopoulos, Thodoris Sotiropoulos, Dimitris Mitropoulos 等FSE 2026
它引用的顶会 Paper14
- TruthfulQA: Measuring How Models Mimic Human FalsehoodsStephanie Lin, Jacob Hilton, Owain EvansACL 2022 · 被引用 3,228 次
- Taxonomy of real faults in deep learning systemsNargiz Humbatova, Gunel Jahangirova, Gabriele Bavota, Vincenzo Riccio 等ICSE 2020 · 被引用 281 次
- A comprehensive study of autonomous vehicle bugsJoshua Garcia, Yang Feng, Junjie Shen, Sumaya Almanee 等ICSE 2020 · 被引用 127 次
- A comprehensive study of deep learning compiler bugsQingchao Shen, Haoyang Ma, Junjie Chen, Yongqiang Tian 等FSE 2021 · 被引用 123 次
- An empirical study on program failures of deep learning jobsRu Zhang, Wencong Xiao, Hongyu Zhang, Yu Liu 等ICSE 2020 · 被引用 96 次
相关 Paper
- Gang of eight: a defect taxonomy for infrastructure as code scriptsAkond Rahman, Effat Farhana, Chris Parnin, Laurie A. WilliamsICSE 2020 · 被引用 58 次
- NSync: Automated Cloud Infrastructure-as-Code Reconciliation with AI AgentsZhenning Yang, Hui Guan, Victor Nicolet, Brandon Paulsen 等ISSTA 2026
- Defects4Log: Benchmarking LLMs for Logging Code Defect Detection and ReasoningXin Wang, Zhenhao Li, Zishuo DingASE 2025 · 被引用 1 次
- From Static to Dynamic: Benchmarking Real-World Code Review with MCR-BenchDewu Zheng, Yanlin Wang, Xiwen Wang, Kefeng Duan 等ISSTA 2026
- Chasing Shadows: Pitfalls in LLM Security ResearchJonathan Evertz, Niklas Risse, Nicolai Neuer, Andreas Müller 等NDSS 2026 · 被引用 17 次
