Practical fault detection in puppet programs
Thodoris Sotiropoulos, Dimitris Mitropoulos, Diomidis Spinellis
摘要
Puppet is a popular computer system configuration management tool. By providing abstractions that model system resources it allows administrators to set up computer systems in a reliable, predictable, and documented fashion. Its use suffers from two potential pitfalls. First, if ordering constraints are not correctly specified whenever a Puppet resource depends on another, the nondeterministic application of resources can lead to race conditions and consequent failures. Second, if a service is not tied to its resources (through the notification construct), the system may operate in a stale state whenever a resource gets modified. Such faults can degrade a computing infrastructure's availability and functionality. We have developed an approach that identifies these issues through the analysis of a Puppet program and its system call trace. Specifically, a formal model for traces allows us to capture the interactions of Puppet resources with the file system. By analyzing these interactions we identify (1) resources that are related to each other (e.g., operate on the same file), and (2) resources that should act as notifiers so that changes are correctly propagated. We then check the relationships from the trace's analysis against the program's dependency graph: a representation containing all the ordering constraints and notifications declared in the program. If a mismatch is detected, our system reports a potential fault. We have evaluated our method on a large set of popular Puppet modules, and discovered 92 previously unknown issues in 33 modules. Performance benchmarking shows that our approach can analyze in seconds real-world configurations with a magnitude measured in thousands of lines and millions of system calls. CCS CONCEPTS • Software and its engineering → Software reliability; Software testing and debugging; File systems management.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper8
- Finding broken Linux configuration specifications by statically analyzing the Kconfig languageJeho Oh, Necip Fazil Yildiran, Julian Braha, Paul GazzilloFSE 2021 · 被引用 46 次
- GLITCH: Automated Polyglot Security Smell Detection in Infrastructure as CodeNuno Saavedra, João F. FerreiraASE 2022 · 被引用 27 次
- When Your Infrastructure Is a Buggy Program: Understanding Faults in Infrastructure as Code EcosystemsGeorgios-Petros Drosos, Thodoris Sotiropoulos, Georgios Alexopoulos, Dimitris Mitropoulos 等OOPSLA 2024 · 被引用 14 次
- State Reconciliation Defects in Infrastructure as CodeMd. Mahadi Hassan, John Salvador, Shubhra Kanti Karmaker Santu, Akond RahmanFSE 2024 · 被引用 8 次
- Maximizing Patch Coverage for Testing of Highly-Configurable Software without Exploding Build TimesNecip Fazil Yildiran, Jeho Oh, Julia Lawall, Paul GazzilloFSE 2024 · 被引用 7 次
相关 Paper
- ConfD: Analyzing Configuration Dependencies of File Systems for Fun and ProfitTabassum Mahmud, Om Rameshwar Gatla, Duo Zhang, Carson Love 等FAST 2023 · 被引用 7 次
- Leveraging Practitioners' Feedback to Improve a Security LinterSofia Reis, Rui Abreu, Marcelo d'Amorim, Daniel FortunatoASE 2022 · 被引用 16 次
- ConfTainter: Static Taint Analysis For Configuration OptionsTeng Wang, Haochen He, Xiaodong Liu, Shanshan Li 等ASE 2023 · 被引用 12 次
- Test-case prioritization for configuration testingRunxiang Cheng, Lingming Zhang, Darko Marinov, Tianyin XuISSTA 2021 · 被引用 34 次
- Approximate Computing Through the Lens of Uncertainty QuantificationKonstantinos Parasyris, James Diffenderfer, Harshitha Menon, Ignacio Laguna 等SC 2022 · 被引用 5 次
