From Leaks to Fixes: Automated Repairs for Resource Leak Warnings
Akshay Utture, Jens Palsberg
摘要
Resource leaks are a common and elusive source of bugs that can result in crashes and security vulnerabilities. The most effective technique to identify such leaks during development is static analysis. However, empirical studies show that in addition to leak warnings, developers often need help in the form of automated fix suggestions to correctly repair such leaks. The only existing tool that can suggest resource-leak fixes is the general-purpose tool Footpatch. Footpatch, however, performs poorly at this task; it generates fixes for only 6% of the leaks, out of which only 27% are correct.
In this paper, we introduce RLFixer, a specialized repair tool that generates high-quality fixes for resource leaks identified by any resource-leak detector. A major challenge for RLFixer is that the most general version of the resource-leak repair problem is at least as hard as compile-time object deallocation, a well-known hard problem for compilers. RLFixer tackles this issue by separating the resource-leaks that are infeasible for a compile-time tool to fix from those that are feasible to fix. RLFixer achieves this separation by using a new data-flow analysis of resource objects to classify how they escape the context of their methods. The same analysis also enables RLFixer to generate correct repairs for the feasibleto-fix leaks. RLFixer is demand-driven and hence only analyzes statements relevant to the leak, thereby keeping overhead low.
We evaluated RLFixer by applying it to warnings generated by five popular Java resource-leak detectors. We show that, on average, RLFixer generates repairs for 66% of their warnings, out of which 95% are correct. It has an average repair time of 14 seconds.
• Software and its engineering → Automated static analysis; Software maintenance tools.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper4
- Repairing Leaks in Resource WrappersSanjay Malakar, Michael D. Ernst, Martin Kellogg, Manu SridharanASE 2025
- Exposing Resource-Exhaustion DoS Vulnerabilities with Leak-Oriented Minimum Path CoversLige Zhan, Yafei He, Jiang Ming, Guojun Peng 等USENIX Security 2026
- SoK: Automated Vulnerability Repair: Methods, Tools, and AssessmentsYiwei Hu, Zhen Li, Kedie Shu, Shenghua Guan 等USENIX Security 2025
- A New Approach to Evaluating Nullability Inference ToolsNima Karimipour, Erfan Arvan, Martin Kellogg, Manu SridharanFSE 2025
它引用的顶会 Paper14
- CURE: Code-Aware Neural Machine Translation for Automatic Program RepairNan Jiang, Thibaud Lutellier, Lin TanICSE 2021 · 被引用 267 次
- Less training, more repairing please: revisiting automated program repair via zero-shot learningChunqiu Steven Xia, Lingming ZhangFSE 2022 · 被引用 223 次
- VulRepair: a T5-based automated software vulnerability repairMichael Fu, Chakkrit Tantithamthavorn, Trung Le, Van Nguyen 等FSE 2022 · 被引用 206 次
- DLFix: context-based code transformation learning for automated program repairYi Li, Shaohua Wang, Tien N. NguyenICSE 2020 · 被引用 201 次
- Neural Program Repair with Execution-based BackpropagationHe Ye, Matias Martinez, Martin MonperrusICSE 2022 · 被引用 146 次
相关 Paper
- Amur: Fixing Multi-Resource Leaks Guided by Resource Flow AnalysisJinyoung Kim, Eunseok LeeASE 2025
- Lightweight and modular resource leak verificationMartin Kellogg, Narges Shadab, Manu Sridharan, Michael D. ErnstFSE 2021 · 被引用 14 次
- JLeaks: A Featured Resource Leak Repository Collected From Hundreds of Open-Source Java ProjectsTianyang Liu, Weixing Ji, Xiaohui Dong, Wuhuang Yao 等ICSE 2024 · 被引用 1 次
- Project-Level Resource Leak Detection through Agent-based Ownership Analysis and Repair Pattern VerificationChengxin Xu, Xiu Zhang, Xiaorui GongICSE 2026
- AsyncLeakBench: A Curated Benchmark of Asynchronous Resource Leaks in Open-Source Java ProjectsJinyoung Kim, Jinseok Heo, Dongwook Choi, Eunseok LeeISSTA 2026
