Judge: Identifying, Understanding, and Evaluating Sources of Unsoundness in Call Graphs
Call graphs are widely used; in particular for advanced control- and data-flow analyses. Even though many call graph algorithms with different precision and scalability properties have been proposed, a comprehensive understanding of sources of unsoundness, their relevance, and the capabilities of existing call graph algorithms in this respect is missing.
To address this problem, we propose Judge, a toolchain that helps with understanding sources of unsoundness and improving the soundness of call graphs. In several experiments, we use Judge and an extensive test suite related to sources of unsoundness to (a) compute capability profiles for call graph implementations of Soot, WALA, DOOP, and OPAL, (b) to determine the prevalence language features and APIs that affect soundness in modern Java Bytecode, (c) to compare the call graphs of Soot, WALA, DOOP, and OPAL, highlighting important differences in their implementations, and (d) to evaluate the necessary effort to achieve project-specific reasonable sound call graphs.
We show that soundness-relevant features/APIs are frequently used and that support for them differs vastly, up to the point where comparing call graphs computed by the same base algorithms (e.g., RTA) but different frameworks is bogus. We also show that Judge can support users in establishing the soundness of call graphs with reasonable effort.
Conference DayFri 19 JulDisplayed time zone: Beijing, Chongqing, Hong Kong, Urumqi change
11:00 - 12:30
|Differentially Testing Soundness and Precision of Program Analyzers|
Christian KlingerUniversity of Texas, Austin, Maria ChristakisMPI-SWS, Valentin WüstholzConsenSys DiligencePre-print
|Judge: Identifying, Understanding, and Evaluating Sources of Unsoundness in Call Graphs|
Michael ReifTU Darmstadt, Germany, Florian KüblerTU Darmstadt, Germany, Michael EichbergTU Darmstadt, Germany, Dominik HelmTU Darmstadt, Germany, Mira MeziniTU Darmstadt, GermanyPre-print File Attached
|Adlib: Analyzer for Mobile Ad Platform Libraries|
Technical PapersDOI Pre-print
|Interactive Metamorphic Testing of Debuggers|
Technical PapersLink to publication DOI Pre-print