Judge: Identifying, Understanding, and Evaluating Sources of Unsoundness in Call Graphs
Call graphs are widely used; in particular for advanced control- and data-flow analyses. Even though many call graph algorithms with different precision and scalability properties have been proposed, a comprehensive understanding of sources of unsoundness, their relevance, and the capabilities of existing call graph algorithms in this respect is missing.
To address this problem, we propose Judge, a toolchain that helps with understanding sources of unsoundness and improving the soundness of call graphs. In several experiments, we use Judge and an extensive test suite related to sources of unsoundness to (a) compute capability profiles for call graph implementations of Soot, WALA, DOOP, and OPAL, (b) to determine the prevalence language features and APIs that affect soundness in modern Java Bytecode, (c) to compare the call graphs of Soot, WALA, DOOP, and OPAL, highlighting important differences in their implementations, and (d) to evaluate the necessary effort to achieve project-specific reasonable sound call graphs.
We show that soundness-relevant features/APIs are frequently used and that support for them differs vastly, up to the point where comparing call graphs computed by the same base algorithms (e.g., RTA) but different frameworks is bogus. We also show that Judge can support users in establishing the soundness of call graphs with reasonable effort.
Fri 19 JulDisplayed time zone: Beijing, Chongqing, Hong Kong, Urumqi change
11:00 - 12:30
|Differentially Testing Soundness and Precision of Program Analyzers|
Christian Klinger University of Texas, Austin, Maria Christakis MPI-SWS, Valentin Wüstholz ConsenSys DiligencePre-print
|Judge: Identifying, Understanding, and Evaluating Sources of Unsoundness in Call Graphs|
Michael Reif TU Darmstadt, Germany, Florian Kübler TU Darmstadt, Germany, Michael Eichberg TU Darmstadt, Germany, Dominik Helm TU Darmstadt, Germany, Mira Mezini TU Darmstadt, GermanyPre-print File Attached
|Adlib: Analyzer for Mobile Ad Platform Libraries|
Technical PapersDOI Pre-print
|Interactive Metamorphic Testing of Debuggers|
Sandro Tolksdorf TU Darmstadt, Daniel Lehmann TU Darmstadt, Michael Pradel TU Darmstadt and FacebookLink to publication DOI Pre-print