PMFuzz: test case generation for persistent memory programs

PMFuzz: test case generation for persistent memory programs
复制标题

DOI:
10.1145/3445814.3446691
复制
发表时间:
2021-04
期刊:
Proceedings of the 26th ACM International Conference on Architectural Support for Programming Languages and Operating Systems
影响因子:
--
通讯作者:
Sihang Liu;Suyash Mahar;Baishakhi Ray;S. Khan
Sihang Liu;Suyash Mahar;Baishakhi Ray;S. Khan
中科院分区:
其他
文献类型:
--
作者:
Sihang Liu;Suyash Mahar;Baishakhi Ray;S. Khan

文献摘要

被引文献

相似文献

持久性内存(PM)技术将存储的持久性与接近DRAM的性能结合在一起。利用PM的程序必须确保数据在发生故障(例如断电)后仍然是可恢复的,因此,很容易出现崩溃一致性错误,从而导致故障后的不正确恢复。以前的工作提供了一些工具,如Pmemcheck、PMTest和XFDetector,它们通过检查PM访问的跟踪是否违反了程序的崩溃一致性保证来检测这些错误。但是,崩溃一致性错误的检测高度依赖于测试用例—只有在执行了有错误的程序路径时才能检测到错误。因此,使用测试用例生成器对于有效地检测崩溃一致性错误是必要的。模糊测试是一种常见的测试用例生成方法,它需要最少的程序知识。我们发现PM程序对模糊测试有特殊的要求。首先,PM程序维护PM映像的持久状态。因此,fuzzer需要有效地生成有效的图像作为测试用例的一部分。其次,这些PM图像也可能是先前崩溃的结果,这也需要模糊器生成崩溃图像。最后,PM程序可以有各种过程,但只有那些执行PM操作的过程才会导致崩溃一致性问题。因此,一个有效的模糊器应该针对这些相关区域。在这项工作中,我们提供了PMFuzz,一个用于满足这些新需求的项目管理程序的测试用例生成器。我们的评估表明,与afl++(一个广泛使用的模糊器)相比,PMFuzz覆盖的pm相关路径多4.6倍。此外,由PMFuzz生成的测试用例在PM程序中发现了12个新的实际错误,这些错误已经被之前的PM测试工作广泛测试过。
The Persistent Memory (PM) technology combines the persistence of storage with the performance approaching that of DRAM. Programs taking advantage of PM must ensure data remains recoverable after a failure (e.g., power outage), and therefore, are susceptible to having crash consistency bugs that lead to incorrect recovery after a failure. Prior works have provided tools, such as Pmemcheck, PMTest, and XFDetector, that detect these bugs by checking whether the trace of PM accesses violates the program’s crash consistency guarantees. However, detection of crash consistency bugs highly depends on test cases—a bug can only be detected if the buggy program path has been executed. Therefore, using a test case generator is necessary to effectively detect crash consistency bugs. Fuzzing is a common test case generation approach that requires minimum knowledge about the program. We identify that PM programs have special requirements for fuzzing. First, a PM program maintains a persistent state on PM images. Therefore, the fuzzer needs to efficiently generate valid images as part of the test case. Second, these PM images can also be a result of a previous crash, which requires the fuzzer to generate crash images as well. Finally, PM programs can have various procedures but only those performing PM operations can lead to crash consistency issues. Thus, an efficient fuzzer should target those relevant regions. In this work, we provide PMFuzz, a test case generator for PM programs that meets these new requirements. Our evaluation shows that PMFuzz covers 4.6× more PM-related paths compared to AFL++, a widely-used fuzzer. Further, test cases generated by PMFuzz discovered 12 new real-world bugs in PM programs which have already been extensively tested by prior PM testing works.