A Large-scale Study on API Misuses in the Wild

A Large-scale Study on API Misuses in the Wild
复制标题

DOI:
10.1109/icst49551.2021.00034
复制
发表时间:
2021-04
期刊:
2021 14th IEEE Conference on Software Testing, Verification and Validation (ICST)
影响因子:
--
通讯作者:
Xia Li;Jiajun Jiang;Samuel Benton;Y. Xiong;Lingming Zhang
Xia Li;Jiajun Jiang;Samuel Benton;Y. Xiong;Lingming Zhang
中科院分区:
其他
文献类型:
--
作者:
Xia Li;Jiajun Jiang;Samuel Benton;Y. Xiong;Lingming Zhang

文献摘要

相似文献

API的滥用非常普遍,危害极大。尽管已经提出了用于API误用检测的各种技术,但是甚至不清楚不同类型的API误用如何分布以及现有技术是否已经覆盖了所有主要类型的API误用。因此,在本文中,我们基于GitHub的528,546个历史错误修复提交(从2011年到2018年)对API误用进行了首次大规模实证研究。通过利用最先进的细粒度AST差异工具GumTree,我们提取了超过一百万个错误修复编辑操作,其中51.7%是API误用。我们进一步系统地将API误用分为九个不同的类别,根据编辑操作和上下文。我们还提取各种频繁的API误用模式的类别和相应的操作的基础上,这可以补充现有的API误用检测工具。我们的研究揭示了关于不同类型的API误用的重要性的各种实用指南。此外,基于我们的数据集,我们进行了一项用户研究,手动分析10个模式的使用限制,以探索挖掘的模式是否可以指导未来的API误用检测工具的设计。具体来说,我们发现在最新的Apache项目中仍然存在7,541个潜在的误用,其中149个已经报告给开发人员。到目前为止,已经确认和解决了57个问题(相应地拒绝了15个滥用问题)。结果表明,研究历史API误用的重要性,并采用我们的挖掘模式来检测未知的API误用的前景广阔。
API misuses are prevalent and extremely harmful. Despite various techniques have been proposed for API-misuse detection, it is not even clear how different types of API misuses distribute and whether existing techniques have covered all major types of API misuses. Therefore, in this paper, we conduct the first large-scale empirical study on API misuses based on 528,546 historical bug-fixing commits from GitHub (from 2011 to 2018). By leveraging a state-of-the-art fine-grained AST differencing tool, GumTree, we extract more than one million bug-fixing edit operations, 51.7% of which are API misuses. We further systematically classify API misuses into nine different categories according to the edit operations and context. We also extract various frequent API-misuse patterns based on the categories and corresponding operations, which can be complementary to existing API-misuse detection tools. Our study reveals various practical guidelines regarding the importance of different types of API misuses. Furthermore, based on our dataset, we perform a user study to manually analyze the usage constraints of 10 patterns to explore whether the mined patterns can guide the design of future API-misuse detection tools. Specifically, we find that 7,541 potential misuses still exist in latest Apache projects and 149 of them have been reported to developers. To date, 57 have already been confirmed and fixed (with 15 rejected misuses correspondingly). The results indicate the importance of studying historical API misuses and the promising future of employing our mined patterns for detecting unknown API misuses.