Snowcat: Efficient Kernel Concurrency Testing using a Learned Coverage Predictor

Snowcat: Efficient Kernel Concurrency Testing using a Learned Coverage Predictor
复制标题

DOI:
10.1145/3600006.3613148
复制
发表时间:
2023-10
期刊:
Proceedings of the 29th Symposium on Operating Systems Principles
影响因子:
--
通讯作者:
Sishuai Gong;Dinglan Peng;Deniz Altinbüken;Google Deepmind;Petros Maniatis
Sishuai Gong;Dinglan Peng;Deniz Altinbüken;Google Deepmind;Petros Maniatis
中科院分区:
其他
文献类型:
--
作者:
Sishuai Gong;Dinglan Peng;Deniz Altinbüken;Google Deepmind;Petros Maniatis

文献摘要

相似文献

基于随机的方法和启发式方法通常在内核并发测试中使用,这是由于现代内核的大量规模和相应的交织空间,缺乏准确且可扩展的方法来分析并发的内核执行方法不幸的是,新测试的有效性。在找到有效的并发测试输入和时间表时,会阻碍整体测试效率。进行同时的测试输入和调度提示,并输出有关是否将使用此预测变量执行某些重要代码块的预测。同时进行的测试可能是徒劳的,并在测试Linux内核一周以上的实际动态执行方面优先考虑,雪猫通过比现有工作更富有成果的测试的优先级测试来发现〜17%的潜在数据竞赛选择。 (15×)比艺术品的测试工具更重要的是,雪猫在连续的环境中达到了理想的竞赛水平,因为Linux内核从雪球总共演变为snowcat在Linux内核6.1中发现了17个新的并发错误,其中13个已确认,固定了6个。
Random-based approaches and heuristics are commonly used in kernel concurrency testing due to the massive scale of modern kernels and corresponding interleaving space. The lack of accurate and scalable approaches to analyze concurrent kernel executions makes existing testing approaches heavily rely on expensive dynamic executions to measure the effectiveness of a new test. Unfortunately, the high cost incurred by dynamic executions limits the breadth of the exploration and puts latency pressure on finding effective concurrent test inputs and schedules, hindering the overall testing effectiveness. This paper proposes Snowcat, a kernel concurrency testing framework that generates effective test inputs and schedules using a learned kernel block-coverage predictor. Using a graph neural network, the coverage predictor takes a concurrent test input and scheduling hints and outputs a prediction on whether certain important code blocks will be executed. Using this predictor, Snowcat can skip concurrent tests that are likely to be fruitless and prioritize the promising ones for actual dynamic execution. After testing the Linux kernel for over a week, Snowcat finds ~17% more potential data races, by prioritizing tests of more fruitful schedules than existing work would have chosen. Snowcat can also find effective test inputs that expose new concurrency bugs with higher probability (1.4×~2.6×), or reproduce known bugs more quickly (15×) than state-of-art testing tools. More importantly, Snowcat is shown to be more efficient at reaching a desirable level of race coverage in the continuous setting, as the Linux kernel evolves from version to version. In total, Snowcat discovered 17 new concurrency bugs in Linux kernel 6.1, of which 13 are confirmed and 6 are fixed.