Paul Dan Marinescu

dblp:42/7893 · DBLP profile ↗
← Back
7ranked-venue papers
6as first author
0since 2021 · last 2014
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 4 · 3 first-authorSoftware engineering, systems software and programming languages · 3 · 3 first-authorSecurity and privacy · 2 · 1 first-author

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Software engineering, system software, and programming languages
5 papers
Software testing · 71% Empirical software engineering · 14% Program analysis · 11%

Topics — the 9 heaviest of 10, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Software testing › test generation
automated test generation
0.222013
KATCH: high-coverage testing of software patches · ESEC/SIGSOFT FSE 2013
Efficient Testing of Recovery Code Using Fault Injection · ACM Trans. Comput. Syst. 2011
Empirical software engineering
mining software repositories
0.212014
Covrig: a framework for the analysis of code, test, and coverage evolution in real software · ISSTA 2014
Software testing
test coverage
0.212014
Covrig: a framework for the analysis of code, test, and coverage evolution in real software · ISSTA 2014
Software testing › test generation
symbolic testing
0.212013
KATCH: high-coverage testing of software patches · ESEC/SIGSOFT FSE 2013
Software testing
regression testing
0.112012
make test-zesti: A symbolic execution solution for improving regression testing · ICSE 2012
Program analysis
symbolic execution
0.112012
make test-zesti: A symbolic execution solution for improving regression testing · ICSE 2012
Software testing › mutation testing
fault injection
0.112011
Efficient Testing of Recovery Code Using Fault Injection · ACM Trans. Comput. Syst. 2011
Software maintenance and evolution › software updates
software patching
0.112014
Covrig: a framework for the analysis of code, test, and coverage evolution in real software · ISSTA 2014
Software testing
test generation
0.012010
An Extensible Technique for High-Precision Testing of Recovery Code · USENIX ATC 2010

Methods — techniques the papers use, named apart from their topics

dynamic analysis · 0.4symbolic execution · 0.3virtualization · 0.2empirical study · 0.2static analysis · 0.2fault injection · 0.1binary analysis · 0.1high-precision testing · 0.1
YearPublicationVenuePosition
2014 Covrig: a framework for the analysis of code, test, and coverage evolution in real software
abstract
Software repositories provide rich information about the construction and evolution of software systems. While static data that can be mined directly from version control systems has been extensively studied, dynamic metrics concerning the execution of the software have received much less attention, due to the inherent difficulty of running and monitoring a large number of software versions. In this paper, we present Covrig, a flexible infrastructure that can be used to run each version of a system in isolation and collect static and dynamic software metrics, using a lightweight virtual machine environment that can be deployed on a cluster of local or cloud machines. We use Covrig to conduct an empirical study examining how code and tests co-evolve in six popular open-source systems. We report the main characteristics of software patches, analyse the evolution of program and patch coverage, assess the impact of nondeterminism on the execution of test suites, and investigate whether the coverage of code containing bugs and bug fixes is higher than average.
Paul Dan Marinescu, Petr Hosek 0001, Cristian Cadar
ISSTA1
2013 KATCH: high-coverage testing of software patches
abstract
One of the distinguishing characteristics of software systems is that they evolve: new patches are committed to software repositories and new versions are released to users on a continuous basis. Unfortunately, many of these changes bring unexpected bugs that break the stability of the system or affect its security. In this paper, we address this problem using a technique for automatically testing code patches. Our technique combines symbolic execution with several novel heuristics based on static and dynamic program analysis which allow it to quickly reach the code of the patch. We have implemented our approach in a tool called KATCH, which we have applied to all the patches written in a combined period of approximately six years for nineteen mature programs from the popular GNU diffutils, GNU binutils and GNU findutils utility suites, which are shipped with virtually all UNIX-based distributions. Our results show that KATCH can automatically synthesise inputs that significantly increase the patch coverage achieved by the existing manual test suites, and find bugs at the moment they are introduced.
Paul Dan Marinescu, Cristian Cadar
ESEC/SIGSOFT FSE1
2012 make test-zesti: A symbolic execution solution for improving regression testing
abstract
Software testing is an expensive and time consuming process, often involving the manual creation of comprehensive regression test suites. However, current testing methodologies do not take full advantage of these tests. In this paper, we present a technique for amplifying the effect of existing test suites using a lightweight symbolic execution mechanism, which thoroughly checks all sensitive operations (e.g., pointer dereferences) executed by the test suite for errors, and explores additional paths around sensitive operations. We implemented this technique in a prototype system called ZESTI (Zero-Effort Symbolic Test Improvement), and applied it to three open-source code bases — GNU Coreutils, libdwarf and readelf — where it found 52 previously unknown bugs, many of which are out of reach of standard symbolic execution. Our technique works transparently to the tester, requiring no additional human effort or changes to source code or tests.
Paul Dan Marinescu, Cristian Cadar
ICSE1
2011 Efficient Testing of Recovery Code Using Fault Injection
abstract
A critical part of developing a reliable software system is testing its recovery code. This code is traditionally difficult to test in the lab, and, in the field, it rarely gets to run; yet, when it does run, it must execute flawlessly in order to recover the system from failure. In this article, we present a library-level fault injection engine that enables the productive use of fault injection for software testing. We describe automated techniques for reliably identifying errors that applications may encounter when interacting with their environment, for automatically identifying high-value injection targets in program binaries, and for producing efficient injection test scenarios. We present a framework for writing precise triggers that inject desired faults, in the form of error return codes and corresponding side effects, at the boundary between applications and libraries. These techniques are embodied in LFI, a new fault injection engine we are distributing http://lfi.epfl.ch. This article includes a report of our initial experience using LFI. Most notably, LFI found 12 serious, previously unreported bugs in the MySQL database server, Git version control system, BIND name server, Pidgin IM client, and PBFT replication system with no developer assistance and no access to source code. LFI also increased recovery-code coverage from virtually zero up to 60% entirely automatically without requiring new tests or human involvement.
Paul Dan Marinescu, George Candea
ACM Trans. Comput. Syst.1
2010 Studying application-library interaction and behavior with LibTrac
abstract
LibTrac is a tool for studying the program/library boundary and answering questions like: Which library functions are called most often ? Are there library usage patterns that distinguish one class of applications from the others? Do programs generally retry failed I/O calls or not? The answers to these questions are essential to anyone employing library-level fault injection in software testing. On the one hand, the program-library boundary is an appealing location for injecting faults, because the cost of doing so is low, and one can emulate a wide range of realworld failures. On the other hand, developers must decide a priori which library calls to fail, when, and in what way. The space of possibilities is vast, so developers need tools like LibTrac to make informed choices for test scenarios. We used LibTrac to study 13 real-world systems; we report here some of the results. Compared to existing library tracers, LibTrac incurs one to two orders of magnitude less overhead, thus offering considerably more realistic study conditions.
Eric Bisolfati, Paul Dan Marinescu, George Candea
DSN2
2010 An Extensible Technique for High-Precision Testing of Recovery Code
Paul Dan Marinescu, Radu Banabic
USENIX ATC1
2009 LFI: A practical and general library-level fault injector
abstract
Fault injection, a critical aspect of testing robust systems, is often overlooked in the development of general-purpose software. We believe this is due to the absence of easy-to-use tools and to the extensive manual labor required to perform fault injection tests. This paper introduces LFI (library fault injector), a tool that automates the preparation of fault scenarios and their injection at the boundary between shared libraries and applications. LFI extends prior work by automatically profiling fault behaviors of libraries via static analysis of their binaries, thus reducing the dependence on human labor and perfect documentation. We present techniques for automatically generating injection scenarios and we describe a simple language for expressing such scenarios. LFI does not require access to libraries' source code and works for Linux, Windows, and Solaris on x86 and SPARC platforms.
Paul Dan Marinescu, George Candea
DSN1