EDBT 2026 Demo / reviewers in the wild / expert
Eelco Dolstra
dblp:82/1700
· DBLP profile ↗
14ranked-venue papers
8as first author
0since 2021 · last 2014
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 13 · 7 first-authorSystems, architecture and hardware · 1 · 1 first-authorDatabases, data management, data science and information retrieval · 1
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Software engineering, system software, and programming languages
3 papers |
Software maintenance and evolution · 87% Program analysis · 7% Operating systems · 7% | |
| Network and information security
1 paper |
Authentication and access control · 100% |
Topics — the 9 heaviest of 10, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Software maintenance and evolution › software ecosystems
license compliance |
0.2 | 1 | 2014 | Tracing software build processes to uncover license compliance inconsistencies · ASE 2014 |
Software maintenance and evolution
software dependencies |
0.2 | 1 | 2014 | Tracing software build processes to uncover license compliance inconsistencies · ASE 2014 |
Software maintenance and evolution
software ecosystems |
0.2 | 1 | 2014 | Tracing software build processes to uncover license compliance inconsistencies · ASE 2014 |
Software maintenance and evolution › software configuration management › software release management
software deployment |
0.1 | 2 | 2005 | Secure sharing between untrusted users in a transparent source/binary deployment model · ASE 2005 Imposing a Memory Management Discipline on Software Deployment · ICSE 2004 |
Program analysis
dynamic analysis |
0.1 | 1 | 2014 | Tracing software build processes to uncover license compliance inconsistencies · ASE 2014 |
Operating systems › operating system interface › system call
system call tracing |
0.1 | 1 | 2014 | Tracing software build processes to uncover license compliance inconsistencies · ASE 2014 |
Software maintenance and evolution › software ecosystems
dependency management |
0.0 | 1 | 2004 | Imposing a Memory Management Discipline on Software Deployment · ICSE 2004 |
Authentication and access control
trust management |
0.0 | 1 | 2005 | Secure sharing between untrusted users in a transparent source/binary deployment model · ASE 2005 |
Software maintenance and evolution › software dependencies › software dependency management
package management |
0.0 | 1 | 2004 | Imposing a Memory Management Discipline on Software Deployment · ICSE 2004 |
Methods — techniques the papers use, named apart from their topics
graph construction · 0.2dynamic system call tracing · 0.2hash rewriting · 0.1content-addressable storage · 0.1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2014 | Tracing software build processes to uncover license compliance inconsistenciesabstractOpen Source Software (OSS) components form the basis for many software systems. While the use of OSS components accelerates development, client systems must comply with the license terms of the OSS components that they use. Failure to do so exposes client system distributors to possible litigation from copyright holders. Yet despite the importance of license compliance, tool support for license compliance assessment is lacking. In this paper, we propose an approach to construct and analyze the Concrete Build Dependency Graph (CBDG) of a software system by tracing system calls that occur at build-time. Through a case study of seven open source systems, we show that the constructed CBDGs: (1) accurately classify sources as included in or excluded from deliverables with 88%-100% precision and 98%-100% recall, and (2) can uncover license compliance inconsistencies in real software systems -- two of which prompted code fixes in the CUPS and FFmpeg systems. Sander van der Burg, Eelco Dolstra, Shane McIntosh, Julius Davies, Daniel M. Germán, Armijn Hemel |
ASE | 2 |
| 2014 | Disnix: A toolset for distributed deployment
Sander van der Burg, Eelco Dolstra |
Sci. Comput. Program. | 2 |
| 2013 | Crowdsourcing GUI TestsabstractGraphical user interfaces are difficult to test: automated tests are hard to create and maintain, while manual tests are time-consuming, expensive and hard to integrate in a continuous testing process. In this paper, we show that it is possible to crowdsource GUI tests, that is, to outsource them to individuals drawn from a large pool of workers on the Internet, by instantiating virtual machines (VMs) running the system under test and letting testers access the VMs through their web browsers. This enables semi-automated continuous testing of GUIs and usability experiments with large numbers of participants at low cost. Several large experiments on the Amazon Mechanical Turk demonstrate that our approach is technically feasible and sufficiently reliable. Eelco Dolstra, Raynor Vliegendhart, Johan A. Pouwelse |
ICST | 1 |
| 2011 | Finding software license violations through binary code clone detectionabstractSoftware released in binary form frequently uses third-party packages without respecting their licensing terms. For instance, many consumer devices have firmware containing the Linux kernel, without the suppliers following the requirements of the GNU General Public License. Such license violations are often accidental, e.g., when vendors receive binary code from their suppliers with no indication of its provenance. To help find such violations, we have developed the Binary Analysis Tool (BAT), a system for code clone detection in binaries. Given a binary, such as a firmware image, it attempts to detect cloning of code from repositories of packages in source and binary form. We evaluate and compare the effectiveness of three of BAT's clone detection techniques: scanning for string literals, detecting similarity through data compression, and detecting similarity by computing binary deltas. Armijn Hemel, Karl Trygve Kalleberg, Rob Vermaas, Eelco Dolstra |
MSR | 4 |
| 2010 | Automating System Tests Using Declarative Virtual MachinesabstractAutomated regression test suites are an essential software engineering practice: they provide developers with rapid feedback on the impact of changes to a system's source code. The inclusion of a test case in an automated test suite requires that the system's build process can automatically provide all the environmental dependencies of the test. These are external elements necessary for a test to succeed, such as shared libraries, running programs, and so on. For some tests (e.g., a compiler's), these requirements are simple to meet. However, many kinds of tests, especially at the integration or system level, have complex dependencies that are hard to provide automatically, such as running database servers, administrative privileges, services on external machines or specific network topologies. As such dependencies make tests difficult to script, they are often only performed manually, if at all. This particularly affects testing of distributed systems and system-level software. This paper shows how we can automatically instantiate the complex environments necessary for tests by creating (networks of) virtual machines on the fly from declarative specifications. Building on NixOS, a Linux distribution with a declarative configuration model, these specifications concisely model the required environmental dependencies. We also describe techniques that allow efficient instantiation of VMs. As a result, complex system tests become as easy to specify and execute as unit tests. We evaluate our approach using a number of representative problems, including automated regression testing of a Linux distribution. Sander van der Burg, Eelco Dolstra |
ISSRE | 2 |
| 2010 | NixOS: A purely functional Linux distributionabstractAbstract Existing package and system configuration management tools suffer from an imperative model , where system administration actions such as package upgrades or changes to system configuration files are stateful: they destructively update the state of the system. This leads to many problems, such as the inability to roll back changes easily, to deploy multiple versions of a package side-by-side, to reproduce a configuration deterministically on another machine, or to reliably upgrade a system. In this paper we show that we can overcome these problems by moving to a purely functional system configuration model . This means that all static parts of a system (such as software packages, configuration files and system startup scripts) are built by pure functions and are immutable, stored in a way analogous to a heap in a purely functional language. We have implemented this model in NixOS , a non-trivial Linux distribution that uses the Nix package manager to build the entire system configuration from a modular, purely functional specification. Eelco Dolstra, Andres Löh, Nicolas Pierron |
J. Funct. Program. | 1 |
| 2010 | Preventing injection attacks with syntax embeddings
Martin Bravenboer, Eelco Dolstra, Eelco Visser |
Sci. Comput. Program. | 2 |
| 2008 | Report on the tenth ICFP programming contestabstractThe ICFP programming contest is a 72-hour contest, which attracts thousands of contestants from all over the world. In this report we describe what it takes to organise this contest, the main ideas behind the contest we organised, the task, how to solve it, how we created it, and how well the contestants did. Eelco Dolstra, Jurriaan Hage, Bastiaan Heeren, Stefan Holdermans, Johan Jeuring, Andres Löh, Clara Löh, Arie Middelkoop, Alexey Rodriguez Yakushev, John van Schie |
ICFP | 1 |
| 2008 | NixOS: a purely functional Linux distributionabstractExisting package and system configuration management tools suffer from an imperative model, where system administration actions such as upgrading packages or changes to system configuration files are stateful: they destructively update the state of the system. This leads to many problems, such as the inability to roll back changes easily, to run multiple versions of a package side-by-side, to reproduce a configuration deterministically on another machine, or to reliably upgrade a system. In this paper we show that we can overcome these problems by moving to a purely functional system configuration model. This means that all static parts of a system (such as software packages, configuration files and system startup scripts) are built by pure functions and are immutable, stored in a way analogously to a heap in a purely function language. We have implemented this model in NixOS, a non-trivial Linux distribution that uses the Nix package manager to build the entire system configuration from a purely functional specification. Eelco Dolstra, Andres Löh |
ICFP | 1 |
| 2007 | Preventing injection attacks with syntax embeddingsabstractSoftware written in one language often needs to construct sentences in another language, such as SQL queries, XML output, or shell command invocations. This is almost always done using unhygienic string manipulation, the concatenation of constants and client-supplied strings. A client can then supply specially crafted input that causes the constructed sentence to be interpreted in an unintended way, leading to an injection attack. We describe a more natural style of programming that yields code that is impervious to injections by construction. Our approach embeds the grammars of the guest languages (e.g., SQL) into that of the host language (e.g., Java) and automatically generates code that maps the embedded language to constructs in the host language that reconstruct the embedded sentences, adding escaping functions where appropriate. This approach is generic, meaning that it can be applied with relative ease to any combination of host and guest languages. Martin Bravenboer, Eelco Dolstra, Eelco Visser |
GPCE | 2 |
| 2007 | Purely Functional System Configuration Management
Eelco Dolstra, Armijn Hemel |
HotOS | 1 |
| 2005 | Secure sharing between untrusted users in a transparent source/binary deployment modelabstractThe Nix software deployment system is based on the paradigm of transparent source/binary deployment: distributors deploy descriptors that build components from source, while client machines can transparently optimise such source builds by downloading pre-built binaries from remote repositories. This model combines the simplicity and flexibility of source deployment with the efficiency of binary deployment. A desirable property is sharing of components: if multiple users install from the same source descriptors, ideally only one remotely built binary should be installed. The problem is that users must trust that remotely downloaded binaries were built from the sources they are claimed to have been built from, while users in general do not have a trust relation with each other or with the same remote repositories.This paper presents three models that enable sharing: the extensional model that requires that all users on a system have the same remote trust relations, the intensional model that does not have this requirement but may be suboptimal in terms of space use, and the mixed model that merges the best properties of both. The latter two models are achieved through a novel technique of hash rewriting in content-addressable component stores, and were implemented in the context of the Nix system. Eelco Dolstra |
ASE | 1 |
| 2004 | Imposing a Memory Management Discipline on Software DeploymentabstractThe deployment of software components frequently fails because dependencies on other components are not declared explicitly or are declared imprecisely. This results in an incomplete reproduction of the environment necessary for proper operation, or in interference between incompatible variants. In this paper, we show that these deployment hazards are similar to pointer hazards in memory models of programming languages and can be countered by imposing a memory management discipline on software deployment. Based on this analysis, we have developed a generic, platform and language independent, discipline for deployment that allows precise dependency verification; exact identification of component variants; computation of complete closures containing all components on which a component depends; maximal sharing of components between such closures; and concurrent installation of revisions and variants of components. We have implemented the approach in the Nix deployment system, and used it for the deployment of a large number of existing Linux packages. We compare its effectiveness to other deployment systems. Eelco Dolstra, Eelco Visser, Merijn de Jonge |
ICSE | 1 |
| 2004 | Nix: A Safe and Policy-Free System for Software Deployment
Eelco Dolstra, Merijn de Jonge, Eelco Visser |
LISA | 1 |