Demonstration venue · read-only. Every page can be browsed; the buttons that would change it are switched off. Create an account to run TaxoReview on your own data.

Eelco Dolstra

dblp:82/1700 · DBLP profile ↗
← Back
14ranked-venue papers
8as first author
0since 2021 · last 2014
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 13 · 7 first-authorSystems, architecture and hardware · 1 · 1 first-authorDatabases, data management, data science and information retrieval · 1

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Software engineering, system software, and programming languages
3 papers
Software maintenance and evolution · 87% Program analysis · 7% Operating systems · 7%
Network and information security
1 paper
Authentication and access control · 100%

Topics — the 9 heaviest of 10, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Software maintenance and evolution › software ecosystems
license compliance
0.212014
Tracing software build processes to uncover license compliance inconsistencies · ASE 2014
Software maintenance and evolution
software dependencies
0.212014
Tracing software build processes to uncover license compliance inconsistencies · ASE 2014
Software maintenance and evolution
software ecosystems
0.212014
Tracing software build processes to uncover license compliance inconsistencies · ASE 2014
Software maintenance and evolution › software configuration management › software release management
software deployment
0.122005
Secure sharing between untrusted users in a transparent source/binary deployment model · ASE 2005
Imposing a Memory Management Discipline on Software Deployment · ICSE 2004
Program analysis
dynamic analysis
0.112014
Tracing software build processes to uncover license compliance inconsistencies · ASE 2014
Operating systems › operating system interface › system call
system call tracing
0.112014
Tracing software build processes to uncover license compliance inconsistencies · ASE 2014
Software maintenance and evolution › software ecosystems
dependency management
0.012004
Imposing a Memory Management Discipline on Software Deployment · ICSE 2004
Authentication and access control
trust management
0.012005
Secure sharing between untrusted users in a transparent source/binary deployment model · ASE 2005
Software maintenance and evolution › software dependencies › software dependency management
package management
0.012004
Imposing a Memory Management Discipline on Software Deployment · ICSE 2004

Methods — techniques the papers use, named apart from their topics

graph construction · 0.2dynamic system call tracing · 0.2hash rewriting · 0.1content-addressable storage · 0.1
YearPublicationVenuePosition
2014 Tracing software build processes to uncover license compliance inconsistencies
abstract
Open Source Software (OSS) components form the basis for many software systems. While the use of OSS components accelerates development, client systems must comply with the license terms of the OSS components that they use. Failure to do so exposes client system distributors to possible litigation from copyright holders. Yet despite the importance of license compliance, tool support for license compliance assessment is lacking. In this paper, we propose an approach to construct and analyze the Concrete Build Dependency Graph (CBDG) of a software system by tracing system calls that occur at build-time. Through a case study of seven open source systems, we show that the constructed CBDGs: (1) accurately classify sources as included in or excluded from deliverables with 88%-100% precision and 98%-100% recall, and (2) can uncover license compliance inconsistencies in real software systems -- two of which prompted code fixes in the CUPS and FFmpeg systems.
Sander van der Burg, Eelco Dolstra, Shane McIntosh, Julius Davies, Daniel M. Germán, Armijn Hemel
ASE2
2014 Disnix: A toolset for distributed deployment
Sander van der Burg, Eelco Dolstra
Sci. Comput. Program.2
2013 Crowdsourcing GUI Tests
abstract
Graphical user interfaces are difficult to test: automated tests are hard to create and maintain, while manual tests are time-consuming, expensive and hard to integrate in a continuous testing process. In this paper, we show that it is possible to crowdsource GUI tests, that is, to outsource them to individuals drawn from a large pool of workers on the Internet, by instantiating virtual machines (VMs) running the system under test and letting testers access the VMs through their web browsers. This enables semi-automated continuous testing of GUIs and usability experiments with large numbers of participants at low cost. Several large experiments on the Amazon Mechanical Turk demonstrate that our approach is technically feasible and sufficiently reliable.
Eelco Dolstra, Raynor Vliegendhart, Johan A. Pouwelse
ICST1
2011 Finding software license violations through binary code clone detection
abstract
Software released in binary form frequently uses third-party packages without respecting their licensing terms. For instance, many consumer devices have firmware containing the Linux kernel, without the suppliers following the requirements of the GNU General Public License. Such license violations are often accidental, e.g., when vendors receive binary code from their suppliers with no indication of its provenance. To help find such violations, we have developed the Binary Analysis Tool (BAT), a system for code clone detection in binaries. Given a binary, such as a firmware image, it attempts to detect cloning of code from repositories of packages in source and binary form. We evaluate and compare the effectiveness of three of BAT's clone detection techniques: scanning for string literals, detecting similarity through data compression, and detecting similarity by computing binary deltas.
Armijn Hemel, Karl Trygve Kalleberg, Rob Vermaas, Eelco Dolstra
MSR4
2010 Automating System Tests Using Declarative Virtual Machines
abstract
Automated regression test suites are an essential software engineering practice: they provide developers with rapid feedback on the impact of changes to a system's source code. The inclusion of a test case in an automated test suite requires that the system's build process can automatically provide all the environmental dependencies of the test. These are external elements necessary for a test to succeed, such as shared libraries, running programs, and so on. For some tests (e.g., a compiler's), these requirements are simple to meet. However, many kinds of tests, especially at the integration or system level, have complex dependencies that are hard to provide automatically, such as running database servers, administrative privileges, services on external machines or specific network topologies. As such dependencies make tests difficult to script, they are often only performed manually, if at all. This particularly affects testing of distributed systems and system-level software. This paper shows how we can automatically instantiate the complex environments necessary for tests by creating (networks of) virtual machines on the fly from declarative specifications. Building on NixOS, a Linux distribution with a declarative configuration model, these specifications concisely model the required environmental dependencies. We also describe techniques that allow efficient instantiation of VMs. As a result, complex system tests become as easy to specify and execute as unit tests. We evaluate our approach using a number of representative problems, including automated regression testing of a Linux distribution.
Sander van der Burg, Eelco Dolstra
ISSRE2
2010 NixOS: A purely functional Linux distribution
abstract
Abstract Existing package and system configuration management tools suffer from an imperative model , where system administration actions such as package upgrades or changes to system configuration files are stateful: they destructively update the state of the system. This leads to many problems, such as the inability to roll back changes easily, to deploy multiple versions of a package side-by-side, to reproduce a configuration deterministically on another machine, or to reliably upgrade a system. In this paper we show that we can overcome these problems by moving to a purely functional system configuration model . This means that all static parts of a system (such as software packages, configuration files and system startup scripts) are built by pure functions and are immutable, stored in a way analogous to a heap in a purely functional language. We have implemented this model in NixOS , a non-trivial Linux distribution that uses the Nix package manager to build the entire system configuration from a modular, purely functional specification.
Eelco Dolstra, Andres Löh, Nicolas Pierron
J. Funct. Program.1
2010 Preventing injection attacks with syntax embeddings
Martin Bravenboer, Eelco Dolstra, Eelco Visser
Sci. Comput. Program.2
2008 Report on the tenth ICFP programming contest
abstract
The ICFP programming contest is a 72-hour contest, which attracts thousands of contestants from all over the world. In this report we describe what it takes to organise this contest, the main ideas behind the contest we organised, the task, how to solve it, how we created it, and how well the contestants did.
Eelco Dolstra, Jurriaan Hage, Bastiaan Heeren, Stefan Holdermans, Johan Jeuring, Andres Löh, Clara Löh, Arie Middelkoop, Alexey Rodriguez Yakushev, John van Schie
ICFP1
2008 NixOS: a purely functional Linux distribution
abstract
Existing package and system configuration management tools suffer from an imperative model, where system administration actions such as upgrading packages or changes to system configuration files are stateful: they destructively update the state of the system. This leads to many problems, such as the inability to roll back changes easily, to run multiple versions of a package side-by-side, to reproduce a configuration deterministically on another machine, or to reliably upgrade a system. In this paper we show that we can overcome these problems by moving to a purely functional system configuration model. This means that all static parts of a system (such as software packages, configuration files and system startup scripts) are built by pure functions and are immutable, stored in a way analogously to a heap in a purely function language. We have implemented this model in NixOS, a non-trivial Linux distribution that uses the Nix package manager to build the entire system configuration from a purely functional specification.
Eelco Dolstra, Andres Löh
ICFP1
2007 Preventing injection attacks with syntax embeddings
abstract
Software written in one language often needs to construct sentences in another language, such as SQL queries, XML output, or shell command invocations. This is almost always done using unhygienic string manipulation, the concatenation of constants and client-supplied strings. A client can then supply specially crafted input that causes the constructed sentence to be interpreted in an unintended way, leading to an injection attack. We describe a more natural style of programming that yields code that is impervious to injections by construction. Our approach embeds the grammars of the guest languages (e.g., SQL) into that of the host language (e.g., Java) and automatically generates code that maps the embedded language to constructs in the host language that reconstruct the embedded sentences, adding escaping functions where appropriate. This approach is generic, meaning that it can be applied with relative ease to any combination of host and guest languages.
Martin Bravenboer, Eelco Dolstra, Eelco Visser
GPCE2
2007 Purely Functional System Configuration Management
Eelco Dolstra, Armijn Hemel
HotOS1
2005 Secure sharing between untrusted users in a transparent source/binary deployment model
abstract
The Nix software deployment system is based on the paradigm of transparent source/binary deployment: distributors deploy descriptors that build components from source, while client machines can transparently optimise such source builds by downloading pre-built binaries from remote repositories. This model combines the simplicity and flexibility of source deployment with the efficiency of binary deployment. A desirable property is sharing of components: if multiple users install from the same source descriptors, ideally only one remotely built binary should be installed. The problem is that users must trust that remotely downloaded binaries were built from the sources they are claimed to have been built from, while users in general do not have a trust relation with each other or with the same remote repositories.This paper presents three models that enable sharing: the extensional model that requires that all users on a system have the same remote trust relations, the intensional model that does not have this requirement but may be suboptimal in terms of space use, and the mixed model that merges the best properties of both. The latter two models are achieved through a novel technique of hash rewriting in content-addressable component stores, and were implemented in the context of the Nix system.
Eelco Dolstra
ASE1
2004 Imposing a Memory Management Discipline on Software Deployment
abstract
The deployment of software components frequently fails because dependencies on other components are not declared explicitly or are declared imprecisely. This results in an incomplete reproduction of the environment necessary for proper operation, or in interference between incompatible variants. In this paper, we show that these deployment hazards are similar to pointer hazards in memory models of programming languages and can be countered by imposing a memory management discipline on software deployment. Based on this analysis, we have developed a generic, platform and language independent, discipline for deployment that allows precise dependency verification; exact identification of component variants; computation of complete closures containing all components on which a component depends; maximal sharing of components between such closures; and concurrent installation of revisions and variants of components. We have implemented the approach in the Nix deployment system, and used it for the deployment of a large number of existing Linux packages. We compare its effectiveness to other deployment systems.
Eelco Dolstra, Eelco Visser, Merijn de Jonge
ICSE1
2004 Nix: A Safe and Policy-Free System for Software Deployment
Eelco Dolstra, Merijn de Jonge, Eelco Visser
LISA1