SEDec 16, 2017

Enhancing Symbolic Execution of Heap-based Programs with Separation Logic for Test Input Generation

arXiv:1712.06025v52 citations
Originality Incremental advance
AI Analysis

This addresses a bottleneck in software testing for programs with complex heap structures, offering an incremental improvement over existing tools.

The paper tackles the problem of generating test inputs for heap-based programs by introducing a symbolic execution method based on separation logic, which reduces invalid test inputs and improves test coverage.

Symbolic execution is a well established method for test input generation. Despite of having achieved tremendous success over numerical domains, existing symbolic execution techniques for heap-based programs are limited due to the lack of a succinct and precise description for symbolic values over unbounded heaps. In this work, we present a new symbolic execution method for heap-based programs based on separation logic. The essence of our proposal is context-sensitive lazy initialization, a novel approach for efficient test input generation. Our approach differs from existing approaches in two ways. Firstly, our approach is based on separation logic, which allows us to precisely capture preconditions of heap-based programs so that we avoid generating invalid test inputs. Secondly, we generate only fully initialized test inputs, which are more useful in practice compared to those partially initialized test inputs generated by the state-of-the-art tools. We have implemented our approach as a tool, called Java StarFinder, and evaluated it on a set of programs with complex heap inputs. The results show that our approach significantly reduces the number of invalid test inputs and improves the test coverage.

Code Implementations1 repo
Foundations

The foundational work for this paper's niche, ranked by how specifically the neighbourhood builds on it — not by global fame.

Your Notes