返回
Demystifying regular expression bugs A comprehensive study on regular expression bug causes, fixes, and testing
DOI:10.1007/s10664-021-10033-1.png)
摘要
En 中文
Regular expressions cause string-related bugs and open security vulnerabilities for DOS attacks. However, beyond ReDoS (Regular expression Denial of Service), little is known about the extent to which regular expression issues affect software development and how these issues are addressed in practice. We conduct an empirical study of 356 regex-related bugs from merged pull requests in Apache, Mozilla, Facebook, and Google GitHub repositories. We identify and classify the nature of the regular expression problems, the fixes, and the related changes in the test code. The most important findings in this paper are as follows: 1) incorrect regular expression semantics is the dominant root cause of regular expression bugs (165/356, 46.3%). The remaining root causes are incorrect API usage (9.3%) and other code issues that require regular expression changes in the fix (29.5%), 2) fixing regular expression bugs is nontrivial as it takes more time and more lines of code to fix them compared to the general pull requests, 3) most (51%) of the regex-related pull requests do not contain test code changes. Certain regex bug types (e.g., compile error, performance issues, regex representation) are less likely to include test code changes than others, and 4) the dominant type of test code changes in regex-related pull requests is test case addition (75%). The results of this study contribute to a broader understanding of the practical problems faced by developers when using, fixing, and testing regular expressions.
Keyword:
Regular expression bug characteristics
Pull requests
Bug fixes
Test code
期刊
IF:
3.6
论文数:
2.0K
被引数:
5.3K
机构
引用论文
Polysialylated Neural Cell Adhesion Molecule Is Involved in Induction of Long-Term Potentiation and Memory Acquisition and Consolidation in a Fear-Conditioning Paradigm聚唾液酸化的神经细胞粘附分子在恐惧调节范式中参与诱导长期增强和记忆获取和巩固

