← Bugs found by SQLancer

Further breakdowns of the same 2038 accepted bug reports the impact page counts. Each system's own page lists the individual reports behind its share.

Which technique found them

SQLancer is an umbrella: alongside the main tool, components such as SQLancer++ and ShQveL count towards these figures. Each record keeps both the tool that found the bug and, where the report says so, the specific technique — they are never collapsed into one label. “Technique not recorded” means the report identifies the campaign but not which oracle fired.

Bugs found by SQLancer, by technique Bugs per technique for 7 categories, largest 1690. Technique not recorded Technique not recorded: 1690 1690 Ternary Logic Partiti... Ternary Logic Partitioning (TLP): 199 199 Non-optimizing Refere... Non-optimizing Reference Engine Construction (NoREC): 77 77 Pivoted Query Synthes... Pivoted Query Synthesis (PQS): 67 67 Differential Query Pl... Differential Query Plans (DQP): 3 3 Constant-Optimization... Constant-Optimization-Driven Testing (CODDTest): 1 1 Query Plan Guidance (... Query Plan Guidance (QPG): 1 1
Show these figures as a table
Technique Bugs
Technique not recorded 1690
Ternary Logic Partitioning (TLP) 199
Non-optimizing Reference Engine Construction (NoREC) 77
Pivoted Query Synthesis (PQS) 67
Differential Query Plans (DQP) 3
Constant-Optimization-Driven Testing (CODDTest) 1
Query Plan Guidance (QPG) 1
Tool Bugs
SQLancer 2037
SQLancer++ 1
How the bug manifested Bugs
Logic bug 195
Unexpected error 168
Crash 91
Hang 3
Unclassified 1581

Every figure on this page is computed from _data/impact/. The attribution policy explains what has to be true for a bug to be counted, and how a technique is credited.