← Bugs found by SQLancer
Further breakdowns of the same 2038 accepted bug reports the
impact page counts. Each
system's own page lists the individual reports behind its share.
Which technique found them
SQLancer is an umbrella: alongside the main tool, components such as
SQLancer++ and ShQveL count towards these figures. Each record keeps both the
tool that found the bug and, where the report says so, the specific technique —
they are never collapsed into one label. “Technique not recorded” means the
report identifies the campaign but not which oracle fired.
Show these figures as a table
| Technique |
Bugs |
| Technique not recorded |
1690 |
| Ternary Logic Partitioning (TLP) |
199 |
| Non-optimizing Reference Engine Construction (NoREC) |
77 |
| Pivoted Query Synthesis (PQS) |
67 |
| Differential Query Plans (DQP) |
3 |
| Constant-Optimization-Driven Testing (CODDTest) |
1 |
| Query Plan Guidance (QPG) |
1 |
| Tool |
Bugs |
| SQLancer |
2037 |
| SQLancer++ |
1 |
| How the bug manifested |
Bugs |
| Logic bug |
195 |
| Unexpected error |
168 |
| Crash |
91 |
| Hang |
3 |
| Unclassified |
1581 |
Every figure on this page is computed from
_data/impact/.
The attribution policy
explains what has to be true for a bug to be counted, and how a technique is
credited.