Thanos: DBMS Bug Detection via Storage Engine Rotation Based Differential Testing
Read the paper · doi:10.1109/icse55347.2025.00257
What this paper does with SQLancer
How it was classified
uses infrastructure — no
SQLancer is run as a baseline; Thanos rotates storage engines beneath a shared SQL layer and nothing indicates its implementation reuses SQLancer's code.
extends technique — no
Thanos's oracle is differential comparison across storage engines, which the paper contrasts with SQLancer's rule-based oracles rather than deriving from them.
compares with — yes
M8 states the comparative study pits Thanos against SQLancer, and M10, M11 and M12 give the per-DBMS bug counts, branch coverage and totals.
Non-optimizing Reference Engine Construction (NoREC)Ternary Logic Partitioning (TLP)
Comparison with Existing Techniques To assess the effectiveness of THANOS, we conducted a comparative study that pitted THANOS against contemporary state-of-the-art DBMS testing methods, namely SQLancer, SQLsmith, and SQUIRREL.
DBMS SQLancer SQLsmith SQUIRREL THANOS MySQL 0 1 1 6 MariaDB 0 0 1 5 Percona 0 0 1 3 Total 0 1 3 14 Increment 14↑ 13↑ 11↑ – TABLE IV: Number of branches covered by THANOS, SQLancer, SQLsmith, and SQUIRREL on 3 DBMSs in 24 hours.
DBMS SQLancer SQLsmith SQUIRREL THANOS MySQL 59,242 93,742 109,323 120,156 MariaDB 60,293 88,923 100,920 132,532 Percona 63,829 89,987 109,823 143,293 Total 183,364 272,652 320,066 395,981 Increment 115.
Specifically, THANOS found 14, 13, and 11 more bugs than SQLancer, SQLsmith, and SQUIRREL, respectively.
describes as state of the art — yes
M1, M2 and M5 each introduce SQLancer as a state-of-the-art DBMS fuzzer or testing tool.
We evaluate THANOS on three widely used and extensively tested DBMSs, namely MySQL, MariaDB, and Percona against state-of-the-art fuzzers SQLancer, SQLsmith, and SQUIRREL.
To assess the effectiveness of THANOS, we compare THANOS against contemporary state-of-the-art DBMS testing methods, namely SQLancer, SQLsmith, and SQUIRREL.
To evaluate the effectiveness of THANOS, we compared THANOS with the state-of-art DBMS test tools, SQUIRREL [22, 23], SQLancer [24], and SQLsmith [25, 26].
SQLancer publications it cites (5)
Bibliography entries that resolved to a SQLancer publication, or to a paper by one of the project's authors. A sentence citing one of these numbers is a reference to SQLancer even when it never writes the name.
| # | Entry | Matched as |
|---|---|---|
| 24 | M. Rigger, “Sqlancer website,” https://github .com/ sqlancer/sqlancer, accessed: August 16, 2024. | sqlancer publication |
| 30 | M. Rigger and Z. Su, “Finding bugs in database systems via query partitioning,” Proceedings of the ACM on 665 Programming Languages, vol. 4, no. OOPSLA, pp. 1– 30, 2020. | sqlancer publication · TLP |
| 31 | Rigger, Manuel and Su, Zhendong, “Detecting optimization bugs in database engines via non-optimizing reference engine construction,” in Proceedings of the 28th ACM Joint Meeting on European Software Engineering Confer... | sqlancer publication · NOREC |
| 33 | M. Rigger and Z. Su, “Testing database engines via pivoted query synthesis,” in 14th USENIX Symposium on Operating Systems Design and Implementation (OSDI 20), 2020, pp. 667–682. | sqlancer publication · PQS |
| 34 | Z.-M. Jiang, S. Liu, M. Rigger, and Z. Su, “Detecting transactional bugs in database engines via GraphBased oracle construction,” in 17th USENIX Symposium on Operating Systems Design and Implementation (OSDI 23). Bost... | project authored |
Every place it refers to SQLancer (20)
20 sentences, each stored verbatim from the extracted text with where it was found and how. “Citation marker” means the sentence names no tool at all and was reached through a reference number that resolved to a SQLancer publication.
| Id | Sentence | Found by | Where |
|---|---|---|---|
| M1 | We evaluate THANOS on three widely used and extensively tested DBMSs, namely MySQL, MariaDB, and Percona against state-of-the-art fuzzers SQLancer, SQLsmith, and SQUIRREL. |
name |
page 1 |
| M2 | To assess the effectiveness of THANOS, we compare THANOS against contemporary state-of-the-art DBMS testing methods, namely SQLancer, SQLsmith, and SQUIRREL. |
name |
I INTRODUCTION page 2 |
| M3 | 72% more branches, and finds 14, 13, and 11 more bugs in 24 hours on three DBMSs than SQLancer, SQLsmith, and SQUIRREL, respectively. |
name |
I INTRODUCTION page 2 |
| M4 | Similarly, metamorphic testing tools like SQLancer, which rely on specially crafted rules still prove ineffective in detecting this particular problem. |
name |
II BACKGROUND ANDMOTIVATION page 3 |
| M5 | To evaluate the effectiveness of THANOS, we compared THANOS with the state-of-art DBMS test tools, SQUIRREL [22, 23], SQLancer [24], and SQLsmith [25, 26]. |
name |
A Evaluation Setup page 7 |
| M6 | SQLancer generates SQL queries and detects the logic bugs of DBMSs. |
name |
A Evaluation Setup page 7 |
| M7 | Or they require adherence to specific rules, as seen in SQLancer where the NOREC test oracle is optimizer-related, and TLP necessitates a pivot row. |
name |
B DBMS Bug Detection page 7 |
| M8 | Comparison with Existing Techniques To assess the effectiveness of THANOS, we conducted a comparative study that pitted THANOS against contemporary state-of-the-art DBMS testing methods, namely SQLancer, SQLsmith, and SQUIRREL. |
name |
C Comparison with Existing Techniques page 8 |
| M9 | Each DBMS underwent a 24hour testing period using these tools, and we documented TABLE III: Number of bugs detected by THANOS, SQLancer, SQLsmith and SQUIRREL on 3 DBMSs in 24 hours. |
name |
C Comparison with Existing Techniques page 8 |
| M10 | DBMS SQLancer SQLsmith SQUIRREL THANOS MySQL 0 1 1 6 MariaDB 0 0 1 5 Percona 0 0 1 3 Total 0 1 3 14 Increment 14↑ 13↑ 11↑ – TABLE IV: Number of branches covered by THANOS, SQLancer, SQLsmith, and SQUIRREL on 3 DBMSs in 24 hours. |
name |
C Comparison with Existing Techniques page 8 |
| M11 | DBMS SQLancer SQLsmith SQUIRREL THANOS MySQL 59,242 93,742 109,323 120,156 MariaDB 60,293 88,923 100,920 132,532 Percona 63,829 89,987 109,823 143,293 Total 183,364 272,652 320,066 395,981 Increment 115. |
name |
C Comparison with Existing Techniques page 8 |
| M12 | Specifically, THANOS found 14, 13, and 11 more bugs than SQLancer, SQLsmith, and SQUIRREL, respectively. |
name |
C Comparison with Existing Techniques page 9 |
| M13 | 72% more branches than SQLancer, SQLsmith, and SQUIRREL, respectively. |
name |
C Comparison with Existing Techniques page 9 |
| M14 | Specifically, the NoREC test oracle in SQLancer detects logical errors in the DBMS optimizer by constructing equivalent optimized and unoptimized queries based on op-timizer rules. |
name |
C Comparison with Existing Techniques page 9 |
| M15 | In comparison, tools like SQLancer and SQLsmith use standard SQL syntax to build test cases, resulting in THANOS covering more branches and detecting more bugs. |
name |
C Comparison with Existing Techniques page 9 |
| M16 | 5: Number of branches covered by THANOS, SQLancer, SQLsmith, and SQUIRREL in the Storage Engine component of each DBMS in 24 hours. |
name |
D Effectiveness of Feature-Oriented Test Case Synthesis page 9 |
| M17 | Metamorphic testing in DBMS involves transforming SQL queries and verifying if the resulting output changes align with expected behavior [28, 29, 30, 31]. |
citation marker |
D Effectiveness of Feature-Oriented Test Case Synthesis page 10 |
| M18 | SQLancer proposes constructing functionally equivalent queries to test one DBMS [30, 31, 33]. |
name |
D Effectiveness of Feature-Oriented Test Case Synthesis page 10 |
| M19 | TxCheck [34] detects transactional bugs of DBMSs through graph-based oracle construction. |
citation marker project authored |
D Effectiveness of Feature-Oriented Test Case Synthesis page 10 |
| M20 | DBMS fuzzers [22, 25, 33, 36, 37, 38, 39, 40, 41, 42], automate this process, focusing on creating complex SQL queries to uncover memory safety issues. |
citation marker |
D Effectiveness of Feature-Oriented Test Case Synthesis page 10 |