Pedro Ferreira · FOSDEM 2025 · 2025 · ClickHouse

Watch the talk

What it does with SQLancer

A ClickHouse engineer on how the system is fuzzed. SQLancer appears on the early list of the fuzzers ClickHouse runs, again where the talk explains detecting wrong results by comparing equivalent queries, and once more in the closing recommendations.

reports adoptionrecognition

Where SQLancer comes up (4)

  • 1:50
    Uh, there are a few here, uh, a few of them probably already know, uh, like, uh, SQL Answer, which was, uh, Pioneer to find the wrong results. Uh, there are others like FAL and WebFuzzer that are known to do
    From the talk's automatic captions — a machine transcription of speech, not the speaker's words as written: it renders the name as “SQL Answer”. Follow the link to hear what was said.
  • 1:50
    The slide "Testing with Fuzzers" names the fuzzers ClickHouse runs, SQLancer first among them.
    The talk at 1:50. The slide "Testing with Fuzzers" names the fuzzers ClickHouse runs, SQLancer first among them.
    A frame from the recording. Nothing is transcribed from it: what the slide says is shown, not quoted.
  • 13:47
    This was, SQLanswer actually started this a few years ago. We can do something like, for example, select count from a query with a predicate
    From the talk's automatic captions — a machine transcription of speech, not the speaker's words as written: it renders the name as “SQLanswer”. Follow the link to hear what was said.
  • 13:47
    The slide "Finding wrong results" credits SQLancer by name with pioneering the comparison of equivalent queries against an oracle.
    The talk at 13:47. The slide "Finding wrong results" credits SQLancer by name with pioneering the comparison of equivalent queries against an oracle.
    A frame from the recording. Nothing is transcribed from it: what the slide says is shown, not quoted.

What was read

  • captions — extracted, 430 caption segments
    Windows around candidate moments, read out of YouTube's transcript panel in a browser. Not the whole talk: only the segments a loose prefilter flagged, so the matcher decides on text a person can check.
  • frame — extracted
    Captured at 1:50.
  • frame — extracted
    Captured at 13:47.

This record is talks.json, under the id talk:youtube:CW4Ntdtp7lg.