Fuzzing databases is difficult
What it does with SQLancer
A ClickHouse engineer on how the system is fuzzed. SQLancer appears on the early list of the fuzzers ClickHouse runs, again where the talk explains detecting wrong results by comparing equivalent queries, and once more in the closing recommendations.
reports adoptionrecognition
Where SQLancer comes up (4)
-
1:50
Uh, there are a few here, uh, a few of them probably already know, uh, like, uh, SQL Answer, which was, uh, Pioneer to find the wrong results. Uh, there are others like FAL and WebFuzzer that are known to do
-
1:50
The talk at 1:50. The slide "Testing with Fuzzers" names the fuzzers ClickHouse runs, SQLancer first among them. -
13:47
This was, SQLanswer actually started this a few years ago. We can do something like, for example, select count from a query with a predicate
-
13:47
The talk at 13:47. The slide "Finding wrong results" credits SQLancer by name with pioneering the comparison of equivalent queries against an oracle.
What was read
- captions — extracted, 430 caption segments
- frame — extracted
- frame — extracted