Enhancing Symbolic Execution of Heap-based Programs with Separation Logic for Test Input Generation

Long H. Pham, Quang Loc Le, Quoc-Sang Phan, Jun Sun, Shengchao Qin

Research output: Contribution to journalConference articlepeer-review

92 Downloads (Pure)


Symbolic execution is a well established method for test input generation. Despite of having achieved tremendous success over numeric domains, existing symbolic execution techniques for heap-based programs are limited due to the lack of a succinct and precise description for symbolic values over unbounded heaps. In this work, we present a new symbolic execution method for heap-based programs based on separation logic. The essence of our proposal is context-sensitive lazy initialization, a novel approach for efficient test input generation. Our approach differs from existing approaches in two ways. Firstly, our approach is based on separation logic, which allows us to precisely capture pre-conditions of heap-based programs so that we avoid generating invalid test inputs. Secondly, we generate only fully initialized test inputs, which are more useful in practice compared to those partially initialized test inputs generated by the state-of-the-art tools. We have implemented our approach as a tool, called Java StarFinder, and evaluated it on a set of programs with complex heap inputs. The results show that our approach significantly reduces the number of invalid test inputs and improves the test coverage.
Original languageEnglish
Number of pages17
JournalLecture Notes in Computer Science
Publication statusPublished - 28 Oct 2019


Dive into the research topics of 'Enhancing Symbolic Execution of Heap-based Programs with Separation Logic for Test Input Generation'. Together they form a unique fingerprint.

Cite this