kirancodes.me
To Proof Maintenance & Beyond!

RAPID: checking API usage for the cloud in the cloud

Michael Emmi, Liana Hadarean, Ranjit Jhala, Lee Pike, Nicolás Rosner, Martin Schäf, Aritra Sengupta, Willem Visser

Abstract

We present RAPID, an industrial-strength analysis developed at AWS that aims to help developers by providing automatic, fast and actionable feedback about correct usage of cloud-service APIs. RAPID’s design is based on the insight that cloud service APIs are structured around short-lived request- and response-objects whose usage patterns can be specified as value-dependent type-state automata and be verified by combining local type-state with global value-flow analyses. We describe various challenges that arose to deploy RAPID at scale. Finally, we present an evaluation that validates our design choices, deployment heuristics, and shows that RAPID is able to quickly and precisely report a wide variety of useful API misuse violations in large, industrial-strength code bases.

BibTeX
@inproceedings{Emmi-al:FSE21,
  author    = {Michael Emmi and
               Liana Hadarean and
               Ranjit Jhala and
               Lee Pike and
               Nicol{\'{a}}s Rosner and
               Martin Sch{\"{a}}f and
               Aritra Sengupta and
               Willem Visser},
  title     = {{RAPID:} checking {API} usage for the cloud in the cloud},
  booktitle = {{ESEC/SIGSOFT} {FSE}},
  pages     = {1416--1426},
  publisher = {{ACM}},
  year      = {2021},
}

Related papers