CodePhage - Automatic bug repair, without access to source code
newsoffice.mit.edu
newsoffice.mit.edu
In summary, for an app with an bug. You must know a) input that causes to bug to show up, b) input that doesnt cause an error. Then it will look for similar code in github, and try inserting the checks done from that code into the new code. And then it reruns the program, hoping that the bug is resolved.
This approach is very cool, and harnesses the power of lots of developer. But its also very limited. However thats what research is for. Small steps together are a big leap for mankind :p
I also like this conlusion in the article:
""" In recent years the increasing scope and volume of software development efforts has produced a broad range of systems with similar or overlapping goals. Together, these systems capture the knowledge and labor of many developers. But each individual system largely reflects the effort of a single team and, like essentially all software systems, still contains errors. We present a new and, to the best of our knowledge, the first, technique for automatically transferring code between systems to eliminate errors. The system that implements this technique, CP, makes it possible to automatically harness the combined efforts of multiple potentially independent development efforts to improve them all regardless of the relationships that may or may not exist across development organizations. In the long run we hope this research will inspire other techniques that identify and combine the best aspects of multiple systems. The ideal result will be significantly more reliable and functional software systems that better serve the needs of our society. """
Not that it isn't impressive, but there's been all sorts of academic projects throughout the years that require lots of manual intervention to work their outwardly powerful techniques, and many of them never even seeing the light of a public release.
But seriously: autogenerating fixes as observed by fuzzing does sound cool.
And yes, lots of Java programs accessing a DB, slapping a front end on it that lets people enter / request stuff in the browser are prime auto-generation suspects.
There is a reason why people are still paying for 'employee list' crud project in framework X while it is easy to find on some other frameworks; we keep reinventing it for every framework on (and off) the web and then forget that ever happened a month later.
Changing the oil in your car is not hard, but most of the people will not do it themselves, not because they cannot, but because they do not want to. Contrary to the hype, programmers are not rockstars, ninjas or the chosen ones.
Maybe in the limit, the building blocks will all be standardized in the perfect balance of abstraction, security and efficiency. I doubt it but even so, people will still keep rearranging the blocks into novel systems to solve (or create) new problems. It will be a different face of programming, but probably not as different as the gulf between punch cards and dragging WebBrowserControls onto FancyPanels.
Edit; this one is open source; is the MIT one ? Couldn't find references on the page?
> An Obama Administration official tells Re/code that recent advances in using automated methods to analyze software code for vulnerabilities have spurred interest in government circles to see if there’s a way to standardize how software is tested for security and safety.
https://recode.net/2015/06/29/famed-security-researcher-mudg...
I just wonder what will happen to Google's Project Vault [1] now that Mudge is gone. Hopefully it will still be on track.
In any case, CS is awesome. Love it when research that a few years ago would have been theoretical is applied.