{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,20]],"date-time":"2025-06-20T04:08:51Z","timestamp":1750392531691,"version":"3.41.0"},"reference-count":73,"publisher":"Association for Computing Machinery (ACM)","issue":"FSE","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Proc. ACM Softw. Eng."],"published-print":{"date-parts":[[2025,6,19]]},"abstract":"<jats:p>When building enterprise applications (EAs) on Java frameworks (e.g., Spring), developers often configure application components via metadata (i.e., Java annotations and XML files). It is challenging for developers to correctly use metadata, because the usage rules can be complex and existing tools provide limited assistance. When developers misuse metadata, EAs become misconfigured, which can trigger erroneous runtime behaviors or introduce security vulnerabilities. To help developers correctly use metadata, this paper presents (1) RSL \u2014 a domain-specific language that domain experts can adopt to prescribe metadata checking rules, and (2) MeCheck \u2014 a tool that takes in RSL rules and EAs to check for rule violations.<\/jats:p>\n          <jats:p>With RSL, domain experts (e.g., owner developers of a Java framework) can specify metadata checking rules by defining content consistency among XML files, annotations, and Java code. Given such RSL rules and a program to scan, MeCheck interprets rules as cross-file static analyzers that scan Java and\/or XML files to gather information and look for consistency violations. For evaluation, we studied the Spring and JUnit documentation to manually define 15 rules, and created 2 datasets with 115 open-source EAs. The first dataset includes 45 EAs, and the ground truth of 45 manually injected bugs. The second dataset includes multiple versions of 70 EAs. We observed that MeCheck identified bugs in the first dataset with 100% precision, 96% recall, and 98% F-score. It reported 152 bugs in the second dataset, 49 of which were already fixed by developers. Our evaluation shows that MeCheck helps ensure the correct usage of metadata.<\/jats:p>","DOI":"10.1145\/3715772","type":"journal-article","created":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T15:15:34Z","timestamp":1750346134000},"page":"1160-1182","source":"Crossref","is-referenced-by-count":0,"title":["Detecting Metadata-Related Bugs in Enterprise Applications"],"prefix":"10.1145","volume":"2","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-6227-1816","authenticated-orcid":false,"given":"Md Mahir Asef","family":"Kabir","sequence":"first","affiliation":[{"name":"Virginia Tech, Blacksburg, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9079-5534","authenticated-orcid":false,"given":"Xiaoyin","family":"Wang","sequence":"additional","affiliation":[{"name":"University of Texas at San Antonio, San Antonio, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0230-5524","authenticated-orcid":false,"given":"Na","family":"Meng","sequence":"additional","affiliation":[{"name":"Virginia Tech, Blacksburg, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2025,6,19]]},"reference":[{"key":"e_1_2_1_1_1","unstructured":"2012. Securing REST urls with Spring. https:\/\/stackoverflow.com\/questions\/13836451\/securing-rest-urls-with-spring"},{"key":"e_1_2_1_2_1","unstructured":"2014. BeanCreationException in spring controller. https:\/\/stackoverflow.com\/questions\/21520827\/beancreationexception-in-spring-controller?rq=3"},{"key":"e_1_2_1_3_1","unstructured":"2014. \"Could not resolve matching constructor\" error when passing in constructor-arg for child class. https:\/\/stackoverflow.com\/questions\/21583399\/could-not-resolve-matching-constructor-error-when-passing-in-constructor-arg-f"},{"key":"e_1_2_1_4_1","unstructured":"2014. Package javax.xml.parsers for processing of XML documents. Oracle Java API Documentation. https:\/\/docs.oracle.com\/javase\/8\/docs\/api\/index.html?javax\/xml\/parsers\/package-summary.html"},{"key":"e_1_2_1_5_1","unstructured":"2016. Could not resolve matching constructor.Ambiguity issue with Spring dependency injection. https:\/\/stackoverflow.com\/questions\/37648984\/could-not-resolve-matching-constructor-ambiguity-issue-with-spring-dependency-in?rq=3"},{"key":"e_1_2_1_6_1","unstructured":"2016. Custom Authentication Filters in multiple HttpSecurity objects using Java Config. https:\/\/stackoverflow.com\/questions\/37304211\/custom-authentication-filters-in-multiple-httpsecurity-objects-using-java-config"},{"key":"e_1_2_1_7_1","unstructured":"2016. org.springframework.beans.factory.BeanCreationException in Spring boot application. https:\/\/stackoverflow.com\/questions\/37938942\/org-springframework-beans-factory-beancreationexception-in-spring-boot-applicati"},{"key":"e_1_2_1_8_1","unstructured":"2016. Spring security JDK based proxy issue while using @Secured annotation on Controller method. https:\/\/stackoverflow.com\/questions\/35860442\/spring-security-jdk-based-proxy-issue-while-using-secured-annotation-on-control"},{"key":"e_1_2_1_9_1","unstructured":"2016. Spring security JDK based proxy issue while using @Secured annotation on Controller method. https:\/\/stackoverflow.com\/questions\/35860442\/spring-security-jdk-based-proxy-issue-while-using-secured-annotation-on-control"},{"key":"e_1_2_1_10_1","unstructured":"2016. XML Based Configuration using Spring and Hibernate. https:\/\/stackoverflow.com\/questions\/39891823\/xml-based-configuration-using-spring-and-hibernate"},{"key":"e_1_2_1_11_1","unstructured":"2019. JUnit No Runnable Methods. https:\/\/examples.javacodegeeks.com\/java-development\/core-java\/junit\/junit-no-runnable-methods\/"},{"key":"e_1_2_1_12_1","unstructured":"2021. Getting error when running the code. https:\/\/www.qtpselenium.com\/selenium-training\/forum\/7159\/getting-error-when-running-the-code"},{"key":"e_1_2_1_13_1","unstructured":"2021. Java EE at a Glance. https:\/\/www.oracle.com\/java\/technologies\/java-ee-glance.html"},{"key":"e_1_2_1_14_1","unstructured":"2021. Spring. https:\/\/spring.io"},{"key":"e_1_2_1_15_1","unstructured":"2021. Spring - Annotation Based Configuration. https:\/\/www.tutorialspoint.com\/spring\/spring_annotation_based_configuration.htm"},{"key":"e_1_2_1_16_1","unstructured":"2021. Spring Framework Documentation. https:\/\/docs.spring.io\/spring-framework\/docs\/current\/reference\/html\/"},{"key":"e_1_2_1_17_1","unstructured":"2021. Spring Tutorial. https:\/\/www.tutorialspoint.com\/spring\/index.htm"},{"key":"e_1_2_1_18_1","unstructured":"2021. Using Java EE Annotations and Dependency Injection. https:\/\/docs.oracle.com\/cd\/E11035_01\/wls100\/programming\/annotate_dependency.html"},{"key":"e_1_2_1_19_1","unstructured":"2021. XML Deployment Descriptors. https:\/\/docs.oracle.com\/cd\/A91202_01\/901_doc\/java.901\/a90188\/xml.htm"},{"key":"e_1_2_1_20_1","unstructured":"2021. XML Elements. https:\/\/www.geeksforgeeks.org\/xml-elements\/"},{"key":"e_1_2_1_21_1","unstructured":"2022. Spring \u2013 init() and destroy() Methods with Example. https:\/\/www.geeksforgeeks.org\/spring-init-and-destroy-methods-with-example\/"},{"key":"e_1_2_1_22_1","unstructured":"2023. Ambiguous argument values for parameter of type [int]. https:\/\/blog.csdn.net\/qq_49676677\/article\/details\/119714497"},{"key":"e_1_2_1_23_1","unstructured":"2024. . https:\/\/github.com\/hannesnolvak\/I377-esk"},{"key":"e_1_2_1_24_1","unstructured":"2024. angular-js-spring-mybatis. https:\/\/github.com\/rurutia\/angular-js-spring-mybatis"},{"key":"e_1_2_1_25_1","unstructured":"2024. brianleesg1\/FileExplorer. https:\/\/github.com\/brianleesg1\/FileExplorer."},{"key":"e_1_2_1_26_1","unstructured":"2024. dawe73\/LIBRARY. https:\/\/github.com\/dawe73\/LIBRARY"},{"key":"e_1_2_1_27_1","unstructured":"2024. gedkang \/ biyam_repository. https:\/\/github.com\/gedkang\/biyam_repository"},{"key":"e_1_2_1_28_1","unstructured":"2024. Github. https:\/\/github.com\/"},{"key":"e_1_2_1_29_1","unstructured":"2024. hopestar720\/aioweb. https:\/\/github.com\/hopestar720\/aioweb"},{"key":"e_1_2_1_30_1","unstructured":"2024. How to create JUnit Test Suite? (with Examples). https:\/\/www.browserstack.com\/guide\/junit-test-suite"},{"key":"e_1_2_1_31_1","unstructured":"2024. JavaCC The most popular parser generator for use with Java applications.. https:\/\/javacc.github.io\/javacc\/"},{"key":"e_1_2_1_32_1","unstructured":"2024. johnsully83\/johnsully83_groovy. https:\/\/github.com\/johnsully83\/johnsully83_groovy."},{"key":"e_1_2_1_33_1","unstructured":"2024. JUnit - Suite Test. https:\/\/www.tutorialspoint.com\/junit\/junit_suite_test.htm"},{"key":"e_1_2_1_34_1","unstructured":"2024. liuzhaomincoding \/ rop. https:\/\/github.com\/liuzhaomincoding\/rop"},{"key":"e_1_2_1_35_1","unstructured":"2024. m2gikbb\/Kognitywistyka. https:\/\/github.com\/m2gikbb\/Kognitywistyka"},{"key":"e_1_2_1_36_1","unstructured":"2024. mcgray\/spring-vaadin. https:\/\/github.com\/mcgray\/spring-vaadin"},{"key":"e_1_2_1_37_1","unstructured":"2024. New Inspections in This Release | Inspectopedia Documentation. https:\/\/www.jetbrains.com\/help\/inspectopedia\/"},{"key":"e_1_2_1_38_1","unstructured":"2024. Parameterized (JUnit API). https:\/\/junit.org\/junit4\/javadoc\/4.12\/org\/junit\/runners\/Parameterized.html"},{"key":"e_1_2_1_39_1","unstructured":"2024. Parameterized test class without data provider method. https:\/\/www.jetbrains.com.cn\/en-us\/help\/inspectopedia\/ParameterizedParametersStaticCollection.html"},{"key":"e_1_2_1_40_1","unstructured":"2024. ReeverPD\/jarvis. https:\/\/github.com\/ReeverPD\/jarvis"},{"key":"e_1_2_1_41_1","unstructured":"2024. ShcUtils. https:\/\/github.com\/535521469\/ShcUtils"},{"key":"e_1_2_1_42_1","unstructured":"2024. smyrouf\/cv-web. https:\/\/github.com\/smyrouf\/cv-web"},{"key":"e_1_2_1_43_1","unstructured":"2024. SOFTWARE TESTING: GETTING STARTED WITH ECLIPSE AND JUNIT (JUNIT 3). https:\/\/www.inf.ed.ac.uk\/teaching\/courses\/st\/2010-2011\/tutorials\/tutorial1j3.html"},{"key":"e_1_2_1_44_1","unstructured":"2024. Soot. https:\/\/github.com\/soot-oss\/soot"},{"key":"e_1_2_1_45_1","unstructured":"2024. sovcn\/enterprise-routing-system. https:\/\/github.com\/sovcn\/enterprise-routing-system"},{"key":"e_1_2_1_46_1","unstructured":"2024. ui-kreinhard\/generica. https:\/\/github.com\/ui-kreinhard\/generica"},{"key":"e_1_2_1_47_1","unstructured":"2024. Unresolved file references in @ImportResource locations. https:\/\/www.jetbrains.com\/help\/inspectopedia\/SpringImportResource.html"},{"key":"e_1_2_1_48_1","unstructured":"2024. WALA. https:\/\/github.com\/wala\/WALA"},{"key":"e_1_2_1_49_1","unstructured":"2025. java lang exception no runnable methods. https:\/\/www.javatpoint.com\/java-lang-exception-no-runnable-methods"},{"key":"e_1_2_1_50_1","unstructured":"2025. PMD. https:\/\/pmd.github.io"},{"key":"e_1_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.5555\/1404014.1404037"},{"key":"e_1_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.5555\/1924943.1924960"},{"key":"e_1_2_1_53_1","doi-asserted-by":"crossref","first-page":"51","DOI":"10.1145\/944746.944711","article-title":"CDuce: an XML-centric general-purpose language","volume":"38","author":"Benzaken V\u00e9ronique","year":"2003","unstructured":"V\u00e9ronique Benzaken, Giuseppe Castagna, and Alain Frisch. 2003. CDuce: an XML-centric general-purpose language. ACM SIGPLAN Notices, 38, 9 (2003), 51\u201363.","journal-title":"ACM SIGPLAN Notices"},{"key":"e_1_2_1_54_1","volume-title":"XQuery: An XML query language. IBM systems journal, 41, 4","author":"Chamberlin Don","year":"2002","unstructured":"Don Chamberlin. 2002. XQuery: An XML query language. IBM systems journal, 41, 4 (2002), 597\u2013615."},{"key":"e_1_2_1_55_1","first-page":"2010","volume-title":"Advances in Software Engineering","author":"Darwin Ian","year":"2009","unstructured":"Ian Darwin. 2009. Annabot: A static verifier for java annotation usage. Advances in Software Engineering, 2010 (2009)."},{"key":"e_1_2_1_56_1","volume-title":"International Conference on Fundamental Approaches to Software Engineering. 237\u2013252","author":"Eichberg Michael","year":"2005","unstructured":"Michael Eichberg, Thorsten Sch\u00e4fer, and Mira Mezini. 2005. Using annotations to check structural properties of classes. In International Conference on Fundamental Approaches to Software Engineering. 237\u2013252."},{"key":"e_1_2_1_57_1","doi-asserted-by":"publisher","DOI":"10.1145\/767193.767195"},{"key":"e_1_2_1_58_1","volume-title":"H\u00fcrsch and Cristina Videira Lopes","author":"Walter","year":"1995","unstructured":"Walter L. H\u00fcrsch and Cristina Videira Lopes. 1995. Separation of Concerns."},{"key":"e_1_2_1_59_1","unstructured":"JavaParser. [n. d.]. JavaParser - Tools for your Java code. https:\/\/javaparser.org\/ Accessed: 2024-07-21"},{"key":"e_1_2_1_60_1","doi-asserted-by":"publisher","DOI":"10.1145\/3180155.3180201"},{"key":"e_1_2_1_61_1","volume-title":"European Conference on Model Driven Architecture-Foundations and Applications. 48\u201362","author":"Noguera Carlos","year":"2008","unstructured":"Carlos Noguera and Laurence Duchien. 2008. Annotation framework validation using domain models. In European Conference on Model Driven Architecture-Foundations and Applications. 48\u201362."},{"key":"e_1_2_1_62_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSM.2012.6405291"},{"key":"e_1_2_1_63_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSME55016.2022.00075"},{"key":"e_1_2_1_64_1","doi-asserted-by":"publisher","DOI":"10.1145\/3468264.3468578"},{"key":"e_1_2_1_65_1","unstructured":"Oracle. 2021. Overview of Enterprise Applications. https:\/\/docs.oracle.com\/javaee\/6\/firstcup\/doc\/gcrky.html"},{"key":"e_1_2_1_66_1","doi-asserted-by":"publisher","DOI":"10.1109\/ASE.2011.6100053"},{"key":"e_1_2_1_67_1","doi-asserted-by":"publisher","DOI":"10.5555\/2337223.2337305"},{"key":"e_1_2_1_68_1","unstructured":"JUnit Team. 2024. JUnit 5. https:\/\/junit.org\/junit5\/ Accessed: 2024-07-25"},{"key":"e_1_2_1_69_1","doi-asserted-by":"publisher","DOI":"10.5555\/3155562.3155641"},{"key":"e_1_2_1_70_1","volume-title":"Inferring and Applying Def-Use Like Configuration Couplings in Deployment Descriptors. In 2020 35th IEEE\/ACM International Conference on Automated Software Engineering (ASE). 672\u2013683","author":"Wen Chengyuan","year":"2020","unstructured":"Chengyuan Wen, Yaxuan Zhang, Xiao He, and Na Meng. 2020. Inferring and Applying Def-Use Like Configuration Couplings in Deployment Descriptors. In 2020 35th IEEE\/ACM International Conference on Automated Software Engineering (ASE). 672\u2013683."},{"key":"e_1_2_1_71_1","doi-asserted-by":"publisher","DOI":"10.1145\/3643759"},{"key":"e_1_2_1_72_1","volume-title":"Proceedings of the 2013 International Conference on Software Engineering (ICSE \u201913)","author":"Zhang Sai","unstructured":"Sai Zhang and Michael D. Ernst. 2013. Automated Diagnosis of Software Configuration Errors. In Proceedings of the 2013 International Conference on Software Engineering (ICSE \u201913). IEEE Press, Piscataway, NJ, USA. 312\u2013321. isbn:978-1-4673-3076-3 http:\/\/dl.acm.org\/citation.cfm?id=2486788.2486830"},{"key":"e_1_2_1_73_1","doi-asserted-by":"publisher","unstructured":"Md Mahir Asef Kabir Xiaoyin Wang and Na Meng. 2025. MeCheck: A Rule-Based Metadata Bug Detector. https:\/\/zenodo.org\/records\/15205192 doi:10.5281\/zenodo.15205192 Accessed: 2025-06-15 10.5281\/zenodo.15205192","DOI":"10.5281\/zenodo.15205192"}],"container-title":["Proceedings of the ACM on Software Engineering"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3715772","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T15:17:58Z","timestamp":1750346278000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3715772"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,6,19]]},"references-count":73,"journal-issue":{"issue":"FSE","published-print":{"date-parts":[[2025,6,19]]}},"alternative-id":["10.1145\/3715772"],"URL":"https:\/\/doi.org\/10.1145\/3715772","relation":{},"ISSN":["2994-970X"],"issn-type":[{"value":"2994-970X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,6,19]]}}}