AI 中文总结
研究针对软件演化中Dockerfile漂移致CI/CD构建失败的问题,提出上下文感知框架Cadre,通过构建CDG并结合两步工作流程来修复,在$D^3$基准上修复率高,相比基线优势明显,还避免提示溢出故障,提升了上下文感知基础设施即代码维护能力。
AI 中文摘要
Docker被广泛用于创建可重现的构建环境,但Dockerfile漂移(即Dockerfile与其不断演化的源代码之间的差异)会导致CI/CD构建失败。现有基于规则和基于检索的修复方法孤立地分析Dockerfile,难以处理上下文相关的故障。我们提出了Cadre,一个用于自动修复Dockerfile漂移的上下文感知框架。它使用静态分析构建上下文感知依赖图(CDG),以映射每个Dockerfile指令到其文件级和指令间的依赖关系。在CDG的引导下,Cadre首先选择与故障因果相关的上下文,然后从该上下文中生成有针对性的补丁。我们还引入了DodeX,一个从GitHub Actions CI日志中挖掘真实世界Dockerfile漂移实例的管道,同时保留静态快照数据集遗漏的完整构建配置。使用DodeX,我们构建了$D^3$,一个包含1040个漂移实例的基准,可使用原始CI参数在本地重现。在$D^3$上,Cadre实现了35.22%的修复率,是基于规则的基线的2.78倍,是最佳基于LLM的基线的1.24倍。其两步工作流程使95.25%的提示低于30k令牌,并避免了导致基于LLM的竞争方法在每种方法的41至58个案例中无法生成补丁的提示溢出故障。消融结果证实,CDG和两步工作流程都提高了修复性能。随着跨提交的漂移时间增加,Cadre相对于仅基于差异的方法的优势也会增加,支持用于上下文感知基础设施即代码维护的显式依赖建模。代码和数据可在该https URL获取。
英文摘要
Docker is widely used to create reproducible build environments, but Dockerfile drift, the divergence between a Dockerfile and its evolving source code, can cause CI/CD builds to fail. Existing rule-based and retrieval-based repair approaches analyze Dockerfiles in isolation and therefore struggle with context-dependent failures. We present Cadre, a context-aware framework for automated Dockerfile drift repair. Cadre uses static analysis to construct a Context-aware Dependency Graph (CDG), which maps each Dockerfile instruction to its file-level and inter-instruction dependencies. Guided by the CDG, Cadre first selects the context causally relevant to a failure and then generates a targeted patch from that context. We also introduce DodeX, a pipeline that mines real-world Dockerfile drift instances from GitHub Actions CI logs while preserving the complete build configurations omitted by static-snapshot datasets. Using DodeX, we construct $D^3$, a benchmark of 1,040 drift instances reproducible locally with the original CI parameters. Across $D^3$, Cadre achieves a 35.22\% repair rate, 2.78$\times$ that of the rule-based baseline and 1.24$\times$ that of the best LLM-based baseline. Its two-step workflow keeps 95.25\% of prompts below 30k tokens and avoids the prompt-overflow failures that prevent competing LLM-based methods from producing patches in 41 to 58 cases per method. Ablation results confirm that both the CDG and the two-step workflow improve repair performance. Cadre's advantage over diff-only approaches also increases as drift ages across commits, supporting explicit dependency modeling for context-aware infrastructure-as-code maintenance. Code and data are available at https://github.com/dw763j/Cadre.
Comments18 pages, 7 figures