arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

Glob生态系统的实证分析

An Empirical Analysis of the Glob Ecosystem

Phyllis Lim, Connor Adkins, Mark Marron

arXiv 2608.02610首次发表:更新:

AI 中文总结

本文通过分析1966个开源项目等多类数据,开展首次Glob生态系统实证研究,揭示其碎片化、安全漏洞等问题,提出标准化路径及GlobSpec规范以解决相关挑战。

AI 中文摘要

Glob模式是一种用于结构化字符串匹配的领域特定语言,是现代软件开发的基础但研究不足的组件,嵌入在从构建脚本、配置文件到Web服务器路由等各类场景中。然而,这种广泛应用建立在脆弱的基础之上:尽管Glob模式在工具和编程语言中无处不在,但缺乏标准化导致其生态系统碎片化,充斥着不一致的行为、安全漏洞和可用性陷阱。本文对Glob生态系统开展了首次实证研究,以量化这些挑战并为稳健解决方案规划路径。通过分析1966个开源项目、1355个GitHub问题、444份CVE报告以及361篇Stack Overflow帖子,我们系统梳理了6种常用Glob生态系统中Glob模式的功能支持情况与实际应用。研究发现,不同Glob实现与开发者采用情况存在显著差异;此外,我们记录了阻碍可移植性、可靠性并引发安全漏洞的不一致性。分析显示,安全漏洞并非极端情况,而是主要问题,几乎占所有开发者讨论内容的四分之一。我们提出了通过标准化推进的路径,并引入Glob的形式化规范GlobSpec,旨在解决语义歧义并弥合当前实现与开发者需求之间的表达力差距。

英文摘要

Glob patterns, a domain-specific language for structured string matching, are a foundational yet understudied component of modern software development embedded in everything from build scripts and configuration files to web server routes. However, this widespread use rests on a fragile foundation. Despite their ubiquity across tools and programming languages, a lack of standardization has led to a fragmented ecosystem rife with inconsistent behaviors, security vulnerabilities, and usability pitfalls. This paper presents the first empirical study of the glob ecosystem to quantify these challenges and chart a path toward robust solutions. Through an analysis of 1,966 open source projects, 1,355 Github issues, 444 CVE reports, and 361 StackOverflow posts, we systematically map the feature support and real-world usage of globs across six common ecosystems that utilize globs. Our findings reveal a stark divide between various globbing implementations and developer adoption. In addition, we document inconsistencies that hinder portability, reliability, and create security flaws. Our analysis reveals that security vulnerabilities are not corner cases, but a dominant concern, comprising almost a quarter of all developer discussions. We propose a path forward through standardization and introduce a formal specification for globs, GlobSpec, designed to resolve semantic ambiguities and bridge the expressiveness gap between current implementations and developer requirements.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑