MSR 2026
Mon 13 - Tue 14 April 2026 Rio de Janeiro, Brazil
co-located with ICSE 2026

This program is tentative and subject to change.

Mon 13 Apr 2026 12:00 - 12:10 at Oceania IV - Session 1-B: Quality & Security I

Modern code review tools, such as Gerrit and GitHub, play a central role in coordinating large-scale software development activities. In Gerrit, developers can associate related changes under a shared "topic'', thereby indicating that these changes collectively form a coherent logical contribution. Although topics are widely used in large ecosystems such as OpenStack, little is known about how they are actually structured, managed, and coordinated in practice. In this paper, we present a large-scale empirical study of the ``topic'' feature in the OpenStack Gerrit instance, covering more than 900K change, 2,372 repositories, and 336,111. Our study first explores the internal structure and prevalence of topics to understand how developers organize related changes. We then examine how topic-linked changes differ from standalone reviews in terms of review dynamics and development activity. Finally, we analyze the sequencing of changes within topics, investigating whether the order in which changes are merged aligns with their original submission order. The results show that the topics are predominantly small and localized: 76% contain a single code change and more than 93% are confined to a single repository and branch. Compared to standalone code changes, topic-linked changes undergo significantly more revisions, have longer review durations, and trigger more discussion messages, inline comments, and CI/CD jobs, indicating higher coordination and validation activity. Analysis of merging behavior further reveals that a large fraction of topics (approximately 40%) are merged out of submission order once they exceed six changes. Topics merged out of order exhibit more revisions, reviewer interactions, and CI executions, whereas those merged in order take longer to complete, but involve fewer interactions. These findings highlight two distinct integration modes in Gerrit: sequential integration, which is slower but more structured, and parallel integration, which is faster but coordination-intensive. Overall, our study provides an empirical characterization of Gerrit topics as a lightweight yet coordination-rich mechanism, offering practical insights for improving code review dependency management and merge-order support in large-scale code review systems.

This program is tentative and subject to change.

Mon 13 Apr

Displayed time zone: Brasilia, Distrito Federal, Brazil change

11:00 - 12:30
Session 1-B: Quality & Security ITechnical Papers / Industry Track / MSR Program at Oceania IV
11:00
10m
Research paper
Where Do Smart Contract Security Analyzers Fall Short?
Technical Papers
Tamer Abdelaziz NYU Abu Dhabi, Salma Alsaghir NYU Abu Dhabi, Karim Ali NYU Abu Dhabi
DOI Pre-print
11:10
10m
Talk
An Empirical Study of Vulnerabilities in Python Packages and Their Detection
Technical Papers
Haowei Quan Monash University, Junjie Wang Tianjin University, Xinzhe Li College of Intelligence and Computing, Tianjin University, Terry Yue Zhuo Monash University and CSIRO's Data61, Xiao Chen University of Newcastle, Xiaoning Du Monash University
11:20
10m
Talk
Does Programming Language Matter? An Empirical Study of Fuzzing Bug Detection
Technical Papers
Tatsuya Shirai Nara Institute of Science and Technology, Olivier Nourry The University of Osaka, Yutaro Kashiwa Nara Institute of Science and Technology, Kenji Fujiwara Nara Women’s University, Hajimu Iida Nara Institute of Science and Technology
11:30
10m
Talk
An Empirical Study on Line-Level Software Defect Prediction
Technical Papers
Enci Zhang Beijing Jiaotong University, Yutong Jiang Beijing Jiaotong University, Tianmeng Zhang Beijing Jiaotong University, Haonan Tong Beijing Jiaotong University
11:40
10m
Talk
Characterizing and Modeling the GitHub Security Advisories Review Pipeline
Technical Papers
Claudio Segal UFF, Paulo Segal UFF, Carlos Eduardo de Schuller Banjar UFRJ, Felipe Paixão Federal University of Bahia (UFBA), Hudson Silva Borges UFMS, Paulo Silveira Neto Federal University Rural of Pernambuco, Eduardo Santana de Almeida Federal University of Bahia, Joanna C. S. Santos University of Notre Dame, Anton Kocheturov Siemens Technology, Gaurav Kumar Srivastava Siemens, Daniel Sadoc Menasche UFRJ, Brazil
Pre-print
11:50
10m
Talk
Linux Kernel Recency Matters, CVE Severity Doesn’t, and History Fades
Technical Papers
Piotr Przymus Nicolaus Copernicus University in Toruń, Poland, Witold Weiner Nicolaus Copernicus University in Toruń and Adtran Networks Sp. z o.o, Krzysztof Rykaczewski Nicolaus Copernicus University in Toruń, Poland, Gunnar Kudrjavets Amazon Web Services, USA
Pre-print
12:00
10m
Talk
Beyond Single Code Changes: An Empirical Study of Topic-Based Code Review Practices in Gerrit for OpenStack
Technical Papers
Moataz Chouchen Concordia University, Mahi Begoug ETS Montreal, Ali Ouni Ecole de Technologie Superieure (ETS)
12:10
10m
Talk
LogSieve: Task-Aware CI Log Reduction for Sustainable LLM-Based Analysis
Technical Papers
Marcus Barnes University of Toronto, Taher A. Ghaleb Trent University, Safwat Hassan University of Toronto
Pre-print
12:20
5m
Talk
Finding Important Stack Frames in Large Systems
Industry Track
Aleksandr Khvorov JetBrains; Constructor University Bremen, Yaroslav Golubev JetBrains Research, Denis Sushentsev JetBrains
12:25
5m
Talk
Stop Comparing Apples and Oranges: Matching for Better Results in Mining Software Repositories Studies
Technical Papers
Sabato Nocera University of Salerno, Nyyti Saarimäki University of Luxembourg, Valentina Lenarduzzi University of Southern Denmark, Davide Taibi University of Southern Denmark and University of Oulu, Sira Vegas Universidad Politecnica de Madrid