You are on page 1of 36

REDWOOD

Collaborative Media

Bu
PR Ma
BE CTIC gem
ild
A na
ST ES en
: t
VOLUME 6 • ISSUE 2 • FEBRUARY 2009 • $8.95 www.stpcollaborative.com

Special STPCon
Preview Issue

Supplies for Keeping

Increase Test
Your Apps Alive page 8

Validit y With
Live Data Loads
The premier event for senior executives
and testing/QA management to share the
latest strategies and stay on top of
emerging best practices
FutureTest 2009
Roosevelt Hotel
New York, NY
February 24-25

Great Sessions! Great Speakers!


Virtually Stress-Free Testing RIAs in a Flash Building and Testing a
Testing in the Cloud Resource Interactive Website From Scratch
Amazon.com Kristopher Schultz Using Crowdsourcing
Jinesh Varia Leader of Rich Internet Application Utest
Technology evangelist Practice Group Doron Reuveni
CEO & Co-founder

The Cyber Tester: Web Bloopers—Avoiding


Blending Human Common Design Mistakes
And Machine UI Wizards
Cigital Jeff Johnson
Participate In
Paco Hope UI Wizards principal consultant,
respected in the art of human-
The FutureTest
Technical manager at software
security consultancy
computer interaction Challenge Awards
Enterprise Security Managing The
You Can Take to the Bank Test People Visit futuretest.net
Bank of America Author
James Apple Judy McKay
/challenge to find
Senior technical manager of
Application Development Security
Quality architect and author of
“Managing the Test People”
out more!
Framework program

Testing In Embed Security in QA

REDWOOD
Turbulent Times By Breaking Web Apps Presented by
AmiBug.com Time Inc.
Robert Sabourin Ryan Townsend Collaborative Media
President, development, testing and Lead security engineer
management consultancy

Checking the Feel Of How HBO Covers Sponsored by


Your UI With An Its Digital Assets
Interaction Audit HBO
eBay Jaswinder Hayre
Dorelle Rabinowitz Program manager of
Design Systems Group application security

Register now at www.futuretest.net


Or call 415.785.3419 Use discount code FT209B to SAVE $200!
Feedback Contributors

GOOD ARTICLE, CRUMMY EDITING JUSTIN CALLISON is the Director


Regarding “Quality Gates” article (STP Vol 5, Issue 12), this of SQA Premium Services and head
month’s theme was of particular interest to me. As a manager of of the Performance Practice for
test automation, I am constantly looking for new ideas and fur- Luxoft, a software consultancy based
ther insight into the process of developing advanced automated in Moscow. In this role, Justin
software test scripts. I anxiously read most of this issue cover to applies his own experience and
cover, concentrating on those articles that addressed the organi- expertise as a performance con-
zation and management of test automation projects. I was able to sultant and coordinates the com-
take away a number of interesting new ideas and I was encour- pany’s capabilities to address client
aged that the structure we’ve chosen and the approach we’ve performance problems. During his
taken aligns quite well with some of the “best practices” proposed
career, Justin has served as support
by your contributors.
specialist, QA tester, release engi-
I was however, disturbed by the quality (or lack thereof)
neer, configuration manager, per-
of some of the writing, particularly the “Quality Gates” arti-
formance engineer, development manager, and technical
cle written by Elfriede
consultant. Beginning on page 8, Justin pulls from his exten-
Dustin. I found the article
very difficult to follow and sive testing experience to describe some of his most impor-
constructed rather oddly. tant and useful techniques for surviving the corporate appli-
Most of the first page was lit- cation performance jungle.
tered with introductions to
sections or items covered As an unusually experienced and
later in the article and ref- accomplished consultant and self-
erences to see the related proclaimed software quality guru,
section. It was also difficult ROSS COLLARD says he functions
to read in part because of best as a trusted senior advisor in
inconsistent verb tenses that information technology.
crop up throughout the arti- The founder in 1980 of Collard
cle; changing mid-sentence & Company, Ross has been called a
sometimes from present to Jedi Master of testing and quality by
past. In Figure 2, there is a the president of the Association of
depiction of the automated software test phases but I could- Software Testing. He has consulted
n’t find an explanation of “ATRT” anywhere in the article.
with top-level management from a
It’s not that the definition of this abbreviation is critical to
diverse variety of companies from
understanding the concept, it’s just that it’s another exam-
Anheuser-Busch to Verizon. On page 29, Ross launches a
ple of poor construction or inadequate proof-reading.
multi-part series on application performance testing with a
I have been involved in product quality for most of my engi-
close look at the use of live data, and explains how it can
neering career, including hardware product safety, regulatory
compliance, technical documentation review, embedded increase test accuracy.
firmware testing and now automated software testing.
Although I certainly benefitted from this month’s issue and I TO CONTACT AN AUTHOR, please send e-mail to feedback@
will continue to read STP when it arrives, the quality engineer stpcollaborative.com.
within me is awakened whenever I encounter “quality” issues in
a product that is targeted at the quality community. The deliv-
erables from a quality organization (or a quality magazine)
should be above reproach. We are, after all, an example to our- Index to Advertisers
selves. If, as a purveyor of quality we don’t hold ourselves to the
same (or higher) standards than those standards we profess, Advertiser URL Page

the message loses credibility.


Thanks for your interesting and enlightening magazine. FutureTest 2009 www.futuretest.net 2-3
Stephen L Crum
Manager, test automation
OpenMake www.openmakesoftware.com 12
Rental Quality Assurance & Testing

FEEDBACK: Letters should include the writer’s name, city, state and e- Electric Cloud www.electric-cloud.com 17
mail address. Send your thoughts to feedback@stpcollaborative.com.
Letters become the property of Redwood Collaborative Media and may be Hewlett-Packard www.hp.com/go/alm 20
edited for space and style.

4 • Software Test & Performance FEBRUARY 2009


VOLUME 6 • ISSUE 2 • FEBRUARY 2009

Contents A REDWOOD
Collaborative Media
Publication

08
COV ER STORY
A Survival Kit For
The Jungle That Is
Enterprise App Performance
The tester’s job is anything but easy. There are preda-
tors, road blocks and traps of every kind. What you
need is some everyday wisdom to help you survive
and thrive. By Justin Callison Performance Testing With
13 Live Data—Don’t Get Boxed In
Some experiments are best performed with the living. Learn
the best ways to select and use live data to increase the valid-
ity and efficiency of your tests. By Ross Collard

STPCon ’09 Preview


Begins after page 10
Here’s your guide to the
Software Test & Performance
Conference, which begins
March 31, in San Mateo, Calif.
This special bound-in section
is complete with full-day tuto-
rial and technical class listings, speaker biographies and a list
of networking opportunities you won’t want to miss.

Depar t ments
4 • Contributors 16 • Best Practices
Get to know this month’s Getting the build right means
experts and the best practices playing by the rules. Bottom
they preach. line? Maintain control and
evolve the infrastructure as
4 • Feedback the needs of the organization
It’s your chance to tell us where change. By Joel Shore
to go.
18 • ST&Pedia
6 • Editorial Industry lingo that gets you up
Nothing ever goes quite the way to speed.
you think. Everything takes
longer than you thought. Some 19 • Future Test
thoughts about planning a tran- When planning test automa-
sition and when thinking it tion, it’s the script writing that
through is the best you can do. demands the greatest skill and
stands to provide the most long-
7 • Out of the Box term benefit. Here are 10 steps
Latest news and products for to automated validation.
testers. By Matthew Hoffman

FEBRUARY 2009 www.stpcollaborative.com • 5


Ed Notes
VOLUME 6 • ISSUE 2 • FEBRUARY 2009

Editor
Edward J. Correia
ecorreia@stpcollaborative.com

Contributing Editors
Things Always
Take Longer
Joel Shore
Matt Heusser
Chris McMahon

Art Director
LuAnn T. Palazzo
lpalazzo@stpcollaborative.com

Publisher This is the first issue of carefully document each step.


Andrew Muns Software Test & Performance to Calculate the time you think it
amuns@stpcollaborative.com
be produced entirely by will require and double it. In the
Associate Publisher Redwood Collaborative Media, beginning, things always take
David Karp
dkarp@stpcollaborative.com
new owner of this magazine, its longer than you expect. If like
conferences and the Test & QA me, you’re lucky enough to be
Director of Events Report e-mail newsletter. I’m working with a talented group of
Donna Esposito
desposito@stpcollaborative.com thrilled beyond words for the dedicated people, your organiza-
opportunity to help shepherd tion will emerge wiser, stronger
Director of
Marketing and Operations these products to the potential and far better organized.
Kristin Muns I’ve always believed was there This isn’t the first time I’ve
kmuns@stpcollaborative.com Edward J. Correia
for the taking. worked for a company that’s
Reprints
The transition also brought to mind a few been acquired by another. But when CMP
Lisa Abelson truths that I believe are universal in busi- Media was purchased in 1999 by United
abelson@stpcollaborative.com ness, and are especially relevant to software Business Media, I had nothing at all to do
(516) 379-7097
testing and IT departments in with the IT logistics. Mine was
Subscriptions/Customer Service general. After years of doing a just a single department


stpmag@halldata.com
847-763-1958 job, adjusting and tweaking among scores of others. In the
business processes, and hiring Redwood transaction, my
Circulation and List Services
Lisa Fiske and dividing workloads, you department was the acquisition
lfiske@stpcollaborative.com tend to lose track of all the target. The technical problems
pieces and parts that go into If you’ve ever were neither unexpected nor
Cover Photograph from Fotolia.com
running a business. Once the insurmountable. They were
ties are severed and a task thought ‘My boss just another story of organiza-
comes due that someone else tional change taking place
used to perform, as is com- has no idea what each day in the thousands of
mon following the consolida- companies in an economy that
tion of an acquisition, the peo- I do,’ you could expands and contracts.
ple that remain must some-

President Chairman
how fill the void. very well have Rise to the Challenge
Andrew Muns Ron Muns If you’ve ever thought (and Tell us your story. In January

105 Maxess Road, Suite 207


perhaps even said) “My boss been right. The we kicked off the FutureTest
Melville, NY 11747
has no idea what I do,” you Challenge (www.futuretest.net
+1-631-393-6051
fax +1-631-393-6057
could ver y well have been
right. It’s hard enough keep-
best you can do is /challenge), a program we
hope will enable us to help
www.stpcollaborative.com
ing track of your own work- each other spread knowledge
load, let alone those of the
think everything and wisdom throughout the
Software Test & Performance (ISSN- #1548-
3460) is published monthly by Redwood half-dozen people that report software testing industr y.
Collaborative Media, 105 Maxess Avenue, Suite
207, Melville, NY, 11747. Periodicals postage to you. To say nothing of peers
through. Simply tell us how you solved a
paid at Huntington, NY and additional offices.
in other departments that challenging test or manage-
Software Test & Performance is a registered
trademark of Redwood Collaborative Media.
All contents copyrighted 2009 Redwood
Collaborative Media. All rights reserved. The
price of a one year subscription is US $49.95,
$69.95 in Canada, $99.95 elsewhere.
might be members of your
team. So when two companies
part ways, it’s nearly impossi-
ble to list each and every task
• ment problem in 300 words or
less of and we’ll publish it an
online knowledgebase. We’ll
also publish the best solutions
POSTMASTER: Send changes of address to that has ever been conducted in an upcoming issue of
Software Test & Performance, 105 Maxess Road, by people whose services will no longer be at Software Test & Performance magazine and
Suite 207, Melville, NY 11747. Software Test &
Performance Subscribers Services may be your disposal. discuss them at the conference.
reached At stpmag@halldata.com or by calling
The best you can do is to think every Are you up to the challenge? Enter today
at www.futuretest.net/challenge. ý
1-847-763-1958.
process through from beginning to end and

6 • Software Test & Performance FEBRUARY 2009


Out of the Box

Software Planner 9.0 Lets Users Be More


Pragmatic
With the release late last year of
Software Planner 9.0, Pragmatic
Software treated users of the ALM solu-
tion to a completely redesigned UI built
around Ajax-based screens, Flash-driven
dashboards and extensive new drag-
and-drop capabilities.
The browser-based tool, which can
be deployed in-house or accessed as a
Web service, now includes numerous
configurable screens, each with the
capability to display defect trends, bug
reports and test case status and other
project information, all in sharp graph-
ics. Dashboard reports permit filtering
based on a multitude of parameters,
and graphics permit drilling in for
more detail. A new grouping feature
permits requirements, test cases and
defects to be categorized into multiple
levels for further drilling. Users now Pragmatic acted as such with its Software Planner 9.0 delivers a UI built
can pull from recently used records approach to the integration, soliciting around Ajax-based screens, Flash-driven
when creating new ones, helping to help from STAR-QA, a software automa- dashboards and extensive new drag-and-drop
reduce data entry errors and save time. tion and QA consultancy, to help it with capabilities.
Software Planner 9.0 also now inte- the integrations. “Integrating automat-
grates with major third-party test ed testing with manual testing provides user for the Enterprise edition. The lat-
automation tools, including Automated a well rounded testing solution for any ter includes integration with Crystal
QA’s Test Complete, Borland Silk, HP’s software team,” said Pragmatic presi- Reports, a documented API, synchro-
QuickTest Pro and WinRunner, and dent and CEO Steve Miller. nization with other software in your
IBM Rational’s Rational Robot and Available now, Software Planner 9.0 organization and document versioning.
Functional Tester. This allows users to pricing starts at US$30 per user per year Software Planner was recognized in
launch automated tests, view results and for the SaaS version (which is hosted by 2008 as a Testers Choice, an annual award
logs from within Software Planner. Pragmatic), or $1000 per concurrent program organized by this publication.

Phoenix Gives Flight to Instant-On PC


Testers know the agony of rebooting CTO and senior vice president of engi- development cycle to the sheer complex-
every time the AUT goes belly-up. neering at Phoenix. “Your productivity is ity of the effort. “While we’re using Xen
Phoenix Technologies, which makes separate from that. You don’t have to rely and Linux as building blocks, we started
many of the BIOS chips in Windows on Windows, and you have an easy way of from scratch, and we had to do lots of
PCs, at the CES in Las Vegas last month restoring it. While your system is being things to do. Also important was compat-
released HyperSpace. The micro-kernel restored, you can still be productive ibility with Windows. It took a long time
based BIOS measures configurable boot because your environment is still available to work out all those things.”
time in fractions of a second and can and you can do it all on a single box.” HyperSpace for Windows XP and
restart Windows without interrupting Under development since late 2007, Vista costs US$39.95; a Vista-only version
access to email, instant messaging and HyperSpace employs Linux kernel and with virtualization costs $59.95 per year.
other browser-based applications. the Xen virtualization environment to Both are available now for download.
“The benefit is that you do not have to provide instant access to network connec- Phoenix also is negotiating OEM agree-
rely on the environment you’re testing tivity, IP-based services and battery-life ments with NEC and other PC makers for
with and modifying,” said Gaurav Banga, optimization. Banga chalks up the long inclusion with their systems.

FEBRUARY 2009 www.stpcollaborative.com • 7


The Performance Tester’s
survival guide
By Justin Callison

n the world of software quality assur- when they want access to the complete knowledge base of

I ance, performance testers are the elite


forces. We are the SWAT teams that are entrusted with the
the organization. It will also allow you to identify the realm
in which your problems occur and to find the right people
to help you solve them. As I like to say: “I don’t know any-
most difficult situations. We are the pinch hitters that are thing, but I know who knows everything.”
sent to bat at the most crucial points in the game. We get
to play with the latest, greatest, and biggest toys that the Learn To Translate
hardware vendors can devise. We live and breathe automa- The need for a performance tester to act as a translator
tion and we almost never have to do manual testing (ick). goes far beyond the strictly technical realm.
Our jobs are so complicated and challenging that we are Communications among team members and between
NEVER bored. So it is a pretty good place to be. business and technical people are often difficult to deci-
But it is anything but easy. We are the only ones who can pher. DBAs, developers, QA testers, managers, and execu-
resolve those problems we are entrusted with and the stakes tives all speak distinct dialects. This dialectical divide cre-
of failure are high. If you do not meet expectations, not ates barriers between groups which eventually lead to
only might you be moved into another role, the entire prac- problems. As a performance tester who has found a criti-
tice could be abandoned. Like a pinch hitter sent to bat in cal problem, proper communication is especially vital. You
the ninth inning of a playoff game, a home run means eter- need to tell the developer where it is in his or her code,
nal glory. A strike out means the whole team is going home. then you need to convince the DBA that there is actually
My road to being an expert in the area of performance something that can be done about it, while being able to
was by no means a straight and easy path. I have taken my convince the business and management folks that this
lumps and I have the scars to prove it. But along the way, I problem has business impact and that it deserves the
have learned a lot and I am hoping that by sharing some resources required to fix it. Finally, you need to work with
of that with you in this brief survival guide, I will help you QA to test the fixes once they have been completed. All of
to knock a few out of the park. this requires you to translate between these groups and
tactfully navigate the jargon, idioms, and buzzwords nec-
Be a Technical Rosetta Stone essary to get everyone on the same page.
Since performance problems can occur at every level of One method that I use to make this process easier is sto-
the technology, they are all within your circle of concern. rytelling. At the Software Test & Performance conference
Even a fairly simple Web system involves operating sys- in San Mateo, Calif., last spring, Karen Johnson gave a talk
tems, storage systems, networking, relational databases, about storytelling that resonated with me. She said that by
development platforms (such as Java or .NET), presenta- creating a story, you can highlight the important data and
tion technologies (such as JSP or Velocity), JavaScript, still be able to explain the situation in a way that is easy to
and client Web-browsers. All of these constitute moving understand. It also allows the information to be easily
parts and all of them are candidates for causing trouble. digested and analyzed instead of having most of the infor-

Special Weapons and Tactics as it Applies To


Software Test and to Life in the Corporate Jungle
To make matters worse, problems often lie in how they mation be ignored. I find storytelling helpful in weaving
these parts work together. together the important technical, user, and business ele-
You are likely thinking “there is no way I can be an ments of a complex situation into something that every-
expert in all of this stuff.” The good news is that you one can understand.
don’t have to be. You don’t need to be an expert, but Translating is also vitally important when it comes to
you need enough of an understanding and vocabulary communicating specific problems to people who are not
so that you can talk to the expert. If you can do this, performance testers. The complex and subtle technical lex-
you will gain two things. icon required for effective execution within the perform-
First, you will be able to use these experts to get the ance testing group can be utterly confounding to those on
answers you need. Second, you will be able to translate the outside. As such, it is critical to be aware of your audi-
between the world of the DBA and that of the Java devel- ence and to communicate in a way that they can under-
oper and from the networking expert to the JavaScript stand. This means simplifying things to provide only the
guru. This will make you the person that people go to information that is required and choosing metrics that are
effective and easy for others to wrap their heads around.
Justin Callison is director of SQA premium services and heads
the performance practice at Luxoft, an application outsourcing
For example, you might consider using Apdex
consultancy headquartered in Moscow. (http://www.apdex.org/), a standardized “application
performance index” instead of reporting the average

FEBRUARY 2009 www.stpcollaborative.com • 9


SWAT TEST

response time. It is also helpful to prepare test specifications development organization to support your initiatives. Developing
that clearly document how your tests were run so that others a relationship with architects is worth the time and energy for
can interpret your metrics. This communication is important both you and them. You can learn a lot from them, but you can
for ensuring that action is taken based on your findings. It is also provide the support they need to achieve their goals. It is a
also critical to job security. If the VP of development does not two-way, productive relationship that is well worth pursuing.
understand what you do and what value you provide, that can
be a somewhat tenuous place to be. Admit When You Do Not Understand
Performance is complicated; there will be lots of things you do
Find One Hole and Dig Deep not understand. Get comfortable saying “I don’t know,” but do
This may seem to contradict my earlier suggestion of devel- not stop there. Demand further explanation, whether that
oping broad but shallow technical fluency. You do not need demand is made of a colleague or of you (i.e. further research).
to be an expert in all areas, but it is well worth it to become At school, my teachers always encouraged us to ask questions. It
an expert in at least one. For me, my hole was the Oracle is almost certain that others will have the same questions but
DBMS. Through gaining my OCP certification and working might be too uncomfortable to ask. This is often the case in
closely with other DBAs, I learned a great deal about core product development teams, in which no one has the courage to
performance concepts, specifically caching, locking, data say that the Emperor has no clothes.
consistency concerns, failure/recovery, clustering, language
parsing, networking, and I/O systems. It gave me a solid Perfect is the Opposite of Good
framework to build on and I was then able to apply these In performance testing, it’s easy to blame failure or lack of
core concepts to understand problems and possible solutions progress on inadequate conditions. The build is not stable
in other realms. There are not enough. The hardware we have
many truly unique problems is insufficient. I do not have the
or solutions, but by concen-
trating on this mature and
highly scaled technology, I was
exposed to most of them.
• right tools. We do not have
enough time. These are all real
impediments, but the biggest
impediment is to wait until you
By learning about a highly You can apply this have a perfect build, the perfect
specific situation and the core testing infrastructure, and as
concepts involved in solving it, knowledge to many other much time as you need. That
you can then apply this knowl- will never happen. If your cost
edge to many other difficult technical situations estimates are based on perfec-
technical situations. A former tion, it is likely you will not get
colleague, whom I worked with approval to start.
early in my career, is a grizzled
veteran who started adminis-
tering Unix systems in the early
1970’s. Every time I would
• Effective performance test-
ing does not require perfec-
tion. Useful work can be done
with a partial implementa-
bring up some fancy new technical term, he would ask for an tion, a desktop, one person with a stopwatch and an after-
explanation. Then he would say “Ah, I get it. We did some- noon. Does that mean you should stop there? Absolutely
thing like that back in the old days. But we called it something not. But it shows that you don’t need perfection to get
different.” The knowledge you learn now will often be appli- started. The biggest mistake and cause of failure in per-
cable down the road. formance testing is starting too late.

Automation is Software Development Tools are Just Tools


A huge pet peeve of mine, and something I believe is the root of When you have a hammer, all your problems start looking like
many evils, is the haphazard way that automation in QA is treat- nails. This is the sort of mentality that can severely limit your per-
ed. Automation is software development and the same principles formance testing success. Too often we choose or inherit a load
apply and are required. Modularization and reuse, proactive testing tool that claims to do everything, including solve world
design, documentation, source control, coding guidelines, and hunger. This often leads to two bad assumptions:
code reviews are all absolutely necessary to allow you to spend • This tool will solve all of my problems
less time writing performance automation and more time doing • My only problems are things this tool can solve
productive work. Failure to do these things results in poor qual- These are both wrong assumptions and will get you into trou-
ity, high maintenance expense, high cost of implementing new ble. First, make sure you understand the problems you face.
features, and complete dependency on one or two individuals. Once you completely understand the problem, decide how to
This is a matter of self respect. Your automation code deserves best and most efficiently solve that problem. Then choose the
the same level of respect as the code that goes into the product. right tool to help you implement your plans, but do not limit
yourself to one tool. Different problems require different solu-
Get to Know the Architect tions and different tools.
Architects are an invaluable ally and tend to be among the Remember too that having a license for the most expensive
smartest people in the organization. They understand the big load testing tool available, replete with every conceivable bell
technical picture and can help you find the right people to and whistle, is still no guarantee of success. Writing scripts and
answer your questions. Often they have the influence within the running tests is the easy part. The hard part is asking the right

10 • Software Test & Performance FEBRUARY 2009


March 31 – April 2, 2009
San Mateo Marriott | San Mateo, CA

Reach Your
Peak Performance
The premier technical conference for
software testers, QA managers and
software developers and managers

Unparalleled Education
• 60+ sessions covering software test/QA and perform-
ance issues across the entire application life cycle
• Full-day tutorials offer complete immersion in the topic

Ultimate Networking
• Share experiences, challenges, ideas, and solutions with
your peers and industry leaders — the STPCon faculty

Presented by
Exciting New Tools & Technologies
• Get a first look at the latest tools and services. Visit with
vendors in a relaxed environment. See the products in
action, and find the tools and technologies that can help
your organization reach its peak performance

Don’t miss the best STPCon yet! Register by March 13th and save up to $300!
Visit www.stpcon.com to register today!
Testing by the Numbers!
Contents N umbers are everything. They’re the bottom line. They’re in your bug list,
your budget and your bank account. They’re the number of days left till
release, the number of people on your team and the number of test cases
Event Schedule 3 they ran. How many bugs did they find? How many were fixed? How many
remain? Of those, how many are critical? It’s all in the numbers.
Conference Planner 4–5 Unfortunately, numbers also dominate the headlines. The number of job losses, the highs and lows of the
stock market, the number of billions for the latest corporate bailout.
Full-Day Tutorials 6
The Software Test & Performance Conference is here to help. With the high cost of software failures,
employing the most effective software testing techniques is one important way to keep costs low. And
Technical Classes 7 – 13
we’ve lowered the price to help make sure that STPCon will not break your budget.

Faculty 14 Security flaws, usability problems, functional defects, performance issues—they all carry a tremendous
price tag. It’s more important than ever to be sure that new applications are written to be secure from the
Hotel & Travel Information 15 start and are deployed only after they’ve been thoroughly tested. Shorter software development cycles and
tightening budgets require testing and performance processes that are as cost-effective as possible.
Pricing and Registration 16
If you’re a software developer trying to gain performance, a test/QA or development manager responsible
for improving the quality of your company’s software, or a test/QA specialist who wants to take your skills to
a higher level, the Software Test & Performance Conference is just right for you. Every year we combine the
“If you want to learn about industry’s best trainers with professional testers from companies just like yours to give you a program that
appeals to testers and managers of all abilities and skill levels.
the latest test and perform-
On March 31–April 2 in San Mateo, select from nearly 70 classes and tutorials given by testers at Cisco,
ance techniques from the Expedia.com, Intuit, Microsoft, Progressive Insurance, Verizon and Volvo. Many of our usual favorites also
industry experts, you want will be there, including Ryan Berg, Hans Buwalda, Bob Galen, Chris Sims and Mary Sweeney. Learn from
these experts how to implement quality assurance across an entire project, pinpoint and fix performance
to attend STPCon!” bottlenecks and adapt testing methods both familiar and emerging.
So join us at STPCon in San Mateo for the newest techniques, tips and tricks to help you improve require-
MICHAEL MARQUIZ,
SOLUTIONS ARCHITECT, ments gathering, UI design, function testing, and load and performance testing—techniques that will have
CISCO SYSTEMS your applications humming in no time.
I hope to see you there.

Edward J. Correia, Conference Chairman

Opening Keynote Wednesday, April 1 — 8:45 am – 9:45 am

To Keep Your Testing Budget, Stop Saying ROI


One way or another, you're going to spend money on software testing. So it’s really not the “invest-
ment” that you’re selling upstairs, but the “return on expenses” that you need to optimize. That’s
Hung Q. Nguyen because with today’s economy, CFOs aren’t signing off on “investments”; they’re battening down the
Chairman and CEO, hatches. Hear from LogiGear co-founder Hung Nguyen how a returned-value analysis can get you the
LogiGear Corp. testing budget you need, while providing total transparency into the value of testing and keeping your
staff motivated and confident in the stability of your company.
Hung Q. Nguyen, LogiGear chairman and CEO, is responsible for the company’s strategic direction and
management. His experience over the past two decades includes leadership roles in software develop-
ment and quality, product and business management at Spinnaker, PowerUp, Electronic Arts and Palm
Computing. Hung teaches software testing at LogiGear University, and at the University of California
Berkeley Extension and Santa Cruz Extension in San Francisco and Silicon Valley.

2 Register Early and Save: www.stpcon.com


Event Schedule
Monday, March 30

Special Conference Events and Features 4:00 pm – 7:00 pm Registration Open

Tuesday, March 31 Tuesday, March 31


7:30 am – 7:00 pm Registration Open

Lightning Talks 5:00 pm – 6:00 pm 7:30 am – 9:00 am


9:00 am – 10:30 am
Continental Breakfast
Full-Day Tutorials
Fast. Targeted. To the point. Don’t miss Lightning Talks, where your favorite speakers
speed-talk on the essence of test concepts and ideas. Each speaker has 5 minutes to
10:30 am – 11:00 am Coffee Break
wow you with an idea. If the speaker goes on too long, you’re invited to let them know 11:00 am – 12:30 pm Full-Day Tutorials (continued)
in not-so-subtle ways! 12:30 pm – 1:45 pm Lunch Break

Hands-on Tool Showcase 6:00 pm – 8:00 pm 1:45 pm – 3:15 pm


3:15 pm – 3:45 pm
Full-Day Tutorials (continued)
Coffee Break
Demos and drinks! Technology meets hospitality in these open-forum sessions from 3:45 pm – 5:00 pm Full-Day Tutorials (continued)
STPCon sponsors. Catch up on the latest techniques and practices while enjoying
food and beverages in a friendly atmosphere. 5:00 pm – 6:00 pm Lightning Talks
6:00 pm – 8:00 pm Hands-On Tool Showcase
Wednesday, April 1
Wednesday, April 1
Open Panel Discussion 1:15 pm – 1:50 pm 7:30 am – 7:00 pm Registration Open
You pick the topic for discussion by a panel of testing experts. 7:30 am – 8:45 am Continental Breakfast
8:45 am – 9:45 am Opening Keynote
Expo Attendee Reception 5:00 pm – 7:00 pm 10:00 am – 11:00 am Technical Classes – 100 series
Food, drinks and pleasant conversation in the Exhibit Hall. 11:15 am – 12:15 pm Technical Classes – 200 series
12:15 pm – 1:15 pm Lunch Break
Thursday, April 2
1:15 pm – 1:50 pm Open Panel Discussion
2:00 pm – 3:00 pm Technical Classes – 300 series
Prize Patrol 12:00 pm – 1:00 pm 3:00 pm – 7:00 pm Exhibit Hall Open
Here’s your chance to win prizes from exhibitors at STPCon. Drawings are conducted 3:00 pm – 3:45 pm Coffee and Ice Cream Social
at each booth and winners are announced on the spot. You could be one of them! in Exhibit Hall
3:45 pm – 4:45 pm Technical Classes – 400 series

Exhibit Hall HOURS:


5:00 pm – 7:00 pm Reception in Exhibit Hall

Get a first look at the latest tools and services from Thursday, April 2
the industry’s top companies. Visit with vendors in Wednesday, April 1 7:45 am – 4:00 pm Registration Open
a relaxed environment. See the products in action, 3:00 pm – 7:00 pm 7:45 am – 8:45 am Continental Breakfast
and find the tools and technologies that can help Thursday, April 2, 8:45 am – 9:45 am Technical Classes – 500 series
your organization reach its peak performance. 9:30 am – 1:15 pm 9:30 am – 1:15 pm Exhibit Hall Open
9:45 am – 10:30 am Coffee and Doughnuts
in Exhibit Hall
10:30 am – 11:30 am Technical Classes – 600 series
11:30 am – 1:00 pm Lunch Break
12:00 pm – 1:00 pm STPCon Prize Patrol
in Exhibit Hall
1:00 pm – 2:00 pm Technical Classes – 700 series
2:00 pm – 2:15 pm Break
2:15 pm – 3:15 pm Technical Classes – 800 series
3:15 pm – 3:30 pm Break
3:30 pm – 4:30 pm Technical Classes – 900 series

Register Early and Save: -1-415-785-3419 3


Conference Planner
Monday, March 30
4:00 am – 7:00 pm Registration Open

Tuesday, March 31 Wednesday, April 1


7:30 am – 7:00 pm 7:30 am – 7:00 pm Registration Open
Registration Open
8:45 am – 9:45 am Opening Keynote
8:45 am – 9:45 am
3:00 pm – 7:00 pm Exhibit Hall Open
Opening Keynote
3:00 pm – 3:45 pm Coffee & Ice Cream Social in Exhibit Hall
3:00 pm – 7:00 pm
Exhibit Hall Open 5:00 pm – 7:00 pm Reception in Exhibit Hall

Tutorials Technical Classes


9:00 am – 5:00 pm 10:00 am – 11:00 am 11:15 am – 12:15 am 2:00 pm – 3:00 pm 3:45 pm – 4:45 pm

T-1 First Steps to Test 101 Quality Through- 201 Model-Based 301 Balancing 401 Techniques for
Automation out the Software Testing for Java Test-to-Break, Influencing
Life Cycle and Web-based Test-to-Validate Upstream
—Walsh GUI Apps and Metrics Decisions
—Feldstein
—Feldstein —Feldstein —Feldstein

T-2 Managing the 102 Agile Test 202 The Most Effective 302 Performance- 402 Performance-
Test People Development Ways to Improve Tuning Java Tuning Java
—McKay —Buwalda Software Quality Applications, Part Applications,
—Sims 1 Part 2
—Bartow —Bartow

T-3 Improving Web 103 Effective Use of 203 The 5% Rules of 303 Requirements 403 Moving to a
Application Static-Analysis Test Automation Analyses and Truly Virtual QA
Performance Testing —Buwalda Collection Lab
Using Six Sigma —Anderson —Quigley and Pries —Knox
—Jain

T-4 Agile & High 104 The Makings 204 Assess Your 304 How to Break 404 The Path To A
Speed Testing of a QA Leader Way to Better Web Software Secure
Techniques —Sims Test Team —Basirico Application
—Galen Performance —Berg
—Hackett

T-5 Automated Data- 105 Testing with 205 Training the 305 Releasing 405 Releasing
base Testing: Stochastic Test Next Generation Products Products
Using Stored Data Of Testers in an Agile in an Agile
Procedures —Rollison —Rollison Enterprise, Part 1 Enterprise, Part 2
—Sweeney —Galen —Galen

T-6 Managed Test 106 Test-First GUIs: 206 Maximizing SQL 306 Automated 406 Static Analysis
Automation The Model-View- Server 2005 Testing on Steroids
—Buwalda Presenter Performance in the .NET —daVeiga
Approach —Sweeney Environment
—Walsh —Sweeney

T-7 Combinatorial 107 Managing the 207 TTo be announced 307 To be announced 407 To be announced
Analysis: A Pair- Test People Please check the Please check the Please check the
Wise Testing Primer —McKay website. website. website.
—Rollison

4 Register Early and Save: www.stpcon.com


“This is where you realize that testers are heroes!”
MEHMET EFE, SENIOR MANAGER, SHOPZILLA

Thursday, April 2
7:45 am – 4:00 pm Registration Open
9:30 am – 1:15 am Exhibit Hall Open
9:45 am – 10:30 pm Coffee & Doughnuts in Exhibit Hall
12:00 pm – 1:00 pm STPCon Prize Patrol in Exhibit Hall

Technical Classes
8:45 am – 9:45 am 10:30 am – 11:30 am 1:00 pm – 2:00 pm 2:15 pm – 3:15 pm 3:30 pm – 4:30 pm

501 The Hunt for 601 Is Your Inversion 701 Effective 801 Performance 901 Tools and
Malicious Code of Control Training Bugs and Techniques for
—Berg Framework of an Offshore Investigation Fixing Memory
Secure? Test Team Strategies Errors
—Berg —Hackett —A. Wong —Gottbrath

502 Tester Career 602 Test Automation 702 A Buzz About 802 Performance 902 GUI Bloopers:
Paths For an of Search Results Fuzz: Finding Testing of Large Avoiding
Outsourced and Other Data- Software Distributed Common Design
Economy driven Apps Vulnerabilities Systems Mistakes
—Hackett —Bulgakov —Basirico —Quigley and Pries —Johnson

503 Strategies for 603 Strategies for 703 The Business 803 Designing with 903 Testing Visibly
Unit Testing in Unit Testing in Value of the Mind in —Kapfhammer
Spite of Legacy Spite of Legacy Usability Mind
Code, Part 1 Code, Part 2 —Johnson —Johnson
—Loeb —Loeb

504 Setting Agile- 604 Testing in an 704 End-to-End Perfor- 804 Performance 904 Test Destiny:
Centric Release Agile mance Process: Engineering for The Psyche of a
Criteria Environment Requirements to Large Application Professional
—Galen —Walsh Production Monitoring Clusters Tester
—A. Wong —Bartow —Massey

505 Testing Live 605 Managing 705 Optimizing The 805 Web Services/ 905 Finding
Apps with Embedded Testing Effort With SOA Testing Vulnerabilities
Virtualization Product Testing Keyword-Driven Made Easy Without
—Ewe —Quigley and Pries Frameworks —Subbarao Attacking
—Massey —McPhee

506 The Marriage of 606 Experience 706 Optimizing Web 806 Testing in the 906 Finding .NET
Agile and Test with Keyword 2.0 Application Cold (And Ideas Performance
Management Automation Performance to Warm You Up) Bottlenecks
—Massey —Buwalda —H. Wong —Buwalda Using PerfMon
—Nandi

507 To be announced 607 To be announced 707 Five Common Mis- 807 To be announced 907 To be announced
Please check the Please check the takes When Secur- Please check the Please check the
website. website. ing Web Applications website. website.
—Ewe

Register Early and Save: -1-415-785-3419 5


Full-Day Tutorials Tuesday, March 31
9:00 am – 5:00 pm

T-1 First Steps to Test Automation T-5 Automated Database Testing:


Robert Walsh Using Stored Procedures
NEW If routine and mundane tests can be automated, Mary Sweeney
testers are free to do more interesting (and valuable) Testers are increasingly expected to create and use SQL
exploratory testing. But many organizations struggle with queries, stored procedures and other relational database
how to get started, or believe that automation requires objects to test data-driven environments. Learn about
expensive tools and trained specialists. This class will testing at the database layer through demonstrations and
demonstrate how to get started with test automation code examples, and discover tips and techniques for
using open-source tools that any experienced tester can creating efficient automated tests of the database back
use. In this hands-on lab, you will work with these tools end using SQL, scripting languages and relational data-
and learn how to make automation work for you. base objects. Also learn how to create simple and effec-
tive automated tests for the back end using Perl and
T-2 Managing the Test People VBScript, and how to successfully test database objects
through examples and sample code.
“I found the material Judy McKay

covered in the NEW Adapted from her book of the same name, “Man- T-6 Managed Test Automation
aging the Test People” explores techniques and methods
for working through problems unique to the software QA Hans Buwalda
Tutorial and Tech profession. Intended for managers, test leads and people NEW Test-case automation—UI and non-UI based—is
Classes exceeded who may soon be in leadership positions, this class is an important objective for test projects. It’s also complex,
about the real world, real problems and real people, pre- and can easily backfire. Using his 5% rules for test
my expectations. sented from a practitioner’s viewpoint, and provides automation—no more than 5% of test cases should be
viable solutions that can actually be implemented. You’ll manual, and automation should be achieved with no
As did the presen- hear stories illustrating concepts and get practical advice more than 5% of testing resources—Hans will teach you
for the novice and affirmation for the expert. how it’s all possible with Action Based Testing, a key-
ters!” NOTE: A one-hour version of this class will be presented word-based test design and automation method. He will
on April 1. also offer ideas for cross-platform automation, device
ROBERT LEE, testing, multimedia, and testing with communication pro-
ENGINEERING MANAGER, tocols.
PROGRESS SOFTWARE T-3 Improving Web Application
Performance With Six Sigma T-7 Combinatorial Analysis:
Mukesh Jain A Pairwise Testing Primer
EXPANDED Quality means more than having a defect- Bj Rollison
free product that meets requirements. Performance is an
implied need; its absence will impact your business. NEW Pairwise testing reduces the number of tests by
Learn practical Six Sigma techniques that can improve selecting a test set that evaluates every pair combina-
Web application performance. Learn how you can plan tion. Historical and root-cause analyses show that most
the right thing, do the right thing and get the right things errors caused by the interaction of variables occur
for users at the right time, every time. Hear how Six between two parameters rather than among the variables
Sigma techniques at Microsoft improved performance of for three or more parameters. This class compares
Outlook and Windows Live services. orthogonal arrays to pairwise analysis and demonstrates
the use of a powerful combinatorial analysis tool—Micro-
soft’s Pairwise Independent Combinatorial Testing
T-4 Agile & High Speed Testing (PICT)—to systematically test complex, interdependent
Techniques parameters.

Bob Galen
NEW Approaching the testing challenge with nimble-
ness and speed, this workshop explores practices, tools,
techniques and philosophies that will allow allow testers
to meet any schedule or product challenge with integrity
and professionalism. You’ll learn a variety of testing tech-
niques to maximize focus, engage stakeholders in deci-
sion-making, and guide the trade-offs that are inevitable
in any successful testing project. The types of testing
covered in this class include context-based testing, just-
in-time, lean, exploratory, risk-based, Pareto-based and
all-pairs testing.

6 Register Early and Save: www.stpcon.com


Wednesday, April 1 Technical Classes
105 Testing With Stochastic Test
100 Series: 10:00 am – 11:00 am Data
Bj Rollison
101 Quality Throughout the Software
Many tests require test data as input for variables. Real-
Life Cycle world test data is important, but it really serves only to
Jeff Feldstein verify nominal input conditions. Also, repeatedly using
the same static data doesn’t provide significant benefit,
Quality cannot be tested into a product; it must be and random data is often shunned because it may not “Great, informative
emphasized, monitored and measured from the begin- be repeatable. Learn techniques to generate random test
ning. Each team involved in the project—from manage- data for positive and negative testing using seed values conference for soft-
ment to marketing—plays a role in quality. A carefully for repeatability, and learn how to test data randomly
planned SDLC is a key requirement of on-time delivery of from a set of static variables based on a weight factor for
ware testers, leads
quality software. Explore the broad phases of develop- preference.
ment from a software-quality perspective, learning the
and managers
activities required at each phase, the precise role of the
tester or QA engineer, and how to catch bugs earlier and 106 Test-First GUIs: The Model- alike. Useful tutori-
avoid common mistakes. View-Presenter Approach als and technical
Robert Walsh
102 Agile Test Development classes of wide
GUIs can be a challenge when migrating to test-driven
Hans Buwalda development. Using a Model-View-Presenter (MVP) pat- variety, but applica-
tern and other common TDD techniques, GUIs can be
EXPANDED The short, iterative cycles, constant feed- ble for many
built and tested as is other code that’s built test-first.
back and team-based approach to quality that work for
This class will show you how to construct graphical user
software also can be applied to automation. The process QA/SQE organiza-
interfaces test-first using MVP. Concrete examples will be
of developing and automating tests requires constant
given in C++ using both Win32 and Qt. The technique is
feedback from developers, managers, customers and
applicable to virtually any development language and tions. Well worth
others outside QA. This class shows how the keyword-
environment.
oriented Action Based Testing method is effective for the small invest-
maintainable automated tests for agile, and why it makes
sense to use agile methods for test development regard- 107 Managing the Test People ment in cost and
less of what’s being done elsewhere in the organization.
Judy McKay time. A must-attend
103 Effective Use Of Static-Analysis NEW Adapted from her book of the same name, “Man-
for all serious
aging the Test People” explores techniques for working
Testing through problems unique to software QA people. It is
intended for managers, test leads and those ascending
QA/SQE profes-
Paul Anderson
into leadership. This class is about the real world, real sionals!”
NEW Static analysis is not a replacement for runtime problems and real people, and provides viable solutions
testing; each technique is good at catching certain types that can actually be implemented.
of bugs, and some important consequences stem from ALAN ABAR,
NOTE: This is a one-hour version of the full-day tutorial. SOFTWARE QUALITY
this difference. For example, the two have different
notions of coverage and precision. Static analysis also ENGINEERING MANAGE,
has a limited view of requirements. So what’s the best COVAD COMMUNICATIONS
way to use static code analysis? Through examples and
sample code, learn the strengths and weaknesses of
200 Series: 11:15 am – 12:15 pm
static analysis and how it can be used effectively in the
context of a broader software-quality initiative. 201 Model-Based Testing For Java
and Web-based GUI Apps
104 The Makings Of a QA Leader Jeff Feldstein
Chris Sims Classic automation repeats the same tests until it stops
One of the best ways to increase your impact on the failing or the application ships. But users rarely traverse
quality of your product, team, company and career is to the application in the same sequence, and they’re likely
step beyond the role of contributor and into leadership. If to find bugs that the automation missed. Model-based
you feel the call to leadership but aren’t sure how to automated testing brings random and flexible behavior to
begin, this class is for you. We’ll use the Nominal Group automated test cases. Learn to implement MBT for Java
Technique (NGT) to gather the group’s experiences and and Web applications, see a demonstration—the XDE
ideas, identify the factors that have had the biggest Tester—and download the source code containing the
impact and efficiently harness the collective wisdom of data structures, concepts and program flow for imple-
the group. menting a large-scale, industrial-strength model-based
test system.

Register Early and Save: -1-415-785-3419 7


Technical Classes Wednesday, April 1

202 The Most Effective Ways To 206 Maximizing SQL Server 2005
Improve Software Quality Performance
Chris Sims Mary Sweeney
What are the best ways to improve software quality? It might be dated, but SQL Server 2005 still performs in a
More testers, better specs, more time for testing? Yes to good many organizations. Do you need help handling
all three, but are they under your control? For most, the bottlenecks and performance problems? Learn tips and
answer is no. So what’s a QA pro to do? More interest- techniques to gain the most from your SQL Server from
ingly, what have you done? Share your most effective an experienced practitioner working on the nation’s
tips, tactics and practices, and tap into the collective fourth largest database. Discover what’s new in SQL
wisdom in the room using the Nominal Group Technique Server 2008 and how it’s different from its predecessor.
(NGT). Walk out ready to make a bigger impact with the You’ll also learn how to fix quirks that stall large queries,
resources already at your disposal. as well as important techniques for boosting SQL Server
2005 and 2008 performance.
203 The 5% Rules of Test
“It solidifies the total
Automation 300 Series: 2:00 pm – 3:00 pm
Hans Buwalda
testing experience UPDATED No more than 5% of test cases should be 301 Balancing Test-to-Break, Test-to-
and opens your manual, and no more than 5% of effort should be spent Validate and Metrics
creating the remaining automation. Learn Hans
Buwalda’s 5% rules (challenges) of test automation, their Jeff Feldstein
eyes to alternative
rationale and how they can be achieved (and missed)
Software is tested to answer two questions: Does it
approaches and from accounts of real projects. Also includes an introduc-
work? Will it break? The tester’s job is to balance invest-
tion to the keyword-driven Action Based Testing meth-
ments in each. Learn how to generate a feedback loop
methods that you ods (which are covered in detail in his full-day tutorial).
among three major areas—test-to-validate, test-to-break
and test metrics—with examples and guidelines for opti-
simply cannot get 204 Assess Your Way to Better Test mizing resources in each. Example metrics also will be
Team Performance explored, along with suggested actions based on results
from books.” and suggestions for communicating these concepts to
Michael Hackett your test team.
JOHN CROFT,
QA MANAGER, Want a road map to quality? Everyone—all development
I4COMMERCE managers, test managers and their organizations—is 302 Performance-Tuning Java
looking for ways to improve quality. Quality improvement Applications, Part 1
can come in many forms: reducing risk by delivering
products of higher, more predictable quality; optimizing Daniel Bartow
time-to-market; increasing productivity; and building a
NEW The Java virtual machine presents an interesting
more manageable organization. Some managers look for
performance challenge. Look at the Java virtual machine
quality improvement by attempting to implement a more
from the inside out with a focus on performance-tuning
standard or formal process. This sounds good, but how
Java applications. Learn how to tweak the JVM to per-
do you get there? In this class, you’ll learn how to evalu-
form better under load. Understand Java memory gener-
ate your test process and strategy, create a culture for
ations, garbage collection and threading, and how they
change, implement change and use effective methods
affect your application. Expand all of these topics to the
for measuring improvement.
system level for a top-down view of your application’s
performance and capacity.
205 Training the Next Generation of
Testers 303 Requirements Analyses and
Bj Rollison Collection
NEW The challenges facing software testers multiply as Jon Quigley and Kim Pries
software and system complexity grow. A fraction of
NEW Requirements analysis follows multiple paths. If
testers have formal training in the discipline and even
user specifications are present, requirements can be
fewer have read more than a single book on software
derived from them; if not, requirements must be elicited
testing. Most university computer science programs lack
from the customer and from the dictates of the environ-
significant discussion of software testing beyond getting
ment, potential regulatory factors and the market seg-
code to compile. This talk discusses specific objectives
ment. Learn how to gather requirements for software
and grass-roots strategies to help managers with on-
quality function deployment, performance, and docu-
boarding new software testers to help them become
ment derivation and creation. Also covered are require-
more productive more quickly.
ment types, attributes of good requirements, prioritization

8 Register Early and Save: www.stpcon.com


Wednesday, April 1 Technical Classes
and constraints (QFD, Pugh, etc.), traceability, stakehold- do their job. But often it’s helpful for test/QA teams to
ers and reviews, feedback verification, modeling to gen- contribute to decisions up the chain. Learn to develop
erate requirements, and change management. test-specific strategies to influence departments within
your organization. Gain techniques for getting good
requirements from marketing and sound, testable code
304 How to Break Web Software from development.
Joe Basirico
The Web and Web services are prime targets for hackers, 402 Performance-Tuning Java
and network security isn’t the answer. Learn a model for Applications, Part 2
Web application testing that covers accountability, avail-
ability, confidentiality and integrity, along with techniques Daniel Bartow (See 302)
for breaking Web applications and methods of mitigation. “This is the best
Go beyond the basics of SQL injection and cross-site
scripting (also covered) to more-advanced and more-sin-
403 Moving to a Truly Virtual QA Lab conference I have
ister attacks. Learn how to think about Web security vul- Ian Knox
nerabilities; techniques for information gathering; and attended. The
attacks on the client side, state, data, language, server Experimenters with virtualization soon realize a need to
and authentication. move from a basic to an automated virtual environment. instructors were
Learn how to make that transition, best practices for
leveraging a virtual lab in your QA process, and real- extremely knowl-
305 Releasing Products world examples of virtual test lab implementations. Learn
In an Agile Enterprise, Part 1 how virtualization is being applied in test labs, how to edgeable and
select a solution, how to implement and configure a vir-
Bob Galen tualized environment, and how to integrate existing test helped me look
and development tools.
NEW Agile projects, when developed in the enterprise, at testing in a new
encounter factors beyond the scope of software devel-
opment that need to be negotiated separately. In this 404 The Path to a Secure Application way.”
two-part class, learn the enterprise extensions for Agile
releases, including methods for integrating agile teams Ryan Berg
ANN SCHWERIN ,
within a traditional management structure; iteration NEW Do you know where to look in your applications to QA ANALYST,
extension models required for testing across the enter- be sure your source code isn’t putting you at risk? This SUNRISE SENIOR LIVING
prise; examples of release planning dynamics required presentation will detail the path you must follow to find
when integrating across multiple teams; and how to and eliminate the coding errors and design flaws that
develop iteration release criteria and metrics that drive expose data, threaten operations, and cost your organi-
improved quality and visibility. zation time and money.

306 Automated Testing 405 Releasing Products


In the .NET Environment In an Agile Enterprise, Part 2
Mary Sweeney Bob Galen (See 305)
Testing .NET apps has gone from black-box to full inte-
gration of development and test within the .NET platform. 406 Static Analysis on Steroids
This class will guide you through the pros and cons of
working in .NET, exploring the impact that testing in .NET Nada daVeiga
has on you, your company and the industry. Learn how
testing in .NET compares with traditional practices, how NEW With the growing popular- ity of automated unit
the approach affects best practices, the problems and testing tools, many developers have the opportunity to
advantages of this approach, and what it can and can’t click a button and get a long list of potential, uncaught
do for you. runtime exceptions in new or legacy code. The larger the
code base, the longer the list. This session will explain
and demonstrate how to apply flow analysis to zero in on

400 Series: 3:45 pm – 4:45 pm the bugs that pose real risks, without having to spend
time examining those that are merely false positives.

401 Techniques for Influencing


Upstream Decisions
Jeff Feldstein
Influencing people who work for you should be easy.
Influencing people who don’t sometimes is not. Testers
often rely on edicts from marketing and development to

Register Early and Save: -1-415-785-3419 9


Technical Classes Thursday, April 2

505 Testing Live Apps


500 Series: 8:45 am – 9:45 am With Virtualization
Lars Ewe
501 The Hunt for Malicious Code
NEW Production applications are notoriously difficult to
Ryan Berg test because of the availability and integrity requirements
of live data. This session will evaluate new zero-impact
NEW Although some exploits are designed to announce
testing methods for live applications, leveraging virtual-
their success, most remain quiet until their day has
ization without adversely affecting the production appli-
come. Malicious code is hard to detect because it often
cation.
shows itself only as a small anomaly. Penetration testing,
static analysis and manual review must be combined to
profile the application, identify potential attack points, 506 The Marriage of Agile
and allow the organization to identify anomalous tech-
nologies lurking within your code. This talk will outline
And Test Management
and demonstrate how to effectively look for malicious Brian Massey
code in your applications.
NEW Agile is about short release cycles and just
enough documentation. Test management brings to
502 Tester Career Paths For mind monolithic test plans. One focuses on customer-
An Outsourced Economy driven unit and function testing, the other on the water-
fall; one on weekly iterations, the other on year-old
Michael Hackett requirements. Can the two coexist? Yes, they can. Learn
how agile and test management and planning can coex-
NEW What work should be recommended for outsourc-
“Knowledgeable ing, and which tasks are best kept in-house? What new
ist to create a tester utopia.
job skills are needed for the team to remain important?
and enthusiastic Should we learn project or automation management,
presenters; pleas- build and release engineering, unit testing or business
modeling? As companies seek to reduce costs, many
600 Series: 10:30 am – 11:30 am
look to outsource testing. Learn through real-world
ant atmosphere, examples the new role of a U.S.-based tester in current
601 Is Your Inversion Of Control
well organized development teams that use or plan to use outsourcing. Framework Secure?
Gain clear strategies to achieve those skills.
Ryan Berg
event; updated and
503 Strategies for Unit Testing in Unlike common application vulnerabilities such as cross-
innovative content.” site scripting or SQL injection attacks, vulnerabilities that
Spite of Legacy Code, Part 1 can occur through improper use of inversion-of-control
NENAD SMILJKOVIC, Bill Loeb frameworks such as Spring and Struts are actually
TEST & QA TEAM MANAGER, design issues that, if not implemented properly, make
SAGA D.O.O. BELGRADE NEW When attempting test-driven development, teams applications just as vulnerable. The right security aware-
face obstacles such as how to handle projects that were ness in the design and testing phase when using these
not designed to be unit tested and old components writ- frameworks can protect enterprises from exploitation
ten in different languages. Learn how to get software after deployment. Learn several types of these newly dis-
under test in spite of legacy code. Using Visual Studio, covered vulnerability classes and best practices for pre-
C#, NUnit and NMock, explore common hurdles when venting them.
introducing unit testing into an existing code base. Part 1
covers code organization, refactoring for unit testability,
and ways to wrap and isolate interactions. Part 2 covers
602 Test Automation Of
using mock objects to handle code dependencies, and Search Results and Other
how they differ from fakes and stubs. Data-driven Apps
Vitaly Bulgakov
504 Setting Agile-Centric Release
Criteria NEW Can testing and analysis of a search-results page
be automated? What is the right test-script architecture?
Bob Galen Learn to use QuickTest Pro and Perl as efficient instru-
ments to serve this purpose. Write tests that are reusable
NEW A huge quality-centered activity among agile
and that require no recording. Learn to program objects
teams is defining “doneness” as it relates to the end of an
for multiple use prior to application readiness, use regular
iteration or sprint. Most teams don’t focus on complex cri-
expressions for website analysis, deploy regression-test
teria, but rather look to deliver features or stories to a mini-
essentials for search engine testing, test advertiser
mal set of acceptance criteria or tests. Learn the four lev-
impressions on your website and in search results, and
els of doneness, see examples of each, and explore
much more.
patterns to exercise collaborative skills to influence teams
toward more-complete and more-valuable work.

10 Register Early and Save: www.stpcon.com


Thursday, April 2 Technical Classes
603 Strategies for Unit Testing in
Spite of Legacy Code, Part 2 700 Series: 1:00 pm – 2:00 pm
By Bill Loeb
701 Effective Training
(See 503)
Of an Offshore Test Team
604 Testing in an Agile Environment Michael Hackett

Robert Walsh Working with offshore teams is a fact of life, but many
still struggle to do it effectively. Training your offshore
Contrary to what some believe, the agile view of testing team is as critical to the success of your project as get-
is not “Don’t test” or “Only developers should test.” Agile ting the right information to and from these remote work-
augments traditional testing by professionals with tests ers. Learn through real-world examples the key elements
written and executed by developers and customers. TDD of successful offshore testing, including training in the “Excellent confer-
and unit testing; user acceptance; and exploratory, areas of process, product/domain knowledge and testing
usability, load and performance, and integration testing, techniques, and how training can be used as a retention ence — provided a
along with other techniques, play significant roles in agile tool for offshore staff.
environments. Learn how various testing efforts are used wide range of top-
in responsible approaches to agile development, and
explore ways that traditional QA efforts can be adapted 702 A Buzz About Fuzz: Finding ics for a variety of
to fit neatly agile processes. Software Vulnerabilities experience levels.
Joe Basirico
605 Managing Embedded Product It provided tools
Fuzzing feeds random inputs to applications in an
Testing attempt to choke them. It’s a simple, highly automatable and techniques
Jon Quigley and Kim Pries way to trap uncommon and unforeseen errors that may
have been overlooked. Learn how to include fuzz testing that I could apply
NEW Testing starts well in advance of the physical work. in your QA efforts, explore fuzz testing tools and tech-
Successful test creation and deployment mean planning niques, and discover how fuzzing provides insight into when I got back,
for testing early in the development effort. By the end of application behavior. Hear examples of how fuzz testing
the class, participants will know how to plan and execute has uncovered hard-to-find bugs and how it can provide as well as many
tests, report results, and record metrics. Learn how verifi- metrics on software correctness. After this class, you’ll
cation via reviews, simulation code, design inspections be able to apply fuzz testing immediately. additional sources
and test fixturing brings an objective set of eyes to the
results of the development team. We’ll also cover soft- of information.”
ware quality attributes, test planning, supporting sys- 703 The Business Value
tems, test statistics and alternatives to testing. Of Usability CAROL RUSCH,
SYSTEMS ANALYST,
Jeff Johnson
606 Experiences with Keyword ASSOCIATED BANK
NEW Learn, in business terms, why it is important for
Automation software development organizations to strive for highly
Hans Buwalda usable products. This class describes how investing in
usability can increase customer satisfaction, reduce the
NEW Keywords are now in the mainstream of test cost of sales and support, increase return on investment,
automation, but they are not a silver bullet. Hear a short decrease time-to-profitability and reduce business risk.
introduction of keyword automation, with an emphasis We will also cover how, when and how much to invest in
on Action Based Testing. Then delve into its pitfalls usability.
through actual project cases involving keyword automa-
tion implementation. This session revolves around the
sometimes reluctant, and often very funny, implementa- 704 End-to-End Performance
tion of this practice. The cases will show the lessons Process: From Requirements
learned—in some cases, quite painfully—and typical do’s
and don’ts.
To Production Monitoring
Alfred Wong
Performance test engineers often engage in projects only
during planning and execution of performance tests.
There are more ways they can contribute, such as by fix-
ing performance bugs or avoiding them in the first place.
Learn a process from requirements to production moni-
toring that focuses on performance each step of the way.
Enhance the performance role of your current process

Register Early and Save: -1-415-785-3419 11


Technical Classes Thursday, April 2

toward increasing tester contribution, forewarning of NOTE: This class builds on End-to-End Performance
possible challenges, and explaining how tools and tech- Process (704) but also may be taken separately.
niques can overcome them.
NOTE: See related class 801. 802 Performance Testing
Of Large Distributed Systems
705 Optimizing The Testing Effort Jon Quigley and Kim Pries
With Keyword-Driven Frameworks
NEW As with other kinds of software, large-scale dis-
Brian Massey tributed embedded systems have a basic tool set. Learn
a four-mode testing approach used at Volvo comprising
Time is always in short supply. Learn about automating
compliance testing, extreme scenario testing, combina-
reusable manual tests created early in a project by using
“This is a conference a keyword-driven framework. Take away that framework
torial testing and stochastic testing. Also covered will be
special handling of specifications, software attributes,
and learn how to integrate it with an automated func-
to help both testers tional testing tool.
interrupts, polling (when and why to use), walkthroughs,
inspections and simulation testing. Learn about testing
and developers as data buses, communication protocols, emergent system
706 Optimizing Web 2.0 Application phenomena and other system-related issues as well as
well as managers Performance effects of code modification on the system and the sub-
system.
and leads. There is Hon Wong

enough variety and NEW The Web has become a dynamic platform where 803 Designing with the Mind In Mind
users and agents work together, share ideas and add
Jeff Johnson
content for every- value across myriad interests. Examine the shortcomings
of today’s Web monitoring techniques. Learn a new, NEW If you’re a software designer, developer or tester
body.” holistic approach to managing the performance of Web who never took cognitive psychology in school, this
2.0 applications, and see how it is applicable to complex class is for you. There’s a psychological basis for UI
MICHAEL FARRUGIA, SOA and Web services technologies. design rules; they’re not simple recipes to be applied
SOFTWARE ENGINEER, mindlessly. To apply them effectively, you must determine
AIR MALTA
707 Five Common Mistakes When their applicability (and precedence) in specific situations.
It also requires balancing the trade-offs that arise when
Securing Web Applications design rules appear to contradict. By understanding the
Lars Ewe underlying psychology, designers enhance their ability to
interpret and apply the rules of good UI design.
Despite the published security practices of the OWASP
and WASC threat classifications, a number of mistakes
are still commonly made. This class explores five com-
804 Performance Engineering for
mon mistakes of securing Web applications and the Large Application Clusters
impact that these design flaws have on the overall secu-
Daniel Bartow
rity of an application. Issues such as client-side trust
relationships, failure to properly secure application redi- NEW When it comes to testing large n-tier applications,
rection mechanisms, and other design and configuration new teams are underequipped and can’t simulate the
elements can quickly undermine application security, expected number of users. The class covers perform-
even when diligent security practices are in place. ance concerns that are unique to large clusters, such as
network crosstalk and bandwidth utilization. Learn how
to conduct performance testing on applications with tens
to hundreds of instances running in production, plan for

800 Series: 2:15 pm – 3:15 pm anticipated user loads in the millions, identify perform-
ance objectives, scale out the right environment for test-
ing, and see the performance testing through to produc-
801 Performance Bugs And tion.
Investigation Strategies
805 Web Services/SOA Testing
Alfred Wong
Made Easy
NEW Performance bugs appear in many shapes and
forms, and each requires its own investigation strategy. Meera Subbarao
Learn about the different types of performance testing. NEW Learn how SoapUI can be used to write functional
Explore the performance bugs common to Web applica- tests by creating and executing test cases against your
tions and the corresponding performance tests that Web services. Includes a demonstration using Groovy
expose them. Discover how to participate actively in a scripts for assertions, properties setup and teardown for
performance bug investigation and how to apply the each test case. Also covers use of the tests in a continu-
strategies to projects. ous integration environment, with the Hudson Java

12 Register Early and Save: www.stpcon.com


Thursday, April 2 Technical Classes
servlet as an example of integration and execution of the organizations can use to operate visibly and transpar-
tests; breaking the build when tests fail; and generating ently. Learn how and why to issue a user manual for
reports. engaging testing services, implement a specific opera-
NOTE: A laptop is strongly recommended for this class.
tional workflow and maintain an open-door policy.

806 Testing in the Cold (And Ideas to 904 Test Destiny: The Psyche of a
Warm You Up) Professional Tester
Brian Massey
Hans Buwalda
NEW Let’s face it, software testers are different. As kids,
NEW “Testing in the cold” happens when a test project we wanted to break things—not to be destructive, but to
is not going your way. Commitment and cooperation are understand how things worked and use them in unin-
lacking, people might show resistance, you might be tended ways. We ask, “What if?” We push the big red
blamed for project failures, or the testing and automation button marked “Don’t push” because we want to know
work might prove more complicated than expected. As a what will happen. We’ve been testing from the begin-
tester or test manager, you can feel left out in the cold. ning—it’s our destiny. Learn how testers are perceived by
Learn more than 45 tips and techniques you can use to peer groups and how that knowledge can help you add
get yourself out of typical situations of testing in the cold. value to your organization. “Great information
from a variety of
905 Finding Vulnerabilities Without
experts in the field.
900 Series: 3:30 pm – 4:30 pm Attacking
they were able to
Rick McPhee
901 Tools and Techniques NEW Dynamic taint propagation allows testers to find provide tried and
For Fixing Memory Errors vulnerabilities without modifying existing functional tests.
It enables security testing inside a QA organization true current infor-
Chris Gottbrath because it allows tight integration with existing QA infra-
NEW An application on the server needs to be restarted
structure and solid usability for security nonexperts. This mation which was
talk will explain how dynamic taint propagation works,
every few days or it slows to a crawl. Is it a memory easy to adapt to
show how to retrofit an existing executable to perform
leak? Do you even know how to find out? Learn how in
dynamic taint propagation, and demonstrate how a
this class, and help developers stop writing leaky code. our environment.”
tester can use a typical suite of functional tests to find
Finding memory leaks is an acquired skill that requires
vulnerabilities without the need for malicious input or
constant vigilance to remain effective. And there is a
security expertise. KAREN KREYLING,
wrong way. Learn the right way, and keep memory errors
AVP SOFTWARE PRODUCT
a distant memory.
MANAGER, SMS
906 Finding .NET Performance
902 GUI Bloopers: Avoiding Bottlenecks Using PerfMon
Common Design Mistakes Joy Nandi
Jeff Johnson NEW We’ve all heard of Microsoft’s Performance Moni-
tor, but does anyone actually use it? Learn how this
Will your application pass the test, or will users be
powerful, free tool can identify performance bottlenecks
gnashing their teeth and shaking their fists? Attend this
in .NET applications by watching six critical areas of per-
session and discover all the blunders that might be in
formance. Learn the significance of each performance
your interface. Based on the book “GUI Bloopers 2.0”
counter and how they can be used to identify critical per-
and presented by its author, this talk is not just about
formance thresholds.
making apps pretty. Bring your sense of humor; this talk
is sprinkled with humorous screen images illustrating NOTE: A working knowledge of Microsoft .NET Frame-
common problems and their solutions. It will leave you work, networking, IIS 2.0 and operating system concepts
better able to critically review apps you develop or test. is recommended.

903 Testing Visibly


David Kapfhammer
One of the worst things a testing organization can do is
to operate in obscurity from the rest of IT. If the testing
organization doesn’t treat developers, business analysts
and users like customers, they’ll lose credibility as the
“team that operates behind the curtain,” and ultimately
become ineffective. Learn a strategic road map that test

Register Early and Save: -1-415-785-3419 13


Faculty
Paul Anderson is VP of engi- oversaw AMD’s systems manageability and related mated unit and acceptance testing, Bill has helped
neering at GrammaTech. A software security strategy and engineering efforts. introduce agile and XP practices to many develop-

O industry veteran, he has worked with ment teams.


Jeff Feldstein manages a team
NASA, the FDA, FAA, MITRE, Draper of 40 testers for Cisco Systems. During David Kapfhammer is prac-

O
Laboratory, GE, Lockheed Martin and his career, he has been a software tice director for the Quality Assurance

O
Boeing to apply automated code analy- developer, tester, development man- and Testing Solutions organization at
sis to critical projects. His experience includes static ager, and computer consultant. His Keane. He is experienced in all aspects
analysis and automated testing and program trans- specialties include internetworking, of systems design and implementation
formation, and his research on static analysis tools real-time embedded systems, communications sys- including organizational leadership,
and techniques has been widely published. tems, hardware diagnostics and firmware, data- technical solution, quality mechanisms and enter-
Dan Bartow is the manager of bases and test technologies. prise architecture. He’s also a doctoral student at
performance engineering at Intuit. Pre- George Mason University.
Bob Galen is an agile methodolo-

O viously he was a senior performance


engineer for ATG, where he helped
deploy large-scale sites for American
Airlines, American Eagle Outfitters,
AT&T Wireless, Best Buy, Neiman Marcus and Sony
Online Entertainment.
O
gist, practitioner, coach, and president
and principal consultant of RGCG,
where he guides companies and teams
with adoption and organizational shifts
to Scrum and other agile methods. He
has held software development and quality assur- O
Brian Massey is a product
manager at IBM Rational, where his
role is to master the domains of func-
tional testing and test management. His
experience includes hardware and soft-
ware system architecture development
Joe Basiricohas is an applica- ance positions at Bayer, Böwe Bell & Howell, Chan- to analysis, design and deployment of network
tions security expert. At Security Inno- nelAdvisor, EMC, Lucent, Unisys, and Thomson. infrastructure, and coding and testing of software

O vation, he is responsible for delivering modules and component-based systems.


Chris Gottbrath is product
security courses to software teams in manager of TotalView Technologies, a Judy McKay is a high tech

O
need of application security expertise. debugging tool maker. Previously, Chris industry veteran. She has managed

O
He has trained developers and testers wrote cosmological simulations using C departments encompassing all aspects
from Microsoft, HP, EMC, Symantec, Liberty and MPI on a small-scale Beowulf clus- of the software life cycle, including
Mutual, Sony, State Farm, Credit Suisse, ter as a graduate student of astro- requirements design and analysis, soft-
Amazon.com, Adobe, ING and other world class physics at the University of Arizona. ware development, quality assurance,
organizations. testing, technical support, professional services,
Michael Hackett is a founding
Ryan Berg is a co-founder and partner of testing services company
configuration management, technical publications

O
lead security architect of Ounce Labs, and software licensing. Her career has spanned
LogiGear. His experience includes soft-

O which develops software vulnerability commercial software companies, aerospace, for-


ware engineering and testing of appli- eign-owned R&D, networking and various Internet
risk-management solutions. Previously, cations developed for deployment
he co-founded kernel-level security pio- companies.
across multiple platforms. He writes
neer Qiave Technologies (acquired by and teaches at LogiGear University and for the UC Rick McPhee is senior director
WatchGuard Technologies). Ryan also served as a Berkeley Extension, and is co-author of Testing of core analysis at security tool maker

O
senior software engineer at GTE Internetworking, Applications on the Web: Test Planning for Mobile Fortify. Previously he held vice presi-
where he led the architecture and implementation of and Internet-Based Systems. dent of engineering positions at data
new managed firewall services. encryption vendor Vormetric and
Mukesh Jain is quality manager
Vitaly Bulgakov joined Veri- for Microsoft Global Foundation Ser-
Sychron, a developer of virtual desktop

O
zon’s Superpages online directory – solutions. Rick holds a PhD in computer science
vices. He is a Six Sigma Black Belt,

O now Idearc – in 2006 to work on per- from the University of Oxford.


TSP coach, PSP instructor, SEI-certi-
formance and stress testing, search fied PSP developer and engineer, ISO Joy Nandi is an application pro-
analysis, data mining and test automa- 9000 internal auditor, CQA, CQIA, grammer at Progressive Insurance,

O
tion. He was a professor at Moscow CSQA, CSTE and Microsoft Office specialist and where he is responsible for perform-
State University of Civil Engineering, and has been has led companies through Six Sigma, ITIL, MOF, ance testing and engineering of .NET-
recognized by the Alexander von Humboldt Foun- TSP/PSP, ISO 9000 and SEI CMM Level 3-5 imple- based Web services and infrastructure
dation and the Norwegian Research Society. mentation and certification. capacity planning. He graduated from
Hans Buwalda leads Jeff Johnson is a respected Arizona State University with a dual MS in com-
LogiGear’s Action Based Testing (ABT) puter-aided-design and IT.
expert and consultant in the field of

O research and development. He is an


internationally recognized expert in
action-based test automation, test
development, and testing technology
management.
Nada daVeiga is product man-
O human-computer interaction, and
author of GUI Bloopers 2.0: Common
User Interface Design Don’ts and Dos.

Ian Knox has been in the software


development industry for more than 15
O
Kim Pries is director of product
integrity and reliability at Stoneridge
Electronics-North America, which man-
ufactures performance analysis sys-
tems for the automotive industry. He
holds master degrees from UTEP and

O
ager of Java solutions at Parasoft. Carnegie Mellon University and teaches the ASQ
years. He is director of product man-

O Nada’s background includes develop- Six Sigma Black Belt Certification class for UTEP
agement for Skytap. Previously, he was professional education. He is author of Six Sigma
ment of service-oriented architecture group product manager for Microsoft’s
for integration of rich media applica- for the Next Millennium: A CSSBB Guidebook.
Visual Studio, and principal consultant
tions such as Artesia Teams, IBM Con- at Pricewaterhouse-Coopers, where he worked on Jon Quigley is manager of Volvo
tent Manager, Stellent Content Server and Virage global software delivery projects for Fortune 500 Trucks 3P’s Electrical/Electronic Sys-

O
Video Logger. clients. tems and Verification group, where he
Lars Ewe is CTO and vice presi- Bill Loeb is an engineering man- creates system engineering specifica-
dent of engineering at Cenzic. His tions for the electrical and electronics
ager at SaaS company ChannelAdvisor,

O O
background includes Web application systems, and manages test and verifi-
which helps retailers maximize profits cation activities. He has secured four U.S. patents
development and security, middleware across multiple e-commerce channels.
infrastructure, software development, and has others pending, and is co-author of Project
He is also experienced in software Management of Complex and Embedded Systems:
and application/system manageability development and management for the
technologies. Previously, he was software develop- Ensuring Product Integrity and Program Quality.
airline and medical industries and with coding class
ment director at Advanced Micro Devices, where he libraries for developers, and is a champion of auto-

14 Register Early and Save: www.stpcon.com


Hotel & Travel
Bj Rollison is a test architect with March 31 – April 2, 2009
Microsoft’s Engineering Excellence

O group, where he designs and develops San Mateo Marriott


technical training curricula in method- San Mateo, CA
ologies and automation. Bj has more
than 16 years of computer industry
experience – mostly with Microsoft – including
Microsoft’s Internal Technical Training group and
test manager in Microsoft’s Internet Client and Con-
sumer Division.
San Mateo Marriott
Chris Sims is a teacher, coach,

O
San Francisco Airport
facilitator, consultant, coder, and agile
evangelist. He’s also founder of the 1770 South Amphlett Blvd.
Technical Management Institute, facili-
tator of the Bay Area Engineering Man-
San Mateo, CA 94402
agers Support Group, chair of the IEEE Phone: +1-650-653-6000
Technical Management Council of Silicon Valley, and
is on the board of the Bay Area chapter of the Agile Fax: +1-650-653-6088
Project Leadership Network.
Meera Subbarao is a senior Reservations
software consultant for Stelligent, where The Software Test & Performance Conference Spring has reserved a block of rooms

O she helps customers create production-


ready software using agile practices. A
17-year software programmer, she has
worked in Asia, the Middle East and
U.S., and is Sun-certified as a Java Programmer
and Web Component Developer.. She’s also team
leader for the Javalobby/dzone book review team,
for attendees at a special rate of US$179 per night. To receive the discounted rate,
call the hotel directly at the number above. Identify yourself as being with the Software
Test & Performance Conference. These rates are available with reservations beginning
on Saturday, March 28 (check-in) through Saturday, April 4 (check-out).

and has had several articles published. You can also use the hotel link on the STPCon website, www.stpcon.com.
Mary Sweeney has been devel- To make reservations through www.marriott.com/sfosa, use the code STPSTPA to
oping, using, and testing relational receive the STPCon rate.

O database systems for more than 20


years for such companies as Boeing
and Software Test Labs. She is a col-
lege professor, the author of Visual
Basic for Testers and A Tester’s Guide to .NET Pro-
gramming, and an MCP in SQL Server. Mary serves
on the board of the International Institute of Soft-
Reservations must be made by Thursday, March 5, 2009.

Hotel Highlights
wareTest. The San Mateo Marriott San Francisco Airport is the hotel of choice for travelers with
Robert Walsh is president and commitments in Silicon Valley and San Francisco. This 11-acre San Francisco airport
manager of application development at hotel combines the look and feel of a first-class San Francisco luxury resort with the

O EnvisionWare, which provides software


solutions for public and academic
libraries. He is an experienced program-
mer, mostly with C and C++. Robert
began applying agile methodologies to his company
several years ago, and has implemented a hybrid of
Scrum and Extreme Programming, and continues to
efficiency of Silicon Valley’s state-of-the-art technology and amenities.
Marriott’s ultra-adaptable room allows you to simply plug in and:
• Display your laptop on the TV
• Use split-screen technology to multitask
refine the process.
• Play your MP3 player through the TV’s speakers
Alfred Wong is the performance
test advisor at Expedia.com. He has • Connect your personal DVD player to the TV

O experience in software design and


development, test management,
resource planning and scheduling,
managing outsourced projects, guiding
performance certification processes, technical con-
sulting, performance tuning and capacity planning.
Alfred holds an MS in electrical engineering.
NEW FOR 2009! >> In-room high speed internet access is INCLUDED for all STPCON
attendees. The charge will be deducted from your hotel bill at check-out.

Centrally located to both San Jose and downtown San Francisco, the reinvented San
Hon Wong is CEO of Symphoniq. Mateo Marriott hotel is convenient for all travelers.
Previously, he co-founded NetIQ and • 10 minutes from San Francisco International Airport

O has also co-founded and served on the


boards of several other companies,
including Centrify, EcoSystems Soft-
ware (acquired by Compuware), Digital
Market (acquired by Oracle) and other technology
companies. He holds BS degrees in electrical engi-
neering and industrial engineering from Northwest-
• 100% nonsmoking hotel
• Less than one half-hour from San Jose International Airport
• Midway between San Francisco and the Silicon Valley high-tech business center

ern University and an MBA from the Wharton • Less than 30 minutes from the Golden Gate Bridge, Chinatown, Pier 39, Alcatraz,
School. Union Square, Fisherman’s Wharf and Half Moon Bay

Register Early and Save: -1-415-785-3419 15


Conference Tuition
All prices are in US$. Super Early Bird Early Bird Bird Rate Full Price
Register By: Jan 23 Feb 20 Mar 13 After Mar 13
Three-Day Full Event Passport $995 $1,095 $1,295 $1,595
Technical Conference & Tutorials
March 31 – April 2, 2009
Two-Day Technical Conference Only $895 $995 $1,195 $1,495
April 1 – 2, 2009
One-Day Tutorials Only — March 31, 2009 $695 $795 $995 $1,195

Exhibits Only — April 1 – 2, 2009 FREE FREE FREE $50

Three-Day Full Event Passport Two-Day Technical Conference One-Day Tutorials Only Exhibit Hall Only Registration
Registration Includes: Only Registration Includes: Registration Includes: Includes:
• Admission to tutorials and technical • Admission to technical classes • Admission to tutorials • Admission to Exhibit Hall
classes • Admission to keynote(s) • Admission to Lightning Talks and • Admission to Attendee Reception
• Admission to keynote(s) • Admission to Exhibit Hall and Hands-On Tool Showcase • Free WiFi in conference areas only
• Admission to Exhibit Hall and Attendee Reception • Conference materials: CD ROM of
Attendee Reception • Conference materials: CD ROM of all presentations available
• Admission to Lightning Talks and all presentations available • Free WiFi in all areas
Hands-On Tool Showcase • Continental breakfast, coffee • Continental breakfast, coffee
• Conference materials: CD ROM of breaks, and lunch where indicated breaks, and lunch where indicated
all presentations available • Free WiFi in all areas • Free WiFi in all areas
• Continental breakfast, coffee
breaks, and lunch where indicated
• Free WiFi in all areas Register Today: -1-415-785-3419 or www.stpcon.com
How to Register Register online at www.stpcon.com and use one
of the following payment methods: Special Discounts Use the discount codes below to save on your
registration fees. Codes cannot be combined.
Credit Card. You can use the secure online form to pay via credit card and get Group. Get an additional $100 off per person if you register 4 or more people
immediate confirmation of your classes. MasterCard, Visa and American from one company for the Full Event Passport. Use code GROUP in the discount
Express are accepted cards. You’ll receive a REGISTRATION RECORD and code field.
RECEIPT. Please print out these pages and bring them with you to the Confer-
Government. Federal, State and Local Government employees can receive an
ence. Present them at the Registration Desk to pick up your badge and any
additional $100 off the Full Event Passport. Enter code GOV in discount code
course materials.
field.
Check. Fill out the online registration form. Print out the REGISTRATION
Educational Institutions. Personnel employed by or attending educational
RECORD and RECEIPT and mail to Redwood Collaborative Media, 105 Maxess
institutions can get $100 off the Full Event Passport with discount code EDU.
Road, Suite 207, Melville, NY 11747 with your payment. Online registrations
that are mailed without payment will not be confirmed until payment is received. Alumni. Have you attended any of previous Software Test & Performance
Conferences? If so, you’re eligible for a $100 alumni discount on the Full Event
Purchase Order. If you register using a P.O., you will be invoiced immediately
Passport. Enter the code ALUMNI in the discount code field.
for the registration amount. Payment must be received before your registration
can be confirmed. User Groups. Contact Donna Esposito, desposito@stpcollaborative.com, to see
if your group is eligible for a discount.

Cancellation PolicyYou can receive a full refund, less a $50 registration fee, for cancellations made by February 24, 2009. Cancellations after this date are non
refundable. Send your cancellation in writing to registration@stpcollaborative.com. Registrations may be transferred to another person.
Questions: Contact Donna Esposito at desposito@stpcollaborative.com or +1-415-785-3419.

March31–
March 31 –April
April2, 2, 2009
2009
San
San Mateo
MateoMarriott
Marriott
San
San Mateo,CA
Mateo, CA
SPRING
Redwood Collaborative
Redwood Media
Collaborative Media
105 Maxess
MaxessRoad,
Road,Suite 207207
Suite
Melville, NY
Melville, NY11747
11747
www.stpcollaborative.com
www.stpcollaborative.com
1-631-393-6051
1-631-393-6051
SWAT TEST

P
question so that you can get an answer that will be useful.
Do not get too caught up in the tool itself or the paradigm ERFORMANCE QUICK REFERENCE
it imposes. Remember, the tool is simply a means to an
end. “A fool with a tool is still a fool,” as the saying goes. • Be a Technical Rosetta Stone
• Learn To Translate
Extract, Aggregate, and Visualize • Find One Hole and Dig Deep
When it comes to data, having too much can be just as bad
• Automation is Software Development!
as not having any. Performance testing, diagnosis and trou-
• Get to know the Architect
bleshooting can generate such massive amounts of data
that there is no way you will ever be able to review it all. • Admit When You Do Not Understand
This is where I rely on two of my best friends: Perl and • Perfect is the Opposite of Good
Excel. Perl allows me to quickly and flexibly process mas- • Tools are Just Tools
sive amounts of data. Using Perl to convert gigabytes of log • Extract, Aggregate, and Visualize
files into concise csv files then allows me to load it into • Understand Reliability vs. Validity
Excel and visualize it by graphing. It is often only when • Think Like a User
data is visualized that anomalies and important trends
• Get Agreement on Goals and Objectives
become apparent.
• Develop Process and Methodology
Perl and Excel are my tools of choice, but there are
innumerable other options. Whatever your preference, • Data is King
your tool box should allow you to deal with massive vol- • Learn From Production
umes of data. It should allow you to extract important • Performance with Manual Testing
information from myriad sources. It should allow you to
aggregate this information into concise, pertinent, and
structured forms. And it should enable you to visualize this ally use them. This distance is often caused by layers of
information such that you can identify trends, outliers, bureaucracy and management that are intended to sepa-
and differences. This will ensure that full value is derived rate product development from end-users. To be success-
from your Performance Testing activities. ful as a performance tester, you need to understand how
the system will really be used in the field. This will allow
Understand Reliability vs. Validity you to design tests effectively and efficiently.
In performance testing, reliability and validity are key con- Learning how to think like a user can be achieved in
cepts to understand. Reliability refers to the consistency of many ways. You can try to “eat your own dog food” and use
repeated measurements. A reliable test produces the same the system for something important to you. You can find
results each time. Validity refers to how well the test actu- ways to open channels to your users or to those that inter-
ally measures what it is intended to measure. A test might act with them. However you do it, get inside the minds of
reliably indicate that the system can handle five logins per your users so that you can design valid tests.
second, but that same test could also be invalid because
the same user account was used for all the tests. Get Agreement on Goals and Objectives
Both reliability and validity are important to producing Personally, I like to think of goals and objectives as two dif-
useful results. Reliability allows you to trust your results ferent things. I see goals as descriptions of the desired end
and to confidently draw conclusions from them (e.g. dif- state, which can be a bit fuzzy and can extend beyond the
ferences before and after a given change is applied). current scope of work. On the other hand, I see objectives
Validity ensures that your results, and the conclusions you as firm deliverables that define success and can be thought
draw, are truly applicable to the real world. of as steps towards a goal. Regardless of whether you share
While there are ways to improve both, reliability and this perspective, the main point is that it is important to
validity are a bit like position and momentum in know where you are going, how you plan to get there, and
Heisenberg’s Uncertainty Principle. At some point, how you will determine if you actually arrived at your des-
improving one will come at the cost of the other. This is tination. These things need to be nailed down in collabo-
simply a reality that must be dealt with, which is why it is ration with all stakeholders before you set out on your per-
important to understand these concepts, how they apply formance testing activities. It helps a great deal to illumi-
to your particular test, and how they relate to your goals. nate areas of ambiguity or unconscious disconnect
In the end, you will have to choose which is more between groups. And it makes sure that you know what
important for your particular end result. For example, you’re supposed to do and that your boss will be happy
for a broad benchmark that will be repeated regularly, with what you finish. Without clear goals and objectives,
reliability will be of the utmost performance. But for an performance testing can easily degenerate into a never
exploratory test aimed at reproducing a subtle concur- ending cycle of activity that yields nothing of value to the
rency issue, validity will be paramount. Understanding larger organization.
these and considering them explicitly will help you to
make better test-design decisions. Develop Process and Methodology
I am not a big fan of process for the sake of process or
Think Like a User strict methodologies which can sometimes be unnecessar-
It amazes me how much distance can grow between the ily constraining. However, process and methodology are
people who develop and test systems and those that actu- important for success and allow your and your practice to

FEBRUARY 2009 www.stpcollaborative.com • 11


SWAT TEST

learn from past experience. Clearly overestimation if the production data- done by different people, using differ-
defining the process and methodology base is actually measured in terabytes. ent test environments, and at different
will provide you with an easy way to com- Undersized or invalid data is one of times. Automation is invaluable, but it
municate with others at your company. the most common reasons why real creates a narrow, optimized, beaten
The process can be used to show your performance problems slip through path. Manual testing involves more valid
manager and other groups which activi- testing undetected breadth and variability. It also allows for
ties are necessary, enable estimation and subjective interpretation that is more
justify resource and time requests. And Learn From Production valuable than any metric.
the methodology continually captures Whenever possible, get involved with To this end, I encourage running per-
new best practices, helping you to get production systems or those who formance tests, calibrated such that the
better and better with time. It also administer them. It can be a tremen- system should handle it while manual
enables others to come up to speed dous boon to your efforts. Your testing testing is underway. This will tell you
quickly and to contribute without need- efforts will always be partial and com- quickly whether performance is really
ing the same level of experience that promises are inevitable. By analyzing sufficient or if manual testers cannot do
you have. real production systems, you can often their jobs. By analyzing the system in the
detect issues before they become prob- same way as you would performing a test
Data is King lems. The production system should in an isolated performance lab, you will
Time and again, I have seen the impor- also inform testing activity, from the identify performance issues that fell
tance of data in performance testing. design of test workloads to the makeup beyond the scope of your testing.
Data in your test system can generally be of test data. And the production system Doing this all the time is not neces-
broken down into two types that I call provides the ultimate feedback and vali- sarily feasible. But when implemented
active and background. Active data is dation of performance improvements. judiciously, combining automated and
what your test users actually use and inter- Building this into your process and manual tests helps you cast a much
act with (user accounts, documents, etc.). methodology allows you to close the wider net than would ever be possible
Background data is not actively used in loop and ensure that resources are with automation alone.
tests, but adds “weight” to the system. focused on the most effective means. This survival guide contains some of
Ensuring that both are valid is critical to the most important things I’ve learned
producing valid test results. Performance with Manual Testing about how to achieve success. I hope
For example, a test run against a 20 Performance, automated functional, that it provides some useful ideas and
megabyte database might yield excel- and manual functional testing are often guidance to help you survive in your
lent results. But it would be a dramatic completely separate efforts. They are own practice. ý

12 • Software Test & Performance FEBRUARY 2009


You’ll Be Amazed How Live Data Can Improve
The Effectiveness of Your Load Testing

By Ross Collard

he objective of performance testing Since we cannot test everything, knowing where to

T is to predict whether a system’s per-


formance and robustness will be acceptable in live
focus and what to avoid is vital.
Our problem (or opportunity) is how to decide
what subset(s) of live data are the most useful for
operation. Because the system is exercised in test testing performance. The most appropriate answer
mode, this prediction tends to have more credibility for you depends on your context. By framing the
than speculating without test runs. During the testing issues, this article lays the foundation to explore
we could use actual data, if available, and measure sys- the opportunities and challenges of live data in
tem performance. Presumably live data increases the performance testing. The idea is to improve your
reliability of prediction. We’d utilize a performance
Ross Collard is founder of Collard & Company, a Manhattan-
monitoring tool to capture live data, and a compati-
based consulting firm that specializes in software quality.
ble performance testing tool to replay it in a test lab.

FEBRUARY 2009 www.stpcollaborative.com • 13


performance testing through the used is a bellwether, we can claim a broad affecting functionality and performance.
smarter use of live data. representation. This assumes that other We also need to be responsible about
factors affecting performance, such as the privacy of real data. This means that
Overview of a Framework the resources available during the test the scope may need to include security
The term “framework” is vague, over- runs, are stable or at least comparable. controls, audits and testing.
used and not worth painstaking defini- With normal data, it may be difficult to
tion here. However, a good framework trigger performance anomalies (bugs). Categorizing Test Projects
organizes, simplifies, brings consistency This data needs to be enhanced for our Performance testing provides evidence
and helps us to work with a diversity of specific purposes, for example to see what to help judge whether a system’s live
complex situations. My favorite example happens when the system is overloaded. performance and robustness will be
is the periodic table of elements in Any model of the data needs in testing has acceptable. The testing exercises the
chemistry, which organizes the available to incorporate these extreme cases. system in a test lab before the system
knowledge about the elements so well Overheads in live data testing can be goes live. Within this broad description
that it led to successfully predicting the cumbersome and expensive. Consider a there is a wide variety of projects.
existence of several unknown elements. stream of transactions, where we expect Clustering test projects together based
The question is not whether to use each to access a database and match a on their similarities is useful, as approach-
live data in performance testing. If avail- previously stored record. With crafted es and solutions often can be shared. We
able, we will use it. Instead, the question test transactions, the size of the test data- can map projects in a multi-dimensional
is how to select live data intelligently for base could be modest, populated with space along axes that represent test objec-
testing, and understand the conse-
quences of our decisions. Since we can-
not test everything, knowing where to
focus and what to avoid is vital.
The follow-up question is not whether
to massage and enhance the live data, or
T YPES OF DATA
Just as Eskimos reportedly have many words for ice and snow, we need multiple terms to
clarify and adequately discuss ideas about data. The differences among these are not hair-
splitting:
to leave it pristine. Instead, the follow-up • Test data means data used in testing.
question is how to massage and enhance • Live data means data encountered in live operation.
this data intelligently, and understand • Captured data is a copied sample of transactions from live traffic workflows.
• Extracted data is a copied sample of stored records from databases and files.
the consequences doing so.
• Extracted data may be in loaded forms (e.g., in a test database ready for use),
and unloaded forms (e.g., data is ready for a database build effort).
What is Live Data? • Only live data that is captured or extracted can become test data.
Live data is any data that we can capture or • Expected, valid data means the manicured, legitimate data that we expect to encounter.
extract from ongoing live operations in • Real data or actual data is what we could feasibly encounter, regardless of whether it
the production environment. This defini- is considered legitimate, e.g., data extracted from a corrupted database.
tion encompasses a huge variety, ranging • Impossible data cannot occur.
• Atomic data is fundamental, and cannot be derived from other data.
from atomic data such as the time an event
• Derived data is not fundamental.
occurred, to data derived from the atomic, • First-order…
such as response time (the elapsed time • Higher-order...
between a related pair of events), to cap- • Metadata is data about data, e.g., metrics
tured copies of workflows and extracted • Derived data is not fundamental.
copies of stored databases, to metadata • First-order is derived directly from atomic only
• Higher-order is derived from atomic and lower-order...
such as software metrics. For more on data
For example:
types, see the nearby sidebar. • A live data example for a data item named Customer Name could be “Mister Peebles”.
The great benefit of using live data is • An expected, valid data example is, in accordance with the edit rules for this data item,
undeniable: it is reality-based, often “Mr. Peebles”. (An example of the edit rules: to be valid the Customer Name must be
with a seemingly haphazard, messy rich- an alphabetic character string, from two to fifteen characters, with at least one alpha
ness. The data variety, vagaries and jux- character, allowing embedded blanks, and delimited by quote marks, that we expect we
tapositions are difficult to replicate, could encounter.
• A real data or actual data example is the character string: “Mister?Peebles”.
even by the most canny tester.
• An impossible example, if we are working in an environment where data length over-
That great benefit is a limitation too. flows are considered impossible, is: ”Peebles is a !@#&$ real jerk and ugly too.”
Let’s say we run a volume of live data in Because these terms and their underlying concepts are similar enough to be confusing, at the
test mode to place demands on a system, risk of redundancy I will strive to be clear each time I use them. When the differences among
though we do not fully understand the them are immaterial, for simplicity I will refer to all as “test data” or “live data”.
implications of what this volume con-
tains. The system’s performance appears
acceptable. “Great”, we proclaim, “We just only enough records to match the tives and scope; live environment and
are making progress!” But what does this transactions one-on-one. With live trans- infrastructure; system under test (SUT)
test prove? Live data is always changing. actions, we need an up-to-date copy of maturity and track record.
With this test run, what evidence do we the full database since any record might Test objectives and scope: the per-
have that the results will be acceptable be needed to match an incoming trans- formance test objectives may include
with any other set of live data? action. Missing database records will assessing system responsiveness, through-
If we can make a case that the live data cause transactions to process differently, put, ability to handle peaks and surges,

14 • Software Test & Performance FEBRUARY 2009


LIVE DATA

resource utilization efficiency, identifying tests, the total coverage by a compact


bottlenecks, pre-production system tun- suite of scripted test cases is likely to be
ing, and the so-called “ilities:” (availability, low regardless of how we measure cov-
recoverability, dependability, scalability, erage. However, the coverage of impor-
testability, ability to handle surges, etc.) tant conditions is high because of the
External (vendor) use: many a vendor focusing. The cost of crafting and main-
has agreements with customers to use live taining individual test cases usually is
data from those customers in the vendor's high for each test case.
own testing. Limitations and controls over Fabricated or Synthetic Data is
external data use tend to be stringent. another alternative to using live data.
Overlap between external and internal This is done by pre-fabricating the test
data sets varies from little to extensive. data with a data generation tool. Unlike
Environment and infrastructure: scripted testing, where test data typical-
depending on the situation, we can test a ly is created or modified continuously as
single application system, such as a web Often the pertinent question is not needed during a test run, fabricated
site with dedicated infrastructure, or a which single source is best, but what data is usually generated at one time,
combination of systems that share mix of data from different sources— before the start of the test run.
resources (devices like servers and live and otherwise—is most appropri- GIGO (garbage-in, garbage-out) often
routers, networks and Internet gateways, ate. If we do not consider all major dominates the data generation: the tool
databases, etc.), and run concurrently. If potential sources of test cases and test output tends to be unfocused, or focused
we are primarily interested in one system data, our perspective (and thus the way for the wrong reasons. Unfamiliarity in
in the mix, the collective other demands we test) may be limited. using these tools, tool quirks, knowing the
on the shared resources can be com- Understanding the alternatives test context and data needs only superfi-
bined into so-called “background noise”. helps improve resource allocation deci- cially, and lack of imagination are com-
Infrastructure categories include web sions: testers benefit by dividing their mon. All can lead to unrecognized values
sites, client/server systems, communica- time appropriately among different test in the fabricated data that give false read-
tions networks, databases and database approaches. Though allocations can ings. And fabricated data often lacks the
servers, real-time embedded systems, and change as a test project progresses and richness of reality.
mainframe systems. we learn more, having a realistic sense In performance testing, the input
System under test (SUT) maturity of the alternatives early (at the project /output data to/from a software pro-
and track record: testing is needed not initiation) helps us plan and estimate. cedure only need to be accurate
just when a system is new and untried, What alternatives to live data are enough to exercise the same branches
but also when it has already been run- available? In my observation, most through the software source code as
ning acceptably in live operation but now testers utilize three main sources of per- the actual data.
has been changed. (An initial impact formance test data: To be most effective, test data
assessment (IIA) attempts to determine if • Live data (copies of captured work needs to be precise (e.g., with the
a change is trivial from a performance flows and sample extracts from data- same number of significant digits as in
perspective, so as to determine if the sys- bases). the actual data), so the computation
tem needs re-testing after the change, • Data generated by scripted (pro- time is the same as for actual data –
and if so where and how much. IIA is grammed) automated test cases. and then in a single-threaded process
beyond the scope of this article.) • Fabricated or synthetic data, creat- only if the computation is on a critical
Changes: even when the SUT is ed by test data generators. (zero slack) path. It is important that
unchanged, performance may be Each of the three has its own charac- the time to process the test data is the
affected by changes to its infrastructure, teristics, pros and cons, though in any same as live data, not that the comput-
its interactions with other systems, or given context the following generaliza- ed result be accurate and precise.
the workload it carries. tions may not hold.
Non-test objectives: performance Scripted Data is one alternative to Three Simple Questions
testers often undertake related non-test- using live data. It is gotten by devising While I have only begun to discuss
ing tasks like setting performance goals, test scenarios and then scripting or pro- nuances, the key questions are:
designing systems for performance, sys- gramming automated tests to support (1) What live data should we utilize?
tem tuning, monitoring on-going per- the scenarios. The test scripts, also (2) How do we capture and manip-
formance in live operation, and capacity called automated test cases, construct ulate this data?
forecasting. While they are not the main the data they need in order to execute. (3) How do we use it in testing?
focus of these articles, I will address these Compared to using captured and An appropriate framework facili-
ancillary topics as appropriate. extracted copies of live data, scripted test tates addressing these questions. In
cases tend to be more effective because this article I have identified the perti-
Sources of Test Data each is focused, aimed at confirming a nent attributes of that framework. ý
Selecting the best data type and source particular behavior or uncovering a par-
for a performance test requires aware- ticular problem. But they work only if we AUTHOR’S NOTE
ness of the available alternatives and know what we are looking for. I want to acknowledge and thank the many people
who have influenced my thinking, specifically those
trade-offs, and the definition of “best” Compared to a high-volume appro- who attended WOPR conferences. A version of this
can be highly context-dependent. ach using an undifferentiated deluge of article series will be presented at WOPR 12.

FEBRUARY 2009 www.stpcollaborative.com • 15


Best Practices

Getting the Build Right


Means Playing by the Rules
In an Iowa cornfield, if you application lifecycle. We a developer to reconfigure after a build
build it, he will come, says go into accounts and se breaks, but where the process falls down
the old movie line. Software scripts hacked together is in their neglect to track what they did.
development is different. If under cover of darkness. “It’s one of those shortcuts often taken to
you build it, you may not And the guy who wrote it meet to deadline,” he says. The failure is
know exactly what you’ve leaves company, it’s a prob- forgetting to communicate to people
built. And that’s not a good lem, because he was the downstream. “What happens is that you
thing. only one who knew what get a false positive, and sooner or later
Builds can go awry for was being built.” something is going to blow up.”
many reasons, too many At a major manufacturer Responsible for production applica-
makefiles, not enough of of handheld telecom de- tions, the IT operations people function
Joel Shore
them, too many cooks in vices, everyone knew that with rigorous controls. But by definition,
the kitchen, and the know-it-all who just moving to a continuous development development people need more flexibil-
can’t resist making that last tweak. “ model would lead to an increase of daily ity in their infrastructure. The challenge,
Jason van Zyl, the creator of Maven, a builds, but no one was ready when the Zentgraf says, is in striking a balance
guy who knows a thing or two about number soared from just two a day to between the ops and development, bal-
build and release, says successful build hundreds. “They had to rethink how ancing flexibility with an appropriate
management requires both transparency they managed their code lines, version level of rigor to attain a consistent envi-
and control. “You have to make sure that naming, and communicating that,” says ronment. The process needs to be flexi-
developers don’t keep pockets of logic TechExcel’s Paul Unterberg. “If develop- ble enough to accommodate those doing
on their own machines,” a common ers are not following processes, they maintenance, as opposed to those doing
problem. “And you should be able to see could constantly be crashing builds forward-looking application develop-
everything that the project does by look- because they’re putting in fixes that ment. “The ability to understand and
ing in the checkout, so that there isn’t won’t compile.” A structure to ensure communicate that makes all the hand-
anything magical happening on a partic- that developers follow established stan- offs, all the bottlenecks that happen
ular developer’s machine or in a particu- dards (assuming they exist), code-review, between development and test, between
lar environment. Those are the sorts of or peer programming are ways he’s seen test and acceptance, and between accept-
things that can really limit the repro- of mitigating these risks. ance and production, so everybody
ducibility of a build.” But that structure is valid only inso- knows what you got through that process
Another issue van Zyl sees too often is far as everyone plays by the rules. is what you expected.”
the relegation of build-and-release engi- When a client claimed that builds were The bottom line is maintaining con-
neering to second-class status. Without being made in exactly three different trol and evolving the infrastructure as
an overseer, these systems usually are ways, a Coverity analysis turned up 27. needs change. “The amount of time
bounced among developers uninterest- “With everyone doing it differently, that development shops lose in pro-
ed in infrastructure work, often resulting there’s not only the likelihood of failed ductivity because of poor process or
in a “rag-tag tapestry of tools.” In a envi- builds, but of risking security expo- poor automation can’t be ignored,”
ronment where a Perl frond-end script sures,” says Schultz. “And this is how a says Zentgraf. “The solution is a con-
starts a Java program that generates an tweaked makefile winds up linking tinuous diligent improvement to your
Ant build file that eventually gets execut- something from Joe’s desktop into that process, no different than a corpora-
ed, “It’s impossible to follow anything final production build.” tion moving its manufacturing opera-
that goes wrong and you can go for days
The same applies to software. ý
Just who gets their hands on manag- tion to an agile just-in-time model.”
without producing anything useable,” ing builds and the toolsets being used
van Zyl says. And it’s everywhere. are additional areas that deserve close
Coverity’s Tom Schultz echoes van scrutiny. According to IBM Rational’s Joel Shore is a 20-year industry veteran and
has authored numerous books on personal com-
Zyl nearly word for word: “The No. 1 Daniel Zentgraf, it’s often a matter of too
puting. He owns and operates Reference Guide,
thing that gets companies into trouble many cooks in the kitchen – in this case a technical product reviewing and documenta-
are people who do not consider build with access to root accounts on build or tion consultancy in Southboro, Mass.
and release a first-class citizen of their test machines. Of course, it’s routine for

16 • Software Test & Performance FEBRUARY 2009


Homegrown build and test systems
getting in your way?

Spend less time and money managing scripts, tools, and servers—and more time
producing great software.
Build, test, and deploy. It sounds so simple. While a homegrown approach may have worked in the past, these
systems have grown over time into a giant ball of scripts, redundant work, and costly, manual maintenance tasks.

We solve that. ElectricCommander® automates and accelerates the software build-test-deploy process that
follows the creation of new code.

(OHFWULF&RPPDQGHUUHPRYHVDVLJQL¿FDQWERWWOHQHFNWRVRIWZDUHGHYHORSPHQWHQDEOLQJFRQWLQXRXVLQWHJUDWLRQ
SUHÀLJKWEXLOGVDQGWHVWVIDVWHUF\FOHWLPHDQGEHWWHUVRIWZDUHTXDOLW\ <RX¶OOVDYHWLPHDQGPRQH\DQGIUHH
your teams to focus on producing great software.

Visit www.electric-cloud.com to learn more.

© 2009 Electric Cloud, Inc. All rights reserved. Electric Cloud and ElectricCommander are trademarks of Electric Cloud, Inc.
ST&Pedia
Translating the jargon of testing into plain English

It’s SOA, Not SOL


An enterprise may have the enterprise and trans- WSDLs are designed to be machine-read-
dozens or hundreds of fers information among able. To a certain extent having WSDLs
business processes. each applications according to helps eliminate the issues involved in
with potentially dozens or those rules. Microsoft altering existing APIs, since clients can
hundreds of inputs and BizTalk Server is an exam- discover in real time the actual capabil-
outputs. Those inputs and ple of a service broker. ities of each service.
outputs take place over spe-
cific protocols: FTP, HTTP, Matt Heusser and ENTERPRISE XML
message queue (MQSeries, Chris McMahon APPLICATION The Extensible Markup Language has the
MSMQ), SQL, SOAP, REST, INTEGRATION (EAI) same roots as HTML, but is designed to
CORBA, filesystem, UI. Each of those Commonly thought of as a synonym for describe information in terms of its con-
protocols has a specific format: XML, SOA. Generally, SOA indicates the consis- tent, not its format. SOAP relies on XML,
JSON, HTML, TLV, ASN.1. Lots of tent use of a specific protocol (see SOAP as do many other SOA information
chances for being SOL. and REST, below) exchange schemes.
Automating business processes where EAI simply
increases efficiency, but because of the implies a consistent JSON (JAY-sun)
level of complexity involved, maintain-
ing each individual connection between
applications is too expensive. We can
tame this complexity if each individual
integration model for
an organization without
the benefit of industry-
wide standards.
• JavaScript Object Nota-
tion is popular in
RESTful SOA schemes,
and provides a tag=>val-
application supplies output in a stan- Like SOA, EAI ue approach to mes-
dard, pluggable way, instead of each SOAP sage data, as opposed
relationship being customized. We call An XML-based stan- implies a consistent to XML, which de-
such outputs "ser vices," and we have dard for communicat- scribes a hierarchy of
come to describe a collection of such ing information across integration model content with tags.
applications a "Ser vice Oriented a network. Formerly
Architecture," or SOA. There are a host defined as "Simple for an organization, ESB
of terms and abbreviations that come Object Access Proto- Enterprise Service Bus.
to mind when we think of SOA; this col," SOAP today is but without the See "Service Bus".
month we'll define a few of them. not an acronym and is
built into so many benefit of POINT-TO-POINT
SERVICE BUS tools as to be trans- (integration)
A notification architecture. Instead of parent. industry-wide The opposite of SOA;
communicating directly with multiple each application is
possible clients, a component will send REST (or ReST) standards wired directly to other
a notice (like billable hours) to a com- Representational State applications using
ponent called the service bus. The serv- Transfer. A RESTful unique connection
ice bus then notifies all the other com-
ponents in a standard way; the other com-
ponents can choose to take action or not.
Although the term "bus" comes from
approach to SOA
allows clients to spec-
ify that certain appli-
cations be in certain
• schemes. For example:
"On the first Monday
of the month, the
time-card system runs
electronics, think of a city bus, where any- states. The applica- a job to create a file
one can get on at any stop, and then get tions reply to the clients either with a sim- that we copy over to the HR system. The
off to accomplish some sort of business. ple acknowledgment or an error. HR system administrator does a (F)ile-
TIBCO was an early implementer of the >(O)pen and inputs hours, the clicks to
service bus. WSDL (WIZ-duhl) create a check run." ý
Web Services Description Language is a
SERVICE BROKER publicly available description of the capa- Matt Heusser and Chris McMahon are career soft-
An SOA architecture where each appli- bilities of the Web services of particular ware developers, testers and bloggers.They’re col-
cation sends output in its own format applications. Thus ser vices (and pro- leagues at Socialtext, where they perform testing
to a central processor. The central grammers) can look up the "function sig- and quality assurance for the company’s Web-
based collaboration software.
processor knows the business rules for natures" of a service over the Internet.
18 • Software Test & Performance FEBRUARY 2009
Future
Future Test
Test

Ten Steps To
tion, submitting data then trying to navi-
gate back to previous page to reenter dupli-
cate information, entering incorrect cred-
it card information, etc.
7. Tests should execute on various

Automated environments. In many instances, soft-


ware applications are installed on vari-
ous environments and each instance will
need tested. The scripts must be flexi-

Validation ble to run on the various environments


such as alpha, beta and production.
There are several concepts that can be
used to create a script that will execute
on these environments such as:
Automated testing can help c. Edit Invoice a. Regular expressions should be used
ROI by providing reusable d. Delete Invoice when asserting specific data
test scripts, but those scripts e. Logout b. Differentiate the environments by pass-
must be designed in a certain 4. Scripts should cleanup ing a variable with the alpha, beta, or
manor to be maintainable the data created. It is impor- production URL at runtime
throughout the life of a proj- tant to clear any data that was 8. Use configuration management. The
ect. Most think of automated created by the automated automated scripts are essentially develop-
testing record and playback. tests. This can cause problems ment files so basic configuration manage-
But that is just one small part for the development team ment practices must be applied to the
of automated testing. It’s the and the functional testers, process. The scripts should be in source
script writing that demands especially if they are verifying control software at all times. The test team
Matthew Hoffman
the greatest skill to gain the certain data in the system. If should develop a document that describes
most long term benefit. you are creating an invoice, then there the deployment of the scripts within a devel-
1. Your automated tester should have should be a script that deletes the invoice opment and production environment. The
some software development experience. from the database. It is also useful to enable document should also consist of script
This person must understand basic con- logging within the automated test tool to development standards so each person on
cepts of software development so he can verify that information was created then the team creates the scripts in the same
set variables, use regular expressions, cre- deleted. manor.
ate loops, extract header data, etc. 5. Be certain of your assertions. It is 9. Schedule regular test runs. It will be
2. Plan out your test scenarios. It is critical for the scripts to have several asser- beneficial if the automated tests ran on a
crucial to design the tests before record- tions throughout the script. The assertions regular basis to ensure the system is still
ing the scripts. Many testers will examine essentially are the driving factor to whether functioning correctly. The scheduler can
the functional specifications and design a test passes or fails. There should be sim- be setup to run when all users logged off
tests to cover the requirements. There are ple assertions like: the system so it might be a good idea to
several questions an automated tester must a. Validate that the page name is displayed schedule the tests in the early mornings.
ask when designing the scripts: for each request 10. Report and distribute results.
a. What areas of the application will be b. Validate the correct fields are displayed Results should be reported after the sched-
reused on each/several of the scripts c. Validate that a message is displayed for uled tests execute. The test results can be
(i.e., login and logout)? incorrect data sent to the development team so they can
b. Are there any variables that will be d. Validate the color of text (i.e., a required analyze the errors to see if there is an issue
reused on each/several of the scripts field might have red text) with the code. Many times the scripts might
(i.e., username, password, hostname, e. Validate enabled/disabled buttons (i.e., fail because of a network outage, change
and port number)? if a invoice is cannot be deleted for some to the system, or a script error. The auto-
3. Organize your tests. The test scripts reason, the delete button might be dis- mated test developer must determine what
must be organized with modularization in abled) kind of error(s) are in the reports and com-
mind. The scripts should be structured to f. Validate confirmation messages municate it with the team.
parallel the flow of the functional areas Follow each of these steps for success-
ful automated test deployment. ý
6. Scripts should test for negative sce-
of an application. For example, if your narios. The purpose of any type of test-
script is testing an invoicing system, the ing is to break the system before the cus-
script might be organized with the follow- tomer breaks it. The automated scripts Matthew Hoffman is manager of systems ver-
ing sections: should try scenarios that can break the sys- ification and validation at Concurrent
a. Login tem such as entering bad data into form Technologies, a nonprofit research and devel-
opment services organization.
b. Create Invoice fields, entering incorrect login informa-

FEBRUARY 2009 www.stpcollaborative.com • 19


7 B J ; H D 7 J ? L ; J > ? D A ? D = 7 8 E K J 7 F F B ? 9 7 J ? E D B ? < ; 9 O 9 B ; C 7 D 7 = ; C ; D J0

9ecfkj[hi:edÉj Hkd Oekh7ffi$


F[efb[:e$
7bj[hdWj_l[ j^_da_d] _i beea_d] X[oedZ j^[ Z[l[befc[dj YoYb[ WdZ
\eYki_d]edYkijec[hiWj_i\WYj_ed$8[YWki[j^[h[WbWffb_YWj_ed
b_\[YoYb[_dlebl[ih[Wbf[efb[ÄWdZj^[Ykijec[hÉif[hY[fj_ed_i
Wbbj^WjcWjj[hi_dj^[[dZ$

>F^[bfioeki[[j^[X_]f_Yjkh[WdZcWdW][j^[Wffb_YWj_ed
b_\[YoYb[$<hecj^[cec[dj_jijWhjiÄ\hecWXki_d[ii]eWb"je
h[gk_h[c[dji"jeZ[l[befc[djWdZgkWb_jocWdW][c[djÄ
WdZ^[h[_ij^[Z_\\[h[dY[ÄWbbj^[mWoj^hek]^jeef[hWj_edi
m^[h[j^[Wffb_YWj_edjekY^[ioekhYkijec[hi$

>F7BCe\\[h_d]i^[bfoek[dikh[j^WjoekhWffb_YWj_edidej
edbo\kdYj_edfhef[hbo"Xkjf[h\ehckdZ[h^[WlobeWZWdZWh[
i[Ykh[\hec^WYa[hi$9WdÉjoek`kij^[WhoekhYkijec[hiY^[[hdem5

J[Y^debe]o \eh X[jj[h Xki_d[ii ekjYec[i$ ^f$Yec%]e%Wbc


ž(&&.>[mb[jj#FWYaWhZ:[l[befc[dj9ecfWdo"B$F$

You might also like