aboutsummaryrefslogtreecommitdiff
path: root/llvm/lib/Fuzzer/test/RepeatedBytesTest.cpp
diff options
context:
space:
mode:
authorKostya Serebryany <kcc@google.com>2016-08-15 17:48:28 +0000
committerKostya Serebryany <kcc@google.com>2016-08-15 17:48:28 +0000
commitdfbe59b03db728a0cdfdf1bf763439a511c5ee09 (patch)
treeaaf9658c1515c4d6dce4df3c2adc4717e1c1820d /llvm/lib/Fuzzer/test/RepeatedBytesTest.cpp
parentd09a44a2201d49a5a8965156035b8b19d610e252 (diff)
downloadllvm-dfbe59b03db728a0cdfdf1bf763439a511c5ee09.zip
llvm-dfbe59b03db728a0cdfdf1bf763439a511c5ee09.tar.gz
llvm-dfbe59b03db728a0cdfdf1bf763439a511c5ee09.tar.bz2
[libFuzzer] add InsertRepeatedBytes and EraseBytes.
New mutation: InsertRepeatedBytes. Updated mutation: EraseByte => EraseBytes. This helps https://github.com/google/sanitizers/issues/710 where libFuzzer was not able to find a known bug. Now it finds it in minutes. Hopefully, the change is general enough to help other targets. llvm-svn: 278687
Diffstat (limited to 'llvm/lib/Fuzzer/test/RepeatedBytesTest.cpp')
-rw-r--r--llvm/lib/Fuzzer/test/RepeatedBytesTest.cpp29
1 files changed, 29 insertions, 0 deletions
diff --git a/llvm/lib/Fuzzer/test/RepeatedBytesTest.cpp b/llvm/lib/Fuzzer/test/RepeatedBytesTest.cpp
new file mode 100644
index 0000000..2fa6c78
--- /dev/null
+++ b/llvm/lib/Fuzzer/test/RepeatedBytesTest.cpp
@@ -0,0 +1,29 @@
+// This file is distributed under the University of Illinois Open Source
+// License. See LICENSE.TXT for details.
+
+// Simple test for a fuzzer. The fuzzer must find repeated bytes.
+#include <assert.h>
+#include <cstdint>
+#include <cstdlib>
+#include <cstddef>
+#include <iostream>
+
+extern "C" int LLVMFuzzerTestOneInput(const uint8_t *Data, size_t Size) {
+ assert(Data);
+ // Looking for AAAAAAAAAAAAAAAAAAAAAA or some such.
+ size_t CurA = 0, MaxA = 0;
+ for (size_t i = 0; i < Size; i++) {
+ // Make sure there are no conditionals in the loop so that
+ // coverage can't help the fuzzer.
+ int EQ = Data[i] == 'A';
+ CurA = EQ * (CurA + 1);
+ int GT = CurA > MaxA;
+ MaxA = GT * CurA + (!GT) * MaxA;
+ }
+ if (MaxA >= 20) {
+ std::cout << "BINGO; Found the target (Max: " << MaxA << "), exiting\n";
+ exit(0);
+ }
+ return 0;
+}
+