2016-02-27 05:33:56 +08:00
|
|
|
//===- FuzzerTracePC.cpp - PC tracing--------------------------------------===//
|
|
|
|
//
|
|
|
|
// The LLVM Compiler Infrastructure
|
|
|
|
//
|
|
|
|
// This file is distributed under the University of Illinois Open Source
|
|
|
|
// License. See LICENSE.TXT for details.
|
|
|
|
//
|
|
|
|
//===----------------------------------------------------------------------===//
|
|
|
|
// Trace PCs.
|
|
|
|
// This module implements __sanitizer_cov_trace_pc, a callback required
|
|
|
|
// for -fsanitize-coverage=trace-pc instrumentation.
|
|
|
|
//
|
|
|
|
//===----------------------------------------------------------------------===//
|
|
|
|
|
|
|
|
#include "FuzzerInternal.h"
|
|
|
|
|
|
|
|
namespace fuzzer {
|
2016-05-11 07:43:15 +08:00
|
|
|
|
2016-08-17 01:37:13 +08:00
|
|
|
static size_t PreviouslyComputedPCHash;
|
|
|
|
static ValueBitMap CurrentPCMap;
|
2016-05-11 07:43:15 +08:00
|
|
|
|
2016-08-17 01:37:13 +08:00
|
|
|
// Merges CurrentPCMap into M, returns the number of new bits.
|
|
|
|
size_t PCMapMergeFromCurrent(ValueBitMap &M) {
|
|
|
|
if (!PreviouslyComputedPCHash)
|
2016-05-11 07:43:15 +08:00
|
|
|
return 0;
|
2016-08-17 01:37:13 +08:00
|
|
|
PreviouslyComputedPCHash = 0;
|
|
|
|
return M.MergeFrom(CurrentPCMap);
|
2016-02-27 05:33:56 +08:00
|
|
|
}
|
|
|
|
|
2016-02-27 09:50:16 +08:00
|
|
|
static void HandlePC(uint32_t PC) {
|
2016-02-27 05:33:56 +08:00
|
|
|
// We take 12 bits of PC and mix it with the previous PCs.
|
2016-08-17 01:37:13 +08:00
|
|
|
uintptr_t Next = (PreviouslyComputedPCHash << 5) ^ (PC & 4095);
|
|
|
|
CurrentPCMap.AddValue(Next);
|
|
|
|
PreviouslyComputedPCHash = Next;
|
2016-02-27 05:33:56 +08:00
|
|
|
}
|
|
|
|
|
|
|
|
} // namespace fuzzer
|
|
|
|
|
2016-06-07 04:27:09 +08:00
|
|
|
extern "C" {
|
|
|
|
void __sanitizer_cov_trace_pc() {
|
2016-02-27 09:50:16 +08:00
|
|
|
fuzzer::HandlePC(static_cast<uint32_t>(
|
|
|
|
reinterpret_cast<uintptr_t>(__builtin_return_address(0))));
|
2016-02-27 05:33:56 +08:00
|
|
|
}
|
2016-06-07 04:27:09 +08:00
|
|
|
|
|
|
|
void __sanitizer_cov_trace_pc_indir(int *) {
|
|
|
|
// Stub to allow linking with code built with
|
|
|
|
// -fsanitize=indirect-calls,trace-pc.
|
|
|
|
// This isn't used currently.
|
|
|
|
}
|
|
|
|
}
|