Kostya Serebryany
|
ae5b9567bc
|
[libFuzzer] do mutations based on memcmp/strcmp interceptors under a separate flag (-use_memcmp, default=1)
llvm-svn: 257873
|
2016-01-15 06:24:05 +00:00 |
Kostya Serebryany
|
98abb2c90a
|
[libFuzzer] make CurrentUnit a POD object instead of vector to avoid extra allocations
llvm-svn: 257713
|
2016-01-13 23:46:01 +00:00 |
Kostya Serebryany
|
d50a3eedb4
|
[libFuzzer] make sure we find buffer overflow in the input buffer. Previously, re-using the same vector object was hiding buffer overflows (unless we used annotated vector)
llvm-svn: 257701
|
2016-01-13 23:02:30 +00:00 |
Kostya Serebryany
|
4b83a4f6fe
|
[libFuzzer] add a macro LLVM_FUZZER_DEFINES_SANITIZER_WEAK_HOOOKS
llvm-svn: 257482
|
2016-01-12 16:50:18 +00:00 |
Kostya Serebryany
|
4174005622
|
[libFuzzer] when a new unit is discovered using a dictionary, print all used dictionary entries
llvm-svn: 257435
|
2016-01-12 02:36:59 +00:00 |
Kostya Serebryany
|
859e86d962
|
[libFuzzer] add various debug prints. Also don't mutate based on a cmp trace like (a eq a) or (a neq a)
llvm-svn: 257434
|
2016-01-12 02:08:37 +00:00 |
Kostya Serebryany
|
e3580956ea
|
[libFuzzer] extend the weak memcmp/strcmp/strncmp interceptors to receive the result of the computations. With that, don't do any mutations if memcmp/etc returned 0
llvm-svn: 257423
|
2016-01-12 00:43:42 +00:00 |
Kostya Serebryany
|
1f9c40db1d
|
[libFuzzer] debug prints in tracing
llvm-svn: 257249
|
2016-01-09 03:46:08 +00:00 |
Kostya Serebryany
|
b65805a939
|
[libFuzzer] change the way trace-based mutations are applied. Instead of a custom code just rely on the automatically created dictionary
llvm-svn: 257248
|
2016-01-09 03:08:58 +00:00 |
Kostya Serebryany
|
c573316eee
|
[libFuzzer] don't limit memcmp tracing with 8 bytes
llvm-svn: 257245
|
2016-01-09 01:39:55 +00:00 |
Kostya Serebryany
|
e7583d21e3
|
[libFuzzer] refactor the way we collect cmp traces (don't use std::vector, don't limit with 8 bytes)
llvm-svn: 257239
|
2016-01-09 00:38:40 +00:00 |
Kostya Serebryany
|
226b734d73
|
[libFuzzer] make trace-based fuzzing not crash in presence of threads
llvm-svn: 256876
|
2016-01-06 00:03:35 +00:00 |
Kostya Serebryany
|
4d62322213
|
[libFuzzer] remove default initializer as a workaround for https://gcc.gnu.org/bugzilla/show_bug.cgi?id=68399. Don't need it anyway.
llvm-svn: 253419
|
2015-11-18 01:08:30 +00:00 |
Kostya Serebryany
|
3287d7a6ed
|
[libFuzzer] Marking exported symbols as visible. Patch by Mike Aizatsky
llvm-svn: 248954
|
2015-09-30 22:22:37 +00:00 |
Kostya Serebryany
|
65f50868e5
|
[libFuzzer] refactor the code to allow building libFuzzer on platforms that don't have dfsan and don't support weak functions
llvm-svn: 247321
|
2015-09-10 18:48:38 +00:00 |
Kostya Serebryany
|
4b82de2e47
|
[libFuzzer] remove a piece of stale code
llvm-svn: 247067
|
2015-09-08 20:40:10 +00:00 |
Kostya Serebryany
|
e641dd6479
|
[libFuzzer] more accurate logic for traces, 80-char fix
llvm-svn: 246888
|
2015-09-04 22:32:25 +00:00 |
Kostya Serebryany
|
12c7837381
|
[libFuzzer] add two flags, -tbm_depth and -tbm_width to control how the trace-based-mutations are applied
llvm-svn: 244712
|
2015-08-12 01:55:37 +00:00 |
Kostya Serebryany
|
d46369d8b3
|
[libFuzzer] avoid build warnings in non-assert build (useful warning in this case)
llvm-svn: 244177
|
2015-08-05 23:44:42 +00:00 |
Kostya Serebryany
|
4cc10d432a
|
[libFuzzer] in dfsan mode, set labels every time we start recording traces as opposed to doing it at process startup. This ensures that the labels are fresh.
llvm-svn: 244165
|
2015-08-05 23:02:57 +00:00 |
Kostya Serebryany
|
7f4227d59a
|
[libFuzzer] use data-flow feedback from strcmp
llvm-svn: 244084
|
2015-08-05 18:23:01 +00:00 |
Kostya Serebryany
|
8ce7424e9c
|
[libFuzzer] start refactoring the Mutator and adding tests to it
llvm-svn: 243817
|
2015-08-01 01:42:51 +00:00 |
Kostya Serebryany
|
fe7e41e8f5
|
[libFuzzer] make sure that 2-byte arguments of switch() are handled properly
llvm-svn: 243781
|
2015-07-31 20:58:55 +00:00 |
Kostya Serebryany
|
73932e5fe3
|
[libFuzzer] record traces from the switch statements only when told to do so
llvm-svn: 243768
|
2015-07-31 18:09:08 +00:00 |
Kostya Serebryany
|
cd6a4665e0
|
[libFuzzer] support switch interception in dfsan mode
llvm-svn: 243760
|
2015-07-31 17:05:05 +00:00 |
Kostya Serebryany
|
fb7d8d9d06
|
[libFuzzer] trace switch statements and apply mutations based on the expected case values
llvm-svn: 243726
|
2015-07-31 01:33:06 +00:00 |
Kostya Serebryany
|
c9dc96bfc6
|
[libFuzzer] fix the strncmp interceptor -- it should respect short strings.
llvm-svn: 243691
|
2015-07-30 21:22:22 +00:00 |
Kostya Serebryany
|
b74ba421fc
|
[libFuzzer] implement strncmp hook for data-flow-guided fuzzing (w/ and w/o dfsan), add a test
llvm-svn: 243611
|
2015-07-30 02:33:45 +00:00 |
Kostya Serebryany
|
0e776a2250
|
[libFuzzer] implement memcmp hook for data-flow-guided fuzzing (w/o dfsan), extend the memcmp fuzzer test
llvm-svn: 243603
|
2015-07-30 01:34:58 +00:00 |
Kostya Serebryany
|
ae7df1ca4d
|
[libFuzzer] ensure that the dfsan tracing hooks actually run (using -verbosity=3 in tests)
llvm-svn: 243365
|
2015-07-28 01:25:00 +00:00 |
Kostya Serebryany
|
35959592a3
|
[libFuzzer] when using cmp traces, first check that the CMP is evaluated to one value much more frequently than to the other value (heuristic)
llvm-svn: 243363
|
2015-07-28 00:59:53 +00:00 |
Kostya Serebryany
|
404c69f2c8
|
[libFuzzer] allow users to supply their own implementation of rand
llvm-svn: 243078
|
2015-07-24 01:06:40 +00:00 |
Kostya Serebryany
|
3fe7682fb0
|
[lib/Fuzzer] relax an assertion
llvm-svn: 238608
|
2015-05-29 20:31:17 +00:00 |
Kostya Serebryany
|
7c180eafc1
|
[lib/Fuzzer] fully get rid of std::cerr in libFuzzer
llvm-svn: 238081
|
2015-05-23 01:22:35 +00:00 |
Kostya Serebryany
|
20e9bcbfc8
|
[lib/Fuzzer] start getting rid of std::cerr. Sadly, these parts of C++ library used in libFuzzer badly interract with the same code used in the target function and also with dfsan. It's easier to just not use std::cerr than to defeat these issues.
llvm-svn: 238078
|
2015-05-23 01:07:46 +00:00 |
Kostya Serebryany
|
d8c54724a8
|
[lib/Fuzzer] remove the -dfsan=1 flag, just use -use_traces=1 (w/ or w/o dfsan)
llvm-svn: 237083
|
2015-05-12 01:58:34 +00:00 |
Kostya Serebryany
|
8817e86efd
|
[lib/Fuzzer] don't record traces when trace collection is off
llvm-svn: 237067
|
2015-05-11 23:25:28 +00:00 |
Kostya Serebryany
|
225262562f
|
[lib/Fuzzer] rename FuzzerDFSan.cpp to FuzzerTraceState.cpp; update comments. NFC expected
llvm-svn: 237050
|
2015-05-11 21:16:27 +00:00 |