diff options
author | Aaron Ballman <aaron@aaronballman.com> | 2015-01-29 16:58:29 +0000 |
---|---|---|
committer | Aaron Ballman <aaron@aaronballman.com> | 2015-01-29 16:58:29 +0000 |
commit | ef11698cac5effc0fb7735188ce667fa837d6f88 (patch) | |
tree | 6b0a1d784599a4253f0b5b54bbafd13920e87d8f /llvm/lib/Fuzzer/FuzzerMutate.cpp | |
parent | 860210bc49555ec7163fb2d3bb3601ea956bbada (diff) | |
download | bcm5719-llvm-ef11698cac5effc0fb7735188ce667fa837d6f88.tar.gz bcm5719-llvm-ef11698cac5effc0fb7735188ce667fa837d6f88.zip |
Reverting r227452, which adds back the fuzzer library. Now excluding the fuzzer library based on LLVM_USE_SANITIZE_COVERAGE being set or unset.
llvm-svn: 227464
Diffstat (limited to 'llvm/lib/Fuzzer/FuzzerMutate.cpp')
-rw-r--r-- | llvm/lib/Fuzzer/FuzzerMutate.cpp | 62 |
1 files changed, 62 insertions, 0 deletions
diff --git a/llvm/lib/Fuzzer/FuzzerMutate.cpp b/llvm/lib/Fuzzer/FuzzerMutate.cpp new file mode 100644 index 00000000000..2db8fac9bc6 --- /dev/null +++ b/llvm/lib/Fuzzer/FuzzerMutate.cpp @@ -0,0 +1,62 @@ +//===- FuzzerMutate.cpp - Mutate a test input -----------------------------===// +// +// The LLVM Compiler Infrastructure +// +// This file is distributed under the University of Illinois Open Source +// License. See LICENSE.TXT for details. +// +//===----------------------------------------------------------------------===// +// Mutate a test input. +//===----------------------------------------------------------------------===// + +#include "FuzzerInternal.h" + +namespace fuzzer { + +static char FlipRandomBit(char X) { + int Bit = rand() % 8; + char Mask = 1 << Bit; + char R; + if (X & (1 << Bit)) + R = X & ~Mask; + else + R = X | Mask; + assert(R != X); + return R; +} + +static char RandCh() { + if (rand() % 2) return rand(); + const char *Special = "!*'();:@&=+$,/?%#[]123ABCxyz-`~."; + return Special[rand() % (sizeof(Special) - 1)]; +} + +void Mutate(Unit *U, size_t MaxLen) { + assert(MaxLen > 0); + assert(U->size() <= MaxLen); + switch (rand() % 3) { + case 0: + if (U->size()) + U->erase(U->begin() + rand() % U->size()); + break; + case 1: + if (U->empty()) { + U->push_back(RandCh()); + } else if (U->size() < MaxLen) { + U->insert(U->begin() + rand() % U->size(), RandCh()); + } else { // At MaxLen. + uint8_t Ch = RandCh(); + size_t Idx = rand() % U->size(); + (*U)[Idx] = Ch; + } + break; + default: + if (!U->empty()) { + size_t idx = rand() % U->size(); + (*U)[idx] = FlipRandomBit((*U)[idx]); + } + break; + } +} + +} // namespace fuzzer |