diff options
author | Kostya Serebryany <kcc@google.com> | 2017-07-20 00:37:08 +0000 |
---|---|---|
committer | Kostya Serebryany <kcc@google.com> | 2017-07-20 00:37:08 +0000 |
commit | 15cc3713d359ed7dd7d40bf85b444531401feacd (patch) | |
tree | 136a318f9a4d72100a52a2376e8847b7e0fbea8b /llvm | |
parent | d00e47fd711239c6cd2ba5330cab8c075334d9e2 (diff) | |
download | bcm5719-llvm-15cc3713d359ed7dd7d40bf85b444531401feacd.tar.gz bcm5719-llvm-15cc3713d359ed7dd7d40bf85b444531401feacd.zip |
[libFuzzer] add DeepRecursionTest, inspired by https://guidovranken.wordpress.com/2017/07/08/libfuzzer-gv-new-techniques-for-dramatically-faster-fuzzing/ (Stack-depth-guided fuzzing). libFuzzer does not solve it yet.
llvm-svn: 308571
Diffstat (limited to 'llvm')
-rw-r--r-- | llvm/lib/Fuzzer/test/CMakeLists.txt | 1 | ||||
-rw-r--r-- | llvm/lib/Fuzzer/test/DeepRecursionTest.cpp | 25 |
2 files changed, 26 insertions, 0 deletions
diff --git a/llvm/lib/Fuzzer/test/CMakeLists.txt b/llvm/lib/Fuzzer/test/CMakeLists.txt index 28de8dc725d..99ca926a51e 100644 --- a/llvm/lib/Fuzzer/test/CMakeLists.txt +++ b/llvm/lib/Fuzzer/test/CMakeLists.txt @@ -86,6 +86,7 @@ set(Tests CustomCrossOverTest CustomMutatorTest CxxStringEqTest + DeepRecursionTest DivTest EmptyTest EquivalenceATest diff --git a/llvm/lib/Fuzzer/test/DeepRecursionTest.cpp b/llvm/lib/Fuzzer/test/DeepRecursionTest.cpp new file mode 100644 index 00000000000..39a1602d7ac --- /dev/null +++ b/llvm/lib/Fuzzer/test/DeepRecursionTest.cpp @@ -0,0 +1,25 @@ +// This file is distributed under the University of Illinois Open Source +// License. See LICENSE.TXT for details. + +// Simple test for a fuzzer. The fuzzer must find the deep recursion. +// To generate a crashy input: +// for((i=0;i<100;i++)); do echo -n ABCDEFGHIJKLMNOPQRSTUVWXYZ >> INPUT; done +#include <cstddef> +#include <cstdint> +#include <cstdlib> + +static volatile int Sink; + +void Recursive(const uint8_t *Data, size_t Size, int Depth) { + if (Depth > 1000) abort(); + if (!Size) return; + if (*Data == ('A' + Depth % 26)) + Recursive(Data + 1, Size - 1, Depth + 1); + Sink++; +} + +extern "C" int LLVMFuzzerTestOneInput(const uint8_t *Data, size_t Size) { + Recursive(Data, Size, 0); + return 0; +} + |