blob: b6f29957c4db8a43d65891f7a84b224359bef9d5 (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
|
//===- FuzzerTracePC.cpp - PC tracing--------------------------------------===//
//
// The LLVM Compiler Infrastructure
//
// This file is distributed under the University of Illinois Open Source
// License. See LICENSE.TXT for details.
//
//===----------------------------------------------------------------------===//
// Trace PCs.
// This module implements __sanitizer_cov_trace_pc, a callback required
// for -fsanitize-coverage=trace-pc instrumentation.
//
// Experimental and not yet tuned for performance.
//===----------------------------------------------------------------------===//
#include "FuzzerInternal.h"
namespace fuzzer {
static const size_t kMapSize = 65371; // Prime.
static uint8_t CurMap[kMapSize];
static uint8_t CombinedMap[kMapSize];
static size_t CombinedMapSize;
static thread_local uintptr_t Prev;
void PcMapResetCurrent() {
if (Prev) {
Prev = 0;
memset(CurMap, 0, sizeof(CurMap));
}
}
// TODO: speed this up.
void PcMapMergeCurrentToCombined() {
if (!Prev) return;
uintptr_t Res = 0;
for (size_t i = 0; i < kMapSize; i++) {
uint8_t p = (CombinedMap[i] |= CurMap[i]);
CurMap[i] = 0;
Res += p != 0;
}
CombinedMapSize = Res;
}
size_t PcMapCombinedSize() { return CombinedMapSize; }
static void HandlePC(uintptr_t PC) {
// We take 12 bits of PC and mix it with the previous PCs.
uintptr_t Idx = (Prev << 5) ^ (PC & 4095);
CurMap[Idx % kMapSize] = 1;
Prev = Idx;
}
} // namespace fuzzer
extern "C" void __sanitizer_cov_trace_pc() {
fuzzer::HandlePC(reinterpret_cast<uintptr_t>(__builtin_return_address(0)));
}
//uintptr_t __sanitizer_get_total_unique_coverage() { return 0; }
//uintptr_t __sanitizer_get_number_of_counters() { return 0; }
|