[compiler-rt] r353488 - [libFuzzer] add a test for built-in CrossOver (there are unit tests for this, but it's worth having a full integration test like this)

Kostya Serebryany via llvm-commits llvm-commits at lists.llvm.org
Thu Feb 7 16:41:30 PST 2019


Author: kcc
Date: Thu Feb  7 16:41:29 2019
New Revision: 353488

URL: http://llvm.org/viewvc/llvm-project?rev=353488&view=rev
Log:
[libFuzzer] add a test for built-in CrossOver (there are unit tests for this, but it's worth having a full integration test like this)

Added:
    compiler-rt/trunk/test/fuzzer/CrossOverTest.cpp
    compiler-rt/trunk/test/fuzzer/cross_over.test

Added: compiler-rt/trunk/test/fuzzer/CrossOverTest.cpp
URL: http://llvm.org/viewvc/llvm-project/compiler-rt/trunk/test/fuzzer/CrossOverTest.cpp?rev=353488&view=auto
==============================================================================
--- compiler-rt/trunk/test/fuzzer/CrossOverTest.cpp (added)
+++ compiler-rt/trunk/test/fuzzer/CrossOverTest.cpp Thu Feb  7 16:41:29 2019
@@ -0,0 +1,54 @@
+// Part of the LLVM Project, under the Apache License v2.0 with LLVM Exceptions.
+// See https://llvm.org/LICENSE.txt for license information.
+// SPDX-License-Identifier: Apache-2.0 WITH LLVM-exception
+
+// Test for a fuzzer. The fuzzer must find the string
+// ABCDEFGHIJ
+// We use it as a test for CrossOver functionality
+// by passing two inputs to it:
+// ABCDE00000
+// ZZZZZFGHIJ
+//
+#include <assert.h>
+#include <cstddef>
+#include <cstdint>
+#include <cstdlib>
+#include <iostream>
+#include <ostream>
+
+static volatile int Sink;
+static volatile int *NullPtr;
+
+// A modified jenkins_one_at_a_time_hash initialized by non-zero,
+// so that simple_hash(0) != 0. See also
+// https://en.wikipedia.org/wiki/Jenkins_hash_function
+static uint32_t simple_hash(const uint8_t *Data, size_t Size) {
+  uint32_t Hash = 0x12039854;
+  for (uint32_t i = 0; i < Size; i++) {
+    Hash += Data[i];
+    Hash += (Hash << 10);
+    Hash ^= (Hash >> 6);
+  }
+  Hash += (Hash << 3);
+  Hash ^= (Hash >> 11);
+  Hash += (Hash << 15);
+  return Hash;
+}
+
+// Don't leave the string in the binary, so that fuzzer don't cheat;
+// const char *ABC = "ABCDEFGHIJ";
+// static uint32_t ExpectedHash = simple_hash((const uint8_t *)ABC, 10);
+static const uint32_t ExpectedHash = 0xe1677acb;
+
+extern "C" int LLVMFuzzerTestOneInput(const uint8_t *Data, size_t Size) {
+  // fprintf(stderr, "ExpectedHash: %x\n", ExpectedHash);
+  if (Size != 10) return 0;
+  if (*Data == 'A')
+    Sink++;
+  if (*Data == 'Z')
+    Sink--;
+  if (ExpectedHash == simple_hash(Data, Size))
+    *NullPtr = 0;
+  return 0;
+}
+

Added: compiler-rt/trunk/test/fuzzer/cross_over.test
URL: http://llvm.org/viewvc/llvm-project/compiler-rt/trunk/test/fuzzer/cross_over.test?rev=353488&view=auto
==============================================================================
--- compiler-rt/trunk/test/fuzzer/cross_over.test (added)
+++ compiler-rt/trunk/test/fuzzer/cross_over.test Thu Feb  7 16:41:29 2019
@@ -0,0 +1,14 @@
+# Tests CrossOverTest.
+# We want to make sure that the test can find the input
+# ABCDEFGHIJ when given two other inputs in the seed corpus:
+# ABCDE00000 and
+# ZZZZZFGHIJ
+#
+RUN: %cpp_compiler %S/CrossOverTest.cpp -o %t-CrossOverTest
+
+RUN: rm -rf %t-corpus
+RUN: mkdir %t-corpus
+RUN: echo -n ABCDE00000 > %t-corpus/A
+RUN: echo -n ZZZZZFGHIJ > %t-corpus/B
+
+RUN: not %run %t-CrossOverTest -max_len=10 -seed=1 -runs=10000000 %t-corpus




More information about the llvm-commits mailing list