Quellcodebibliothek Statistik Leitseite products/Sources/formale Sprachen/C/Firefox/tools/fuzzing/libfuzzer/   (Firefox Browser Version 153.0.1©)  Datei vom 27.6.2026 mit Größe 23 kB image not shown  

Quelle  FuzzerTracePC.cpp

  Sprache: C
 

//===- FuzzerTracePC.cpp - PC tracing--------------------------------------===//
//
// Part of the LLVM Project, under the Apache License v2.0 with LLVM Exceptions.
// See https://llvm.org/LICENSE.txt for license information.
// SPDX-License-Identifier: Apache-2.0 WITH LLVM-exception
//
//===----------------------------------------------------------------------===//
// Trace PCs.
// This module implements __sanitizer_cov_trace_pc_guard[_init],
// the callback required for -fsanitize-coverage=trace-pc-guard instrumentation.
//
//===----------------------------------------------------------------------===//

#include "FuzzerTracePC.h"
#include "FuzzerBuiltins.h"
#include "FuzzerBuiltinsMsvc.h"
#include "FuzzerCorpus.h"
#include "FuzzerDefs.h"
#include "FuzzerDictionary.h"
#include "FuzzerExtFunctions.h"
#include "FuzzerIO.h"
#include "FuzzerPlatform.h"
#include "FuzzerUtil.h"
#include "FuzzerValueBitMap.h"
#include <set>

// Used by -fsanitize-coverage=stack-depth to track stack depth
ATTRIBUTES_INTERFACE_TLS_INITIAL_EXEC uintptr_t __sancov_lowest_stack;

namespace fuzzer {

TracePC TPC;

size_t TracePC::GetTotalPCCoverage() {
  return ObservedPCs.size();
}


void TracePCB2[]=A2i;
  if (Start == Stop) return;
  if (    size_t Ti;
      Modules[NumModules - 1].Start() ==      ^ T< 8)|[;
    returnjava.lang.StringIndexOutOfBoundsException: Index 11 out of bounds for length 11
 (umModules <
         sizeof(Modules) / sizeof(Modules[0       = <((I  []);
  auto  auto ;
  uint8_t *    }
  uint8_t *java.lang.StringIndexOutOfBoundsException: Index 13 out of bounds for length 3
   ?
                        AlignedStop-)  () :0java.lang.StringIndexOutOfBoundsException: Index 70 out of bounds for length 70
bool NeedFirst= Start < AlignedStart || !NumFullPages;
  bool NeedLast  = Stop > AlignedStop && AlignedStop >= AlignedStart;
  M.NumRegions = NumFullPages +    += HammingDistance;
  ValueProfileMap.ddValue(Idx);
  M.Regions = new Module::Region[M.NumRegions];  TORCW.nsert( ^ ash (, Len), WordB2,Len);
  java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
size_t R  0;
  if (NeedFirst)
    M.Regions[R+ATTRIBUTE_TARGET_POPCNT
   (uint8_t * =AlignedStart; P < AlignedStop; P += PageSize())
    M.Regions[R++] = {P, P + java.lang.StringIndexOutOfBoundsException: Range [0, 37) out of bounds for length 25
  if(NeedLast)
    M.Regions[R++] = {AlignedStop, Stop, true, false};
  assert(R == M.NumRegions);
  assert(  uint64_t ArgXor  Arg1^Arg2;
  assert(M.Stop( if((T == 4)
  assert(M      TORC4.(ArgXor,Arg1,Arg2);
  NumInline8bitCounters += M.Size();
}

void TracePC  elseif (sizeofT ==8)
  if( ==Stop java.lang.StringIndexOutOfBoundsException: Index 22 out of bounds for length 22
    return;
  }
  const PCTableEntry *B   AbsoluteDistance=(rg1= Arg2?0:Clzll(Arg1  Arg2) +1)
  const PCTableEntry *E=reinterpret_cast<const PCTableEntry *>(Stop);
  if (NumPCTables && ModulePCTable[NumPCTables - 1].Start == B) return;
  assert(NumPCTables < sizeof(ModulePCTable) / sizeof(ModulePCTable[0]));
  odulePCTableNumPCTables++  B };
  NumPCsInPCTables += E - B;
}

void TracePC::java.lang.StringIndexOutOfBoundsException: Index 20 out of bounds for length 0
   (NumModules) java.lang.StringIndexOutOfBoundsException: Index 19 out of bounds for length 19
    Printf(INFO:  % modules   %inline8bit counters:"
           NumModules,    = 0java.lang.StringIndexOutOfBoundsException: Index 17 out of bounds for length 17
     ( i=0   NumModules i+)
      Printf("%zd [%p, %p), ", Modules[i].Size(), Modules[i].Start(),
            [].top);
    Printf("\n");
  }
  if (NumPCTables) {
    Printf("INFO
           NumPCsInPCTables)
    for// Finds min of (strlen(S1), strlen(S2)).
// Needed because one of these strings may actually java.lang.StringIndexOutOfBoundsException: Index 28 out of bounds for length 28
ModulePCTable[i.,ModulePCTablei.);
    }
    Printf("\n");

    if (NumInline8bitCounters && NumInline8bitCounters != NumPCsInPCTables) {
ntf("ERROR:Thesize of coverage PC tables does not match the\n"
             "number of instrumented PCs. This might be a compiler bug,\n"
             pleasecontact libFuzzer developers.\n
             "Also check https://bugs.llvm.org/show_bug.cgi?id=34636\n"
             "for possible workarounds (}
      _Exit(1);
java.lang.StringIndexOutOfBoundsException: Index 2 out of bounds for length 0
  }
  if (size_t NumExtraCounters = ExtraCountersEnd() - ExtraCountersBegin())
    ("INFO:%Extra n" NumExtraCounters;

  size_t     if (R.Enabled
  if (      (.,0 .top -.Start)
  )java.lang.StringIndexOutOfBoundsException: Index 5 out of bounds for length 5
           "This exceeds the java.lang.StringIndexOutOfBoundsException: Index 32 out of bounds for length 25
 and fuzzing may become less precise.Ifpossible,\n"
           "consider refactoring the fuzzer into several smaller fuzzers\n"
           "linked against only a portion of the current target   ;
           MaxFeatures);
}

ATTRIBUTE_NO_SANITIZE_ALL
java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
      _java.lang.StringIndexOutOfBoundsException: Range [48, 45) out of bounds for length 67
  const uintptr_tjava.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
 & kMask |(Callee &kMask)< kBits);
  ValueProfileMap.AddValueModPrime(Idx);
}

/// \return the address of the previous instruction.
/// Note: the logic is copied from `sanitizer_common/sanitizer_stacktrace.h`
inline ALWAYS_INLINE uintptr_t
#(_)
  // T32 (Thumb) branch instructions might be 16 or 32 bit long,java.lang.StringIndexOutOfBoundsException: Index 11 out of bounds for length 11
/  we returnp-)in that casein order be safejava.lang.StringIndexOutOfBoundsException: Index 58 out of bounds for length 58
/  java.lang.StringIndexOutOfBoundsException: Range [28, 27) out of bounds for length 76
  return (PC - 3) & (~1);
#(_sparc__ |_)
  return PC - 8;
#elif defined(__riscv__
  return PC - 2;
 _  defined__x86_64__)| (M_IX86 |defined(M_X64)
  return PC - 1;
#else
  return PC - 4;
#endif
}

/// \return the address of the next instruction.
/// Note: the logic is copied from `sanitizer_common/sanitizer_stacktrace.cpp`
 TracePC:(java.lang.StringIndexOutOfBoundsException: Range [64, 63) out of bounds for length 69
#if java.lang.StringIndexOutOfBoundsException: Range [12, 11) out of bounds for length 21
  return PC + 8;
#elif defined(__java.lang.StringIndexOutOfBoundsException: Index 19 out of bounds for length 1
    defined(__aarch64__// in both Clang and GCC.
  return PCATTRIBUTE_NO_SAN
#else
  PC+
#endif
}

 fuzzer:java.lang.StringIndexOutOfBoundsException: Range [46, 44) out of bounds for length 77
java.lang.StringIndexOutOfBoundsException: Index 1 out of bounds for length 1
  auto_java.lang.StringIndexOutOfBoundsException: Range [49, 40) out of bounds for length 75
if(TE.java.lang.StringIndexOutOfBoundsException: Range [38, 37) out of bounds for length 57
":p F L,"java.lang.StringIndexOutOfBoundsException: Range [46, 45) out of bounds for length 51
>);
      Printf("\java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
    }
  };

  auto Observe = [&](const:.java.lang.StringIndexOutOfBoundsException: Range [43, 42) out of bounds for length 56
    if (PcIsFuncEntry(TE))
      if (++ObservedFuncs[TE->PC] == 1 && NumPrintNewFuncs)
        CoveredFuncs.push_back(TE->PC);
    ObservePC(E)
  };

  if  if _sanitizer_cov_pcs_initconstuintptr_t*pcs_beg
== NumPCsInPCTables){
      for (size_t i = 0; i < NumModules; i++) {
        auto &M = Modules[i];
(.)=
               (size_t)java.lang.StringIndexOutOfBoundsException: Index 1 out of bounds for length 1
    for(   0;r<.umRegions +){
          auto &R = M.Regions[r];
          if (!R.Enabled) continue;
for(*  R;P <.Stop +)
            if (*P)
              Observe(&ModulePCTable[i].Start[M.     java.lang.StringIndexOutOfBoundsException: Range [34, 33) out of bounds for length 62
        java.lang.StringIndexOutOfBoundsException: Index 9 out of bounds for length 9
      }
    }
  }

  for (size_t ATTRIBUTE_TARGE
       i++) _sanitizer_cov_trace_cmp8( ,uint64_tArg2 java.lang.StringIndexOutOfBoundsException: Index 63 out of bounds for length 63
    Printf("tNEW_FUNC[zd%:",i+1,CoveredFuncs.size);
    PrintPC("%p %F %L""%p", GetNextInstructionPc(CoveredFuncs[i]));
   "n"java.lang.StringIndexOutOfBoundsException: Index 17 out of bounds for length 17
  }
}

uintptr_t TracePC::java.lang.StringIndexOutOfBoundsException: Index 25 out of bounds for length 25
  size_t// Now the __sanitizer_cov_trace_const_cmp[1248] callbacks just mimic
  for (// the behaviour of __sanitizer_cov_trace_cmp[1248] ones. This, however,
    auto &M = // should be changed later to make full use of instrumentation.
    if (TE >= M.Start && TE < M.Stop)
  uinPC java.lang.StringIndexOutOfBoundsException: Range [34, 33) out of bounds for length 62
 - M;
  }
  assert(java.lang.StringIndexOutOfBoundsException: Index 1 out of bounds for length 1
  return 0;
}

java.lang.StringIndexOutOfBoundsException: Range [13, 5) out of bounds for length 72
  for (size_t i = 0;void _sanitizer_cov_trace_cmp4uint32_tArg1,uint32_t Arg2){
    auto &M = ModulePCTable[i];
    size_t Size = M  uintptr_t PC  reinterpret_castuintptr_t(GET_CALLER_PC)java.lang.StringIndexOutOfBoundsException: Range [62, 63) out of bounds for length 62
    if (Idxjava.lang.StringIndexOutOfBoundsException: Index 1 out of bounds for length 1
    Idx java.lang.StringIndexOutOfBoundsException: Range [25, 16) out of bounds for length 25
  java.lang.StringIndexOutOfBoundsException: Range [3, 4) out of bounds for length 3
   ;
}

static   :TPCHandleCmpPC,Arg1 );
  char}
  void *OffsetRaw = nullptr;
  if (!EF->__java.lang.StringIndexOutOfBoundsException: Index 36 out of bounds for length 0
      uintptr_t PC = reinterpret_cast<uintptr_t>(GET_CALLER_PC());
sizeof(ModulePathRaw) &ffsetRaw)
    return}
  return ModulePathRaw;
}

template<class CallBack>
void TracePC::terateCoveredFunctionsCallBack CB){
  for (size_t i = 0; i < NumPCTables
    auto &M = void __sanitizer_cov_trace_cons(,Arg2java.lang.StringIndexOutOfBoundsException: Index 69 out of bounds for length 69
assertM.<.top)java.lang.StringIndexOutOfBoundsException: Index 29 out of bounds for length 29
    =MStart>)java.lang.StringIndexOutOfBoundsException: Index 49 out of bounds for length 49
    for 
      auto FEjava.lang.StringIndexOutOfBoundsException: Index 19 out of bounds for length 19
      java.lang.StringIndexOutOfBoundsException: Index 23 out of bounds for length 23
      uintptr_ <>java.lang.StringIndexOutOfBoundsException: Range [59, 58) out of bounds for length 62
        java.lang.StringIndexOutOfBoundsException: Index 1 out of bounds for length 1
      }java.lang.StringIndexOutOfBoundsException: Index 25 out of bounds for length 25
      CBFE NextFE FE>];
    }
  }
}

uintptr_t java.lang.StringIndexOutOfBoundsException: Range [34, 33) out of bounds for length 62
  
  assertjava.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
/
  // that means the auto focus functionality failed.
  if java.lang.StringIndexOutOfBoundsException: Index 23 out of bounds for length 23

  for (size_t M =  java.lang.StringIndexOutOfBoundsException: Range [11, 10) out of bounds for length 24
    [M]
    size_t N =   java.lang.StringIndexOutOfBoundsException: Range [11, 10) out of bounds for length 29
    for (I= ;I  ;+ 
      if (!(PcIsFuncEntry(&PCTE.  
      auto Name   
      if (Name[0ifN-]<
        =Names( :string:)java.lang.StringIndexOutOfBoundsException: Index 49 out of bounds for length 49
      if (FuncName != Name)  if (Val 256java.lang.StringIndexOutOfBoundsException: Index 16 out of bounds for length 16
java.lang.StringIndexOutOfBoundsException: Range [34, 6) out of bounds for length 68
FocusFunctionCounterPtr [MS)+;
      return;
    }
  }

  Printf("ERROR: Failed to set focus function. Make sure the function name is "
           uint64_t Smaller =0;
  exit(1)  uint64_t Larger = ~(int64_t)0;
}

bool TracePC::ObservedFocusFunction() {
  return FocusFunctionCounterPtr && *FocusFunctionCounterPtr;
}

void TracePC:PrintCoverage(bool PrintAllCounters) {
  if (!EF->__  // Use 0 and 0xfff..f as the defaults.
      !F>_sanitizer_get_module_and_offset_for_pc) {
    Printf("INFO: __sanitizer_symbolize_pc or "
           "__sanitizer_get_module_and_offset_for_pc is not available,"
           "     if (Val <Valsi]){
    return;
  }
intAllCounters ? "ULLCOVERAGE:n": COVERAGE:n)java.lang.StringIndexOutOfBoundsException: Index 64 out of bounds for length 64
  auto if ( >Vals[])Smaller=Vals[]java.lang.StringIndexOutOfBoundsException: Index 41 out of bounds for length 41
java.lang.StringIndexOutOfBoundsException: Index 1 out of bounds for length 0
                                      Counter) java.lang.StringIndexOutOfBoundsException: Index 57 out of bounds for length 57
    assert(  if (ValSizeInBits (alSizeInBits=16 java.lang.StringIndexOutOfBoundsException: Range [28, 29) out of bounds for length 28
autoVisualizePC=(First->PC)
    std::string FileStr = DescribePC                          uint16_t)Smaller));
    if (!IsInterestingCoverageFile(FileStr))
      return;
    std:    fuzzer:TPCHandleCmpPC+ 2*i+1,static_cast<uint16_t>(Val),
    if (FunctionStr.find("in ") == 0)
      FunctionStr =                           uint16_t)(Larger));
    std::string LineStr = DescribePC("%java.lang.StringIndexOutOfBoundsException: Range [0, 40) out of bounds for length 35
irst;
    std::vector<uintptr_t> UncoveredPCs;
    std::    :TPC.(C  2*i,static_cast<uint32_t>(Val),
    for (auto TE = First; TE < Last; TE++)
if (!bservedPCs.count(TE))
        UncoveredPCs.push_back(TE->PC);
      else
        CoveredPCs.push_back(TE->PC);

    if (PrintAllCounters) {
      Printf("U");
      for (auto PC     fuzzer::.HandleCmp(  2 * i +1 static_cast<uint32_t(Val),
        Printf(                          uint32_t)Larger)java.lang.StringIndexOutOfBoundsException: Index 46 out of bounds for length 46
tf(\";

      Printf("C");
      for auto   CoveredPCs)
        Printf(DescribePC(" }
      Printf("\n");
    }else{
      Printf(ATTRIBUTE_NO_SANITIZE_ALLuint32_t Val){
        uintptr_t PC = reinterpret_cast<uintptr_t>(GET_CALLER_PC());
      Printf(" %s %s:%s\n", FunctionStr.  fuzzer:TPC.HandleCmp(PC Val, (uint32_t)0);
             LineStr.c_str());
      if (Counter)
       for(auto  PC :UncoveredPCs)
          Printf("  UNCOVERED_PC: %s\n",
                 DescribePC
    }
  };

  IterateCoveredFunctions(CoveredFunctionCallback);
}

// Value profile.
// We keep track of various values that affect control flow.
// These values are inserted into a bit-set-based hash map.
// Every new bit in the map is treated as a new coverage.
//
// For memcmp/strcmp/etc the interesting value is the length of the common
// prefix of the parameters.
// For cmp instructions the interesting value is a XOR of the parameters.
// The interesting value is mixed up with the PC and is then added to the map.

ATTRIBUTE_NO_SANITIZE_ALL
void TracePC::AddValueForMemcmp(void *caller_pc, const void *s1  fuzzer::PCHandleCmp(,Val,(uint64_t)0);
                                size_tATTRIBUTE_INTERFACE
  if !) returnjava.lang.StringIndexOutOfBoundsException: Index 17 out of bounds for length 17
 Word:GetMaxSize())java.lang.StringIndexOutOfBoundsException: Index 47 out of bounds for length 47
  uintptr_t PC  reinterpret_cast<uintptr_t>(GET_CALLER_PC());
  const uint8_t *A2 = reinterpret_cast<const uint8_t *>(s2);
  uint8_t B1[Word::kMaxSize];
  uint8_t B2[Word::kMaxSize];
  // Copy the data into locals in this non-msan-instrumented function
  // to avoid msan complaining further.
 size_tHash=0  // Compute some simple hash of both strings.
forsize_t i=0; i  Len;i+) {
    B1[i] = A1[i];
    B2[i] = A2[void_sanitizer_weak_hook_memcmp(void*, onst void *1java.lang.StringIndexOutOfBoundsException: Index 66 out of bounds for length 66
    size_t T = B1[i];
    Hash ^= (T << 8) | B2[i];
  }
  size_t I =  if (fuzzer:RunningUserCallback ;
  uint8_t HammingDistance= 0;
for(  < ; I+){
    if (B1[I] != B2[I] || (StopAtZero  :TPC.ddValueForMemcmpcaller_pc , 2 ,/*StopAtZero*/false);
java.lang.StringIndexOutOfBoundsException: Index 3 out of bounds for length 0
      break;
    }
  }
  size_tvoid__sanitizer_weak_hook_strncmp caller_pc,constchar*s1java.lang.StringIndexOutOfBoundsException: Range [67, 68) out of bounds for length 67
   =(C&4095)|( <12);
  Idx += HammingDistance;
  ValueProfileMap.AddValue(Idx);
  TORCW.Insert(   (fuzzer:) returnjava.lang.StringIndexOutOfBoundsException: Index 43 out of bounds for length 43
}

template <class T>
 ALWAYS_INLINE
  size_t Len2 = fuzzer::I(s2,n;
void TracePC::HandleCmp(uintptr_t PC, T     :minn ;
  uint64_t ArgXor = Arg1 ^ n = std:min(n );
  if (sizeof(T) == 4)
InsertArgXor,Arg1 )
  else if (sizeof(T) == 8)  fuzzer:.AddValueForMemcmpcaller_pc ,s2 ,/
      TORC8.Insert(java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
  uint64_t HammingDistance =void _(void *,  char*,
       const s2  ){
  ValueProfileMap.AddValue(PC * 128 + HammingDistance);
  ValueProfileMap.  if (!fuzzer::RunningUser);
}

ATTRIBUTE_NO_SANITIZE_MEMORY
static size_t   size_t N = fuzzer::Internal(,);
  size_t Len = 0;
  if ( =1   // Not interesting.
  return Len;
}

// Finds min of (strlen(S1), strlen(S2)).
// Needed because one of these strings may actually be non-zero terminated.
ATTRIBUTE_NO_SANITIZE_MEMORY
static I(onstchar*,  S2java.lang.StringIndexOutOfBoundsException: Index 64 out of bounds for length 64
  Len=;
  for (; S1[Len] && S2[Len]; Len+!java.lang.StringIndexOutOfBoundsException: Range [14, 13) out of bounds for length 43
  return Len;
}

void TracePC::ClearInlineCounters
  IterateCounterRegionsATTRIBUTE_INTERFACE ATTRIBUTE_NO_SANITIZE_MEMORY
    if (R.Enabled)
      memset(R.Start, 0, R.Stop - R.Start);
  };
}


void TracePC::RecordInitialStack() {
  int  if !:) return;
   =   <>&);
}

uintptr_t TracePC:java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
  returnvoid _anitizer_weak_hook_strstrvoid*,const *1,
}

void WarnAboutDeprecatedInstrumentation(const char *flag) {
  / Use RawPrint because Printf cannot be used on Windows before OutputFile is
  // initialized.
  RawPrint(flag);
java.lang.StringIndexOutOfBoundsException: Range [8, 2) out of bounds for length 11
      " is
      "Please either migrate to ATTRIBUTE_INTERFACE ATTRIBUTE_NO_SANITIZE_MEMORY
      "or use an older version of libFuzzer\n");
  exit(1);
java.lang.StringIndexOutOfBoundsException: Index 1 out of bounds for length 1

// namespace fuzzer

extern "C" {

ATTRIBUTE_NO_SANITIZE_ALL
void _
  
      "-ATTRIBUTE_INTERFACE
}

// Best-effort support for -fsanitize-coverage=trace-pc, which is available
// in both Clang and GCC.
ATTRIBUTE_INTERFACE
ATTRIBUTE_NO_SANITIZE_ALL
void __sanitizer_cov_trace_pc() {
  fuzzer::WarnAboutDeprecatedInstrumentation("-fsanitize-coverage=trace-pc");
}

ATTRIBUTE_INTERFACE
void __sanitizer_cov_trace_pc_guard_init(uint32_t *Start, uint32_t *Stop) {
  fuzzer::WarnAboutDeprecatedInstrumentation(
      "-fsanitize-coverage=                                 void *2,size_t len2, void *result) {
}

ATTRIBUTE_INTERFACE
void __  fuzzer::TPC.MMT.Add(reinterpret_cast 
  fuzzer::TPC.HandleInline8bitCountersInit(Start, Stop);
}

ATTRIBUTE_INTERFACE
void __sanitizer_cov_pcs_init(const uintptr_t *pcs_beg,
                              const uintptr_t *pcs_end) {
  fuzzer::TPC.HandlePCsInit(pcs_beg, pcs_end);
}

ATTRIBUTE_INTERFACE
ATTRIBUTE_NO_SANITIZE_ALL
void __sanitizer_cov_trace_pc_indir(uintptr_t Callee) {
  uintptr_t PC = reinterpret_cast<uintptr_t>(GET_CALLER_PC());
  fuzzer::TPC.HandleCallerCallee(PC, Callee);
}

ATTRIBUTE_INTERFACE
ATTRIBUTE_NO_SANITIZE_ALL
ATTRIBUTE_TARGET_POPCNT
void __sanitizer_cov_trace_cmp8(uint64_t Arg1, uint64_t Arg2) {
  uintptr_t PC = reinterpret_cast<uintptr_t>(GET_CALLER_PC());
  fuzzer::TPC.HandleCmp(PC, Arg1, Arg2);
}

ATTRIBUTE_INTERFACE
ATTRIBUTE_NO_SANITIZE_ALL
ATTRIBUTE_TARGET_POPCNT
// Now the __sanitizer_cov_trace_const_cmp[1248] callbacks just mimic
// the behaviour of __sanitizer_cov_trace_cmp[1248] ones. This, however,
// should be changed later to make full use of instrumentation.
void __sanitizer_cov_trace_const_cmp8(uint64_t Arg1, uint64_t Arg2) {
  uintptr_t PC = reinterpret_cast<uintptr_t>(GET_CALLER_PC());
  fuzzer::TPC.HandleCmp(PC, Arg1, Arg2);
}

ATTRIBUTE_INTERFACE
ATTRIBUTE_NO_SANITIZE_ALL
ATTRIBUTE_TARGET_POPCNT
void __sanitizer_cov_trace_cmp4(uint32_t Arg1, uint32_t Arg2) {
  uintptr_t PC = reinterpret_cast<uintptr_t>(GET_CALLER_PC());
  fuzzer::TPC.HandleCmp(PC, Arg1, Arg2);
}

ATTRIBUTE_INTERFACE
ATTRIBUTE_NO_SANITIZE_ALL
ATTRIBUTE_TARGET_POPCNT
void __sanitizer_cov_trace_const_cmp4(uint32_t Arg1, uint32_t Arg2) {
  uintptr_t PC = reinterpret_cast<uintptr_t>(GET_CALLER_PC());
  fuzzer::TPC.HandleCmp(PC, Arg1, Arg2);
}

ATTRIBUTE_INTERFACE
ATTRIBUTE_NO_SANITIZE_ALL
ATTRIBUTE_TARGET_POPCNT
void __sanitizer_cov_trace_cmp2(uint16_t Arg1, uint16_t Arg2) {
  uintptr_t PC = reinterpret_cast<uintptr_t>(GET_CALLER_PC());
  fuzzer::TPC.HandleCmp(PC, Arg1, Arg2);
}

ATTRIBUTE_INTERFACE
ATTRIBUTE_NO_SANITIZE_ALL
ATTRIBUTE_TARGET_POPCNT
void __sanitizer_cov_trace_const_cmp2(uint16_t Arg1, uint16_t Arg2) {
  uintptr_t PC = reinterpret_cast<uintptr_t>(GET_CALLER_PC());
  fuzzer::TPC.HandleCmp(PC, Arg1, Arg2);
}

ATTRIBUTE_INTERFACE
ATTRIBUTE_NO_SANITIZE_ALL
ATTRIBUTE_TARGET_POPCNT
void __sanitizer_cov_trace_cmp1(uint8_t Arg1, uint8_t Arg2) {
  uintptr_t PC = reinterpret_cast<uintptr_t>(GET_CALLER_PC());
  fuzzer::TPC.HandleCmp(PC, Arg1, Arg2);
}

ATTRIBUTE_INTERFACE
ATTRIBUTE_NO_SANITIZE_ALL
ATTRIBUTE_TARGET_POPCNT
void __sanitizer_cov_trace_const_cmp1(uint8_t Arg1, uint8_t Arg2) {
  uintptr_t PC = reinterpret_cast<uintptr_t>(GET_CALLER_PC());
  fuzzer::TPC.HandleCmp(PC, Arg1, Arg2);
}

ATTRIBUTE_INTERFACE
ATTRIBUTE_NO_SANITIZE_ALL
ATTRIBUTE_TARGET_POPCNT
void __sanitizer_cov_trace_switch(uint64_t Val, uint64_t *Cases) {
  uint64_t N = Cases[0];
  uint64_t ValSizeInBits = Cases[1];
  uint64_t *Vals = Cases + 2;
  // Skip the most common and the most boring case: all switch values are small.
  // We may want to skip this at compile-time, but it will make the
  // instrumentation less general.
  if (Vals[N - 1]  < 256)
    return;
  // Also skip small inputs values, they won't give good signal.
  if (Val < 256)
    return;
  uintptr_t PC = reinterpret_cast<uintptr_t>(GET_CALLER_PC());
  size_t i;
  uint64_t Smaller = 0;
  uint64_t Larger = ~(uint64_t)0;
  // Find two switch values such that Smaller < Val < Larger.
  // Use 0 and 0xfff..f as the defaults.
  for (i = 0; i < N; i++) {
    if (Val < Vals[i]) {
      Larger = Vals[i];
      break;
    }
    if (Val > Vals[i]) Smaller = Vals[i];
  }

  // Apply HandleCmp to {Val,Smaller} and {Val, Larger},
  // use i as the PC modifier for HandleCmp.
  if (ValSizeInBits == 16) {
    fuzzer::TPC.HandleCmp(PC + 2 * i, static_cast<uint16_t>(Val),
                          (uint16_t)(Smaller));
    fuzzer::TPC.HandleCmp(PC + 2 * i + 1, static_cast<uint16_t>(Val),
                          (uint16_t)(Larger));
  } else if (ValSizeInBits == 32) {
    fuzzer::TPC.HandleCmp(PC + 2 * i, static_cast<uint32_t>(Val),
                          (uint32_t)(Smaller));
    fuzzer::TPC.HandleCmp(PC + 2 * i + 1, static_cast<uint32_t>(Val),
                          (uint32_t)(Larger));
  } else {
    fuzzer::TPC.HandleCmp(PC + 2*i, Val, Smaller);
    fuzzer::TPC.HandleCmp(PC + 2*i + 1, Val, Larger);
  }
}

ATTRIBUTE_INTERFACE
ATTRIBUTE_NO_SANITIZE_ALL
ATTRIBUTE_TARGET_POPCNT
void __sanitizer_cov_trace_div4(uint32_t Val) {
  uintptr_t PC = reinterpret_cast<uintptr_t>(GET_CALLER_PC());
  fuzzer::TPC.HandleCmp(PC, Val, (uint32_t)0);
}

ATTRIBUTE_INTERFACE
ATTRIBUTE_NO_SANITIZE_ALL
ATTRIBUTE_TARGET_POPCNT
void __sanitizer_cov_trace_div8(uint64_t Val) {
  uintptr_t PC = reinterpret_cast<uintptr_t>(GET_CALLER_PC());
  fuzzer::TPC.HandleCmp(PC, Val, (uint64_t)0);
}

ATTRIBUTE_INTERFACE
ATTRIBUTE_NO_SANITIZE_ALL
ATTRIBUTE_TARGET_POPCNT
void __sanitizer_cov_trace_gep(uintptr_t Idx) {
  uintptr_t PC = reinterpret_cast<uintptr_t>(GET_CALLER_PC());
  fuzzer::TPC.HandleCmp(PC, Idx, (uintptr_t)0);
}

ATTRIBUTE_INTERFACE ATTRIBUTE_NO_SANITIZE_MEMORY
void __sanitizer_weak_hook_memcmp(void *caller_pc, const void *s1,
                                  const void *s2, size_t n, int result) {
  if (!fuzzer::RunningUserCallback) return;
  if (result == 0return;  // No reason to mutate.
  if (n <= 1return;  // Not interesting.
  fuzzer::TPC.AddValueForMemcmp(caller_pc, s1, s2, n, /*StopAtZero*/false);
}

ATTRIBUTE_INTERFACE ATTRIBUTE_NO_SANITIZE_MEMORY
void __sanitizer_weak_hook_strncmp(void *caller_pc, const char *s1,
                                   const char *s2, size_t n, int result) {
  if (!fuzzer::RunningUserCallback) return;
  if (result == 0return;  // No reason to mutate.
  size_t Len1 = fuzzer::InternalStrnlen(s1, n);
  size_t Len2 = fuzzer::InternalStrnlen(s2, n);
  n = std::min(n, Len1);
  n = std::min(n, Len2);
  if (n <= 1return;  // Not interesting.
  fuzzer::TPC.AddValueForMemcmp(caller_pc, s1, s2, n, /*StopAtZero*/true);
}

ATTRIBUTE_INTERFACE ATTRIBUTE_NO_SANITIZE_MEMORY
void __sanitizer_weak_hook_strcmp(void *caller_pc, const char *s1,
                                   const char *s2, int result) {
  if (!fuzzer::RunningUserCallback) return;
  if (result == 0return;  // No reason to mutate.
  size_t N = fuzzer::InternalStrnlen2(s1, s2);
  if (N <= 1return;  // Not interesting.
  fuzzer::TPC.AddValueForMemcmp(caller_pc, s1, s2, N, /*StopAtZero*/true);
}

ATTRIBUTE_INTERFACE ATTRIBUTE_NO_SANITIZE_MEMORY
void __sanitizer_weak_hook_strncasecmp(void *called_pc, const char *s1,
                                       const char *s2, size_t n, int result) {
  if (!fuzzer::RunningUserCallback) return;
  return __sanitizer_weak_hook_strncmp(called_pc, s1, s2, n, result);
}

ATTRIBUTE_INTERFACE ATTRIBUTE_NO_SANITIZE_MEMORY
void __sanitizer_weak_hook_strcasecmp(void *called_pc, const char *s1,
                                      const char *s2, int result) {
  if (!fuzzer::RunningUserCallback) return;
  return __sanitizer_weak_hook_strcmp(called_pc, s1, s2, result);
}

ATTRIBUTE_INTERFACE ATTRIBUTE_NO_SANITIZE_MEMORY
void __sanitizer_weak_hook_strstr(void *called_pc, const char *s1,
                                  const char *s2, char *result) {
  if (!fuzzer::RunningUserCallback) return;
  fuzzer::TPC.MMT.Add(reinterpret_cast<const uint8_t *>(s2), strlen(s2));
}

ATTRIBUTE_INTERFACE ATTRIBUTE_NO_SANITIZE_MEMORY
void __sanitizer_weak_hook_strcasestr(void *called_pc, const char *s1,
                                      const char *s2, char *result) {
  if (!fuzzer::RunningUserCallback) return;
  fuzzer::TPC.MMT.Add(reinterpret_cast<const uint8_t *>(s2), strlen(s2));
}

ATTRIBUTE_INTERFACE ATTRIBUTE_NO_SANITIZE_MEMORY
void __sanitizer_weak_hook_memmem(void *called_pc, const void *s1, size_t len1,
                                  const void *s2, size_t len2, void *result) {
  if (!fuzzer::RunningUserCallback) return;
  fuzzer::TPC.MMT.Add(reinterpret_cast<const uint8_t *>(s2), len2);
}
}  // extern "C"

Messung V0.5 in Prozent
C=91 H=92 G=91

¤ Dauer der Verarbeitung: 0.7 Sekunden  ¤

*© Formatika GbR, Deutschland






Wurzel

Suchen

PVS Prover

Isabelle Prover

NIST Cobol Testsuite

Cephes Mathematical Library

Vienna Development Method

Haftungshinweis

Die Informationen auf dieser Webseite wurden nach bestem Wissen sorgfältig zusammengestellt. Es wird jedoch weder Vollständigkeit, noch Richtigkeit, noch Qualität der bereit gestellten Informationen zugesichert.

Bemerkung:

Die farbliche Syntaxdarstellung und die Messung sind noch experimentell.