about summary refs log tree commit diff
path: root/custom_mutators/libfuzzer/FuzzerExtraCounters.cpp
diff options
context:
space:
mode:
authorvan Hauser <vh@thc.org>2020-09-10 15:26:46 +0200
committervan Hauser <vh@thc.org>2020-09-10 15:26:46 +0200
commit380051868a7531830d94d312f0f11b0e19e3284f (patch)
treea06cd1b2e2127b2ce2c7de4714fcdccab4a9502e /custom_mutators/libfuzzer/FuzzerExtraCounters.cpp
parentfdb0452245672db94be0832288f1335e905a2fc8 (diff)
downloadafl++-380051868a7531830d94d312f0f11b0e19e3284f.tar.gz
add libfuzzer custom mutator, minor enhancements and fixes
Diffstat (limited to 'custom_mutators/libfuzzer/FuzzerExtraCounters.cpp')
-rw-r--r--custom_mutators/libfuzzer/FuzzerExtraCounters.cpp71
1 files changed, 71 insertions, 0 deletions
diff --git a/custom_mutators/libfuzzer/FuzzerExtraCounters.cpp b/custom_mutators/libfuzzer/FuzzerExtraCounters.cpp
new file mode 100644
index 00000000..3ff9b0d5
--- /dev/null
+++ b/custom_mutators/libfuzzer/FuzzerExtraCounters.cpp
@@ -0,0 +1,71 @@
+//===- FuzzerExtraCounters.cpp - Extra coverage counters ------------------===//
+//
+// Part of the LLVM Project, under the Apache License v2.0 with LLVM Exceptions.
+// See https://llvm.org/LICENSE.txt for license information.
+// SPDX-License-Identifier: Apache-2.0 WITH LLVM-exception
+//
+//===----------------------------------------------------------------------===//
+// Extra coverage counters defined by user code.
+//===----------------------------------------------------------------------===//
+
+#include "FuzzerPlatform.h"
+#include <cstdint>
+
+#if LIBFUZZER_LINUX || LIBFUZZER_NETBSD || LIBFUZZER_FREEBSD || \
+    LIBFUZZER_OPENBSD || LIBFUZZER_FUCHSIA || LIBFUZZER_EMSCRIPTEN
+__attribute__((weak)) extern uint8_t __start___libfuzzer_extra_counters;
+__attribute__((weak)) extern uint8_t __stop___libfuzzer_extra_counters;
+
+namespace fuzzer {
+
+uint8_t *ExtraCountersBegin() {
+
+  return &__start___libfuzzer_extra_counters;
+
+}
+
+uint8_t *ExtraCountersEnd() {
+
+  return &__stop___libfuzzer_extra_counters;
+
+}
+
+ATTRIBUTE_NO_SANITIZE_ALL
+void ClearExtraCounters() {  // hand-written memset, don't asan-ify.
+  uintptr_t *Beg = reinterpret_cast<uintptr_t *>(ExtraCountersBegin());
+  uintptr_t *End = reinterpret_cast<uintptr_t *>(ExtraCountersEnd());
+  for (; Beg < End; Beg++) {
+
+    *Beg = 0;
+    __asm__ __volatile__("" : : : "memory");
+
+  }
+
+}
+
+}  // namespace fuzzer
+
+#else
+// TODO: implement for other platforms.
+namespace fuzzer {
+
+uint8_t *ExtraCountersBegin() {
+
+  return nullptr;
+
+}
+
+uint8_t *ExtraCountersEnd() {
+
+  return nullptr;
+
+}
+
+void ClearExtraCounters() {
+
+}
+
+}  // namespace fuzzer
+
+#endif
+