Conversation
…th invalid parameters `LLVMFuzzerTestOneInput` allows two return values: 0 and -1. While 0 allows for the input to be (potentially) saved in the corpus, -1 tells the fuzzer not to save it. In the words of the [fine documentation](https://llvm.org/docs/LibFuzzer.html#rejecting-unwanted-inputs): > It may be desirable to reject some inputs, i.e. to not add them to the corpus. > For example, when fuzzing an API consisting of parsing and other logic, one may want > to allow only those inputs into the corpus that parse successfully. > If the fuzz target returns -1 on a given input, libFuzzer will not add that > input to the corpus, regardless of what coverage it triggers.
Member
Author
|
@github-actions crossbow submit -g cpp |
|
Revision: 389b79d Submitted crossbow builds: ursacomputing/crossbow @ actions-199c3ed102 |
Member
Author
|
CI failures are unrelated. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Rationale for this change
LLVMFuzzerTestOneInputallows two return values: 0 and -1. While 0 allows for the input to be (potentially) saved in the corpus, -1 tells the fuzzer not to save it.In the words of the fine documentation:
What changes are included in this PR?
FuzzStatustype that allows telling the fuzzing engine whether an input should be skipped (i.e. not saved in the corpus).Are these changes tested?
Manually, by running the fuzzer from the command line and watching logs with
ARROW_FUZZING_VERBOSITYenabled.Without a seed corpus and trying to generate 100k inputs (
./build/out/arrow/parquet-encoding-fuzz -seed=42 -runs=100000), I get:It seems that this PR allows the fuzzer to proceed much faster when mutation generates such inputs. Despite running faster, it also reaches more coverage (see doc about the
cov:andft:values).(caveat: these measurements is with a fixed random seed, and without a seed corpus)
(of course, ideally the fuzzer would not produce such inputs at all, but ensuring that is more involved)
Are there any user-facing changes?
No.
Was AI used for this PR?
In accordance to the AI generation guidelines, please disclose below whether and how AI was used in this PR.
PR code and description written by:
Reviewed before submission by: