Official Go implementation of the Ethereum protocol
You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
 
 
 
 
 
 
go-ethereum/tests/fuzzers
rjl493456442 8c8a9e5ca1
core, ethdb, tests, trie: introduce database snapshot (#24486)
3 years ago
..
abi tests/fuzzers/abi: fixed one-off panic with int.Min64 value (#22233) 4 years ago
bitutil tests/fuzzers: fix false positive in bitutil fuzzer (#22076) 4 years ago
bls12381 all: add go:build lines (#23468) 3 years ago
bn256 core, ethdb, tests, trie: implement NewBatchWithSize API for batcher (#24392) 3 years ago
difficulty consensus/ethash: implement faster difficulty calculators (#21976) 4 years ago
keystore tests/fuzzers: improve the fuzzers (#21829) 4 years ago
les tests/fuzzers: fix goroutine leak in les fuzzer (#22455) 4 years ago
rangeproof core, eth, ethdb, trie: simplify range proofs 4 years ago
rlp tests/fuzzers: improve the fuzzers (#21829) 4 years ago
runtime common,crypto: move fuzzers out of core (#22029) 4 years ago
secp256k1 crypto/secp256k1: fix undefined behavior in BitCurve.Add (#22621) 4 years ago
snap tests/fuzzzers. eth/protocols/snap: add snap protocol fuzzers (#23957) 3 years ago
stacktrie core, ethdb, tests, trie: introduce database snapshot (#24486) 3 years ago
trie core, light, tests, trie: add state metrics (#23433) 3 years ago
txfetcher tests/fuzzers: improve the fuzzers (#21829) 4 years ago
vflux les, tests: fix les clientpool (#22756) 4 years ago
README.md all: fix typos in comments (#21118) 5 years ago

README.md

Fuzzers

To run a fuzzer locally, you need go-fuzz installed.

First build a fuzzing-binary out of the selected package:

(cd ./rlp && CGO_ENABLED=0 go-fuzz-build .)

That command should generate a rlp-fuzz.zip in the rlp/ directory. If you are already in that directory, you can do

[user@work rlp]$ go-fuzz
2019/11/26 13:36:54 workers: 6, corpus: 3 (3s ago), crashers: 0, restarts: 1/0, execs: 0 (0/sec), cover: 0, uptime: 3s
2019/11/26 13:36:57 workers: 6, corpus: 3 (6s ago), crashers: 0, restarts: 1/0, execs: 0 (0/sec), cover: 1054, uptime: 6s
2019/11/26 13:37:00 workers: 6, corpus: 3 (9s ago), crashers: 0, restarts: 1/8358, execs: 25074 (2786/sec), cover: 1054, uptime: 9s
2019/11/26 13:37:03 workers: 6, corpus: 3 (12s ago), crashers: 0, restarts: 1/8497, execs: 50986 (4249/sec), cover: 1054, uptime: 12s
2019/11/26 13:37:06 workers: 6, corpus: 3 (15s ago), crashers: 0, restarts: 1/9330, execs: 74640 (4976/sec), cover: 1054, uptime: 15s
2019/11/26 13:37:09 workers: 6, corpus: 3 (18s ago), crashers: 0, restarts: 1/9948, execs: 99482 (5527/sec), cover: 1054, uptime: 18s
2019/11/26 13:37:12 workers: 6, corpus: 3 (21s ago), crashers: 0, restarts: 1/9428, execs: 122568 (5836/sec), cover: 1054, uptime: 21s
2019/11/26 13:37:15 workers: 6, corpus: 3 (24s ago), crashers: 0, restarts: 1/9676, execs: 145152 (6048/sec), cover: 1054, uptime: 24s
2019/11/26 13:37:18 workers: 6, corpus: 3 (27s ago), crashers: 0, restarts: 1/9855, execs: 167538 (6205/sec), cover: 1054, uptime: 27s
2019/11/26 13:37:21 workers: 6, corpus: 3 (30s ago), crashers: 0, restarts: 1/9645, execs: 192901 (6430/sec), cover: 1054, uptime: 30s
2019/11/26 13:37:24 workers: 6, corpus: 3 (33s ago), crashers: 0, restarts: 1/9967, execs: 219294 (6645/sec), cover: 1054, uptime: 33s

Otherwise:

go-fuzz -bin ./rlp/rlp-fuzz.zip

Notes

Once a 'crasher' is found, the fuzzer tries to avoid reporting the same vector twice, so stores the fault in the suppressions folder. Thus, if you e.g. make changes to fix a bug, you should remove all data from the suppressions-folder, to verify that the issue is indeed resolved.

Also, if you have only one and the same exit-point for multiple different types of test, the suppression can make the fuzzer hide different types of errors. So make sure that each type of failure is unique (for an example, see the rlp fuzzer, where a counter i is used to differentiate between failures:

		if !bytes.Equal(input, output) {
			panic(fmt.Sprintf("case %d: encode-decode is not equal, \ninput : %x\noutput: %x", i, input, output))
		}