FuzzerMutate.cpp 1.7 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071
  1. //===- FuzzerMutate.cpp - Mutate a test input -----------------------------===//
  2. //
  3. // The LLVM Compiler Infrastructure
  4. //
  5. // This file is distributed under the University of Illinois Open Source
  6. // License. See LICENSE.TXT for details.
  7. //
  8. //===----------------------------------------------------------------------===//
  9. // Mutate a test input.
  10. //===----------------------------------------------------------------------===//
  11. #include <cstring>
  12. #include "FuzzerInternal.h"
  13. namespace fuzzer {
  14. static char FlipRandomBit(char X) {
  15. int Bit = rand() % 8;
  16. char Mask = 1 << Bit;
  17. char R;
  18. if (X & (1 << Bit))
  19. R = X & ~Mask;
  20. else
  21. R = X | Mask;
  22. assert(R != X);
  23. return R;
  24. }
  25. static char RandCh() {
  26. if (rand() % 2) return rand();
  27. const char *Special = "!*'();:@&=+$,/?%#[]123ABCxyz-`~.";
  28. return Special[rand() % (sizeof(Special) - 1)];
  29. }
  30. // Mutates Data in place, returns new size.
  31. size_t Mutate(uint8_t *Data, size_t Size, size_t MaxSize) {
  32. assert(MaxSize > 0);
  33. assert(Size <= MaxSize);
  34. if (Size == 0) {
  35. for (size_t i = 0; i < MaxSize; i++)
  36. Data[i] = RandCh();
  37. return MaxSize;
  38. }
  39. assert(Size > 0);
  40. size_t Idx = rand() % Size;
  41. switch (rand() % 3) {
  42. case 0:
  43. if (Size > 1) {
  44. // Erase Data[Idx].
  45. memmove(Data + Idx, Data + Idx + 1, Size - Idx - 1);
  46. Size = Size - 1;
  47. }
  48. [[clang::fallthrough]];
  49. case 1:
  50. if (Size < MaxSize) {
  51. // Insert new value at Data[Idx].
  52. memmove(Data + Idx + 1, Data + Idx, Size - Idx);
  53. Data[Idx] = RandCh();
  54. }
  55. Data[Idx] = RandCh();
  56. break;
  57. case 2:
  58. Data[Idx] = FlipRandomBit(Data[Idx]);
  59. break;
  60. }
  61. assert(Size > 0);
  62. return Size;
  63. }
  64. } // namespace fuzzer