fuzzer_context.cpp 9.2 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186
  1. // Copyright (c) 2019 Google LLC
  2. //
  3. // Licensed under the Apache License, Version 2.0 (the "License");
  4. // you may not use this file except in compliance with the License.
  5. // You may obtain a copy of the License at
  6. //
  7. // http://www.apache.org/licenses/LICENSE-2.0
  8. //
  9. // Unless required by applicable law or agreed to in writing, software
  10. // distributed under the License is distributed on an "AS IS" BASIS,
  11. // WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  12. // See the License for the specific language governing permissions and
  13. // limitations under the License.
  14. #include "source/fuzz/fuzzer_context.h"
  15. #include <cmath>
  16. namespace spvtools {
  17. namespace fuzz {
  18. namespace {
  19. // Default <minimum, maximum> pairs of probabilities for applying various
  20. // transformations. All values are percentages. Keep them in alphabetical order.
  21. const std::pair<uint32_t, uint32_t> kChanceOfAddingAccessChain = {5, 50};
  22. const std::pair<uint32_t, uint32_t> kChanceOfAddingAnotherStructField = {20,
  23. 90};
  24. const std::pair<uint32_t, uint32_t> kChanceOfAddingArrayOrStructType = {20, 90};
  25. const std::pair<uint32_t, uint32_t> kChanceOfAddingDeadBlock = {20, 90};
  26. const std::pair<uint32_t, uint32_t> kChanceOfAddingDeadBreak = {5, 80};
  27. const std::pair<uint32_t, uint32_t> kChanceOfAddingDeadContinue = {5, 80};
  28. const std::pair<uint32_t, uint32_t> kChanceOfAddingEquationInstruction = {5,
  29. 90};
  30. const std::pair<uint32_t, uint32_t> kChanceOfAddingGlobalVariable = {20, 90};
  31. const std::pair<uint32_t, uint32_t> kChanceOfAddingLoad = {5, 50};
  32. const std::pair<uint32_t, uint32_t> kChanceOfAddingLocalVariable = {20, 90};
  33. const std::pair<uint32_t, uint32_t> kChanceOfAddingMatrixType = {20, 70};
  34. const std::pair<uint32_t, uint32_t> kChanceOfAddingNoContractionDecoration = {
  35. 5, 70};
  36. const std::pair<uint32_t, uint32_t> kChanceOfAddingStore = {5, 50};
  37. const std::pair<uint32_t, uint32_t> kChanceOfAddingVectorType = {20, 70};
  38. const std::pair<uint32_t, uint32_t> kChanceOfAdjustingBranchWeights = {20, 90};
  39. const std::pair<uint32_t, uint32_t> kChanceOfAdjustingFunctionControl = {20,
  40. 70};
  41. const std::pair<uint32_t, uint32_t> kChanceOfAdjustingLoopControl = {20, 90};
  42. const std::pair<uint32_t, uint32_t> kChanceOfAdjustingMemoryOperandsMask = {20,
  43. 90};
  44. const std::pair<uint32_t, uint32_t> kChanceOfAdjustingSelectionControl = {20,
  45. 90};
  46. const std::pair<uint32_t, uint32_t> kChanceOfCallingFunction = {1, 10};
  47. const std::pair<uint32_t, uint32_t> kChanceOfChoosingStructTypeVsArrayType = {
  48. 20, 80};
  49. const std::pair<uint32_t, uint32_t> kChanceOfConstructingComposite = {20, 50};
  50. const std::pair<uint32_t, uint32_t> kChanceOfCopyingObject = {20, 50};
  51. const std::pair<uint32_t, uint32_t> kChanceOfDonatingAdditionalModule = {5, 50};
  52. const std::pair<uint32_t, uint32_t> kChanceOfGoingDeeperWhenMakingAccessChain =
  53. {50, 95};
  54. const std::pair<uint32_t, uint32_t> kChanceOfMakingDonorLivesafe = {40, 60};
  55. const std::pair<uint32_t, uint32_t> kChanceOfMergingBlocks = {20, 95};
  56. const std::pair<uint32_t, uint32_t> kChanceOfMovingBlockDown = {20, 50};
  57. const std::pair<uint32_t, uint32_t> kChanceOfObfuscatingConstant = {10, 90};
  58. const std::pair<uint32_t, uint32_t> kChanceOfOutliningFunction = {10, 90};
  59. const std::pair<uint32_t, uint32_t> kChanceOfPermutingParameters = {30, 90};
  60. const std::pair<uint32_t, uint32_t> kChanceOfReplacingIdWithSynonym = {10, 90};
  61. const std::pair<uint32_t, uint32_t> kChanceOfSplittingBlock = {40, 95};
  62. const std::pair<uint32_t, uint32_t> kChanceOfTogglingAccessChainInstruction = {
  63. 20, 90};
  64. // Default limits for various quantities that are chosen during fuzzing.
  65. // Keep them in alphabetical order.
  66. const uint32_t kDefaultMaxEquivalenceClassSizeForDataSynonymFactClosure = 1000;
  67. const uint32_t kDefaultMaxLoopControlPartialCount = 100;
  68. const uint32_t kDefaultMaxLoopControlPeelCount = 100;
  69. const uint32_t kDefaultMaxLoopLimit = 20;
  70. const uint32_t kDefaultMaxNewArraySizeLimit = 100;
  71. // Default functions for controlling how deep to go during recursive
  72. // generation/transformation. Keep them in alphabetical order.
  73. const std::function<bool(uint32_t, RandomGenerator*)>
  74. kDefaultGoDeeperInConstantObfuscation =
  75. [](uint32_t current_depth, RandomGenerator* random_generator) -> bool {
  76. double chance = 1.0 / std::pow(3.0, static_cast<float>(current_depth + 1));
  77. return random_generator->RandomDouble() < chance;
  78. };
  79. } // namespace
  80. FuzzerContext::FuzzerContext(RandomGenerator* random_generator,
  81. uint32_t min_fresh_id)
  82. : random_generator_(random_generator),
  83. next_fresh_id_(min_fresh_id),
  84. max_equivalence_class_size_for_data_synonym_fact_closure_(
  85. kDefaultMaxEquivalenceClassSizeForDataSynonymFactClosure),
  86. max_loop_control_partial_count_(kDefaultMaxLoopControlPartialCount),
  87. max_loop_control_peel_count_(kDefaultMaxLoopControlPeelCount),
  88. max_loop_limit_(kDefaultMaxLoopLimit),
  89. max_new_array_size_limit_(kDefaultMaxNewArraySizeLimit),
  90. go_deeper_in_constant_obfuscation_(
  91. kDefaultGoDeeperInConstantObfuscation) {
  92. chance_of_adding_access_chain_ =
  93. ChooseBetweenMinAndMax(kChanceOfAddingAccessChain);
  94. chance_of_adding_another_struct_field_ =
  95. ChooseBetweenMinAndMax(kChanceOfAddingAnotherStructField);
  96. chance_of_adding_array_or_struct_type_ =
  97. ChooseBetweenMinAndMax(kChanceOfAddingArrayOrStructType);
  98. chance_of_adding_dead_block_ =
  99. ChooseBetweenMinAndMax(kChanceOfAddingDeadBlock);
  100. chance_of_adding_dead_break_ =
  101. ChooseBetweenMinAndMax(kChanceOfAddingDeadBreak);
  102. chance_of_adding_dead_continue_ =
  103. ChooseBetweenMinAndMax(kChanceOfAddingDeadContinue);
  104. chance_of_adding_equation_instruction_ =
  105. ChooseBetweenMinAndMax(kChanceOfAddingEquationInstruction);
  106. chance_of_adding_global_variable_ =
  107. ChooseBetweenMinAndMax(kChanceOfAddingGlobalVariable);
  108. chance_of_adding_load_ = ChooseBetweenMinAndMax(kChanceOfAddingLoad);
  109. chance_of_adding_local_variable_ =
  110. ChooseBetweenMinAndMax(kChanceOfAddingLocalVariable);
  111. chance_of_adding_matrix_type_ =
  112. ChooseBetweenMinAndMax(kChanceOfAddingMatrixType);
  113. chance_of_adding_no_contraction_decoration_ =
  114. ChooseBetweenMinAndMax(kChanceOfAddingNoContractionDecoration);
  115. chance_of_adding_store_ = ChooseBetweenMinAndMax(kChanceOfAddingStore);
  116. chance_of_adding_vector_type_ =
  117. ChooseBetweenMinAndMax(kChanceOfAddingVectorType);
  118. chance_of_adjusting_branch_weights_ =
  119. ChooseBetweenMinAndMax(kChanceOfAdjustingBranchWeights);
  120. chance_of_adjusting_function_control_ =
  121. ChooseBetweenMinAndMax(kChanceOfAdjustingFunctionControl);
  122. chance_of_adjusting_loop_control_ =
  123. ChooseBetweenMinAndMax(kChanceOfAdjustingLoopControl);
  124. chance_of_adjusting_memory_operands_mask_ =
  125. ChooseBetweenMinAndMax(kChanceOfAdjustingMemoryOperandsMask);
  126. chance_of_adjusting_selection_control_ =
  127. ChooseBetweenMinAndMax(kChanceOfAdjustingSelectionControl);
  128. chance_of_calling_function_ =
  129. ChooseBetweenMinAndMax(kChanceOfCallingFunction);
  130. chance_of_choosing_struct_type_vs_array_type_ =
  131. ChooseBetweenMinAndMax(kChanceOfChoosingStructTypeVsArrayType);
  132. chance_of_constructing_composite_ =
  133. ChooseBetweenMinAndMax(kChanceOfConstructingComposite);
  134. chance_of_copying_object_ = ChooseBetweenMinAndMax(kChanceOfCopyingObject);
  135. chance_of_donating_additional_module_ =
  136. ChooseBetweenMinAndMax(kChanceOfDonatingAdditionalModule);
  137. chance_of_going_deeper_when_making_access_chain_ =
  138. ChooseBetweenMinAndMax(kChanceOfGoingDeeperWhenMakingAccessChain);
  139. chance_of_making_donor_livesafe_ =
  140. ChooseBetweenMinAndMax(kChanceOfMakingDonorLivesafe);
  141. chance_of_merging_blocks_ = ChooseBetweenMinAndMax(kChanceOfMergingBlocks);
  142. chance_of_moving_block_down_ =
  143. ChooseBetweenMinAndMax(kChanceOfMovingBlockDown);
  144. chance_of_obfuscating_constant_ =
  145. ChooseBetweenMinAndMax(kChanceOfObfuscatingConstant);
  146. chance_of_outlining_function_ =
  147. ChooseBetweenMinAndMax(kChanceOfOutliningFunction);
  148. chance_of_permuting_parameters_ =
  149. ChooseBetweenMinAndMax(kChanceOfPermutingParameters);
  150. chance_of_replacing_id_with_synonym_ =
  151. ChooseBetweenMinAndMax(kChanceOfReplacingIdWithSynonym);
  152. chance_of_splitting_block_ = ChooseBetweenMinAndMax(kChanceOfSplittingBlock);
  153. chance_of_toggling_access_chain_instruction_ =
  154. ChooseBetweenMinAndMax(kChanceOfTogglingAccessChainInstruction);
  155. }
  156. FuzzerContext::~FuzzerContext() = default;
  157. uint32_t FuzzerContext::GetFreshId() { return next_fresh_id_++; }
  158. bool FuzzerContext::ChooseEven() { return random_generator_->RandomBool(); }
  159. bool FuzzerContext::ChoosePercentage(uint32_t percentage_chance) {
  160. assert(percentage_chance <= 100);
  161. return random_generator_->RandomPercentage() < percentage_chance;
  162. }
  163. uint32_t FuzzerContext::ChooseBetweenMinAndMax(
  164. const std::pair<uint32_t, uint32_t>& min_max) {
  165. assert(min_max.first <= min_max.second);
  166. return min_max.first +
  167. random_generator_->RandomUint32(min_max.second - min_max.first + 1);
  168. }
  169. } // namespace fuzz
  170. } // namespace spvtools