blob: 53f1ea3fb5c18c93864faf41c3b38026cde51e55 [file] [log] [blame]
Jaggerbaa20ea2015-09-06 01:12:08 +02001/*
2 *
3 * honggfuzz - display statistics
4 * -----------------------------------------
5 *
6 * Author: Robert Swiecki <swiecki@google.com>
7 *
8 * Copyright 2010-2015 by Google Inc. All Rights Reserved.
9 *
10 * Licensed under the Apache License, Version 2.0 (the "License"); you may
11 * not use this file except in compliance with the License. You may obtain
12 * a copy of the License at
13 *
14 * http://www.apache.org/licenses/LICENSE-2.0
15 *
16 * Unless required by applicable law or agreed to in writing, software
17 * distributed under the License is distributed on an "AS IS" BASIS,
18 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or
19 * implied. See the License for the specific language governing
20 * permissions and limitations under the License.
21 *
22 */
23
24#define _WITH_DPRINTF
25
26#include "common.h"
27#include "display.h"
28
29#include <string.h>
Jagger7acbf2e2015-09-06 20:02:32 +020030#include <stdarg.h>
Jaggerbaa20ea2015-09-06 01:12:08 +020031#include <stdio.h>
32#include <unistd.h>
Anestis Bechtsoudise83ec672015-12-26 20:28:28 +020033#include <inttypes.h>
Jaggerbaa20ea2015-09-06 01:12:08 +020034
35#include "log.h"
Robert Swiecki81c6a0d2015-09-08 15:43:20 +020036#include "util.h"
Jaggerbaa20ea2015-09-06 01:12:08 +020037
Jaggerbaa20ea2015-09-06 01:12:08 +020038#define ESC_CLEAR "\033[H\033[2J"
39#define ESC_NAV(x,y) "\033["#x";"#y"H"
Jagger76b11bc2015-09-06 02:11:44 +020040#define ESC_BOLD "\033[1m"
41#define ESC_RESET "\033[0m"
Jaggerbaa20ea2015-09-06 01:12:08 +020042
Robert Swiecki508b19a2016-08-31 17:26:45 +020043#if defined(_HF_ARCH_LINUX)
44#define _HF_MONETARY_MOD "'"
45#else
46#define _HF_MONETARY_MOD ""
47#endif
48
Jagger7acbf2e2015-09-06 20:02:32 +020049static void display_put(const char *fmt, ...)
50{
Jagger7acbf2e2015-09-06 20:02:32 +020051 va_list args;
52 va_start(args, fmt);
Jaggerff4a4202016-03-22 12:41:41 +010053 vdprintf(STDOUT_FILENO, fmt, args);
Jagger7acbf2e2015-09-06 20:02:32 +020054 va_end(args);
Jagger7acbf2e2015-09-06 20:02:32 +020055}
56
Jaggera7d893d2016-08-30 23:43:28 +020057static void display_printKMG(uint64_t val)
58{
59 if (val >= 1000000000UL) {
60 display_put(" [%.2lfG]", (double)val / 1000000.0);
61 } else if (val >= 1000000UL) {
62 display_put(" [%.2lfM]", (double)val / 1000000.0);
63 } else if (val >= 1000UL) {
64 display_put(" [%.2lfk]", (double)val / 1000.0);
65 }
66}
67
Robert Swiecki7353a8d2015-09-08 15:53:59 +020068static void display_displayLocked(honggfuzz_t * hfuzz)
Jaggerbaa20ea2015-09-06 01:12:08 +020069{
wifiadmin4aef9572016-05-15 11:02:07 +080070 unsigned long elapsed_second = (unsigned long)(time(NULL) - hfuzz->timeStart);
wifiadmin4aef9572016-05-15 11:02:07 +080071
Jagger286413c2016-05-15 14:58:24 +020072 unsigned int day, hour, min, second;
73 char time_elapsed_str[64];
74
75 if (elapsed_second < 24 * 3600) {
76 hour = elapsed_second / 3600;
77 min = (elapsed_second - 3600 * hour) / 60;
78 second = elapsed_second - hour * 3600 - min * 60;
79 snprintf(time_elapsed_str, sizeof(time_elapsed_str), "%u hrs %u min %u sec", hour, min,
80 second);
81 } else {
82 day = elapsed_second / 24 / 3600;
83 elapsed_second = elapsed_second - day * 24 * 3600;
84 hour = elapsed_second / 3600;
85 min = (elapsed_second - 3600 * hour) / 60;
86 second = elapsed_second - hour * 3600 - min * 60;
87 snprintf(time_elapsed_str, sizeof(time_elapsed_str), "%u days %u hrs %u min %u sec", day,
88 hour, min, second);
wifiadmin4aef9572016-05-15 11:02:07 +080089 }
Robert Swiecki81c6a0d2015-09-08 15:43:20 +020090
Jaggerd34417d2016-03-16 01:26:54 +010091 size_t curr_exec_cnt = ATOMIC_GET(hfuzz->mutationsCnt);
Robert Swiecki81c6a0d2015-09-08 15:43:20 +020092 /*
93 * We increase the mutation counter unconditionally in threads, but if it's
94 * above hfuzz->mutationsMax we don't really execute the fuzzing loop.
95 * Therefore at the end of fuzzing, the mutation counter might be higher
96 * than hfuzz->mutationsMax
97 */
98 if (hfuzz->mutationsMax > 0 && curr_exec_cnt > hfuzz->mutationsMax) {
99 curr_exec_cnt = hfuzz->mutationsMax;
100 }
Robert Swiecki4eab0b52016-07-26 16:56:38 +0200101 float exeProgress = 0.0f;
102 if (hfuzz->mutationsMax > 0) {
103 exeProgress = ((float)curr_exec_cnt * 100 / hfuzz->mutationsMax);
104 }
105
Jaggerbaa20ea2015-09-06 01:12:08 +0200106 static size_t prev_exec_cnt = 0UL;
Jaggerbaa20ea2015-09-06 01:12:08 +0200107 uintptr_t exec_per_sec = curr_exec_cnt - prev_exec_cnt;
108 prev_exec_cnt = curr_exec_cnt;
109
Robert Swiecki0212d692016-08-30 16:45:33 +0200110 MX_SCOPED_LOCK(logMutexGet());
111
Jagger7acbf2e2015-09-06 20:02:32 +0200112 display_put("%s", ESC_CLEAR);
Robert Swiecki837c1d42016-04-12 12:01:00 +0200113 display_put("==================================== STAT ====================================\n");
Jaggerbaa20ea2015-09-06 01:12:08 +0200114
Robert Swiecki508b19a2016-08-31 17:26:45 +0200115 display_put("Iterations: " ESC_BOLD "%" _HF_MONETARY_MOD "zu" ESC_RESET, curr_exec_cnt);
Jaggera7d893d2016-08-30 23:43:28 +0200116 display_printKMG(curr_exec_cnt);
Jaggerbaa20ea2015-09-06 01:12:08 +0200117 if (hfuzz->mutationsMax) {
Robert Swiecki4eab0b52016-07-26 16:56:38 +0200118 display_put(" (out of: " ESC_BOLD "%zu" ESC_RESET " [" ESC_BOLD "%.2f%%" ESC_RESET "])",
119 hfuzz->mutationsMax, exeProgress);
Jaggerbaa20ea2015-09-06 01:12:08 +0200120 }
Jaggerbcd57852015-09-06 23:10:44 +0200121 display_put("\n");
Jagger56ed7642015-09-06 04:06:57 +0200122
Robert Swiecki81c6a0d2015-09-08 15:43:20 +0200123 char start_time_str[128];
124 util_getLocalTime("%F %T", start_time_str, sizeof(start_time_str), hfuzz->timeStart);
Jagger59b4d892016-08-30 23:49:19 +0200125 display_put("Run time: " ESC_BOLD "%s" ESC_RESET " (since: " ESC_BOLD "%s" ESC_RESET ")\n",
126 time_elapsed_str, start_time_str);
Jaggerbaa20ea2015-09-06 01:12:08 +0200127
Jagger7acbf2e2015-09-06 20:02:32 +0200128 display_put("Input file/dir: '" ESC_BOLD "%s" ESC_RESET "'\n", hfuzz->inputFile);
Robert Swiecki72d2bef2016-01-19 14:39:26 +0100129 display_put("Fuzzed cmd: '" ESC_BOLD "%s" ESC_RESET "'\n", hfuzz->cmdline_txt);
Jagger247c3b42016-03-21 23:24:05 +0100130 if (hfuzz->linux.pid > 0) {
Anestis Bechtsoudis7c88d7a2016-02-09 17:55:38 +0200131 display_put("Remote cmd [" ESC_BOLD "%d" ESC_RESET "]: '" ESC_BOLD "%s" ESC_RESET "'\n",
Jagger247c3b42016-03-21 23:24:05 +0100132 hfuzz->linux.pid, hfuzz->linux.pidCmd);
Anestis Bechtsoudis7c88d7a2016-02-09 17:55:38 +0200133 }
Jaggerbaa20ea2015-09-06 01:12:08 +0200134
Jagger7acbf2e2015-09-06 20:02:32 +0200135 display_put("Fuzzing threads: " ESC_BOLD "%zu" ESC_RESET "\n", hfuzz->threadsMax);
Robert Swieckiba08c892016-08-31 17:31:23 +0200136 display_put("%s per second: " ESC_BOLD "% " _HF_MONETARY_MOD "zu" ESC_RESET " (avg: " ESC_BOLD
137 "%" _HF_MONETARY_MOD "zu" ESC_RESET ")\n", hfuzz->persistent ? "Rounds" : "Execs",
138 exec_per_sec, elapsed_second ? (curr_exec_cnt / elapsed_second) : 0);
Jaggerbaa20ea2015-09-06 01:12:08 +0200139
Anestis Bechtsoudis46ea10e2015-11-07 18:16:25 +0200140 /* If dry run, print also the input file count */
Robert Swieckia96d78d2016-03-14 16:50:50 +0100141 if (hfuzz->origFlipRate == 0.0L && hfuzz->useVerifier) {
Jagger55a54a02016-08-31 21:41:05 +0200142 display_put("Input Files: '" ESC_BOLD "%" _HF_MONETARY_MOD "zu" ESC_RESET "'\n",
143 hfuzz->fileCnt);
Anestis Bechtsoudis46ea10e2015-11-07 18:16:25 +0200144 }
145
Anestis Bechtsoudisd59af692015-09-21 15:15:05 +0300146 display_put("Crashes: " ESC_BOLD "%zu" ESC_RESET " (unique: " ESC_BOLD "%zu" ESC_RESET
Anestis Bechtsoudis79b799e2015-11-01 00:02:25 +0200147 ", blacklist: " ESC_BOLD "%zu" ESC_RESET ", verified: " ESC_BOLD "%zu" ESC_RESET
Anestis Bechtsoudisbfcba122016-04-28 10:55:20 +0300148 ")\n", ATOMIC_GET(hfuzz->crashesCnt),
Jaggerd34417d2016-03-16 01:26:54 +0100149 ATOMIC_GET(hfuzz->uniqueCrashesCnt),
150 ATOMIC_GET(hfuzz->blCrashesCnt), ATOMIC_GET(hfuzz->verifiedCrashesCnt));
Jagger55a54a02016-08-31 21:41:05 +0200151 display_put("Timeouts (%" _HF_MONETARY_MOD "zu sec): " ESC_BOLD "%" _HF_MONETARY_MOD "zu"
152 ESC_RESET "\n", hfuzz->tmOut, ATOMIC_GET(hfuzz->timeoutedCnt));
Jaggerbaa20ea2015-09-06 01:12:08 +0200153
Anestis Bechtsoudis02b99be2015-12-27 11:53:01 +0200154 /* Feedback data sources are enabled. Start with common headers. */
155 if (hfuzz->dynFileMethod != _HF_DYNFILE_NONE || hfuzz->useSanCov) {
Robert Swieckiba08c892016-08-31 17:31:23 +0200156 display_put("File corpus size: " ESC_BOLD "%" _HF_MONETARY_MOD "zu" ESC_RESET "\n",
157 hfuzz->dynfileqCnt);
Robert Swiecki53958402015-09-08 16:20:50 +0200158 display_put("Coverage (max):\n");
Jaggerbaa20ea2015-09-06 01:12:08 +0200159 }
Anestis Bechtsoudis02b99be2015-12-27 11:53:01 +0200160
161 /* HW perf specific counters */
Robert Swiecki53958402015-09-08 16:20:50 +0200162 if (hfuzz->dynFileMethod & _HF_DYNFILE_INSTR_COUNT) {
Robert Swieckiba08c892016-08-31 17:31:23 +0200163 display_put(" - instructions: " ESC_BOLD "%" _HF_MONETARY_MOD PRIu64 ESC_RESET "\n",
Jagger247c3b42016-03-21 23:24:05 +0100164 ATOMIC_GET(hfuzz->linux.hwCnts.cpuInstrCnt));
Robert Swiecki53958402015-09-08 16:20:50 +0200165 }
166 if (hfuzz->dynFileMethod & _HF_DYNFILE_BRANCH_COUNT) {
Robert Swieckiba08c892016-08-31 17:31:23 +0200167 display_put(" - branches: " ESC_BOLD "%" _HF_MONETARY_MOD PRIu64 ESC_RESET "\n",
Jagger247c3b42016-03-21 23:24:05 +0100168 ATOMIC_GET(hfuzz->linux.hwCnts.cpuBranchCnt));
Robert Swiecki53958402015-09-08 16:20:50 +0200169 }
Jagger3abc5602016-02-04 00:53:43 +0100170 if (hfuzz->dynFileMethod & _HF_DYNFILE_BTS_BLOCK) {
Robert Swieckiba08c892016-08-31 17:31:23 +0200171 display_put(" - BTS blocks: " ESC_BOLD "%" _HF_MONETARY_MOD PRIu64 ESC_RESET "\n",
Jagger247c3b42016-03-21 23:24:05 +0100172 ATOMIC_GET(hfuzz->linux.hwCnts.bbCnt));
Robert Swiecki53958402015-09-08 16:20:50 +0200173 }
Jagger3abc5602016-02-04 00:53:43 +0100174 if (hfuzz->dynFileMethod & _HF_DYNFILE_BTS_EDGE) {
Robert Swieckiba08c892016-08-31 17:31:23 +0200175 display_put(" - BTS edges: " ESC_BOLD "%" _HF_MONETARY_MOD PRIu64 ESC_RESET "\n",
Jagger247c3b42016-03-21 23:24:05 +0100176 ATOMIC_GET(hfuzz->linux.hwCnts.bbCnt));
Robert Swiecki53958402015-09-08 16:20:50 +0200177 }
Jaggera2addb62016-02-04 03:53:53 +0100178 if (hfuzz->dynFileMethod & _HF_DYNFILE_IPT_BLOCK) {
Robert Swieckiba08c892016-08-31 17:31:23 +0200179 display_put(" - PT blocks: " ESC_BOLD "%" _HF_MONETARY_MOD PRIu64 ESC_RESET "\n",
Jagger247c3b42016-03-21 23:24:05 +0100180 ATOMIC_GET(hfuzz->linux.hwCnts.bbCnt));
Jaggera2addb62016-02-04 03:53:53 +0100181 }
Robert Swiecki53958402015-09-08 16:20:50 +0200182 if (hfuzz->dynFileMethod & _HF_DYNFILE_CUSTOM) {
Robert Swieckiba08c892016-08-31 17:31:23 +0200183 display_put(" - custom counter: " ESC_BOLD "%" _HF_MONETARY_MOD PRIu64 ESC_RESET "\n",
Jagger247c3b42016-03-21 23:24:05 +0100184 ATOMIC_GET(hfuzz->linux.hwCnts.customCnt));
Robert Swiecki53958402015-09-08 16:20:50 +0200185 }
Jaggerb01aaae2016-08-20 03:35:38 +0200186 if (hfuzz->dynFileMethod & _HF_DYNFILE_SOFT) {
Robert Swieckiba08c892016-08-31 17:31:23 +0200187 display_put(" - functions seen: " ESC_BOLD "%" _HF_MONETARY_MOD PRIu64 ESC_RESET "\n",
Jaggerb01aaae2016-08-20 03:35:38 +0200188 ATOMIC_GET(hfuzz->linux.hwCnts.softCnt));
189 }
Anestis Bechtsoudis02b99be2015-12-27 11:53:01 +0200190
191 /* Sanitizer coverage specific counters */
Anestis Bechtsoudise83ec672015-12-26 20:28:28 +0200192 if (hfuzz->useSanCov) {
Jaggerd34417d2016-03-16 01:26:54 +0100193 uint64_t hitBB = ATOMIC_GET(hfuzz->sanCovCnts.hitBBCnt);
Jagger66e54602016-08-17 01:07:24 +0200194 uint64_t totalBB = ATOMIC_GET(hfuzz->sanCovCnts.totalBBCnt);
195 float covPer = totalBB ? (((float)hitBB * 100) / totalBB) : 0.0;
Jagger55a54a02016-08-31 21:41:05 +0200196 display_put(" - total hit #bb: " ESC_BOLD "%" _HF_MONETARY_MOD PRIu64 ESC_RESET
197 " (coverage " ESC_BOLD "%.2f%%" ESC_RESET ")\n", hitBB, covPer);
Jaggered282272016-08-31 20:00:33 +0200198 display_put(" - total #dso: " ESC_BOLD "%" _HF_MONETARY_MOD PRIu64 ESC_RESET
Jagger66e54602016-08-17 01:07:24 +0200199 " (instrumented only)\n", ATOMIC_GET(hfuzz->sanCovCnts.iDsoCnt));
Jaggered282272016-08-31 20:00:33 +0200200 display_put(" - discovered #bb: " ESC_BOLD "%" _HF_MONETARY_MOD PRIu64 ESC_RESET
Jagger66e54602016-08-17 01:07:24 +0200201 " (new from input seed)\n", ATOMIC_GET(hfuzz->sanCovCnts.newBBCnt));
Jaggered282272016-08-31 20:00:33 +0200202 display_put(" - crashes: " ESC_BOLD "%" _HF_MONETARY_MOD PRIu64 ESC_RESET "\n",
Jagger66e54602016-08-17 01:07:24 +0200203 ATOMIC_GET(hfuzz->sanCovCnts.crashesCnt));
Anestis Bechtsoudise83ec672015-12-26 20:28:28 +0200204 }
Robert Swiecki837c1d42016-04-12 12:01:00 +0200205 display_put("==================================== LOGS ====================================\n");
Jaggerbaa20ea2015-09-06 01:12:08 +0200206}
Robert Swiecki7353a8d2015-09-08 15:53:59 +0200207
208extern void display_display(honggfuzz_t * hfuzz)
209{
Robert Swiecki7353a8d2015-09-08 15:53:59 +0200210 display_displayLocked(hfuzz);
Robert Swiecki7353a8d2015-09-08 15:53:59 +0200211}