blob: 66df98a66f5da71cfec7450097a0d978cea3e4b3 [file] [log] [blame]
Aaron Ballmanef116982015-01-29 16:58:29 +00001//===- FuzzerMutate.cpp - Mutate a test input -----------------------------===//
2//
3// The LLVM Compiler Infrastructure
4//
5// This file is distributed under the University of Illinois Open Source
6// License. See LICENSE.TXT for details.
7//
8//===----------------------------------------------------------------------===//
9// Mutate a test input.
10//===----------------------------------------------------------------------===//
11
Kostya Serebryanyf3424592015-05-22 22:35:31 +000012#include <cstring>
13
Aaron Ballmanef116982015-01-29 16:58:29 +000014#include "FuzzerInternal.h"
15
16namespace fuzzer {
17
Kostya Serebryany404c69f2015-07-24 01:06:40 +000018static char FlipRandomBit(char X, FuzzerRandomBase &Rand) {
19 int Bit = Rand(8);
Aaron Ballmanef116982015-01-29 16:58:29 +000020 char Mask = 1 << Bit;
21 char R;
22 if (X & (1 << Bit))
23 R = X & ~Mask;
24 else
25 R = X | Mask;
26 assert(R != X);
27 return R;
28}
29
Kostya Serebryany404c69f2015-07-24 01:06:40 +000030static char RandCh(FuzzerRandomBase &Rand) {
31 if (Rand.RandBool()) return Rand(256);
Aaron Ballmanef116982015-01-29 16:58:29 +000032 const char *Special = "!*'();:@&=+$,/?%#[]123ABCxyz-`~.";
Kostya Serebryany404c69f2015-07-24 01:06:40 +000033 return Special[Rand(sizeof(Special) - 1)];
Aaron Ballmanef116982015-01-29 16:58:29 +000034}
35
Kostya Serebryanyf3424592015-05-22 22:35:31 +000036// Mutates Data in place, returns new size.
Kostya Serebryany404c69f2015-07-24 01:06:40 +000037size_t Mutate(uint8_t *Data, size_t Size, size_t MaxSize,
38 FuzzerRandomBase &Rand) {
Kostya Serebryanyf3424592015-05-22 22:35:31 +000039 assert(MaxSize > 0);
40 assert(Size <= MaxSize);
41 if (Size == 0) {
42 for (size_t i = 0; i < MaxSize; i++)
Kostya Serebryany404c69f2015-07-24 01:06:40 +000043 Data[i] = RandCh(Rand);
Kostya Serebryanyf3424592015-05-22 22:35:31 +000044 return MaxSize;
Kostya Serebryany5b266a82015-02-04 19:10:20 +000045 }
Kostya Serebryanyf3424592015-05-22 22:35:31 +000046 assert(Size > 0);
Kostya Serebryany404c69f2015-07-24 01:06:40 +000047 size_t Idx = Rand(Size);
48 switch (Rand(3)) {
Aaron Ballmanef116982015-01-29 16:58:29 +000049 case 0:
Kostya Serebryanyf3424592015-05-22 22:35:31 +000050 if (Size > 1) {
51 // Erase Data[Idx].
52 memmove(Data + Idx, Data + Idx + 1, Size - Idx - 1);
53 Size = Size - 1;
Kostya Serebryany5b266a82015-02-04 19:10:20 +000054 }
Kostya Serebryany21172692015-02-19 18:21:12 +000055 [[clang::fallthrough]];
Aaron Ballmanef116982015-01-29 16:58:29 +000056 case 1:
Kostya Serebryanyf3424592015-05-22 22:35:31 +000057 if (Size < MaxSize) {
58 // Insert new value at Data[Idx].
59 memmove(Data + Idx + 1, Data + Idx, Size - Idx);
Kostya Serebryany404c69f2015-07-24 01:06:40 +000060 Data[Idx] = RandCh(Rand);
Aaron Ballmanef116982015-01-29 16:58:29 +000061 }
Kostya Serebryany404c69f2015-07-24 01:06:40 +000062 Data[Idx] = RandCh(Rand);
Aaron Ballmanef116982015-01-29 16:58:29 +000063 break;
Kostya Serebryanyf3424592015-05-22 22:35:31 +000064 case 2:
Kostya Serebryany404c69f2015-07-24 01:06:40 +000065 Data[Idx] = FlipRandomBit(Data[Idx], Rand);
Aaron Ballmanef116982015-01-29 16:58:29 +000066 break;
67 }
Kostya Serebryanyf3424592015-05-22 22:35:31 +000068 assert(Size > 0);
69 return Size;
Aaron Ballmanef116982015-01-29 16:58:29 +000070}
71
72} // namespace fuzzer