blob: eec6475f9b8464cee515afa0b4af14a2f51e4dd5 [file] [log] [blame]
Aaron Ballmanef116982015-01-29 16:58:29 +00001//===- FuzzerMutate.cpp - Mutate a test input -----------------------------===//
2//
3// The LLVM Compiler Infrastructure
4//
5// This file is distributed under the University of Illinois Open Source
6// License. See LICENSE.TXT for details.
7//
8//===----------------------------------------------------------------------===//
9// Mutate a test input.
10//===----------------------------------------------------------------------===//
11
Kostya Serebryanyf3424592015-05-22 22:35:31 +000012#include <cstring>
13
Aaron Ballmanef116982015-01-29 16:58:29 +000014#include "FuzzerInternal.h"
15
16namespace fuzzer {
17
Kostya Serebryany404c69f2015-07-24 01:06:40 +000018static char FlipRandomBit(char X, FuzzerRandomBase &Rand) {
19 int Bit = Rand(8);
Aaron Ballmanef116982015-01-29 16:58:29 +000020 char Mask = 1 << Bit;
21 char R;
22 if (X & (1 << Bit))
23 R = X & ~Mask;
24 else
25 R = X | Mask;
26 assert(R != X);
27 return R;
28}
29
Kostya Serebryany404c69f2015-07-24 01:06:40 +000030static char RandCh(FuzzerRandomBase &Rand) {
31 if (Rand.RandBool()) return Rand(256);
Aaron Ballmanef116982015-01-29 16:58:29 +000032 const char *Special = "!*'();:@&=+$,/?%#[]123ABCxyz-`~.";
Kostya Serebryany404c69f2015-07-24 01:06:40 +000033 return Special[Rand(sizeof(Special) - 1)];
Aaron Ballmanef116982015-01-29 16:58:29 +000034}
35
Kostya Serebryany8ce74242015-08-01 01:42:51 +000036size_t Mutate_EraseByte(uint8_t *Data, size_t Size, size_t MaxSize,
37 FuzzerRandomBase &Rand) {
38 assert(Size);
39 if (Size == 1) return Size;
40 size_t Idx = Rand(Size);
41 // Erase Data[Idx].
42 memmove(Data + Idx, Data + Idx + 1, Size - Idx - 1);
43 return Size - 1;
44}
45
Kostya Serebryanyf3424592015-05-22 22:35:31 +000046// Mutates Data in place, returns new size.
Kostya Serebryany404c69f2015-07-24 01:06:40 +000047size_t Mutate(uint8_t *Data, size_t Size, size_t MaxSize,
48 FuzzerRandomBase &Rand) {
Kostya Serebryanyf3424592015-05-22 22:35:31 +000049 assert(MaxSize > 0);
50 assert(Size <= MaxSize);
51 if (Size == 0) {
52 for (size_t i = 0; i < MaxSize; i++)
Kostya Serebryany404c69f2015-07-24 01:06:40 +000053 Data[i] = RandCh(Rand);
Kostya Serebryanyf3424592015-05-22 22:35:31 +000054 return MaxSize;
Kostya Serebryany5b266a82015-02-04 19:10:20 +000055 }
Kostya Serebryanyf3424592015-05-22 22:35:31 +000056 assert(Size > 0);
Kostya Serebryany404c69f2015-07-24 01:06:40 +000057 size_t Idx = Rand(Size);
58 switch (Rand(3)) {
Kostya Serebryany8ce74242015-08-01 01:42:51 +000059 case 0: Size = Mutate_EraseByte(Data, Size, MaxSize, Rand); break;
Aaron Ballmanef116982015-01-29 16:58:29 +000060 case 1:
Kostya Serebryanyf3424592015-05-22 22:35:31 +000061 if (Size < MaxSize) {
62 // Insert new value at Data[Idx].
63 memmove(Data + Idx + 1, Data + Idx, Size - Idx);
Kostya Serebryany404c69f2015-07-24 01:06:40 +000064 Data[Idx] = RandCh(Rand);
Aaron Ballmanef116982015-01-29 16:58:29 +000065 }
Kostya Serebryany404c69f2015-07-24 01:06:40 +000066 Data[Idx] = RandCh(Rand);
Aaron Ballmanef116982015-01-29 16:58:29 +000067 break;
Kostya Serebryanyf3424592015-05-22 22:35:31 +000068 case 2:
Kostya Serebryany404c69f2015-07-24 01:06:40 +000069 Data[Idx] = FlipRandomBit(Data[Idx], Rand);
Aaron Ballmanef116982015-01-29 16:58:29 +000070 break;
71 }
Kostya Serebryanyf3424592015-05-22 22:35:31 +000072 assert(Size > 0);
73 return Size;
Aaron Ballmanef116982015-01-29 16:58:29 +000074}
75
76} // namespace fuzzer