summary refs log tree commit diff stats
path: root/scripts/oss-fuzz/reorder_fuzzer_qtest_trace.py
diff options
context:
space:
mode:
authorAlexander Bulekov <alxndr@bu.edu>2020-10-23 11:07:31 -0400
committerThomas Huth <thuth@redhat.com>2020-10-24 07:43:48 +0200
commitda9bf5319838c193f92a3444bd3258b32c606980 (patch)
treec184dc511cb05553bc409237dc244556ed9e169c /scripts/oss-fuzz/reorder_fuzzer_qtest_trace.py
parentfb5ef4eeecd88b583d5a6dc8f7dc217179cbfc98 (diff)
downloadfocaccia-qemu-da9bf5319838c193f92a3444bd3258b32c606980.tar.gz
focaccia-qemu-da9bf5319838c193f92a3444bd3258b32c606980.zip
fuzz: Add generic virtual-device fuzzer
This is a generic fuzzer designed to fuzz a virtual device's
MemoryRegions, as long as they exist within the Memory or Port IO (if it
exists) AddressSpaces. The fuzzer's input is interpreted into a sequence
of qtest commands (outb, readw, etc). The interpreted commands are
separated by a magic seaparator, which should be easy for the fuzzer to
guess. Without ASan, the separator can be specified as a "dictionary
value" using the -dict argument (see libFuzzer documentation).

Reviewed-by: Darren Kenny <darren.kenny@oracle.com>
Signed-off-by: Alexander Bulekov <alxndr@bu.edu>
Message-Id: <20201023150746.107063-3-alxndr@bu.edu>
Signed-off-by: Thomas Huth <thuth@redhat.com>
Diffstat (limited to 'scripts/oss-fuzz/reorder_fuzzer_qtest_trace.py')
0 files changed, 0 insertions, 0 deletions