feat(verify): save and replay fuzz corpora
Assisted-by: GLM 5.3 Flash
This commit is contained in:
@@ -79,6 +79,8 @@ Assemble FILE, map it into executable memory, and run dynamic checks.
|
||||
| `--buf <spec>` | Buffer spec for `--call`: `name:size:pattern[,name:size:pattern]` |
|
||||
| `--args <spec>` | Scalar args for `--call`: `name=value[,name=value]` (decimal or `0x` hex) |
|
||||
| `--repeat <n>` | Number of times to repeat a `--call` invocation (default: 1) |
|
||||
| `--save-corpus <dir>` | With `--fuzz`: write each failing input to DIR as replayable JSON |
|
||||
| `--replay <dir>` | Re-run saved corpus entries (JSON in DIR), one child process per entry |
|
||||
|
||||
The `--fuzz` mode runs each function in a subprocess; a partial function
|
||||
(e.g. a decoder that faults on malformed input) is reported as
|
||||
@@ -92,6 +94,12 @@ offsets, and prints the arg block before and after the call, showing
|
||||
return values and any output written to the buffers. Scalar parameters
|
||||
are supplied with `--args` (decimal, or `0x` hex) at their ABI0 offsets.
|
||||
|
||||
The `--save-corpus` mode records the logical arguments (buffer contents and
|
||||
scalars, not raw pointers) of every failing fuzz input as JSON. `--replay`
|
||||
rebuilds a live argument block from each entry and calls it in its own child
|
||||
process, reporting `OK`, `CRASH (reproduced)` or `FAIL` per entry and
|
||||
exiting non-zero when any entry fails.
|
||||
|
||||
## `gasm debug [--func <name>] [--buf spec] [--script file] <file.s>`
|
||||
|
||||
Interactive debugger for JIT-assembled functions (amd64, arm64, riscv64,
|
||||
|
||||
Reference in New Issue
Block a user