Repository navigation
fuzzing: don't return 1 from bb_fuzzer on unexpected exceptions (fixes #1224) - #1233
Merged
Merged
Conversation
…#1224) libFuzzer only accepts 0 and -1 from LLVMFuzzerTestOneInput; any other non-zero value is treated as -1 and the input is dropped from the corpus. nlohmann parse/type errors are not in ExceptionFilter, so most inputs took this path: on the seed corpus only 1 of 5 files was kept (cov 650); with the fall-through to `return 0` all 5 are kept (cov 1607). The message is still printed. The other two fuzzers already return 0 on every path. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Fixes #1224.
LLVMFuzzerTestOneInputinfuzzing/bb_fuzzer.cppreturned 1 for exceptions not listed inExceptionFilter. libFuzzer only accepts 0 and -1; any other non-zero value is treated as -1, so the input is rejected from the corpus. nlohmannparse_error/type_errorare not in the filter, so most inputs took this path.Removing the
return 1;lets the function fall through toreturn 0;. The message is still printed, and the other two fuzzers already return 0 on every path.Verified locally with clang-21 libFuzzer, seed corpus
fuzzing/corpus/bb_corpus,-runs=0:A 20k-execution run from the new corpus finished without findings (cov 2808).
🤖 Generated with Claude Code