Skip to content

fuzzing: don't return 1 from bb_fuzzer on unexpected exceptions (fixes #1224) - #1233

Merged
facontidavide merged 1 commit into
masterfrom
fix/1224-fuzzer-return-value
Oct 10, 2026
Merged

facontidavide merged 1 commit into
masterfrom
fix/1224-fuzzer-return-value

Conversation

@facontidavide

Copy link
Copy Markdown
Collaborator

Fixes #1224.

LLVMFuzzerTestOneInput in fuzzing/bb_fuzzer.cpp returned 1 for exceptions not listed in ExceptionFilter. libFuzzer only accepts 0 and -1; any other non-zero value is treated as -1, so the input is rejected from the corpus. nlohmann parse_error/type_error are not in the filter, so most inputs took this path.

Removing the return 1; lets the function fall through to return 0;. The message is still printed, and the other two fuzzers already return 0 on every path.

Verified locally with clang-21 libFuzzer, seed corpus fuzzing/corpus/bb_corpus, -runs=0:

corpus kept cov
master 1/5 650
this PR 5/5 1607

A 20k-execution run from the new corpus finished without findings (cov 2808).

🤖 Generated with Claude Code

…#1224)

libFuzzer only accepts 0 and -1 from LLVMFuzzerTestOneInput; any other
non-zero value is treated as -1 and the input is dropped from the corpus.
nlohmann parse/type errors are not in ExceptionFilter, so most inputs took
this path: on the seed corpus only 1 of 5 files was kept (cov 650); with
the fall-through to `return 0` all 5 are kept (cov 1607). The message is
still printed. The other two fuzzers already return 0 on every path.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@sonarqubecloud

Copy link
Copy Markdown

@facontidavide
facontidavide merged commit 7c46865 into master Oct 10, 2026
17 checks passed
@facontidavide
facontidavide deleted the fix/1224-fuzzer-return-value branch October 10, 2026 06:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

fuzzing/bb_fuzzer.cpp returns 1 from LLVMFuzzerTestOneInput

1 participant