/src/immer/extra/fuzzer/array-gc.cpp
Line | Count | Source |
1 | | // |
2 | | // immer: immutable data structures for C++ |
3 | | // Copyright (C) 2016, 2017, 2018 Juan Pedro Bolivar Puente |
4 | | // |
5 | | // This software is distributed under the Boost Software License, Version 1.0. |
6 | | // See accompanying file LICENSE or copy at http://boost.org/LICENSE_1_0.txt |
7 | | // |
8 | | |
9 | | #include "fuzzer_gc_guard.hpp" |
10 | | #include "fuzzer_input.hpp" |
11 | | |
12 | | #include <immer/array.hpp> |
13 | | #include <immer/array_transient.hpp> |
14 | | #include <immer/heap/gc_heap.hpp> |
15 | | #include <immer/refcount/no_refcount_policy.hpp> |
16 | | |
17 | | #include <array> |
18 | | |
19 | | using gc_memory = immer::memory_policy<immer::heap_policy<immer::gc_heap>, |
20 | | immer::no_refcount_policy, |
21 | | immer::default_lock_policy, |
22 | | immer::gc_transience_policy, |
23 | | false>; |
24 | | |
25 | | extern "C" int LLVMFuzzerTestOneInput(const std::uint8_t* data, |
26 | | std::size_t size) |
27 | 961 | { |
28 | 961 | constexpr auto var_count = 4; |
29 | | |
30 | 961 | auto guard = fuzzer_gc_guard{}; |
31 | | |
32 | 961 | using array_t = immer::array<int, gc_memory>; |
33 | 961 | using transient_t = typename array_t::transient_type; |
34 | 961 | using size_t = std::uint8_t; |
35 | | |
36 | 961 | auto vs = std::array<array_t, var_count>{}; |
37 | 961 | auto ts = std::array<transient_t, var_count>{}; |
38 | | |
39 | 1.67M | auto is_valid_var = [&](auto idx) { return idx >= 0 && idx < var_count; }; |
40 | 6.02k | auto is_valid_index = [](auto& v) { |
41 | 61.6k | return [&](auto idx) { return idx >= 0 && idx < v.size(); }; array-gc.cpp:auto LLVMFuzzerTestOneInput::$_1::operator()<immer::array<int, immer::memory_policy<immer::heap_policy<immer::gc_heap>, immer::no_refcount_policy, immer::spinlock_policy, immer::gc_transience_policy, false, false> > >(immer::array<int, immer::memory_policy<immer::heap_policy<immer::gc_heap>, immer::no_refcount_policy, immer::spinlock_policy, immer::gc_transience_policy, false, false> >&) const::{lambda(auto:1)#1}::operator()<unsigned char>(unsigned char) const Line | Count | Source | 41 | 8.07k | return [&](auto idx) { return idx >= 0 && idx < v.size(); }; |
array-gc.cpp:auto LLVMFuzzerTestOneInput::$_1::operator()<immer::array_transient<int, immer::memory_policy<immer::heap_policy<immer::gc_heap>, immer::no_refcount_policy, immer::spinlock_policy, immer::gc_transience_policy, false, false> > >(immer::array_transient<int, immer::memory_policy<immer::heap_policy<immer::gc_heap>, immer::no_refcount_policy, immer::spinlock_policy, immer::gc_transience_policy, false, false> >&) const::{lambda(auto:1)#1}::operator()<unsigned char>(unsigned char) const Line | Count | Source | 41 | 53.5k | return [&](auto idx) { return idx >= 0 && idx < v.size(); }; |
|
42 | 6.02k | }; array-gc.cpp:auto LLVMFuzzerTestOneInput::$_1::operator()<immer::array<int, immer::memory_policy<immer::heap_policy<immer::gc_heap>, immer::no_refcount_policy, immer::spinlock_policy, immer::gc_transience_policy, false, false> > >(immer::array<int, immer::memory_policy<immer::heap_policy<immer::gc_heap>, immer::no_refcount_policy, immer::spinlock_policy, immer::gc_transience_policy, false, false> >&) const Line | Count | Source | 40 | 5.03k | auto is_valid_index = [](auto& v) { | 41 | 5.03k | return [&](auto idx) { return idx >= 0 && idx < v.size(); }; | 42 | 5.03k | }; |
array-gc.cpp:auto LLVMFuzzerTestOneInput::$_1::operator()<immer::array_transient<int, immer::memory_policy<immer::heap_policy<immer::gc_heap>, immer::no_refcount_policy, immer::spinlock_policy, immer::gc_transience_policy, false, false> > >(immer::array_transient<int, immer::memory_policy<immer::heap_policy<immer::gc_heap>, immer::no_refcount_policy, immer::spinlock_policy, immer::gc_transience_policy, false, false> >&) const Line | Count | Source | 40 | 986 | auto is_valid_index = [](auto& v) { | 41 | 986 | return [&](auto idx) { return idx >= 0 && idx < v.size(); }; | 42 | 986 | }; |
|
43 | 6.52k | auto is_valid_size = [](auto& v) { |
44 | 17.6k | return [&](auto idx) { return idx >= 0 && idx <= v.size(); }; array-gc.cpp:auto LLVMFuzzerTestOneInput::$_2::operator()<immer::array<int, immer::memory_policy<immer::heap_policy<immer::gc_heap>, immer::no_refcount_policy, immer::spinlock_policy, immer::gc_transience_policy, false, false> > >(immer::array<int, immer::memory_policy<immer::heap_policy<immer::gc_heap>, immer::no_refcount_policy, immer::spinlock_policy, immer::gc_transience_policy, false, false> >&) const::{lambda(auto:1)#1}::operator()<unsigned char>(unsigned char) const Line | Count | Source | 44 | 11.2k | return [&](auto idx) { return idx >= 0 && idx <= v.size(); }; |
array-gc.cpp:auto LLVMFuzzerTestOneInput::$_2::operator()<immer::array_transient<int, immer::memory_policy<immer::heap_policy<immer::gc_heap>, immer::no_refcount_policy, immer::spinlock_policy, immer::gc_transience_policy, false, false> > >(immer::array_transient<int, immer::memory_policy<immer::heap_policy<immer::gc_heap>, immer::no_refcount_policy, immer::spinlock_policy, immer::gc_transience_policy, false, false> >&) const::{lambda(auto:1)#1}::operator()<unsigned char>(unsigned char) const Line | Count | Source | 44 | 6.35k | return [&](auto idx) { return idx >= 0 && idx <= v.size(); }; |
|
45 | 6.52k | }; array-gc.cpp:auto LLVMFuzzerTestOneInput::$_2::operator()<immer::array<int, immer::memory_policy<immer::heap_policy<immer::gc_heap>, immer::no_refcount_policy, immer::spinlock_policy, immer::gc_transience_policy, false, false> > >(immer::array<int, immer::memory_policy<immer::heap_policy<immer::gc_heap>, immer::no_refcount_policy, immer::spinlock_policy, immer::gc_transience_policy, false, false> >&) const Line | Count | Source | 43 | 2.25k | auto is_valid_size = [](auto& v) { | 44 | 2.25k | return [&](auto idx) { return idx >= 0 && idx <= v.size(); }; | 45 | 2.25k | }; |
array-gc.cpp:auto LLVMFuzzerTestOneInput::$_2::operator()<immer::array_transient<int, immer::memory_policy<immer::heap_policy<immer::gc_heap>, immer::no_refcount_policy, immer::spinlock_policy, immer::gc_transience_policy, false, false> > >(immer::array_transient<int, immer::memory_policy<immer::heap_policy<immer::gc_heap>, immer::no_refcount_policy, immer::spinlock_policy, immer::gc_transience_policy, false, false> >&) const Line | Count | Source | 43 | 4.27k | auto is_valid_size = [](auto& v) { | 44 | 4.27k | return [&](auto idx) { return idx >= 0 && idx <= v.size(); }; | 45 | 4.27k | }; |
|
46 | | // limit doing immutable pushes on vectors that are too big already to |
47 | | // prevent timeouts |
48 | 1.56M | auto too_big = [](auto&& v) { return v.size() > (std::size_t{1} << 10); }; |
49 | 1.59M | return fuzzer_input{data, size}.run([&](auto& in) { |
50 | 1.59M | enum ops |
51 | 1.59M | { |
52 | 1.59M | op_transient, |
53 | 1.59M | op_persistent, |
54 | 1.59M | op_push_back, |
55 | 1.59M | op_update, |
56 | 1.59M | op_take, |
57 | 1.59M | op_push_back_mut, |
58 | 1.59M | op_update_mut, |
59 | 1.59M | op_take_mut, |
60 | 1.59M | }; |
61 | 1.59M | auto dst = read<char>(in, is_valid_var); |
62 | 1.59M | switch (read<char>(in)) { |
63 | 13.1k | case op_transient: { |
64 | 13.1k | auto src = read<char>(in, is_valid_var); |
65 | 13.1k | ts[dst] = vs[src].transient(); |
66 | 13.1k | break; |
67 | 0 | } |
68 | 3.07k | case op_persistent: { |
69 | 3.07k | auto src = read<char>(in, is_valid_var); |
70 | 3.07k | vs[dst] = ts[src].persistent(); |
71 | 3.07k | break; |
72 | 0 | } |
73 | 5.14k | case op_push_back: { |
74 | 5.14k | auto src = read<char>(in, is_valid_var); |
75 | 5.14k | if (!too_big(vs[src])) |
76 | 3.65k | vs[dst] = vs[src].push_back(42); |
77 | 5.14k | break; |
78 | 0 | } |
79 | 5.07k | case op_update: { |
80 | 5.07k | auto src = read<char>(in, is_valid_var); |
81 | 5.07k | auto idx = read<size_t>(in, is_valid_index(vs[src])); |
82 | 5.07k | vs[dst] = vs[src].update(idx, [](auto x) { return x + 1; }); |
83 | 5.07k | break; |
84 | 0 | } |
85 | 2.28k | case op_take: { |
86 | 2.28k | auto src = read<char>(in, is_valid_var); |
87 | 2.28k | auto idx = read<size_t>(in, is_valid_size(vs[src])); |
88 | 2.28k | vs[dst] = vs[src].take(idx); |
89 | 2.28k | break; |
90 | 0 | } |
91 | 1.56M | case op_push_back_mut: { |
92 | 1.56M | if (!too_big(vs[dst])) |
93 | 1.49M | ts[dst].push_back(13); |
94 | 1.56M | break; |
95 | 0 | } |
96 | 986 | case op_update_mut: { |
97 | 986 | auto idx = read<size_t>(in, is_valid_index(ts[dst])); |
98 | 986 | ts[dst].update(idx, [](auto x) { return x + 1; }); |
99 | 986 | break; |
100 | 0 | } |
101 | 4.27k | case op_take_mut: { |
102 | 4.27k | auto idx = read<size_t>(in, is_valid_size(ts[dst])); |
103 | 4.27k | ts[dst].take(idx); |
104 | 4.27k | break; |
105 | 0 | } |
106 | 1.52k | default: |
107 | 1.52k | break; |
108 | 1.59M | }; |
109 | 1.59M | return true; |
110 | 1.59M | }); |
111 | 961 | } |