AFLplusplus / AFLplusplus/LibAFL

[libafl_libfuzzer] `libafl::feedbacks::map::MapNoveltiesMetadata not found` on `cargo fuzz coverage`

Open
#3,786 1 comment 0 reactions 0 assignees View on GitHub
bug
Dominant language
Rust
Stars
2.6k
Forks
481
Avg merge
2d 30m
Merged PRs (30d)
16

Description

**Describe the bug**

When using `libafl_libfuzzer` as a shim for `cargo fuzz`, there seems to be a bug that prevents computing the coverage of a corpus via `cargo fuzz coverage `. In particular, the error happens during corpus minimization (`merge=1`):

```
Failed to load initial corpus at [...]: Key: `libafl::feedbacks::map::MapNoveltiesMetadata not found` - not found
```

I am using LibAFL built from the main branch, commit aeb53e6821b4f5af0e7e062deb13c4b4152ce6b6.

**To Reproduce**

I have discovered the issue while playing with Rust fuzzers in a toy repository.

Steps to reproduce the behavior:
1. Make sure `cargo-fuzz` is installed (`cargo install cargo-fuzz`)
2. `git clone -b libfuzzer-libafl https://github.com/suidpit/rust-fuzz-garden`
3. Run `cargo fuzz coverage take_string` to generate the coverage of the pre-pushed corpus
4. Observe that the operation fails with the `MapNoveltiesMetadata not found` error.

**Expected behavior**

The `cargo fuzz coverage` command should successfully produce the coverage, rather than crashing.

**Additional context**

I think the issue lies in `libafl/crates/libafl_libfuzzer/runtime/src/merge.rs`, when the `MapObserver` for the `MinMapFeedback` is created:

```rust
let edges_observer =
MappedEdgeMapObserver::new(edges_observer, SizeTimeValueObserver::new(time))
```

because the `edges_observer` does not have `track_novelties()` enabled.

Is this a bug, or is there another intended way of profiling coverage?

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.