AFLplusplus / AFLplusplus/LibAFL

[libafl_libfuzzer] `libafl::feedbacks::map::MapNoveltiesMetadata not found` on `cargo fuzz coverage`

Abierto
#3,786 1 comentario 0 reacciones 0 asignados Ver en GitHub
bug
Lenguaje dominante
Rust
Estrellas
2.6k
Forks
481
Merge medio
2 d 30 min
PR fusionados (30 d)
16

Descripción

**Describe the bug**

When using `libafl_libfuzzer` as a shim for `cargo fuzz`, there seems to be a bug that prevents computing the coverage of a corpus via `cargo fuzz coverage `. In particular, the error happens during corpus minimization (`merge=1`):

```
Failed to load initial corpus at [...]: Key: `libafl::feedbacks::map::MapNoveltiesMetadata not found` - not found
```

I am using LibAFL built from the main branch, commit aeb53e6821b4f5af0e7e062deb13c4b4152ce6b6.

**To Reproduce**

I have discovered the issue while playing with Rust fuzzers in a toy repository.

Steps to reproduce the behavior:
1. Make sure `cargo-fuzz` is installed (`cargo install cargo-fuzz`)
2. `git clone -b libfuzzer-libafl https://github.com/suidpit/rust-fuzz-garden`
3. Run `cargo fuzz coverage take_string` to generate the coverage of the pre-pushed corpus
4. Observe that the operation fails with the `MapNoveltiesMetadata not found` error.

**Expected behavior**

The `cargo fuzz coverage` command should successfully produce the coverage, rather than crashing.

**Additional context**

I think the issue lies in `libafl/crates/libafl_libfuzzer/runtime/src/merge.rs`, when the `MapObserver` for the `MinMapFeedback` is created:

```rust
let edges_observer =
MappedEdgeMapObserver::new(edges_observer, SizeTimeValueObserver::new(time))
```

because the `edges_observer` does not have `track_novelties()` enabled.

Is this a bug, or is there another intended way of profiling coverage?

Guía de contribución

Abrir la guía de contribución

Evaluación

Este issue todavía no se ha evaluado.

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.