AFLplusplus / AFLplusplus/LibAFL

[libafl_libfuzzer] `libafl::feedbacks::map::MapNoveltiesMetadata not found` on `cargo fuzz coverage`

未关闭
#3,786 1 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
bug
主要语言
Rust
星标
2.6k
派生
481
平均合并
2 天 30 分钟
30 天内合并 PR
16

描述

**Describe the bug**

When using `libafl_libfuzzer` as a shim for `cargo fuzz`, there seems to be a bug that prevents computing the coverage of a corpus via `cargo fuzz coverage `. In particular, the error happens during corpus minimization (`merge=1`):

```
Failed to load initial corpus at [...]: Key: `libafl::feedbacks::map::MapNoveltiesMetadata not found` - not found
```

I am using LibAFL built from the main branch, commit aeb53e6821b4f5af0e7e062deb13c4b4152ce6b6.

**To Reproduce**

I have discovered the issue while playing with Rust fuzzers in a toy repository.

Steps to reproduce the behavior:
1. Make sure `cargo-fuzz` is installed (`cargo install cargo-fuzz`)
2. `git clone -b libfuzzer-libafl https://github.com/suidpit/rust-fuzz-garden`
3. Run `cargo fuzz coverage take_string` to generate the coverage of the pre-pushed corpus
4. Observe that the operation fails with the `MapNoveltiesMetadata not found` error.

**Expected behavior**

The `cargo fuzz coverage` command should successfully produce the coverage, rather than crashing.

**Additional context**

I think the issue lies in `libafl/crates/libafl_libfuzzer/runtime/src/merge.rs`, when the `MapObserver` for the `MinMapFeedback` is created:

```rust
let edges_observer =
MappedEdgeMapObserver::new(edges_observer, SizeTimeValueObserver::new(time))
```

because the `edges_observer` does not have `track_novelties()` enabled.

Is this a bug, or is there another intended way of profiling coverage?

贡献指南

打开贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。