AFLplusplus / AFLplusplus/fuzz-reachability

reachability run --lang c can use the wrong llvm-link and pick .conftest as the artifact

Open
#3 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Python
Stars
20
Forks
2
PR merge metrics
No merged PRs in 30d

Description

I started by putting together a PR for this, but realized I should have opened an issue first to document the problem clearly.

`reachability run --lang c --project examples/bluez/` hit two C/C++ acquisition bugs:
1. `get-bc` used an ambient `llvm-link` from `PATH` instead of the LLVM toolchain resolved by reachability.
2. Artifact auto-detection selected `.conftest.c.o` from `./configure` instead of a real built binary.

can be reproduced with [bluez repo](https://github.com/bluez/bluez) `reachability run --lang c --project examples/bluez/ --out bluez-reachable-run/`

First failure:

`llvm-link: ... error: Invalid attribute group entry (Producer: 'LLVM22.1.8' Reader: 'LLVM 18.1.3')`

After fixing that, second failure:

```
artifact: .conftest.c.o
error: analyzer failed (exit 1):
error: no entry symbol resolved. Requested: main LLVMFuzzerTestOneInput
```

## Expected
- C/C++ bitcode extraction should use the same resolved LLVM toolchain as reachability check-toolchain, including llvm-link.
- Artifact detection should ignore autotools probe files like .conftest* and prefer real executables over stray object files.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.