AFLplusplus / AFLplusplus/fuzz-reachability

reachability run --lang c can use the wrong llvm-link and pick .conftest as the artifact

オープン
#3 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る
主要言語
Python
スター
20
フォーク
2
PR マージ指標
30日以内にマージされた PR はありません

説明

I started by putting together a PR for this, but realized I should have opened an issue first to document the problem clearly.

`reachability run --lang c --project examples/bluez/` hit two C/C++ acquisition bugs:
1. `get-bc` used an ambient `llvm-link` from `PATH` instead of the LLVM toolchain resolved by reachability.
2. Artifact auto-detection selected `.conftest.c.o` from `./configure` instead of a real built binary.

can be reproduced with [bluez repo](https://github.com/bluez/bluez) `reachability run --lang c --project examples/bluez/ --out bluez-reachable-run/`

First failure:

`llvm-link: ... error: Invalid attribute group entry (Producer: 'LLVM22.1.8' Reader: 'LLVM 18.1.3')`

After fixing that, second failure:

```
artifact: .conftest.c.o
error: analyzer failed (exit 1):
error: no entry symbol resolved. Requested: main LLVMFuzzerTestOneInput
```

## Expected
- C/C++ bitcode extraction should use the same resolved LLVM toolchain as reachability check-toolchain, including llvm-link.
- Artifact detection should ignore autotools probe files like .conftest* and prefer real executables over stray object files.

コントリビューションガイド

このリポジトリのコントリビューションガイドは索引されていません

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。