AFLplusplus / AFLplusplus/fuzz-reachability

reachability run --lang c can use the wrong llvm-link and pick .conftest as the artifact

未关闭
#3 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
主要语言
Python
星标
20
派生
2
PR 合并指标
30 天内没有已合并 PR

描述

I started by putting together a PR for this, but realized I should have opened an issue first to document the problem clearly.

`reachability run --lang c --project examples/bluez/` hit two C/C++ acquisition bugs:
1. `get-bc` used an ambient `llvm-link` from `PATH` instead of the LLVM toolchain resolved by reachability.
2. Artifact auto-detection selected `.conftest.c.o` from `./configure` instead of a real built binary.

can be reproduced with [bluez repo](https://github.com/bluez/bluez) `reachability run --lang c --project examples/bluez/ --out bluez-reachable-run/`

First failure:

`llvm-link: ... error: Invalid attribute group entry (Producer: 'LLVM22.1.8' Reader: 'LLVM 18.1.3')`

After fixing that, second failure:

```
artifact: .conftest.c.o
error: analyzer failed (exit 1):
error: no entry symbol resolved. Requested: main LLVMFuzzerTestOneInput
```

## Expected
- C/C++ bitcode extraction should use the same resolved LLVM toolchain as reachability check-toolchain, including llvm-link.
- Artifact detection should ignore autotools probe files like .conftest* and prefer real executables over stray object files.

贡献指南

这个仓库没有索引到贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。