Skip to content
File

Blob: src/workerd/api/fuzzilli.h

cpp64 lines
1#pragma once
2 
3#ifdef __linux__
4#include <workerd/jsg/jsg.h>
5 
6#include <assert.h>
7#include <fcntl.h>
8#include <stdio.h>
9#include <stdlib.h>
10#include <sys/mman.h>
11#include <sys/stat.h>
12#include <sys/wait.h>
13#include <unistd.h>
14 
15#include <cstdint>
16 
17#define SHM_SIZE 0x200000
18#define MAX_EDGES ((SHM_SIZE - 4) * 8)
19 
20struct shmem_data {
21 uint32_t num_edges;
22 unsigned char edges[];
23};
24 
25// NOLINTBEGIN(edgeworker-mutable-globals)
26extern struct shmem_data* __shmem;
27extern uint32_t* __edges_start;
28extern uint32_t* __edges_stop;
29// NOLINTEND(edgeworker-mutable-globals)
30 
31void __sanitizer_cov_reset_edgeguards();
32 
33//Fuzzilli sockets for communication
34#define REPRL_CRFD 100
35#define REPRL_CWFD 101
36#define REPRL_DRFD 102
37#define REPRL_DWFD 103
38#define USE(...) \
39 do { \
40 (void)(__VA_ARGS__); \
41 } while (false)
42 
43#define CHECK(condition) \
44 do { \
45 if (!(condition)) { \
46 fprintf(stderr, "Error: %s:%d: condition failed: %s\n", __FILE__, __LINE__, #condition); \
47 exit(EXIT_FAILURE); \
48 } \
49 } while (0)
50 
51void perform_wild_write();
52void sanitizer_cov_reset_edgeguards();
53uint32_t sanitizer_cov_count_discovered_edges();
54void sanitizer_cov_prepare_for_hardware_sandbox();
55void cov_init_builtins_edges(uint32_t num_edges);
56 
57void fuzzilli_handler(workerd::jsg::Lock& js, workerd::jsg::Arguments<workerd::jsg::Value>& args);
58 
59// TODO: this would only work with the profiler like in d8
60// void cov_update_builtins_basic_block_coverage(const std::vector<bool>& cov_map);
61// https://github.com/v8/v8/blob/a63b49495eac716c1a4ccbef57e2e1c7e98f27e4/src/d8/d8.cc#L7284-L7286
62//
63#endif