1--- 2title: 'Fuzzing' 3linkTitle: 'Fuzzing' 4--- 5 6## Reproducing using `fuzz` 7 8We assume that you can [build Skia](/docs/user/build). Many fuzzes only 9reproduce when building with ASAN or MSAN; see 10[those instructions for more details](../xsan). 11 12When building, you should add the following args to BUILD.gn to make reproducing 13less machine- and platform- dependent: 14 15 skia_use_fontconfig=false 16 skia_use_freetype=true 17 skia_use_system_freetype2=false 18 skia_use_wuffs=true 19 skia_enable_skottie=true 20 skia_enable_fontmgr_custom_directory=false 21 skia_enable_fontmgr_custom_embedded=false 22 skia_enable_fontmgr_custom_empty=true 23 24All that is needed to reproduce a fuzz downloaded from ClusterFuzz or oss-fuzz 25is to run something like: 26 27 out/ASAN/fuzz -b /path/to/downloaded/testcase 28 29The fuzz binary will try its best to guess what the type/name should be based on 30the name of the testcase. Manually providing type and name is also supported, 31like: 32 33 out/ASAN/fuzz -t filter_fuzz -b /path/to/downloaded/testcase 34 out/ASAN/fuzz -t api -n RasterN32Canvas -b /path/to/downloaded/testcase 35 36To enumerate all supported types and names, run the following: 37 38 out/ASAN/fuzz --help # will list all types 39 out/ASAN/fuzz -t api # will list all names 40 41If the crash does not show up, try to add the flag --loops: 42 43 out/ASAN/fuzz -b /path/to/downloaded/testcase --loops <times-to-run> 44 45## Writing fuzzers with libfuzzer 46 47libfuzzer is an easy way to write new fuzzers, and how we run them on oss-fuzz. 48Your fuzzer entry point should implement this API: 49 50 extern "C" int LLVMFuzzerTestOneInput(const uint8_t*, size_t); 51 52First install Clang and libfuzzer, e.g. 53 54 sudo apt install clang-10 libc++-10-dev libfuzzer-10-dev 55 56You should now be able to use `-fsanitize=fuzzer` with Clang. 57 58Set up GN args to use libfuzzer: 59 60 cc = "clang-10" 61 cxx = "clang++-10" 62 sanitize = "fuzzer" 63 extra_cflags = [ "-O1" ] # Or whatever you want. 64 ... 65 66Build Skia and your fuzzer entry point: 67 68 ninja -C out/libfuzzer skia 69 clang++-10 -I. -O1 -fsanitize=fuzzer fuzz/oss_fuzz/whatever.cpp out/libfuzzer/libskia.a 70 71Run your new fuzzer binary 72 73 ./a.out 74 75## Fuzzing Defines 76 77There are some defines that can help guide a fuzzer to be more productive (e.g. 78avoid OOMs, avoid unnecessarily slow code). 79 80 // Required for fuzzing with afl-fuzz to prevent OOMs from adding noise. 81 SK_BUILD_FOR_AFL_FUZZ 82 83 // Required for fuzzing with libfuzzer 84 SK_BUILD_FOR_LIBFUZZER 85 86 // This define adds in guards to abort when we think some code path will take a long time or 87 // use a lot of RAM. It is set by default when either of the above defines are set. 88 SK_BUILD_FOR_FUZZER 89