mirror of
https://github.com/reactos/syzkaller.git
synced 2024-11-27 21:30:33 +00:00
8365c3838d
Currently syzkaller uses per-call basic block (BB) coverage. This change implements edge (not-per-call) coverage. Edge coverage is more detailed than BB coverage as it captures not-taken branches, looping, etc. So it provides better feedback signal. This coverage is now called "signal" throughout the code. BB code coverage is also collected as it is required for visualisation. Not doing per-call coverage reduces corpus ~6-7x (from ~35K to ~5K), this has profound effect on fuzzing efficiency. |
||
---|---|---|
.. | ||
kcovtrace | ||
syz-benchcmp | ||
syz-crush | ||
syz-db | ||
syz-execprog | ||
syz-mutate | ||
syz-prog2c | ||
syz-report | ||
syz-repro | ||
syz-stress | ||
syz-symbolize | ||
syz-upgrade | ||
create-gce-image.sh | ||
create-image.sh |