3 ms·
The Rust ecosystem has a team that tries to fuzz as many crates (rust packages) as possible [1]. Unlike C/C++ and like Python, fuzzing Rust code is not really
by paulgdp 8y ago
The Rust ecosystem has a team that tries to fuzz as many crates (rust packages) as possible [1].
Unlike C/C++ and like Python, fuzzing Rust code is not really about finding memory bugs but more about finding logical errors [2].
To do this, a project has been set up with 83 (so far) targets fuzzing the public API of 48 (so far) important crates [3].
All those targets can be fuzzed using any of the three major native code feedback-based fuzzers (AFL, LibFuzzer, and Honggfuzz).
[1] https://github.com/rust-fuzz/targets https://github.com/rust-fuzz/targets
[2] see the trophy case: https://github.com/rust-fuzz/trophy-case https://github.com/rust-fuzz/trophy-case
[3] https://github.com/rust-fuzz/targets/blob/master/common/src/lib.rs https://github.com/rust-fuzz/targets/blob/master/common/src/...
Disclaimer: I'm a member of this team and the author of the honggfuzz crate that makes honggfuzz work with Rust code.
- cpeterso 8y agoAnd Cargo has good support for integrating Rust fuzzers into one's own projects: https://medium.com/@seasoned_sw/fuzz-testing-in-rust-with-cargo-fuzz-13b89feecc30 https://medium.com/@seasoned_sw/fuzz-testing-in-rust-with-ca... btw, I'm impressed that the rust-fuzz trophy list includes only one UAF, one uninitialized memory read, and no segfaults. :) https://github.com/rust-fuzz/trophy-case https://github.com/rust-fuzz/trophy-case