3 ms·
If you're using clang, I can recommend starting with libFuzzer. It's pretty straightforward to use - basically add one C file with a function definition, which
by nuclx 8y ago
If you're using clang, I can recommend starting with libFuzzer. It's pretty straightforward to use - basically add one C file with a function definition, which gets called by the fuzzer engine with the test data. Add a bunch of compiler switches to the build, and you're done.
Note that for coverage-guided fuzzing you need a custom C/C++ build with some kind of coverage-tracking active.
See https://llvm.org/docs/LibFuzzer.html https://llvm.org/docs/LibFuzzer.html.