Skip to content

Avoid false fuzzing constraint failures at pointer boundaries - #818

Merged
Alan-Jowett merged 1 commit into
iovisor:mainfrom
Alan-Jowett:fix/fuzzer-boundary-constraints
Sep 30, 2026
Merged

Alan-Jowett merged 1 commit into
iovisor:mainfrom
Alan-Jowett:fix/fuzzer-boundary-constraints

Conversation

@Alan-Jowett

Copy link
Copy Markdown
Collaborator

The fuzzing job found a minimized crash in the constraint-checking oracle for an empty packet. Values equal to data_end, stack_end, or the context boundary are ambiguous: they can represent verifier pointers or numeric values produced by arithmetic. Leave those boundary values unconstrained while retaining concrete signed/unsigned constraints for other unknown values. Reproduced and fixed the minimized crash locally; a short constrained fuzz run also completes successfully.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings September 30, 2026 18:17

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The focused change correctly addresses boundary ambiguity without weakening constraints for other unknown values.

Review effort: Balanced
Findings: None

What changed in this PR

Prevents false fuzz-oracle failures by leaving ambiguous pointer-boundary values unconstrained.

Changes:

  • Exempts packet, stack, and context end values from scalar constraints.
  • Retains signed/unsigned constraints for other unknown values.
File Description
libfuzzer/​libfuzz_harness.cc Handles ambiguous boundary values during verifier constraint checks.

💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@coveralls

Copy link
Copy Markdown

Coverage Status

coverage: 78.594%. remained the same — Alan-Jowett:fix/fuzzer-boundary-constraints into iovisor:main

@Alan-Jowett
Alan-Jowett merged commit 9a8e73b into iovisor:main Sep 30, 2026
54 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants