Fix centipede:coverage_test under ubsan. This is done by disabling coverage instrumentation for input printing in test_fuzz_target, which introduces coverage noise under ubsan. PiperOrigin-RevId: 986183783
diff --git a/centipede/control_flow_test.cc b/centipede/control_flow_test.cc index 3fe2282..0c687c7 100644 --- a/centipede/control_flow_test.cc +++ b/centipede/control_flow_test.cc
@@ -313,7 +313,7 @@ has_llvm_fuzzer_test_one_input = true; EXPECT_THAT( symbols.location(i), - testing::HasSubstr("centipede/testing/test_fuzz_target.cc:73")); + testing::HasSubstr("centipede/testing/test_fuzz_target.cc:84")); } } EXPECT_TRUE(has_llvm_fuzzer_test_one_input);
diff --git a/centipede/testing/centipede_main_test.sh b/centipede/testing/centipede_main_test.sh index a74e8ad..53e5919 100755 --- a/centipede/testing/centipede_main_test.sh +++ b/centipede/testing/centipede_main_test.sh
@@ -74,7 +74,7 @@ --symbolizer_path="${LLVM_SYMBOLIZER}" | tee "${LOG}" fuzztest::internal::assert_regex_in_file 'Custom mutator detected; will use it' "${LOG}" # Note: the test assumes LLVMFuzzerTestOneInput is defined on a specific line. - fuzztest::internal::assert_regex_in_file "FUNC: LLVMFuzzerTestOneInput .*testing/test_fuzz_target.cc:73" "${LOG}" + fuzztest::internal::assert_regex_in_file "FUNC: LLVMFuzzerTestOneInput .*testing/test_fuzz_target.cc:84" "${LOG}" fuzztest::internal::assert_regex_in_file "EDGE: LLVMFuzzerTestOneInput .*testing/test_fuzz_target.cc" "${LOG}" echo "============ ${FUNC}: add func1/func2-A inputs to the corpus."
diff --git a/centipede/testing/test_fuzz_target.cc b/centipede/testing/test_fuzz_target.cc index 37ad23d..99217b7 100644 --- a/centipede/testing/test_fuzz_target.cc +++ b/centipede/testing/test_fuzz_target.cc
@@ -62,6 +62,17 @@ static int non_cost_global[10]; static const int const_global[10] = {0, 1, 2, 3, 4, 5, 6, 7, 8, 9}; +__attribute__((noinline, no_sanitize("coverage"))) void PrintInput( + const uint8_t* data, size_t size) { + printf("{"); + for (size_t i = 0; i < size; i++) { + // This loop generates different coverage counters + // depending on the number of iterations. + printf("%02x%s", (int)data[i], i + 1 == size ? "" : ", "); + } + printf("}\n"); +} + // See https://llvm.org/docs/LibFuzzer.html#fuzz-target. // control_flow_test.cc and centipede_main_test.sh verify the exact line where // LLVMFuzzerTestOneInput is declared. @@ -72,13 +83,7 @@ static volatile void *ptr_sink = nullptr; extern "C" int LLVMFuzzerTestOneInput(const uint8_t *data, size_t size) { // Print the input. It will be tested in runner_test. - printf("{"); - for (size_t i = 0; i < size; i++) { - // This loop generates different coverage counters - // depending on the number of iterations. - printf("%02x%s", (int)data[i], i + 1 == size ? "" : ", "); - } - printf("}\n"); + PrintInput(data, size); // If the input is 'cntX', run X iterations of a do-while loop. // Runs one iteration if X is 0. Used to test --use_counter_features.