Skip to content

gate-mutate --guided: coverage-guided fuzzing with mirth's block coverage; findings 56-58 - #45

Merged
zmaril merged 1 commit into
mainfrom
mirth/covfuzz
Oct 10, 2026
Merged

zmaril merged 1 commit into
mainfrom
mirth/covfuzz

Conversation

@zmaril

@zmaril zmaril commented Oct 10, 2026

Copy link
Copy Markdown
Contributor

Adds coverage-guided fuzzing to mirth-lab gate-mutate, using mirth's block coverage as feedback.

How it works

  • --guided compiles each mutant with the coverage-instrumented compiler (build-blk, MIRTH_OUT set per compile; each log is deleted after reading).
  • A mutant joins a corpus if it reaches sites that no coverage suite reached (--coverage-from: a snapshot of every cov-suites/*/union.txt, 400,501 sites) and that no earlier input in the run reached. Its energy is proportional to the number of new sites.
  • Three mutants in four are drawn from the corpus by energy (new sites ÷ (1 + times picked)), AFL-style. Each is then spliced with another corpus entry or a UI test, moved, gated, or edited.
  • --measure counts new sites the same way but draws mutants as usual; it is the unguided baseline.
  • --minutes sets a time budget, --sites gives a per-crate and per-file report of where the new sites are, and --suite writes the new sites as a coverage suite.
  • A guided run resumes from its saved corpus.
  • Compile gains an env option.

Guided vs unguided

150 minutes each, run side by side with the same seed and snapshot (table in docs/checks.md).

mutants new sites ICE/hang mutants signatures
guided 33,100 53,352 766 19
unguided 29,500 53,699 95 14
  • Coverage: about the same. 47,356 sites were reached by both runs, and 59,695 together; both are saved as coverage suites (guided-gate-mutate, unguided-gate-mutate).
  • Where the guided corpus spent its energy: on tests whose own flags print compiler internals (-Zunpretty, thir-print). Weighting energy away from those tests is the next thing to try.
  • Crashes: guided mutates its ICE-prone corpus entries again, so it reaches more crashes.

Findings 56–58 (look new, low severity)

  • 56: a generic #[repr(simd)] #[derive(Clone)] struct ICEs in MIR validation on plain nightly, without -Zvalidate-mir. Reproduces on 1.90.0 through nightly; 1.89.0 is fine.
  • 57: a gca const parameter default gives "const parameter out of range".
  • 58: -Zassumptions-on-binders with reborrow panics with "region constraints already solved".

The other new signatures are routes to findings 50 and 53, or to the open issue #162338. Finding numbers may need renumbering if other branches merge first.

🤖 Generated with Claude Code

https://claude.ai/code/session_01QXiEXbESemwqMLYKaWLDbT

…rage (MIRTH_OUT) as feedback; --measure for the unguided baseline; findings 56-58

A mutant reaching sites no coverage suite and no earlier input reached joins a corpus with
energy proportional to its new sites; three mutants in four are drawn from it by energy
(splices with corpus entries or UI tests, moves, gates, edits). 150 minutes each, side by side:
the same new coverage (53,352 vs 53,699 sites; 59,695 together, saved as two coverage suites),
more crashes guided (19 signatures vs 14). Compile gains an env option (MIRTH_OUT).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QXiEXbESemwqMLYKaWLDbT
@zmaril
zmaril merged commit d6fade5 into main Oct 10, 2026
0 of 3 checks passed
@zmaril

zmaril commented Oct 10, 2026

Copy link
Copy Markdown
Contributor Author

Merged into main with #41–#46; renumbered at merge: findings 56–58 are now 60–62 (docs/hunt.md).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant