Repository navigation
gate-mutate --guided: coverage-guided fuzzing with mirth's block coverage; findings 56-58 - #45
Merged
Merged
Conversation
…rage (MIRTH_OUT) as feedback; --measure for the unguided baseline; findings 56-58 A mutant reaching sites no coverage suite and no earlier input reached joins a corpus with energy proportional to its new sites; three mutants in four are drawn from it by energy (splices with corpus entries or UI tests, moves, gates, edits). 150 minutes each, side by side: the same new coverage (53,352 vs 53,699 sites; 59,695 together, saved as two coverage suites), more crashes guided (19 signatures vs 14). Compile gains an env option (MIRTH_OUT). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01QXiEXbESemwqMLYKaWLDbT
Contributor
Author
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Adds coverage-guided fuzzing to
mirth-lab gate-mutate, using mirth's block coverage as feedback.How it works
--guidedcompiles each mutant with the coverage-instrumented compiler (build-blk,MIRTH_OUTset per compile; each log is deleted after reading).--coverage-from: a snapshot of everycov-suites/*/union.txt, 400,501 sites) and that no earlier input in the run reached. Its energy is proportional to the number of new sites.--measurecounts new sites the same way but draws mutants as usual; it is the unguided baseline.--minutessets a time budget,--sitesgives a per-crate and per-file report of where the new sites are, and--suitewrites the new sites as a coverage suite.Compilegains anenvoption.Guided vs unguided
150 minutes each, run side by side with the same seed and snapshot (table in
docs/checks.md).guided-gate-mutate,unguided-gate-mutate).-Zunpretty,thir-print). Weighting energy away from those tests is the next thing to try.Findings 56–58 (look new, low severity)
#[repr(simd)] #[derive(Clone)]struct ICEs in MIR validation on plain nightly, without-Zvalidate-mir. Reproduces on 1.90.0 through nightly; 1.89.0 is fine.-Zassumptions-on-binderswithreborrowpanics with "region constraints already solved".The other new signatures are routes to findings 50 and 53, or to the open issue #162338. Finding numbers may need renumbering if other branches merge first.
🤖 Generated with Claude Code
https://claude.ai/code/session_01QXiEXbESemwqMLYKaWLDbT