Skip to main content

FuzzCmd

Enum FuzzCmd 

Source
pub enum FuzzCmd {
    Init {
        program_name: String,
    },
    Run {
Show 25 fields program_name: String, test_name: String, binary_in: Option<PathBuf>, release: bool, coverage: bool, timeout: Option<u64>, cores: Option<usize>, corpus_in: Option<PathBuf>, corpus_out: Option<PathBuf>, crashes_out: Option<PathBuf>, crashes_meta_out: Option<PathBuf>, replay: Option<PathBuf>, dry_run: bool, seed: Option<u64>, stop_on_crash: bool, max_actions: Option<usize>, no_tracing: bool, stateful: bool, max_depth: Option<u32>, pool_size: Option<u64>, program_so: Option<PathBuf>, symbols: Option<PathBuf>, mode: Option<String>, lcov_out: Option<PathBuf>, stats: bool,
}, List { program_name: Option<String>, harness_dir: Option<PathBuf>, }, Show { program_name: String, crash_file: Option<String>, replay: bool, regen: bool, crashes_dir: Option<PathBuf>, crash_meta_dir: Option<PathBuf>, }, Tmin { program_name: String, test_name: String, crash_file: Option<String>, all: bool, release: bool, crash_meta_dir: Option<PathBuf>, }, Cmin { program_name: String, test_name: String, corpus_dir: Option<PathBuf>, corpus_in: Option<PathBuf>, corpus_out: Option<PathBuf>, release: bool, }, }

Variants§

§

Init

Create a new fuzz harness for a program

Fields

§program_name: String

Program name

§

Run

Run a fuzz test

Fields

§program_name: String

Program name

§test_name: String

Test name (corresponds to a Cargo feature)

§binary_in: Option<PathBuf>

Run a prebuilt harness binary directly

§release: bool

Build in release mode

§coverage: bool

Enable coverage reporting (single-core only)

§timeout: Option<u64>

Stop after N seconds

§cores: Option<usize>

Run N parallel fuzzer workers

§corpus_in: Option<PathBuf>

Load seed corpus from directory

§corpus_out: Option<PathBuf>

Write corpus to directory

§crashes_out: Option<PathBuf>

Custom crash output directory

§crashes_meta_out: Option<PathBuf>

Custom directory for .meta.json files (default: same as crashes_out)

§replay: Option<PathBuf>

Replay a single crash/input file

§dry_run: bool

Validate setup without fuzzing

§seed: Option<u64>

Random seed for reproducible fuzzing

§stop_on_crash: bool

Stop fuzzing on first crash

§max_actions: Option<usize>

Maximum number of actions per fuzzer iteration (default: 8 stateless, 100 stateful)

§no_tracing: bool

Disable SVM register tracing for higher throughput (no coverage guidance)

§stateful: bool

Stateful fuzzing: single action per iteration with state pool

§max_depth: Option<u32>

Maximum state depth (action chain length) in stateful mode (default: 15)

§pool_size: Option<u64>

State pool capacity in stateful mode (default: 256000)

§program_so: Option<PathBuf>

Path to alternative program .so binary

§symbols: Option<PathBuf>

Path to debug binary with DWARF symbols (for source-level coverage with –coverage)

§mode: Option<String>

Remote fuzzing operational mode (dry_run, explore, coverage, reproduce, corpus_merge)

§lcov_out: Option<PathBuf>

LCOV coverage output path

§stats: bool

Show detailed performance stats (profiling, memory, pick/exec breakdown)

§

List

List available fuzz tests

Fields

§program_name: Option<String>

Program name (omit to list all)

§harness_dir: Option<PathBuf>

Use this directory instead of ./fuzz/<program_name>/

§

Show

View/replay crashes

Fields

§program_name: String

Program name (use “.” to auto-detect)

§crash_file: Option<String>

Crash file to inspect

§replay: bool

Actually replay the crash (requires compiled binary)

§regen: bool

Batch-regenerate .meta.json for all crashes (requires –replay)

§crashes_dir: Option<PathBuf>

Custom crashes directory to read from

§crash_meta_dir: Option<PathBuf>

Custom directory for .meta.json files (default: same as crashes_dir)

§

Tmin

Minimize a crash to smallest reproducing action sequence

Fields

§program_name: String

Program name

§test_name: String

Test name

§crash_file: Option<String>

Crash file to minimize (filename only, not full path)

§all: bool

Minimize all crashes for this test

§release: bool

Build in release mode

§crash_meta_dir: Option<PathBuf>

Custom directory for .meta.json files (default: same as crashes directory)

§

Cmin

Minimize corpus to smallest set preserving coverage

Fields

§program_name: String

Program name

§test_name: String

Test name

§corpus_dir: Option<PathBuf>

Input corpus directory (positional)

§corpus_in: Option<PathBuf>

Input corpus directory (flag alternative)

§corpus_out: Option<PathBuf>

Output directory (default: overwrite input)

§release: bool

Build in release mode

Trait Implementations§

Source§

impl Debug for FuzzCmd

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl FromArgMatches for FuzzCmd

Source§

fn from_arg_matches(__clap_arg_matches: &ArgMatches) -> Result<Self, Error>

Instantiate Self from ArgMatches, parsing the arguments as needed. Read more
Source§

fn from_arg_matches_mut( __clap_arg_matches: &mut ArgMatches, ) -> Result<Self, Error>

Instantiate Self from ArgMatches, parsing the arguments as needed. Read more
Source§

fn update_from_arg_matches( &mut self, __clap_arg_matches: &ArgMatches, ) -> Result<(), Error>

Assign values from ArgMatches to self.
Source§

fn update_from_arg_matches_mut<'b>( &mut self, __clap_arg_matches: &mut ArgMatches, ) -> Result<(), Error>

Assign values from ArgMatches to self.
Source§

impl Subcommand for FuzzCmd

Source§

fn augment_subcommands<'b>(__clap_app: Command) -> Command

Append to Command so it can instantiate Self via FromArgMatches::from_arg_matches_mut Read more
Source§

fn augment_subcommands_for_update<'b>(__clap_app: Command) -> Command

Append to Command so it can instantiate self via FromArgMatches::update_from_arg_matches_mut Read more
Source§

fn has_subcommand(__clap_name: &str) -> bool

Test whether Self can parse a specific subcommand

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.