Fuzzing
Purpose
Guide agents through setting up and running coverage-guided fuzz testing: libFuzzer (in-process) and AFL++ (fork-based), with sanitizer integration and CI pipeline setup.
Triggers
- "How do I fuzz-test my parser/deserializer?"
- "What is a fuzz target / how do I write one?"
- "How do I set up libFuzzer?"
- "How do I use AFL++ on my program?"
- "How do I run fuzzing in CI?"
- "Fuzzer found a crash — how do I reproduce it?"
Workflow
1. Write a fuzz target (libFuzzer)
A fuzz target is a function that accepts arbitrary bytes and exercises the code under test.
Key rules:
- Never call
abort(),exit(), or use global state that persists across calls - Handle all inputs gracefully (crash = bug found)
- Keep the target fast: the fuzzer calls it millions of times
2. Build with libFuzzer
-fsanitize=fuzzer links libFuzzer and provides main(). Do not provide your own main() in the fuzz target.
3. Run libFuzzer
Common flags:
4. Reproduce a crash
libFuzzer writes crash inputs to files named crash-<hash>, oom-<hash>, timeout-<hash>.
5. AFL++ setup
AFL++ is a fork-based fuzzer that works on arbitrary programs (not just those with a fuzz entry point).
6. AFL++ with persistent mode (faster)
Persistent mode avoids fork() per input — much faster for library fuzzing:
7. Corpus management
8. CI integration
For long-duration fuzzing, use OSS-Fuzz or ClusterFuzz infrastructure.
9. Structure-aware fuzzing (libFuzzer)
Use when naive bit-flipping breaks checksums/headers before reaching deep code paths.
10. Atheris (Python fuzzing)
11. Dataflow tracing
Produces traces showing which input bytes influenced branches — guides dictionary and structure-aware mutators.
12. OSS-Fuzz integration
13. Zig fuzz testing
Zig fuzz integrates with zig test and sanitizer builds for native targets.
14. Dictionary files
Dictionaries contain interesting tokens to guide mutation:
References
For fuzz target templates, corpus seed examples, and OSS-Fuzz integration guidance, see references/targets.md [blocked].
Related skills
- Use
skills/runtimes/sanitizersto add ASan/UBSan to fuzz builds - Use
skills/compilers/clangfor Clang-specific libFuzzer flags - Use
skills/debuggers/gdbto debug crash inputs found by the fuzzer - Use
skills/zig/zig-testingfor Zigbuild test --fuzzworkflows - Use
skills/security/kernel-securityfor kernel fuzzing with syzkaller


