The Day I Fell in Love with Fuzzing
Assuming you’ve got the necessary tools installed (make, gcc, afl), here’s how easy it is to start fuzzing binitools:
The utility takes INI as input and produces BINI as output, so it’s far more interesting to fuzz than its inverse, . Once I combed out all the fuzzer-discovered bugs, and I agreed with the parser on how all the various edge cases should be handled, I turned the fuzzer’s corpus into a test suite — though not directly. Have a look at all the wacky inputs invented by the fuzzer starting from my single, minimal input:
This essentially locks down the parser, and the test suite ensures a particular build behaves in a very specific way.
Source: nullprogram.com