Pin fuzzing to newly created actors in IPC fuzzing
Categories
(Core :: Fuzzing, enhancement)
Tracking
()
People
(Reporter: decoder, Assigned: decoder)
Details
(Keywords: sec-other, Whiteboard: [adv-main105-])
Attachments
(1 file)
Currently, the fuzzer sometimes creates new actors as expected (just by sending a constructor message with the right parameters). However, once the actor is successfully created, there is no special handling for that new actor. In particular, the chance that it is selected for further messages is not higher than it is for any other actor.
We should change the code to pin the fuzzing to the newly created actor at least for a certain amount of messages. After these messages have been sent, we should decide if we want to stay pinned on that particular port (since it's more likely that more messages on the same port where the new actor was created could trigger a bug).
Assignee | ||
Comment 1•2 years ago
|
||
Depends on D153344
Comment 2•2 years ago
|
||
Pin IPC fuzzing to new actor / last port after constructor. r=truber
https://hg.mozilla.org/integration/autoland/rev/111a081318aee284b38a18a3b7ed6d11882dd34c
https://hg.mozilla.org/mozilla-central/rev/111a081318ae
Updated•2 years ago
|
Updated•2 years ago
|
Updated•2 years ago
|
Updated•1 year ago
|
Description
•