How Firezone combines sans-IO design, deterministic simulation testing and coverage-guided fuzzing into one test harness for its WireGuard data plane.
2 comments
mabliang6 days ago
Does coverage guidance actually help much here, or does most of the value come from having a good generator and reference model?
wh33zle6 days ago
Coverage is just the feedback loop. If you don't have a good generator, feedback that certain areas are uncovered doesn't really help. But without coverage, the generator doesn't really explore deeper states.
Under the hood, the fuzzer actually works with _features_, not source code coverage and there are ways in explicitly giving the fuzzer additional feedback. Some early data suggests that this is very effevtive.
Read the full thread on Hacker News →
Related stories
- Finding Bugsmatklad.github.ioHacker News · 1 points · 10 days ago
- Finding Bugsmatklad.github.ioLobsters · 6 points · about 5 hours ago
- Finding Bugsmatklad.github.ioHacker News · 1 points · 6 days ago
- Hacker News · 2 points · 4 days ago
- Finding bugs in systems through formalizationandy.hammerhartes.deLobsters · 8 points · over 8 years ago
- Finding bugs in Haskell code by proving itjoachim-breitner.deLobsters · 19 points · almost 9 years ago