GrayC: Greybox Fuzzing of Compilers and Analysers for C
Karine Even-Mendoza, Arindam Sharma, Alastair F. Donaldson, Cristian Cadar
Abstract
Fuzzing of compilers and code analysers has led to a large number of bugs being found and fixed in widely-used frameworks such as LLVM, GCC and Frama-C. Most such fuzzing techniques have taken a blackbox approach, with compilers and code analysers starting to become relatively immune to such fuzzers. We propose a coverage-directed, mutation-based approach for fuzzing C compilers and code analysers, inspired by the success of this type of greybox fuzzing in other application domains. The main challenge of applying mutation-based fuzzing in this context is that naive mutations are likely to generate programs that do not compile. Such programs are not useful for finding deep bugs that affect optimisation, analysis, and code generation routines. We have designed a novel greybox fuzzer for C compilers and analysers by developing a new set of mutations to target common C constructs, and transforming fuzzed programs so that they produce meaningful output, allowing differential testing to be used as a test oracle, and paving the way for fuzzer-generated programs to be integrated into compiler and code analyser regression test suites. We have implemented our approach in GrayC, a new opensource LibFuzzer-based tool, and present experiments showing that it provides more coverage on the middle-and back-end stages of compilers and analysers compared to other mutation-based approaches, including Clang-Fuzzer, PolyGlot, and a technique similar to LangFuzz. We have used GrayC to identify 30 confirmed compiler and code analyser bugs: 25 previously unknown bugs (with 22 of them already fixed in response to our reports) and 5 confirmed bugs reported independently shortly before we found them. A further 3 bug reports are under investigation. Apart from the results above, we have contributed 24 simplified versions of coverage-enhancing test cases produced by GrayC to the Clang/LLVM test suite, targeting 78 previously uncovered functions in the LLVM codebase.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 1250061d-107c-48b3-aef8-f9ab8c57ba7eCited by top-tier papers32
- Fuzz4All: Universal Fuzzing with Large Language ModelsChunqiu Steven Xia, Matteo Paltenghi, Jia Le Tian, Michael Pradel et al.ICSE 2024 · 155 citations
- WhiteFox: White-Box Compiler Fuzzing Empowered by Large Language ModelsChenyuan Yang, Yinlin Deng, Runyu Lu, Jiayi Yao et al.OOPSLA 2024 · 74 citations
- The Mutators Reloaded: Fuzzing Compilers with Large Language Model Generated Mutation OperatorsXianfei Ou, Cong Li, Yanyan Jiang, Chang XuASPLOS 2024 · 25 citations
- Boosting Compiler Testing by Injecting Real-World CodeShaohua Li, Theodoros Theodoridis, Zhendong SuPLDI 2024 · 24 citations
- Towards Understanding the Bugs in Solidity CompilerHaoyang Ma, Wuqi Zhang, Qingchao Shen, Yongqiang Tian et al.ISSTA 2024 · 9 citations
Builds on4
- NAUTILUS: Fishing for Deep Bugs with GrammarsCornelius Aschermann, Tommaso Frassetto, Thorsten Holz, Patrick Jauernig et al.NDSS 2019 · 291 citations
- Random testing for C and C++ compilers with YARPGenVsevolod Livinskii, Dmitry Babokin, John RegehrOOPSLA 2020 · 140 citations
- Detecting optimization bugs in database engines via non-optimizing reference engine constructionManuel Rigger, Zhendong SuFSE 2020 · 104 citations
- One Engine to Fuzz 'em All: Generic Language Processor Testing with Semantic ValidationYongheng Chen, Rui Zhong, Hong Hu, Hangfan Zhang et al.S&P 2021 · 70 citations
Related papers
- Optimization-Directed Compiler Fuzzing for Continuous Translation ValidationJaeseong Kwon, Bongjun Jang, Juneyoung Lee, Kihong HeoPLDI 2025 · 5 citations
- IRFuzzer: Specialized Fuzzing for LLVM Backend Code GenerationYuyang Rong, Zhanghan Yu, Zhenkai Weng, Stephen Neuendorffer et al.ICSE 2025 · 1 citation
- Repair-Driven Greybox FuzzingBachir Bendrissou, Alastair F. Donaldson, Cristian CadarISSTA 2026
- InstruGuard: Find and Fix Instrumentation Errors for Coverage-based Greybox FuzzingYuwei Liu, Yanhao Wang, Purui Su, Yuanping Yu et al.ASE 2021 · 8 citations
- Guiding Greybox Fuzzing with Mutation TestingVasudev Vikram, Isabella Laybourn, Ao Li, Nicole Nair et al.ISSTA 2023 · 22 citations
