diff --git a/FUZZING.md b/FUZZING.md index 3474cbc71..df45af5e4 100644 --- a/FUZZING.md +++ b/FUZZING.md @@ -28,7 +28,17 @@ From the `build/` directory, you can then run the fuzzers. For example: The arguments to `jobs` and `workers` should be the number of cores that you wish to dedicate to fuzzing. By default, libFuzzer uses the largest test in the corpus (or 64 if empty) as the maximum test case length. The `max_len` argument overrides this. -The recommended values of `max_len` for each test may be found in `.options` files alongside the test source. These were determined by rounding up the length of the largest case in the corpus. When writing a new fuzzer, configure `max_len` in a similar file. +The recommended values of `max_len` for each test are: + +| Test | `max_len` value | +|-----------|-----------------| +| `privkey` | 2048 | +| `cert` | 3072 | +| `server` | 4096 | +| `client` | 20000 | + + +These were determined by rounding up the length of the largest case in the corpus. There are directories in `fuzz/` for each of the fuzzing tests which contain seed files for fuzzing. Some of the seed files were generated manually but many of them are “interesting” results generated by the fuzzing itself. (Where “interesting” means that it triggered a previously unknown path in the code.) diff --git a/fuzz/cert.options b/fuzz/cert.options deleted file mode 100644 index 1c91af358..000000000 --- a/fuzz/cert.options +++ /dev/null @@ -1,2 +0,0 @@ -[libfuzzer] -max_len = 3072 \ No newline at end of file diff --git a/fuzz/client.options b/fuzz/client.options deleted file mode 100644 index db49f1571..000000000 --- a/fuzz/client.options +++ /dev/null @@ -1,2 +0,0 @@ -[libfuzzer] -max_len = 20000 diff --git a/fuzz/privkey.options b/fuzz/privkey.options deleted file mode 100644 index 60bd9b0b2..000000000 --- a/fuzz/privkey.options +++ /dev/null @@ -1,2 +0,0 @@ -[libfuzzer] -max_len = 2048 diff --git a/fuzz/server.options b/fuzz/server.options deleted file mode 100644 index 9fda93fcb..000000000 --- a/fuzz/server.options +++ /dev/null @@ -1,2 +0,0 @@ -[libfuzzer] -max_len = 4096