You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
jianglk.darker 7ee447c011
8 months ago
cmake/external v811_spc009_project 8 months ago
examples v811_spc009_project 8 months ago
port v811_spc009_project 8 months ago
src v811_spc009_project 8 months ago
.clang-format v811_spc009_project 8 months ago
.travis.yml v811_spc009_project 8 months ago
AUTHORS v811_spc009_project 8 months ago
Android.bp v811_spc009_project 8 months ago
CMakeLists.txt v811_spc009_project 8 months ago
CONTRIBUTING v811_spc009_project 8 months ago
LICENSE v811_spc009_project 8 months ago
METADATA v811_spc009_project 8 months ago
MODULE_LICENSE_APACHE2 v811_spc009_project 8 months ago
OWNERS v811_spc009_project 8 months ago v811_spc009_project 8 months ago v811_spc009_project 8 months ago v811_spc009_project 8 months ago


TravisCI Build Status Fuzzing Status


libprotobuf-mutator is a library to randomly mutate protobuffers.
It could be used together with guided fuzzing engines, such as libFuzzer.

Quick start on Debian/Ubuntu

Install prerequisites:

sudo apt-get update
sudo apt-get install protobuf-compiler libprotobuf-dev binutils cmake \
  ninja-build liblzma-dev libz-dev pkg-config autoconf libtool

Compile and test everything:

mkdir build
cd build
ninja check

Clang is only needed for libFuzzer integration.
By default, the system-installed version of protobuf is used. However, on some systems, the system version is too old. You can pass LIB_PROTO_MUTATOR_DOWNLOAD_PROTOBUF=ON to cmake to automatically download and build a working version of protobuf.


sudo ninja install

This installs the headers, pkg-config, and static library. By default the headers are put in /usr/local/include/libprotobuf-mutator.


To use libprotobuf-mutator simply include mutator.h and into your build files.

The ProtobufMutator class implements mutations of the protobuf tree structure and mutations of individual fields. The field mutation logic is very basic -- for better results you should override the ProtobufMutator::Mutate* methods with more sophisticated logic, e.g. using libFuzzer's mutators.

To apply one mutation to a protobuf object do the following:

class MyProtobufMutator : public protobuf_mutator::Mutator {
  // Optionally redefine the Mutate* methods to perform more sophisticated mutations.
void Mutate(MyMessage* message) {
  MyProtobufMutator mutator;
  mutator.Mutate(message, 200);

See also the ProtobufMutatorMessagesTest.UsageExample test from

Integrating with libFuzzer

LibFuzzerProtobufMutator can help to integrate with libFuzzer. For example

#include "src/libfuzzer/libfuzzer_macro.h"

DEFINE_PROTO_FUZZER(const MyMessageType& input) {
  // Code which needs to be fuzzed.

Please see as an example.

Mutation post-processing (experimental)

Sometimes it's necessary to keep particular values in some fields without which the proto is going to be rejected by fuzzed code. E.g. code may expect consistency between some fields or it may use some fields as checksums. Such constraints are going to be significant bottleneck for fuzzer even if it's capable of inserting acceptable values with time.

PostProcessorRegistration can be used to avoid such issue and guide your fuzzer towards interesting code. It registers callback which will be called for each message of particular type after each mutation.

static protobuf_mutator::libfuzzer::PostProcessorRegistration<MyMessageType> reg = {
    [](MyMessageType* message, unsigned int seed) {
      TweakMyMessage(message, seed);

DEFINE_PROTO_FUZZER(const MyMessageType& input) {
  // Code which needs to be fuzzed.

Optional: Use seed if callback uses random numbers. It may help later with debugging.

Important: Callbacks should be deterministic and avoid modifying good messages. Callbacks are called for both: mutator generated and user provided inputs, like corpus or bug reproducer. So if callback performs unnecessary transformation it may corrupt the reproducer so it stops triggering the bug.

Note: You can add callback for any nested message and you can add multiple callbacks for the same message type.

DEFINE_PROTO_FUZZER(const MyMessageType& input) {
  static PostProcessorRegistration reg1 = {
      [](MyMessageType* message, unsigned int seed) {
        TweakMyMessage(message, seed);
  static PostProcessorRegistration reg2 = {
      [](MyMessageType* message, unsigned int seed) {
        DifferentTweakMyMessage(message, seed);
  static PostProcessorRegistration reg_nested = {
      [](MyMessageType::Nested* message, unsigned int seed) {
        TweakMyNestedMessage(message, seed);

  // Code which needs to be fuzzed.

UTF-8 strings

"proto2" and "proto3" handle invalid UTF-8 strings differently. In both cases string should be UTF-8, however only "proto3" enforces that. So if fuzzer is applied to "proto2" type libprotobuf-mutator will generate any strings including invalid UTF-8. If it's a "proto3" message type, only valid UTF-8 will be used.

Users of the library

Bugs found with help of the library

