1#!/bin/bash
2# Copyright 2012 the V8 project authors. All rights reserved.
3# Redistribution and use in source and binary forms, with or without
4# modification, are permitted provided that the following conditions are
5# met:
6#
7#     * Redistributions of source code must retain the above copyright
8#       notice, this list of conditions and the following disclaimer.
9#     * Redistributions in binary form must reproduce the above
10#       copyright notice, this list of conditions and the following
11#       disclaimer in the documentation and/or other materials provided
12#       with the distribution.
13#     * Neither the name of Google Inc. nor the names of its
14#       contributors may be used to endorse or promote products derived
15#       from this software without specific prior written permission.
16#
17# THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
18# "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
19# LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
20# A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT
21# OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
22# SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT
23# LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
24# DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
25# THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
26# (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE
27# OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
28
29# A simple harness that downloads and runs 'jsfunfuzz' against d8. This
30# takes a long time because it runs many iterations and is intended for
31# automated usage. The package containing 'jsfunfuzz' can be found as an
32# attachment to this bug:
33# https://bugzilla.mozilla.org/show_bug.cgi?id=jsfunfuzz
34
35JSFUNFUZZ_URL="https://bugzilla.mozilla.org/attachment.cgi?id=310631"
36JSFUNFUZZ_MD5="d0e497201c5cd7bffbb1cdc1574f4e32"
37
38v8_root=$(readlink -f $(dirname $BASH_SOURCE)/../)
39
40if [ -n "$1" ]; then
41  d8="${v8_root}/$1"
42else
43  d8="${v8_root}/d8"
44fi
45
46if [ ! -f "$d8" ]; then
47  echo "Failed to find d8 binary: $d8"
48  exit 1
49fi
50
51jsfunfuzz_file="$v8_root/tools/jsfunfuzz.zip"
52if [ ! -f "$jsfunfuzz_file" ]; then
53  echo "Downloading $jsfunfuzz_file ..."
54  wget -q -O "$jsfunfuzz_file" $JSFUNFUZZ_URL || exit 1
55fi
56
57jsfunfuzz_sum=$(md5sum "$jsfunfuzz_file" | awk '{ print $1 }')
58if [ $jsfunfuzz_sum != $JSFUNFUZZ_MD5 ]; then
59  echo "Failed to verify checksum!"
60  exit 1
61fi
62
63jsfunfuzz_dir="$v8_root/tools/jsfunfuzz"
64if [ ! -d "$jsfunfuzz_dir" ]; then
65  echo "Unpacking into $jsfunfuzz_dir ..."
66  unzip "$jsfunfuzz_file" -d "$jsfunfuzz_dir" || exit 1
67  echo "Patching runner ..."
68  cat << EOF | patch -s -p0 -d "$v8_root"
69--- tools/jsfunfuzz/jsfunfuzz/multi_timed_run.py~
70+++ tools/jsfunfuzz/jsfunfuzz/multi_timed_run.py
71@@ -125,7 +125,7 @@
72 
73 def many_timed_runs():
74     iteration = 0
75-    while True:
76+    while iteration < 100:
77         iteration += 1
78         logfilename = "w%d" % iteration
79         one_timed_run(logfilename)
80EOF
81fi
82
83flags='--debug-code --expose-gc --verify-gc'
84python -u "$jsfunfuzz_dir/jsfunfuzz/multi_timed_run.py" 300 \
85    "$d8" $flags "$jsfunfuzz_dir/jsfunfuzz/jsfunfuzz.js"
86exit_code=$(cat w* | grep " looking good" -c)
87exit_code=$((100-exit_code))
88tar -cjf fuzz-results-$(date +%Y%m%d%H%M%S).tar.bz2 err-* w*
89rm -f err-* w*
90
91echo "Total failures: $exit_code"
92exit $exit_code
93