;;; GNU Guix --- Functional package management for GNU
-;;; Copyright © 2014 Eric Bavier <bavier@member.fsf.org>
+;;; Copyright © 2014, 2015, 2016, 2017 Eric Bavier <bavier@member.fsf.org>
+;;; Copyright © 2016, 2017, 2018 Efraim Flashner <efraim@flashner.co.il>
;;;
;;; This file is part of GNU Guix.
;;;
#:use-module (guix packages)
#:use-module (guix licenses)
#:use-module (guix download)
+ #:use-module (guix git-download)
#:use-module (guix utils)
#:use-module (guix build-system gnu)
+ #:use-module (gnu packages autotools)
+ #:use-module (gnu packages base)
#:use-module (gnu packages bash)
#:use-module (gnu packages flex)
+ #:use-module (gnu packages golang)
#:use-module (gnu packages indent)
#:use-module (gnu packages llvm)
#:use-module (gnu packages perl)
- #:use-module (gnu packages pretty-print))
+ #:use-module (gnu packages pretty-print)
+ #:use-module (gnu packages virtualization)
+ #:use-module (ice-9 match)
+ #:use-module (srfi srfi-1))
(define-public delta
(package
`(("perl" ,perl)))
(arguments
`(#:phases
- (alist-replace
- 'install
- (lambda* (#:key outputs #:allow-other-keys)
- ;; Makefile contains no install target
- (let* ((out (assoc-ref outputs "out"))
- (bin (string-append out "/bin"))
- (doc (string-append out "/share/doc/delta-" ,version)))
- (begin
- (mkdir-p bin)
- (mkdir-p doc)
- (for-each (lambda (h)
- (copy-file h (string-append doc "/" (basename h))))
- `("License.txt" ,@(find-files "www" ".*\\.html")))
- (for-each (lambda (b)
- (copy-file b (string-append bin "/" b)))
- `("delta" "multidelta" "topformflat")))))
- (alist-delete 'configure %standard-phases))))
+ (modify-phases %standard-phases
+ (replace 'install
+ (lambda* (#:key outputs #:allow-other-keys)
+ ;; Makefile contains no install target
+ (let* ((out (assoc-ref outputs "out"))
+ (bin (string-append out "/bin"))
+ (doc (string-append out "/share/doc/delta-" ,version)))
+ (begin
+ (mkdir-p bin)
+ (mkdir-p doc)
+ (for-each (lambda (h)
+ (install-file h doc))
+ `("License.txt" ,@(find-files "www" ".*\\.html")))
+ (for-each (lambda (b)
+ (install-file b bin))
+ `("delta" "multidelta" "topformflat"))))
+ #t))
+ (delete 'configure))))
(home-page "http://delta.tigris.org/")
(synopsis "Heuristical file minimizer")
(description
(define-public c-reduce
(package
(name "c-reduce")
- (version "2.2.1")
+ (version "2.5.0")
(source
(origin
(method url-fetch)
"creduce-" version ".tar.gz")))
(sha256
(base32
- "0wh0fkyg2l41d2wkndrgdiai9g2qiav7jik7cys21vmgzq01pyy2"))
- (modules '((guix build utils)))
- (snippet
- '(substitute* "clang_delta/TransformationManager.cpp"
- (("llvm/Config/config.h") "llvm/Config/llvm-config.h")))))
+ "1r23lhzq3dz8vi2dalxk5las8bf0av2w94hxxbs61pr73m77ik9d"))))
(build-system gnu-build-system)
(inputs
`(("astyle" ,astyle)
- ("delta" ,delta)
- ("llvm" ,llvm-3.5)
- ("clang" ,clang-3.5)
+ ("llvm" ,llvm)
+ ("clang" ,clang)
("flex" ,flex)
("indent" ,indent)
("perl" ,perl)
- ("benchmark-timer" ,perl-benchmark-timer)
("exporter-lite" ,perl-exporter-lite)
("file-which" ,perl-file-which)
("getopt-tabular" ,perl-getopt-tabular)
("regex-common" ,perl-regexp-common)
- ("sys-cpu" ,perl-sys-cpu)))
+ ("sys-cpu" ,perl-sys-cpu)
+ ("term-readkey" ,perl-term-readkey)))
(arguments
- `(#:phases (alist-cons-after
- 'install 'set-load-paths
- (lambda* (#:key inputs outputs #:allow-other-keys)
- ;; Tell creduce where to find the perl modules it needs.
- (let* ((out (assoc-ref outputs "out"))
- (prog (string-append out "/bin/creduce")))
- (wrap-program
- prog
- `("PERL5LIB" ":" prefix
- ,(map (lambda (p)
- (string-append (assoc-ref inputs p)
- "/lib/perl5/site_perl/"
- ,(package-version perl)))
- '("benchmark-timer" "exporter-lite"
- "file-which" "getopt-tabular"
- "regex-common" "sys-cpu"))))))
- %standard-phases)))
+ `(#:phases
+ (modify-phases %standard-phases
+ (add-after 'install 'set-load-paths
+ (lambda* (#:key inputs outputs #:allow-other-keys)
+ ;; Tell creduce where to find the perl modules it needs.
+ (let* ((out (assoc-ref outputs "out"))
+ (prog (string-append out "/bin/creduce")))
+ (wrap-program
+ prog
+ `("PERL5LIB" ":" prefix
+ ,(map (lambda (p)
+ (string-append (assoc-ref inputs p)
+ "/lib/perl5/site_perl/"
+ ,(package-version perl)))
+ '("term-readkey" "exporter-lite"
+ "file-which" "getopt-tabular"
+ "regex-common" "sys-cpu")))))
+ #t)))))
(home-page "http://embed.cs.utah.edu/creduce")
(synopsis "Reducer for interesting code")
(description
intended for use by people who discover and report bugs in compilers and other
tools that process C/C++ code.")
(license ncsa)))
+
+(define-public american-fuzzy-lop
+ (let ((machine (match (or (%current-target-system)
+ (%current-system))
+ ("x86_64-linux" "x86_64")
+ ("i686-linux" "i386")
+ ("aarch64-linux" "aarch64")
+ ("armhf-linux" "arm")
+ ("mips64el-linux" "mips64el")
+ ;; Prevent errors when querying this package on unsupported
+ ;; platforms, e.g. when running "guix package --search="
+ (_ "UNSUPPORTED"))))
+ (package
+ (name "american-fuzzy-lop")
+ (version "2.52b") ;It seems all releases have the 'b' suffix
+ (source
+ (origin
+ (method url-fetch)
+ (uri (string-append "http://lcamtuf.coredump.cx/afl/releases/"
+ "afl-" version ".tgz"))
+ (sha256
+ (base32
+ "0ig0ij4n1pwry5dw1hk4q88801jzzy2cric6y2gd6560j55lnqa3"))))
+ (build-system gnu-build-system)
+ (inputs
+ `(("custom-qemu"
+ ;; The afl-qemu tool builds qemu 2.10.0 with a few patches applied.
+ ,(package (inherit qemu-minimal)
+ (name "afl-qemu")
+ (inputs
+ `(("afl-src" ,source)
+ ,@(package-inputs qemu-minimal)))
+ ;; afl only supports using a single afl-qemu-trace executable, so
+ ;; we only build qemu for the native target.
+ (arguments
+ `(#:modules ((srfi srfi-1)
+ ,@%gnu-build-system-modules)
+ ,@(substitute-keyword-arguments (package-arguments qemu-minimal)
+ ((#:configure-flags config-flags)
+ ``(,(string-append "--target-list=" ,machine "-linux-user")
+ ,@(remove (λ (f) (string-prefix? "--target-list=" f))
+ ,config-flags)))
+ ((#:phases qemu-phases)
+ `(modify-phases ,qemu-phases
+ (add-after
+ 'unpack 'apply-afl-patches
+ (lambda* (#:key inputs #:allow-other-keys)
+ (let* ((afl-dir (string-append "afl-" ,version))
+ (patch-dir
+ (string-append afl-dir
+ "/qemu_mode/patches")))
+ (unless (zero?
+ (system* "tar" "xf"
+ (assoc-ref inputs "afl-src")))
+ (error "tar failed to unpack afl-src"))
+ (install-file (string-append patch-dir
+ "/afl-qemu-cpu-inl.h")
+ ".")
+ (copy-file (string-append afl-dir "/config.h")
+ "./afl-config.h")
+ (install-file (string-append afl-dir "/types.h")
+ ".")
+ (substitute* "afl-qemu-cpu-inl.h"
+ (("\\.\\./\\.\\./config.h") "afl-config.h"))
+ (substitute* (string-append patch-dir
+ "/cpu-exec.diff")
+ (("\\.\\./patches/") ""))
+ (every (lambda (patch-file)
+ (zero? (system* "patch" "--force" "-p1"
+ "--input" patch-file)))
+ (find-files patch-dir
+ "\\.diff$"))))))))))))))
+ (arguments
+ `(#:make-flags (list (string-append "PREFIX=" (assoc-ref %outputs "out"))
+ "CC=gcc")
+ #:phases (modify-phases %standard-phases
+ (delete 'configure)
+ ,@(if (string=? (%current-system) (or "x86_64-linux"
+ "i686-linux"))
+ '()
+ '((add-before 'build 'set-afl-flag
+ (lambda _ (setenv "AFL_NO_X86" "1") #t))
+ (add-after 'install 'remove-x86-programs
+ (lambda* (#:key outputs #:allow-other-keys)
+ (let* ((out (assoc-ref outputs "out"))
+ (bin (string-append out "/bin/")))
+ (delete-file (string-append bin "afl-gcc"))
+ (delete-file (string-append bin "afl-g++"))
+ (delete-file (string-append bin "afl-clang"))
+ (delete-file (string-append bin "afl-clang++")))
+ #t))))
+ (add-after
+ ;; TODO: Build and install the afl-llvm tool.
+ 'install 'install-qemu
+ (lambda* (#:key inputs outputs #:allow-other-keys)
+ (let ((qemu (assoc-ref inputs "custom-qemu"))
+ (out (assoc-ref outputs "out")))
+ (symlink (string-append qemu "/bin/qemu-" ,machine)
+ (string-append out "/bin/afl-qemu-trace"))
+ #t)))
+ (delete 'check)))) ; Tests are run during 'install phase.
+ (home-page "http://lcamtuf.coredump.cx/afl")
+ (synopsis "Security-oriented fuzzer")
+ (description
+ "American fuzzy lop is a security-oriented fuzzer that employs a novel
+type of compile-time instrumentation and genetic algorithms to automatically
+discover clean, interesting test cases that trigger new internal states in the
+targeted binary. This substantially improves the functional coverage for the
+fuzzed code. The compact synthesized corpora produced by the tool are also
+useful for seeding other, more labor- or resource-intensive testing regimes
+down the road.")
+ (license asl2.0))))
+
+(define-public stress-make
+ (let ((commit "506e6cfd98d165f22bee91c408b7c20117a682c4")
+ (revision "0")) ;No official source distribution
+ (package
+ (name "stress-make")
+ (version (string-append "1.0-" revision "." (string-take commit 7)))
+ (source
+ (origin
+ (method git-fetch)
+ (uri (git-reference
+ (url "https://github.com/losalamos/stress-make.git")
+ (commit commit)))
+ (file-name (string-append name "-" version "-checkout"))
+ (sha256
+ (base32
+ "1j330yqhc7plwin04qxbh8afpg5nfnw1xvnmh8rk6mmqg9w6ik70"))))
+ (build-system gnu-build-system)
+ (native-inputs
+ `(("autoconf" ,autoconf)
+ ("automake" ,automake)
+ ("go" ,go)))
+ (inputs
+ `(("make-source" ,(package-source gnu-make))))
+ (arguments
+ ;; stress-make's configure script insists on having a tarball and does
+ ;; not accept a directory name instead. To let the gnu-build-system's
+ ;; patch-* phases work properly, we unpack the source first, then
+ ;; repack before the configure phase.
+ (let ((make-dir (string-append "make-" (package-version gnu-make))))
+ `(#:configure-flags '("--with-make-tar=./make.tar.xz")
+ #:phases
+ (modify-phases %standard-phases
+ (add-after 'unpack 'unpack-make
+ (lambda* (#:key inputs #:allow-other-keys)
+ (zero? (system* "tar" "xf" (assoc-ref inputs "make-source")))))
+ (add-after 'unpack-make 'set-default-shell
+ (lambda _
+ ;; Taken mostly directly from (@ (gnu packages base) gnu-make)
+ (substitute* (string-append ,make-dir "/job.c")
+ (("default_shell = .*$")
+ (format #f "default_shell = \"~a\";\n"
+ (which "sh"))))))
+ (add-before 'configure 'repack-make
+ (lambda _
+ (zero? (system* "tar" "cJf" "./make.tar.xz" ,make-dir))))
+ (add-after 'unpack 'bootstrap
+ (lambda _
+ (zero? (system* "autoreconf" "-vfi"))))))))
+ (home-page "https://github.com/losalamos/stress-make")
+ (synopsis "Expose race conditions in Makefiles")
+ (description
+ "Stress Make is a customized GNU Make that explicitely manages the order
+in which concurrent jobs are run to provoke erroneous behavior into becoming
+manifest. It can run jobs in the order in which they're launched, in backwards
+order, or in random order. The thought is that if code builds correctly with
+Stress Make, then it is likely that the @code{Makefile} contains no race
+conditions.")
+ ;; stress-make wrapper is under BSD-3-modifications-must-be-indicated,
+ ;; and patched GNU Make is under its own license.
+ (license (list (non-copyleft "COPYING.md")
+ (package-license gnu-make))))))
+
+(define-public zzuf
+ (package
+ (name "zzuf")
+ (version "0.15")
+ (source
+ (origin
+ (method url-fetch)
+ (uri (string-append
+ "https://github.com/samhocevar/zzuf/releases/download/v"
+ version "/" name "-" version ".tar.gz"))
+ (file-name (string-append name "-" version ".tar.gz"))
+ (sha256
+ (base32
+ "1mpzjaksc2qg2hzqflf39pl06p53qam2dn3hkhkcv6p00d2n4kx3"))))
+ (build-system gnu-build-system)
+ (home-page "https://github.com/samhocevar/zzuf")
+ (synopsis "Transparent application input fuzzer")
+ (description "Zzuf is a transparent application input fuzzer. It works by
+intercepting file operations and changing random bits in the program's
+input. Zzuf's behaviour is deterministic, making it easy to reproduce bugs.")
+ (license (non-copyleft "http://www.wtfpl.net/txt/copying/"))))