RSashimi retweetledi

The fuzzer that found project-zero.issues.chromium.org/issues?q=compo… (and a number of issues prior to that as well) is now open-source: crrev.com/c/7580844
It uses pkeys, trap-handling and single-stepping to intercept and mutate in-sandbox reads (see trap-fuzzer.h). Definitely had fun writing it!
English











