crucible-triage¶
The standalone binary replays fuzzer inputs, combines process facts with text evidence, deduplicates by Exact identity, and writes unrated investigation reports.
It does not automatically confirm vulnerabilities, score CVSS, or infer affected versions.
Replay mode¶
crucible-triage \
--artifact-kind input \
--crashes ./crashes \
--harness ./harness/libfuzzer/crucible-libfuzzer-model \
--output ./reports \
--target model-loader \
--sarif ./reports/results.sarif
| Flag | Default | Meaning |
|---|---|---|
--artifact-kind | input | input replays reproducers; banked-log is skipped because another execution's text carries no process facts for this run |
--crashes | ./crashes | input directory |
--output | ./reports | investigation report directory |
--harness | none | executable used to replay binary inputs |
--minimize | false | minimize while preserving the observed identity |
--replay-timeout | 30s | per-execution deadline |
--replay-env | none | KEY=VALUE, repeatable; environment is part of the evidence |
--target | auto | target surface, normally inferred from the harness name |
--sarif | none | SARIF 2.1.0 destination |
Invalid artifact kinds fail. Binary inputs without an executable harness are incomplete and exit non-zero; they are never interpreted as text. Banked logs also exit non-zero after being counted as unadjudicated work.
What it records¶
Each surfaced observation includes:
- process outcome and evidence class;
- crash taxonomy and CWE hint;
- Exact identity for build-local buckets;
- Stable identity and normalized target site for cross-build comparison;
- legacy
HashStackfor historical oracle compatibility; - harness, replay environment, target, input, and minimized path;
- raw stack evidence and explicit unattributed state.
Generated reports default to UNRATED, unknown affected versions, and no CVSS vector. CWE is a taxonomy hint that still requires source-level validation.
SARIF¶
crucible-triage \
--artifact-kind input \
--crashes ./crashes \
--harness ./harness \
--sarif ./results.sarif
SARIF levels are taxonomy-based, not CVSS-based: memory-safety is error, crash-only is warning, and resource exhaustion is note. Importing the file does not upgrade observations to confirmed vulnerabilities.
Watch mode¶
crucible-triage watch \
--harness ./harness/libfuzzer/crucible-libfuzzer-deep \
--crashes ./crashes \
--output ./crashes/dedup \
--interval 30s
Watch mode:
- discovers newly written crash artifacts;
- replays each through the harness;
- discards executions that establish no triage-worthy fault;
- deduplicates by Exact identity;
- copies unique inputs using Exact-based filenames;
- appends a versioned checkpoint only after the output is safely written.
Checkpoint entries bind the harness hash, environment digest, artifact hash, Exact identity, and legacy hash. On restore, incompatible or incomplete entries are discarded and reported instead of being silently trusted.
| Flag | Default | Meaning |
|---|---|---|
--harness | required | replay binary |
--crashes | ./crashes | root to poll |
--output | ./crashes/dedup | unique-artifact/checkpoint directory |
--interval | 30s | poll period |
--replay-timeout | 30s | per-input replay deadline |
--replay-env | none | repeatable replay environment |
Watch mode is a triage queue, not disclosure automation. Every unique observation still requires manual replay, source inspection, HEAD verification, severity ratification, and a human disclosure decision.
Relationship to the main CLI¶
crucible triage and crucible report use the same report-producing path for one-shot runs. The standalone binary exists for dedicated triage/watch deployments. For the full operational sequence, see Campaign Operations and Crash Triage.