Skip to content

3: ggml-rpc exchange

sequenceDiagram
    participant LF as libFuzzer
    participant MUT as LLVMFuzzerCustomMutator<br/>(Go c-archive)
    participant H as harness_rpc_graph<br/>(fuzz thread)
    participant TCP as TCP loopback<br/>50100–50999
    participant SRV as rpc_serve_client<br/>(spawned std::thread)
    participant GGML as ggml backend

    LF->>MUT: data · size · maxSize · seed
    Note over LF,MUT: RESOLVED seed reaches getMutator
    MUT->>MUT: GraphComputePayload.Unmarshal(data)
    MUT->>MUT: 1–3 weighted Strategy.Mutate draws
    MUT->>MUT: GraphComputePayload.Marshal()
    Note over MUT: maxSize handling is part of the archive contract
    MUT-->>LF: mutated []byte · outLen ≤ maxSize
    LF->>H: data · size
    H->>TCP: connect 127.0.0.1:port
    TCP->>SRV: accepted socket_ptr
    H->>SRV: HELLO opcode + profile-derived body size
    SRV-->>H: msg_size(8 LE) | data
    H->>SRV: GRAPH_COMPUTE opcode + length + profiled payload
    SRV->>SRV: device + nodes + tensors length checks
    SRV->>GGML: ggml_cgraph
    GGML-->>SRV: compute result / GGML_ABORT
    SRV-->>H: msg_size(8 LE) | data
    Note over H,SRV: command values and wire sizes are measured from the pinned target

Reviewed: 2026-08-20.