Classpath类找不到:使用Sydr-Fuzz测试json-sanitizer遇阻求助
我按照指南尝试用Sydr-Fuzz(基于Jazzer后端)对json-sanitizer(Java)项目进行模糊测试,已创建项目,结构如下:
├── BUILD ├── build.sh ├── DenylistFuzzer.iml ├── pom.xml ├── project.yaml ├── src │ └── Deny │ └── DenylistFuzzer.java └── target ├── archive-tmp ├── Deny │ └── DenylistFuzzer.class ├── DenylistFuzzer-1.0.jar ├── DenylistFuzzer-1.0-SNAPSHOT.jar └── maven-archiver └── pom.properties
pom.xml中已配置json-sanitizer和jazzer-api依赖,执行mvn package生成jar文件后,运行模糊测试目标时出现Class not found错误。初始CLASSPATH为空,手动添加所需jar后问题仍未解决。
可能的解决方案
1. 确认模糊测试类的全限定名
运行命令时必须使用类的全限定名(包含包路径)。你的类位于Deny包下,因此正确的类名应为Deny.DenylistFuzzer,而非仅DenylistFuzzer。
示例运行命令(替换为你的实际文件路径):
sydr-fuzz --cp target/DenylistFuzzer-1.0-SNAPSHOT.jar:~/.m2/repository/com/google/code/json-sanitizer/json-sanitizer/1.2.0/json-sanitizer-1.2.0.jar:~/.m2/repository/com/code-intelligence/jazzer/jazzer-api/0.17.0/jazzer-api-0.17.0.jar Deny.DenylistFuzzer
2. 确保依赖被正确加载
如果你的项目jar未包含依赖,需确保CLASSPATH覆盖所有必要文件:项目jar、json-sanitizer jar、jazzer-api jar。
可以用Maven命令将依赖统一复制到指定目录:
mvn dependency:copy-dependencies -DoutputDirectory=lib
之后运行时的CLASSPATH可简化为:
--cp target/DenylistFuzzer-1.0-SNAPSHOT.jar:lib/*
或者修改pom.xml,使用maven-assembly-plugin打包成包含所有依赖的jar:
<build> <plugins> <plugin> <artifactId>maven-assembly-plugin</artifactId> <version>3.6.0</version> <configuration> <descriptorRefs> <descriptorRef>jar-with-dependencies</descriptorRef> </descriptorRefs> </configuration> <executions> <execution> <id>make-assembly</id> <phase>package</phase> <goals> <goal>single</goal> </goals> </execution> </executions> </plugin> </plugins> </build>
执行mvn package后会生成DenylistFuzzer-1.0-SNAPSHOT-jar-with-dependencies.jar,运行时直接使用该jar作为CLASSPATH即可。
3. 验证类是否存在于jar中
用jar tf命令检查项目jar是否包含编译后的类文件:
jar tf target/DenylistFuzzer-1.0-SNAPSHOT.jar
输出需包含Deny/DenylistFuzzer.class。如果没有,说明Maven打包配置有误,需调整pom.xml的源码目录配置:
<build> <sourceDirectory>src</sourceDirectory> </build>
4. 检查Sydr-Fuzz命令格式
确保命令格式正确,类路径分隔符在Linux/macOS下用:,Windows下用;:
sydr-fuzz --cp <完整类路径> <全限定类名>
内容的提问来源于stack exchange,提问作者rendoteru

