Skip to content

Add power Doppler seed energy schedule (--schedule doppler) - #45

Merged
daedalus merged 2 commits into
masterfrom
ccr-63ba4490-n2d7rz
Oct 1, 2026
Merged

daedalus merged 2 commits into
masterfrom
ccr-63ba4490-n2d7rz

Conversation

@daedalus

@daedalus daedalus commented Oct 1, 2026 •

Copy link
Copy Markdown
Owner

Power Doppler on coverage: slow time = mutants of one seed, pixel = edge, sample = log2(1+hits).

mutants ─▶ X[n,e] ─▶ mean removal ─▶ SVD wall filter ─▶ CFAR χ² ─▶ flow power ─▶ energy∈[0,1]
            (static path)   (drop path-wide "flash")  (input-sensitive edges)
  • core/power_doppler.py: doppler_power() + PowerDoppler (LRU-bounded ensembles, ≤16 MiB). Gram eigendecomposition replaces full SVD (~6× faster close).
  • SeedScorer doppler schedule: energy → [1, max_mult], same clamp as katz.
  • Wiring: fuzz_one feeds SHM hit counts per execution (zero cost when off); pick path reads energy; CLI choice; enabled-features list.
  • Docs: DEEP_DIVE, README, TODO (A/B owed), architecture graph.

Tests: tests/test_power_doppler.py — falsification (static ensemble/seed → no energy), adversarial (flash is clutter; flow survives flash; out-of-range energy clamped), Gram-vs-LAPACK equivalence, memory caps, end-to-end loop wiring (clang).

Cost: ~100 µs/exec at 2k live edges, mostly get_edge_counts() dict → numpy. Unmeasured on fuzzgoat.

🤖 Generated with Claude Code

https://claude.ai/code/session_019AERo9TJciJNQMw2uc18qM


Generated by Claude Code

Summary by Sourcery

Add a coverage-driven Power Doppler schedule that prioritizes seeds whose mutants produce localized, input-sensitive edge movement.

New Features:

  • Add the --schedule doppler power schedule to derive seed mutation energy from input-sensitive coverage changes across mutant ensembles.

Enhancements:

  • Implement bounded Power Doppler scoring with static-path and coherent-flash filtering, CFAR flow detection, normalized energy, and flow-edge reporting.
  • Wire per-execution shared-memory hit counts into Doppler observation and use the resulting energy during seed selection, with neutral behavior when unscored.

Documentation:

  • Document the Doppler schedule, CLI option, architecture, performance characteristics, and pending benchmarking work.

Tests:

  • Add unit, adversarial, numerical-equivalence, resource-bound, schedule-clamping, and end-to-end wiring tests for Power Doppler.

Slow time = mutants of one seed; pixel = edge; sample = log2(1+hits).
Mean removal + SVD wall filter (participation ratio drops path-wide
"flash" components), CFAR chi^2 detection, flow power -> [0,1] energy,
scaled to [1, max_mult] like katz. Bounded LRU ensembles; Gram
eigendecomposition instead of full SVD (~6x faster close).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019AERo9TJciJNQMw2uc18qM
@sourcery-ai

sourcery-ai Bot commented Oct 1, 2026

Copy link
Copy Markdown

Reviewer's Guide

Introduces a SHM-coverage-based power Doppler signal that aggregates mutant ensembles per seed, filters static/coherent coverage, detects input-sensitive flow, and converts it into a bounded mutation-energy multiplier exposed through --schedule doppler; documentation, architecture diagrams, and comprehensive unit/integration tests are included.

Sequence diagram for the Doppler seed-energy feedback loop

sequenceDiagram
    participant Fuzzer
    participant SHM as SHMcoverage
    participant Doppler as PowerDoppler
    participant Scorer as SeedScorer

    Fuzzer->>SHM: get_edge_counts()
    SHM-->>Fuzzer: hit counts per edge
    Fuzzer->>Doppler: observe(seed_key, hits)
    Doppler->>Doppler: doppler_power(ensemble)
    Doppler-->>Fuzzer: energy(seed_key)
    Fuzzer->>Scorer: score(doppler_energy)
    Scorer-->>Fuzzer: mutation energy multiplier
Loading

Flow diagram for power Doppler energy computation

flowchart LR
    A["Mutant executions for one seed"] --> B["X[n,e] = log2(1 + SHM hits)"]
    B --> C["Remove per-edge mean"]
    C --> D["Gram eigendecomposition"]
    D --> E["Drop coherent flash components"]
    E --> F["CFAR chi-squared flow detection"]
    F --> G["Sum residual flow power"]
    G --> H["Log-normalize energy to 0..1"]
    H --> I["Scale SeedScorer energy to 1..max_mult"]
Loading

File-Level Changes

Change Details Files
Add the power Doppler signal-processing implementation and bounded per-seed ensemble state.
  • Transforms successive SHM hit-count maps into log-scaled edge samples.
  • Removes static and spatially coherent clutter using mean filtering and Gram-based eigendecomposition.
  • Applies CFAR chi-squared detection and log-normalizes flow power into seed energy.
  • Bounds open ensembles, edge columns, and closed scores with LRU/capacity limits.
src/fuzzer_tool/core/power_doppler.py
Expose Doppler energy as a selectable seed power schedule.
  • Adds doppler to SeedScorer schedules and clamps energy to the existing [1, max_mult] multiplier range.
  • Adds the --schedule doppler CLI option and enabled-feature reporting.
  • Documents the algorithm, resource bounds, expected runtime, and outstanding A/B measurement work.
src/fuzzer_tool/core/schedules.py
src/fuzzer_tool/cli/commands.py
README.md
docs/DEEP_DIVE.md
docs/TODO.md
Wire per-execution coverage observations into scheduling and consume energy during seed selection.
  • Initializes PowerDoppler only when the Doppler schedule is enabled.
  • Feeds non-crash, non-timeout SHM hit counts under the parent seed key.
  • Passes the current seed's Doppler energy into scoring.
src/fuzzer_tool/services/fuzzer.py
Update the architecture visualization to include the new scheduling path.
  • Refreshes the DOT graph and rendered SVG.
docs/architecture.dot
docs/images/architecture.svg
Add algorithmic, bounded-resource, schedule, and integration coverage for Doppler.
  • Tests static ensembles, coherent flashes, local flow, Gram/SVD equivalence, degenerate inputs, clamping, and late edge discovery.
  • Tests ensemble closure, flow-edge reporting, LRU and edge caps, invalid parameters, and saturated counts.
  • Runs a clang-built end-to-end fuzzing loop to verify SHM observations close ensembles.
tests/test_power_doppler.py

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@daedalus
daedalus marked this pull request as ready for review October 1, 2026 00:15
Copilot AI balanced review requested due to automatic review settings October 1, 2026 00:15
@daedalus
daedalus merged commit 19867c6 into master Oct 1, 2026

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry @daedalus, you've used your own review budget of 250,000 diff characters for the last 7 days.

You can request another review in 2 days and 15 hours by commenting @sourcery-ai review. Upgrade to get a review now.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Multi-target correctness, empty-sample handling, cache behavior, and memory usage must be addressed.

Review effort: Balanced
Findings: 1 High severity · 4 Medium severity · 1 Low severity

Open (6)
What changed in this PR

Adds a coverage-driven Doppler seed-energy schedule using mutant hit-count ensembles.

Changes:

  • Implements Doppler filtering, CFAR scoring, and bounded caches.
  • Wires scoring into SHM execution, scheduling, CLI, and tests.
  • Updates user, architecture, and release documentation.
File Description
src/​fuzzer_tool/​core/​power_doppler.py Implements Doppler analysis and caching.
src/​fuzzer_tool/​core/​schedules.py Applies Doppler energy to seed scores.
src/​fuzzer_tool/​services/​fuzzer.py Collects samples and reads seed energy.
src/​fuzzer_tool/​cli/​commands.py Adds the CLI schedule option.
tests/​test_power_doppler.py Adds algorithm and integration tests.
README.md Lists the schedule.
CHANGELOG.md Records the feature.
docs/​DEEP_DIVE.md Documents algorithm and behavior.
docs/​TODO.md Tracks benchmarking work.
docs/​architecture.dot Adds Doppler to the architecture source.
docs/​images/​architecture.svg Regenerates the SVG diagram.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

and not is_crash
and not is_timeout
):
self._doppler.observe(self._seed_key(data), scanned_shm.get_edge_counts())
Comment on lines +219 to +220
self._open: LRUCache = LRUCache(max_seeds)
self._scores: LRUCache = LRUCache(max_scores, on_evict=self._evicted)
old = self._scores.get(seed_key)
if old is not None and old[0] >= self._max_power:
self._max_stale = True
self._scores[seed_key] = (power, frozenset(ens.ids[: ens.m][flow].tolist()))
Comment on lines +2349 to +2352
if schedule == "doppler":
from fuzzer_tool.core.power_doppler import PowerDoppler

self._doppler = PowerDoppler()
Comment on lines +239 to +240
if r.returncode != 0:
pytest.skip(f"driver failed to build: {r.stderr[:300]}")
Comment thread docs/architecture.dot
label="1 · Scheduling — what to fuzz next";
color="#bcd0c4"; fillcolor="#f2f8f4"; fontcolor="#33604a";
picker [label="services/seed_picker.py + core/schedules.py\lweights · Pareto front · crowding · saturation gate\lFAST COE RARE MMOPT LIN QUAD GO AFLGO ENTROPIC KATZ\lKRUSKAL-COUNT (coupling walkers · recombination)\l",
picker [label="services/seed_picker.py + core/schedules.py\lweights · Pareto front · crowding · saturation gate\lFAST COE RARE MMOPT LIN QUAD GO AFLGO ENTROPIC KATZ DOPPLER\lKRUSKAL-COUNT (coupling walkers · recombination)\l",
daedalus added a commit that referenced this pull request Oct 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants