OSS-Fuzz: Five months later, and rewarding projects
opensource.googleblog.com
opensource.googleblog.com
[1] http://blog.jessitron.com/2013/04/property-based-testing-wha...
https://github.com/silentbicycle/theft
Slides on automated tool below. They use "model-based testing" which is another phrase to get interesting search results.
https://www.slideshare.net/dganesan11/ganesan-automated-test...
Also combinational testing which showed promise at catching in high 90's of defect percentage with test case minimization as a bonus. See summary and slides.
https://lcamtuf.blogspot.com/2015/04/finding-bugs-in-sqlite-...
I think they eventually incorporated AFL into their continuous testing and squashed several dozen bugs. OSS Fuzz scales it up, but yup - the bottom line is that you might think you have 100% test coverage, but you really still need to fuzz =)
One hundred percent line coverage is admirable, but it's just a start! (Edit: I see that they had far more than just 100% line coverage, but as you can see even this is not enough to find all cases.)
The linked document answers that both repeatedly and at length:
> The SQLite core, including the unix VFS, has 100% branch test coverage under TH3 in its default configuration as measured by gcov.
[follow half a dozen paragraph explaining what they mean precisely by branch coverage]
char buffer[15];
.....
memcpy(buffer, source, strlen(source));
Depending on the `source`, the bug can be triggered or not, but the coverage is the same for different `source` values.