aboutsummaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorvan Hauser <vh@thc.org>2021-03-11 19:13:53 +0100
committerGitHub <noreply@github.com>2021-03-11 19:13:53 +0100
commite5bdba4b9f22c0f2e4ff60ffc9bfa8fbaeb586d2 (patch)
tree7ee95ab6f5f6b64cddb331d09adb4d823885b3e5
parente549102563ecfacc941f6451f2751681aa8d19c8 (diff)
parentc725cb71de1f7be2f2f8f78a95716267f515336d (diff)
downloadafl++-e5bdba4b9f22c0f2e4ff60ffc9bfa8fbaeb586d2.tar.gz
Merge pull request #807 from AFLplusplus/dev
push to stable
-rw-r--r--src/afl-fuzz.c22
-rwxr-xr-xtest/test-llvm.sh4
2 files changed, 13 insertions, 13 deletions
diff --git a/src/afl-fuzz.c b/src/afl-fuzz.c
index dbf4df37..7fe89c11 100644
--- a/src/afl-fuzz.c
+++ b/src/afl-fuzz.c
@@ -1596,9 +1596,9 @@ int main(int argc, char **argv_orig, char **envp) {
&afl->fsrv, afl->argv, &afl->stop_soon, afl->afl_env.afl_debug_child);
// only reinitialize when it makes sense
- if (map_size < new_map_size ||
- (!afl->cmplog_binary && new_map_size < map_size &&
- map_size - new_map_size > MAP_SIZE)) {
+ if ((map_size < new_map_size ||
+ (new_map_size != MAP_SIZE && new_map_size < map_size &&
+ map_size - new_map_size > MAP_SIZE))) {
OKF("Re-initializing maps to %u bytes", new_map_size);
@@ -1644,7 +1644,7 @@ int main(int argc, char **argv_orig, char **envp) {
if (map_size <= 8000000 && !afl->non_instrumented_mode &&
!afl->fsrv.qemu_mode && !afl->unicorn_mode) {
- afl->fsrv.map_size = 8000000; // dummy temporary value
+ afl->cmplog_fsrv.map_size = 8000000; // dummy temporary value
setenv("AFL_MAP_SIZE", "8000000", 1);
}
@@ -1654,8 +1654,7 @@ int main(int argc, char **argv_orig, char **envp) {
afl->afl_env.afl_debug_child);
// only reinitialize when it needs to be larger
- if (map_size < new_map_size ||
- (new_map_size < map_size && map_size - new_map_size > MAP_SIZE)) {
+ if (map_size < new_map_size) {
OKF("Re-initializing maps to %u bytes due cmplog", new_map_size);
@@ -1674,22 +1673,23 @@ int main(int argc, char **argv_orig, char **envp) {
afl_fsrv_kill(&afl->fsrv);
afl_fsrv_kill(&afl->cmplog_fsrv);
afl_shm_deinit(&afl->shm);
+
afl->cmplog_fsrv.map_size = new_map_size; // non-cmplog stays the same
+ map_size = new_map_size;
+ setenv("AFL_NO_AUTODICT", "1", 1); // loaded already
afl->fsrv.trace_bits =
afl_shm_init(&afl->shm, new_map_size, afl->non_instrumented_mode);
- setenv("AFL_NO_AUTODICT", "1", 1); // loaded already
afl_fsrv_start(&afl->fsrv, afl->argv, &afl->stop_soon,
afl->afl_env.afl_debug_child);
-
afl_fsrv_start(&afl->cmplog_fsrv, afl->argv, &afl->stop_soon,
afl->afl_env.afl_debug_child);
- map_size = new_map_size;
+ } else {
- }
+ afl->cmplog_fsrv.map_size = new_map_size;
- afl->cmplog_fsrv.map_size = map_size;
+ }
OKF("Cmplog forkserver successfully started");
diff --git a/test/test-llvm.sh b/test/test-llvm.sh
index 1bcf013a..6503cd98 100755
--- a/test/test-llvm.sh
+++ b/test/test-llvm.sh
@@ -162,9 +162,9 @@ test -e ../afl-clang-fast -a -e ../split-switches-pass.so && {
test -e test-floatingpoint && {
mkdir -p in
echo ZZZZ > in/in
- $ECHO "$GREY[*] running afl-fuzz with floating point splitting, this will take max. 30 seconds"
+ $ECHO "$GREY[*] running afl-fuzz with floating point splitting, this will take max. 45 seconds"
{
- AFL_BENCH_UNTIL_CRASH=1 AFL_NO_UI=1 ../afl-fuzz -Z -s 1 -V30 -m ${MEM_LIMIT} -i in -o out -D -- ./test-floatingpoint >>errors 2>&1
+ AFL_BENCH_UNTIL_CRASH=1 AFL_NO_UI=1 ../afl-fuzz -Z -s 1 -V45 -m ${MEM_LIMIT} -i in -o out -D -- ./test-floatingpoint >>errors 2>&1
} >>errors 2>&1
test -n "$( ls out/default/crashes/id:* 2>/dev/null )" && {
$ECHO "$GREEN[+] llvm_mode laf-intel floatingpoint splitting feature works correctly"