about summary refs log tree commit diff
path: root/examples/aflpp_driver
diff options
context:
space:
mode:
authorAndrea Fioraldi <andreafioraldi@gmail.com>2020-06-03 11:38:44 +0200
committerAndrea Fioraldi <andreafioraldi@gmail.com>2020-06-03 11:38:44 +0200
commitf1192b2d16116fb6c8dc2673e37ec426b7792312 (patch)
treeea90d1c56dbdd18625940e529ee601d9fec02f53 /examples/aflpp_driver
parent1c95e2e8e0674b69bf38e3e097948c6db9f07493 (diff)
downloadafl++-f1192b2d16116fb6c8dc2673e37ec426b7792312.tar.gz
AFL_QEMU_DRIVER_NO_HOOK
Diffstat (limited to 'examples/aflpp_driver')
-rw-r--r--examples/aflpp_driver/aflpp_qemu_driver.c23
1 files changed, 21 insertions, 2 deletions
diff --git a/examples/aflpp_driver/aflpp_qemu_driver.c b/examples/aflpp_driver/aflpp_qemu_driver.c
index dd272408..0944148e 100644
--- a/examples/aflpp_driver/aflpp_qemu_driver.c
+++ b/examples/aflpp_driver/aflpp_qemu_driver.c
@@ -1,17 +1,36 @@
 #include <stdint.h>
 #include <stdlib.h>
+#include <unistd.h>
 
 // libFuzzer interface is thin, so we don't include any libFuzzer headers.
 int LLVMFuzzerTestOneInput(const uint8_t *Data, size_t Size);
 __attribute__((weak)) int LLVMFuzzerInitialize(int *argc, char ***argv);
 
+static const size_t kMaxAflInputSize = 1 << 20;
+static uint8_t AflInputBuf[kMaxAflInputSize];
+
+void afl_qemu_driver_stdin_input(void) {
+
+  size_t l = read(0, AflInputBuf, kMaxAflInputSize);
+  LLVMFuzzerTestOneInput(AflInputBuf, l);
+
+}
+
 int main(int argc, char **argv) {
   if (LLVMFuzzerInitialize)
     LLVMFuzzerInitialize(&argc, &argv);
   // Do any other expensive one-time initialization here.
 
-  uint8_t dummy_input[1] = {0};
-  LLVMFuzzerTestOneInput(dummy_input, 1);
+  if (getenv("AFL_QEMU_DRIVER_NO_HOOK")) {
+
+    afl_qemu_driver_stdin_input();
+
+  } else {
+
+    uint8_t dummy_input[1] = {0};
+    LLVMFuzzerTestOneInput(dummy_input, 1);
+
+  }
   
   return 0;
 }