diff options
| author | vanhauser-thc <vh@thc.org> | 2020-09-05 12:11:48 +0200 |
|---|---|---|
| committer | vanhauser-thc <vh@thc.org> | 2020-09-05 12:11:48 +0200 |
| commit | 996986bed5f2dd97a3d76f584d8eddc1203f8396 (patch) | |
| tree | 245d4b208ecb1dcf38c34987aabbd8e44c2703c9 /instrumentation/README.ctx.md | |
| parent | fac108476c1cb5326cf4339b2a4c846828698816 (diff) | |
| download | afl++-996986bed5f2dd97a3d76f584d8eddc1203f8396.tar.gz | |
first batch of changes
Diffstat (limited to 'instrumentation/README.ctx.md')
| -rw-r--r-- | instrumentation/README.ctx.md | 22 |
1 files changed, 22 insertions, 0 deletions
diff --git a/instrumentation/README.ctx.md b/instrumentation/README.ctx.md new file mode 100644 index 00000000..caf2c09a --- /dev/null +++ b/instrumentation/README.ctx.md @@ -0,0 +1,22 @@ +# AFL Context Sensitive Branch Coverage + +## What is this? + +This is an LLVM-based implementation of the context sensitive branch coverage. + +Basically every function gets its own ID and that ID is combined with the +edges of the called functions. + +So if both function A and function B call a function C, the coverage +collected in C will be different. + +In math the coverage is collected as follows: +`map[current_location_ID ^ previous_location_ID >> 1 ^ previous_callee_ID] += 1` + +## Usage + +Set the `AFL_LLVM_INSTRUMENT=CTX` or `AFL_LLVM_CTX=1` environment variable. + +It is highly recommended to increase the MAP_SIZE_POW2 definition in +config.h to at least 18 and maybe up to 20 for this as otherwise too +many map collisions occur. |
