diff options
author | van Hauser <vh@thc.org> | 2021-07-19 10:54:12 +0200 |
---|---|---|
committer | GitHub <noreply@github.com> | 2021-07-19 10:54:12 +0200 |
commit | 815161827689c339d335233b7b232ac9b120b79b (patch) | |
tree | 4e686574ccf1f47cea79fc24514c8455e3a1fbc1 /utils/aflpp_driver/README.md | |
parent | 9321a24e682b5c8bf6278961bd014cb883b87295 (diff) | |
parent | cc57cc5f463e9b79980c2087d19b4a1e1360ec52 (diff) | |
download | afl++-815161827689c339d335233b7b232ac9b120b79b.tar.gz |
Merge branch 'release' into stable
Diffstat (limited to 'utils/aflpp_driver/README.md')
-rw-r--r-- | utils/aflpp_driver/README.md | 7 |
1 files changed, 0 insertions, 7 deletions
diff --git a/utils/aflpp_driver/README.md b/utils/aflpp_driver/README.md index 4ca59776..f03c2fe3 100644 --- a/utils/aflpp_driver/README.md +++ b/utils/aflpp_driver/README.md @@ -22,8 +22,6 @@ or `@@` as command line parameters. ## aflpp_qemu_driver -Note that you can use the driver too for frida_mode (`-O`). - aflpp_qemu_driver is used for libfuzzer `LLVMFuzzerTestOneInput()` targets that are to be fuzzed in qemu_mode. So we compile them with clang/clang++, without -fsantize=fuzzer or afl-clang-fast, and link in libAFLQemuDriver.a: @@ -36,8 +34,3 @@ Then just do (where the name of the binary is `fuzz`): AFL_QEMU_PERSISTENT_ADDR=0x$(nm fuzz | grep "T LLVMFuzzerTestOneInput" | awk '{print $1}') AFL_QEMU_PERSISTENT_HOOK=/path/to/aflpp_qemu_driver_hook.so afl-fuzz -Q ... -- ./fuzz` ``` - -if you use afl-cmin or `afl-showmap -C` with the aflpp_qemu_driver you need to -set the set same AFL_QEMU_... (or AFL_FRIDA_...) environment variables. -If you want to use afl-showmap (without -C) or afl-cmin.bash then you may not -set these environment variables and rather set `AFL_QEMU_DRIVER_NO_HOOK=1`. |