AFLplusplus / AFLplusplus/LibAFL

Document more clearly that EmulatorHooks.post_exec get called at the end of the harness

Abierto
#2,765 1 comentario 0 reacciones 0 asignados Ver en GitHub
enhancement qemu
Lenguaje dominante
Rust
Estrellas
2.6k
Forks
481
Merge medio
2 d 30 min
PR fusionados (30 d)
16

Descripción

**Is your feature request related to a problem? Please describe.**
I just wasted multiple days trying to figure out why my fuzzer, that I based on [qemu_baremetal/low_level](https://github.com/AFLplusplus/LibAFL/blob/main/fuzzers/full_system/qemu_baremetal/src/fuzzer_breakpoint.rs), reported incorrect values for a memory location that I read from my custom module in the `post_exec` step.

This was due to the fact that the snapshot had already been restored and the memory reset to its original value
https://github.com/AFLplusplus/LibAFL/blob/be21fae4909018c2a7dfdc496d70c33a237f6a54/fuzzers/full_system/qemu_baremetal/src/fuzzer_low_level.rs#L192

**Describe the solution you'd like**
Maybe change the post_exec name to post_harness? Also to differentiate against observers?

**Describe alternatives you've considered**
Update the comment to state that the hooks run after the harness

**Additional context**

What would be the correct way to read a chunk of memory after this line has returned?
https://github.com/AFLplusplus/LibAFL/blob/be21fae4909018c2a7dfdc496d70c33a237f6a54/fuzzers/full_system/qemu_baremetal/src/fuzzer_low_level.rs#L160

I can't do it in an observer, because observers need to be serializable, so I can't add a `Qemu` struct to it.
I'm currently storing the return value of `emulator.qemu().run()` in a local var, reading the memory and then match of the stored value but that feels very hacky.

Guía de contribución

Abrir la guía de contribución

Evaluación

Este issue todavía no se ha evaluado.

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.