AFLplusplus / AFLplusplus/LibAFL

Document more clearly that EmulatorHooks.post_exec get called at the end of the harness

未关闭
#2,765 1 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
enhancement qemu
主要语言
Rust
星标
2.6k
派生
481
平均合并
2 天 30 分钟
30 天内合并 PR
16

描述

**Is your feature request related to a problem? Please describe.**
I just wasted multiple days trying to figure out why my fuzzer, that I based on [qemu_baremetal/low_level](https://github.com/AFLplusplus/LibAFL/blob/main/fuzzers/full_system/qemu_baremetal/src/fuzzer_breakpoint.rs), reported incorrect values for a memory location that I read from my custom module in the `post_exec` step.

This was due to the fact that the snapshot had already been restored and the memory reset to its original value
https://github.com/AFLplusplus/LibAFL/blob/be21fae4909018c2a7dfdc496d70c33a237f6a54/fuzzers/full_system/qemu_baremetal/src/fuzzer_low_level.rs#L192

**Describe the solution you'd like**
Maybe change the post_exec name to post_harness? Also to differentiate against observers?

**Describe alternatives you've considered**
Update the comment to state that the hooks run after the harness

**Additional context**

What would be the correct way to read a chunk of memory after this line has returned?
https://github.com/AFLplusplus/LibAFL/blob/be21fae4909018c2a7dfdc496d70c33a237f6a54/fuzzers/full_system/qemu_baremetal/src/fuzzer_low_level.rs#L160

I can't do it in an observer, because observers need to be serializable, so I can't add a `Qemu` struct to it.
I'm currently storing the return value of `emulator.qemu().run()` in a local var, reading the memory and then match of the stored value but that feels very hacky.

贡献指南

打开贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。