AFLplusplus / AFLplusplus/LibAFL
Restart after n target executions, instead of n fuzz_loops
Open
enhancement
help wanted
- Dominant language
- Rust
- Stars
- 2.6k
- Forks
- 481
- Avg merge
- 2d 30m
- Merged PRs (30d)
- 16
Description
So far, we have the option to restart an InProcess target after n rounds of fuzzing.
This means, however, that the number of target executions per round potentially grows after more testcases have been added to the corpus.
Instead, we should offer the option to restart after a fixed amount of iterations, to make sure targets leaking memory won't explode over time.
This could either be done by counting executions in the harness, and raising a signal accordingly (not taking it as objective), or by counting outside of the executor and retuning from the current stage.
Contributor guide
Assessment
This issue has not been assessed yet.