This commit is contained in:
van Hauser
2020-08-09 12:15:36 +02:00
parent 0bb59ba116
commit a1129b67c2
4 changed files with 31 additions and 8 deletions

View File

@ -896,6 +896,7 @@ void write_bitmap(afl_state_t *);
u32 count_bits(afl_state_t *, u8 *); u32 count_bits(afl_state_t *, u8 *);
u32 count_bits_len(afl_state_t *, u8 *, u32); u32 count_bits_len(afl_state_t *, u8 *, u32);
u32 count_bytes(afl_state_t *, u8 *); u32 count_bytes(afl_state_t *, u8 *);
u32 count_bytes_len(afl_state_t *, u8 *, u32);
u32 count_non_255_bytes(afl_state_t *, u8 *); u32 count_non_255_bytes(afl_state_t *, u8 *);
#ifdef WORD_SIZE_64 #ifdef WORD_SIZE_64
void simplify_trace(afl_state_t *, u64 *); void simplify_trace(afl_state_t *, u64 *);

View File

@ -235,6 +235,29 @@ u32 count_bytes(afl_state_t *afl, u8 *mem) {
} }
u32 count_bytes_len(afl_state_t *afl, u8 *mem, u32 len) {
u32 *ptr = (u32 *)mem;
u32 i = (len >> 2);
u32 ret = 0;
while (i--) {
u32 v = *(ptr++);
if (!v) { continue; }
if (v & 0x000000ff) { ++ret; }
if (v & 0x0000ff00) { ++ret; }
if (v & 0x00ff0000) { ++ret; }
if (v & 0xff000000) { ++ret; }
}
return ret;
}
/* Count the number of non-255 bytes set in the bitmap. Used strictly for the /* Count the number of non-255 bytes set in the bitmap. Used strictly for the
status screen, several calls per second or so. */ status screen, several calls per second or so. */

View File

@ -479,10 +479,11 @@ abort_calibration:
if (afl_fsrv_run_target(&afl->taint_fsrv, use_tmout, &afl->stop_soon) == if (afl_fsrv_run_target(&afl->taint_fsrv, use_tmout, &afl->stop_soon) ==
0) { 0) {
u32 len = q->len / 8; u32 len = q->len;
if (q->len % 8) len++; if (len % 4)
u32 bits = count_bits_len(afl, afl->taint_fsrv.trace_bits, len); len = len + 4 - (q->len % 4);
if (afl->debug) fprintf(stderr, "Debug: tainted bytes: %u\n", bits); u32 bytes = count_bytes_len(afl, afl->taint_fsrv.trace_bits, len);
if (afl->debug) fprintf(stderr, "Debug: tainted bytes: %u\n", bytes);
} }

View File

@ -825,11 +825,9 @@ int main(int argc, char **argv_orig, char **envp) {
} }
if (afl->fsrv.taint_mode && afl->fsrv.map_size < (MAX_FILE / 8) + 1) { if (afl->fsrv.taint_mode && afl->fsrv.map_size < MAX_FILE) {
afl->shm.map_size = (MAX_FILE / 8); afl->fsrv.map_size = afl->shm.map_size = MAX_FILE;
if (MAX_FILE % 8) afl->shm.map_size++;
afl->fsrv.map_size = afl->shm.map_size;
} }