Files
bacnet_stack/apps/fuzz-afl
Steve Karg 1372e52aa7 Feature/mstp extended frames (#529)
* added MSTP extended frames to bacnet/datalink/mstp.c module. Thank you, Simon!

* auto-size some FIFO buffers for MSTP

* add COBS library to MSTP builds

---------

Co-authored-by: Steve Karg <skarg@users.sourceforge.net>
2023-11-08 15:54:18 -06:00
..
2023-07-17 10:06:32 -05:00
2023-11-08 15:54:18 -06:00
2023-07-17 10:06:32 -05:00

Getting Started

  • Install AFL, ensure afl-gcc exists on the system:
$ afl-gcc
afl-cc 2.57b by <lcamtuf@google.com>
  • Build via make fuzz-afl from repository root
  • Clone a decent corpus
  • Start AFL and feed it the input/output directories along with target executable
afl-fuzz -i </path/to/corpus/> -o </path/to/output_dir/> -m none ./apps/fuzz-afl/fuzz-afl

Caveats:

  • This builds the target with ASAN (Address Sanitizer). This makes AFL require the -m none to not interpret ASAN's behavior as a crash
  • AFL uses a fork/exec model to launch the target. This is nice because each testcase is from a clean state. But this also brings in a lot of overhead. If you need something faster, check out ../fuzz-libfuzzer/