aboutsummaryrefslogtreecommitdiff
path: root/docs
diff options
context:
space:
mode:
authorDominik Maier <domenukk@gmail.com>2020-11-18 02:41:35 +0100
committerDominik Maier <domenukk@gmail.com>2020-11-18 02:41:35 +0100
commit57f8aec3814e1959d36210815a0369d7bc149ac7 (patch)
treeee0df9ff58e24f6b19b95d5009a007017746933c /docs
parent23f37ff5054d77abf7baf7b6d01d660b435d81cd (diff)
downloadAFLplusplus-57f8aec3814e1959d36210815a0369d7bc149ac7.tar.gz
brought back missing env vars
Diffstat (limited to 'docs')
-rw-r--r--docs/env_variables.md15
1 files changed, 15 insertions, 0 deletions
diff --git a/docs/env_variables.md b/docs/env_variables.md
index a36f2b4e..469fc957 100644
--- a/docs/env_variables.md
+++ b/docs/env_variables.md
@@ -306,6 +306,14 @@ checks or alter some of the more exotic semantics of the tool:
don't want AFL++ to spend too much time classifying that stuff and just
rapidly put all timeouts in that bin.
+ - Setting `AFL_FORKSRV_INIT_TMOUT` allows yout to specify a different timeout
+ to wait for the forkserver to spin up. The default is the `-t` value times
+ `FORK_WAIT_MULT` from `config.h` (usually 10), so for a `-t 100`, the
+ default would wait `1000` milis. Setting a different time here is useful
+ if the target has a very slow startup time, for example when doing
+ full-system fuzzing or emulation, but you don't want the actual runs
+ to wait too long for timeouts.
+
- `AFL_NO_ARITH` causes AFL++ to skip most of the deterministic arithmetics.
This can be useful to speed up the fuzzing of text-based file formats.
@@ -389,6 +397,13 @@ checks or alter some of the more exotic semantics of the tool:
for an existing out folder, even if a different `-i` was provided.
Without this setting, afl-fuzz will refuse execution for a long-fuzzed out dir.
+ - Setting `AFL_MAX_DET_EXRAS` will change the threshold at what number of elements
+ in the `-x` dictionary and LTO autodict (combined) the probabilistic mode will
+ kick off. In probabilistic mode, not all dictionary entires will be used all
+ of the times for fuzzing mutations to not make fuzzing slower by it.
+ The default count is `200` element. So for the 200 + 1st element, there is a
+ 1 in 201 chance, that one of the dictionary entry will not be used directly.
+
- Setting `AFL_NO_FORKSRV` disables the forkserver optimization, reverting to
fork + execve() call for every tested input. This is useful mostly when
working with unruly libraries that create threads or do other crazy