Hi,
I recently had a conversation with Kostya about this and he said he
implemented something in LibFuzzer that seems pretty smart to me.
If I recall correctly libfuzzer is trying to capture strcmp/memcmp
calls and then tries to find one of the strings in the input file and
replaces it with the other one.
I wonder if you want to consider something like this for afl.
Also in the past you put a lot of emphasis on the ease of use of afl.
If it's possible it would certainly the best if whatever mechanism gets
implemented would "just work" without any manual effort. I think
there's nothing in principle that would prevent that.
--
Hanno Böck
https://hboeck.de/
mail/jabber:
ha...@hboeck.de
GPG: BBB51E42