LibFuzzer runs in the same process as the code you want to test, right? Doesn't that mean you have to take special care to recover from errors? I mean, if it messes up the heap, for example, it would be possible but tricky to continue running. And continue is what you want, because then you save a process restart when exploring the parameter space (which makes it very fast).