[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [PATCH v10 00/22] Add virtual device fuzzing support
From: |
Stefan Hajnoczi |
Subject: |
Re: [PATCH v10 00/22] Add virtual device fuzzing support |
Date: |
Fri, 21 Feb 2020 15:17:51 +0000 |
On Wed, Feb 19, 2020 at 11:10:56PM -0500, Alexander Bulekov wrote:
> Hello,
>
> This series adds a framework for coverage-guided fuzzing of
> virtual-devices. Fuzzing targets are based on qtest and can make use of
> libqos. Fuzzing can help discover device bugs, such as
> assertion-failures, timeouts, and overflows, triggerable from within
> guests.
>
> V10:
> * Update MAINTAINERS for vl.c, main.c and tests/qtest/fuzz
> * Fix changes to checkpatch
> * Fix typos in virtio-scsi fuzzer
>
> V9:
> * Fix bug in the virtio-scsi fuzzer. Virtqueues were being kicked only
> if free_head != 0 (which it never was).
> * Move vl.c and main.c into a new directory: softmmu/
> * virtio-net-fuzz: refactor the looop over used descriptor.
> * Improve comments for i440fx and virtio-scsi fuzzers.
>
> V8:
> * Small fixes to the virtio-net.
> * Keep rcu_atfork when not using qtest.
>
> V7:
> * virtio-net: add virtio-net-check-used which waits for inputs on
> the tx/ctrl vq by watching the used vring.
> * virtio-net: add virtio-net-socket which uses the socket backend and can
> exercise the rx components of virtio-net.
> * virtio-net: add virtio-net-slirp which uses the user backend and exercises
> slirp. This may lead to real traffic emitted by qemu so it is best to
> run in an isolated network environment.
> * build should succeed after each commit
>
> V5/V6:
> * added virtio-scsi fuzzer
> * add support for using fork-based fuzzers with multiple libfuzzer
> workers
> * misc fixes addressing V4 comments
> * cleanup in-process handlers/globals in libqtest.c
> * small fixes to fork-based fuzzing and support for multiple workers
> * changes to the virtio-net fuzzer to kick after each vq add
>
> V4:
> * add/transfer license headers to new files
> * restructure the added QTestClientTransportOps struct
> * restructure the FuzzTarget struct and fuzzer skeleton
> * fork-based fuzzer now directly mmaps shm over the coverage bitmaps
> * fixes to i440 and virtio-net fuzz targets
> * undo the changes to qtest_memwrite
> * possible to build /fuzz and /all in the same build-dir
> * misc fixes to address V3 comments
>
> V3:
> * rebased onto v4.1.0+
> * add the fuzzer as a new build-target type in the build-system
> * add indirection to qtest client/server communication functions
> * remove ramfile and snapshot-based fuzzing support
> * add i440fx fuzz-target as a reference for developers.
> * add linker-script to assist with fork-based fuzzer
>
> V2:
> * split off changes to qos virtio-net and qtest server to other patches
> * move vl:main initialization into new func: qemu_init
> * moved useful functions from qos-test.c to a separate object
> * use struct of function pointers for add_fuzz_target(), instead of
> arguments
> * move ramfile to migration/qemu-file
> * rewrite fork-based fuzzer pending patch to libfuzzer
> * pass check-patch
>
> Alexander Bulekov (22):
> softmmu: move vl.c to softmmu/
> softmmu: split off vl.c:main() into main.c
> module: check module wasn't already initialized
> fuzz: add FUZZ_TARGET module type
> qtest: add qtest_server_send abstraction
> libqtest: add a layer of abstraction to send/recv
> libqtest: make bufwrite rely on the TransportOps
> qtest: add in-process incoming command handler
> libqos: rename i2c_send and i2c_recv
> libqos: split qos-test and libqos makefile vars
> libqos: move useful qos-test funcs to qos_external
> fuzz: add fuzzer skeleton
> exec: keep ram block across fork when using qtest
> main: keep rcu_atfork callback enabled for qtest
> fuzz: support for fork-based fuzzing.
> fuzz: add support for qos-assisted fuzz targets
> fuzz: add target/fuzz makefile rules
> fuzz: add configure flag --enable-fuzzing
> fuzz: add i440fx fuzz targets
> fuzz: add virtio-net fuzz target
> fuzz: add virtio-scsi fuzz target
> fuzz: add documentation to docs/devel/
>
> MAINTAINERS | 11 +-
> Makefile | 15 +-
> Makefile.objs | 2 -
> Makefile.target | 19 ++-
> configure | 39 +++++
> docs/devel/fuzzing.txt | 116 ++++++++++++++
> exec.c | 12 +-
> include/qemu/module.h | 4 +-
> include/sysemu/qtest.h | 4 +
> include/sysemu/sysemu.h | 4 +
> qtest.c | 31 +++-
> scripts/checkpatch.pl | 2 +-
> scripts/get_maintainer.pl | 3 +-
> softmmu/Makefile.objs | 3 +
> softmmu/main.c | 53 +++++++
> vl.c => softmmu/vl.c | 48 +++---
> tests/qtest/Makefile.include | 72 ++++-----
> tests/qtest/fuzz/Makefile.include | 18 +++
> tests/qtest/fuzz/fork_fuzz.c | 55 +++++++
> tests/qtest/fuzz/fork_fuzz.h | 23 +++
> tests/qtest/fuzz/fork_fuzz.ld | 37 +++++
> tests/qtest/fuzz/fuzz.c | 179 +++++++++++++++++++++
> tests/qtest/fuzz/fuzz.h | 95 +++++++++++
> tests/qtest/fuzz/i440fx_fuzz.c | 193 +++++++++++++++++++++++
> tests/qtest/fuzz/qos_fuzz.c | 234 ++++++++++++++++++++++++++++
> tests/qtest/fuzz/qos_fuzz.h | 33 ++++
> tests/qtest/fuzz/virtio_net_fuzz.c | 198 +++++++++++++++++++++++
> tests/qtest/fuzz/virtio_scsi_fuzz.c | 213 +++++++++++++++++++++++++
> tests/qtest/libqos/i2c.c | 10 +-
> tests/qtest/libqos/i2c.h | 4 +-
> tests/qtest/libqos/qos_external.c | 168 ++++++++++++++++++++
> tests/qtest/libqos/qos_external.h | 28 ++++
> tests/qtest/libqtest.c | 119 ++++++++++++--
> tests/qtest/libqtest.h | 4 +
> tests/qtest/pca9552-test.c | 10 +-
> tests/qtest/qos-test.c | 132 +---------------
> util/module.c | 7 +
> 37 files changed, 1969 insertions(+), 229 deletions(-)
> create mode 100644 docs/devel/fuzzing.txt
> create mode 100644 softmmu/Makefile.objs
> create mode 100644 softmmu/main.c
> rename vl.c => softmmu/vl.c (99%)
> create mode 100644 tests/qtest/fuzz/Makefile.include
> create mode 100644 tests/qtest/fuzz/fork_fuzz.c
> create mode 100644 tests/qtest/fuzz/fork_fuzz.h
> create mode 100644 tests/qtest/fuzz/fork_fuzz.ld
> create mode 100644 tests/qtest/fuzz/fuzz.c
> create mode 100644 tests/qtest/fuzz/fuzz.h
> create mode 100644 tests/qtest/fuzz/i440fx_fuzz.c
> create mode 100644 tests/qtest/fuzz/qos_fuzz.c
> create mode 100644 tests/qtest/fuzz/qos_fuzz.h
> create mode 100644 tests/qtest/fuzz/virtio_net_fuzz.c
> create mode 100644 tests/qtest/fuzz/virtio_scsi_fuzz.c
> create mode 100644 tests/qtest/libqos/qos_external.c
> create mode 100644 tests/qtest/libqos/qos_external.h
Thomas Huth (tests/ maintainer) is away on leave and the device fuzzer
covers virtio-blk/scsi, so I will merge this.
Thanks, applied to my block tree:
https://github.com/stefanha/qemu/commits/block
Stefan
signature.asc
Description: PGP signature
- [PATCH v10 16/22] fuzz: add support for qos-assisted fuzz targets, (continued)
- [PATCH v10 16/22] fuzz: add support for qos-assisted fuzz targets, Alexander Bulekov, 2020/02/19
- [PATCH v10 17/22] fuzz: add target/fuzz makefile rules, Alexander Bulekov, 2020/02/19
- [PATCH v10 19/22] fuzz: add i440fx fuzz targets, Alexander Bulekov, 2020/02/19
- [PATCH v10 20/22] fuzz: add virtio-net fuzz target, Alexander Bulekov, 2020/02/19
- [PATCH v10 21/22] fuzz: add virtio-scsi fuzz target, Alexander Bulekov, 2020/02/19
- [PATCH v10 22/22] fuzz: add documentation to docs/devel/, Alexander Bulekov, 2020/02/19
- Re: [PATCH v10 00/22] Add virtual device fuzzing support,
Stefan Hajnoczi <=