[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[PATCH v7 00/17] Add a Generic Virtual Device Fuzzer
From: |
Alexander Bulekov |
Subject: |
[PATCH v7 00/17] Add a Generic Virtual Device Fuzzer |
Date: |
Fri, 23 Oct 2020 11:07:29 -0400 |
https://gitlab.com/a1xndr/qemu/-/pipelines/206883920
^^ This is still running, but I also performed some local oss-fuzz
builds. Hopefully there should not be any failures.
v7:
- Use hard-links instead of duplicating the same fuzzer binary
(Patch 16)
- Trivial formatting-changes and null-ptr checks as suggested by
Darren
v6:
- Some More "General" -> "Generic"
- Fix broken build between commits (build-tested after each commit
and through gitlab CI)
- Fix some predefined generic-fuzz configs that failed to run
v5:
- Replace GArray-based predefined fuzzer configs with a static
struct array
- "General" -> "Generic"
- Fix bugs with wrong timeout denominator and skipping DMA memwrites
without QTEST_LOG
v4:
- Replace yaml + c template-based oss-fuzz configs, with C code to
register a FuzzTarget for each config (as suggested by Paolo)
- Replicate the functionality of address_space_write_rom to ensure
matching behavior when QTEST_LOG is enabled
- Improve code documentation/comments
- Small formatting changes
v3:
- Use flatviews to help select regions for fuzzing
- Meson-related changes
- Add some documentation
- Improve minimalization script to trim write{bwlq} commands
v2:
- Remove QOS dependency.
- Add a custom crossover function
- Fix broken minimization scripts
- Fixes to the IO region and DMA handling code
This is a general virtual-device fuzzer, designed to fuzz devices over Port IO,
MMIO, and DMA.
To get started with this:
1. Build the fuzzers (see docs/devel/fuzzing.txt)
Note: Build with --enable-sanitizers, or create a "dictionary file":
echo kw1=\"FUZZ\" > dict
and pass it as an argument to libFuzzer with -dict=./dict
This magic value is a command separator that lets the fuzzer perform
multiple IO actions with a single input.
2. Pick the qemu arguments you wish to fuzz:
export QEMU_FUZZ_ARGS="-M q35 -device virtio-balloon"
3. Tell the fuzzer which QOM objects or MemoryRegion names to fuzz. I find the
"info qom-tree", "info qtree" and "info mtree" commands useful for identifying
these. Supports globbing. Here I will try to simultaneously fuzz(for no good
reason) virtio-balloon and e1000e, which is included by default in the q35:
export QEMU_FUZZ_OBJECTS='virtio* e1000*'
You can also try to fuzz the whole machine:
export QEMU_FUZZ_OBJECTS='*'
4. Run the fuzzer for 0 inputs. The fuzzer should output a list of
MemoryRegions/PCI Devices it will try to fuzz. Confirm that these match your
expectations.
./i386-softmmu/qemu-fuzz-i386 --fuzz-target=general-fuzz -runs=0
5. Run the fuzzer:
./i386-softmmu/qemu-fuzz-i386 --fuzz-target=general-fuzz
Basically, at the core, this fuzzer is an interpreter that splits the input
into a series of commands, such as mmio_write, pio_write, etc. We structure
these commands to hit only MemoryRegions that are associated with the devices
specified in QEMU_FUZZ_OBJECTS. Additionally, these patches add "hooks" to
functions that are typically used by virtual-devices to read from RAM (DMA).
These hooks attempt to populate these DMA regions with fuzzed data, just in
time.
Some of the issues I have found or reproduced with this fuzzer:
https://bugs.launchpad.net/bugs/1525123
https://bugs.launchpad.net/bugs/1681439
https://bugs.launchpad.net/bugs/1777315
https://bugs.launchpad.net/bugs/1878034
https://bugs.launchpad.net/bugs/1878043
https://bugs.launchpad.net/bugs/1878054
https://bugs.launchpad.net/bugs/1878057
https://bugs.launchpad.net/bugs/1878067
https://bugs.launchpad.net/bugs/1878134
https://bugs.launchpad.net/bugs/1878136
https://bugs.launchpad.net/bugs/1878253
https://bugs.launchpad.net/bugs/1878255
https://bugs.launchpad.net/bugs/1878259
https://bugs.launchpad.net/bugs/1878263
https://bugs.launchpad.net/bugs/1878323
https://bugs.launchpad.net/bugs/1878641
https://bugs.launchpad.net/bugs/1878642
https://bugs.launchpad.net/bugs/1878645
https://bugs.launchpad.net/bugs/1878651
https://bugs.launchpad.net/bugs/1879223
https://bugs.launchpad.net/bugs/1879227
https://bugs.launchpad.net/bugs/1879531
https://bugs.launchpad.net/bugs/1880355
https://bugs.launchpad.net/bugs/1880539
https://bugs.launchpad.net/bugs/1884693
https://bugs.launchpad.net/bugs/1886362
https://bugs.launchpad.net/bugs/1887303
https://bugs.launchpad.net/bugs/1887309
https://bugs.launchpad.net/bugs/697510
Alexander Bulekov (17):
memory: Add FlatView foreach function
fuzz: Add generic virtual-device fuzzer
fuzz: Add PCI features to the generic fuzzer
fuzz: Add DMA support to the generic-fuzzer
fuzz: Declare DMA Read callback function
fuzz: Add fuzzer callbacks to DMA-read functions
fuzz: Add support for custom crossover functions
fuzz: add a DISABLE_PCI op to generic-fuzzer
fuzz: add a crossover function to generic-fuzzer
scripts/oss-fuzz: Add script to reorder a generic-fuzzer trace
scripts/oss-fuzz: Add crash trace minimization script
fuzz: Add instructions for using generic-fuzz
fuzz: add an "opaque" to the FuzzTarget struct
fuzz: add generic-fuzz configs for oss-fuzz
fuzz: register predefined generic-fuzz configs
scripts/oss-fuzz: use hardlinks instead of copying
scripts/oss-fuzz: ignore the generic-fuzz target
docs/devel/fuzzing.txt | 39 +
include/exec/memory.h | 21 +
include/exec/memory_ldst_cached.h.inc | 3 +
memory_ldst.c.inc | 4 +
scripts/oss-fuzz/build.sh | 14 +-
scripts/oss-fuzz/minimize_qtest_trace.py | 157 +++
.../oss-fuzz/reorder_fuzzer_qtest_trace.py | 103 ++
softmmu/memory.c | 27 +
softmmu/physmem.c | 2 +
tests/qtest/fuzz/fuzz.c | 13 +
tests/qtest/fuzz/fuzz.h | 28 +
tests/qtest/fuzz/generic_fuzz.c | 952 ++++++++++++++++++
tests/qtest/fuzz/generic_fuzz_configs.h | 121 +++
tests/qtest/fuzz/meson.build | 1 +
14 files changed, 1484 insertions(+), 1 deletion(-)
create mode 100755 scripts/oss-fuzz/minimize_qtest_trace.py
create mode 100755 scripts/oss-fuzz/reorder_fuzzer_qtest_trace.py
create mode 100644 tests/qtest/fuzz/generic_fuzz.c
create mode 100644 tests/qtest/fuzz/generic_fuzz_configs.h
--
2.28.0
- [PATCH v7 00/17] Add a Generic Virtual Device Fuzzer,
Alexander Bulekov <=
- [PATCH v7 06/17] fuzz: Add fuzzer callbacks to DMA-read functions, Alexander Bulekov, 2020/10/23
- [PATCH v7 07/17] fuzz: Add support for custom crossover functions, Alexander Bulekov, 2020/10/23
- [PATCH v7 08/17] fuzz: add a DISABLE_PCI op to generic-fuzzer, Alexander Bulekov, 2020/10/23
- [PATCH v7 01/17] memory: Add FlatView foreach function, Alexander Bulekov, 2020/10/23
- [PATCH v7 02/17] fuzz: Add generic virtual-device fuzzer, Alexander Bulekov, 2020/10/23
- [PATCH v7 09/17] fuzz: add a crossover function to generic-fuzzer, Alexander Bulekov, 2020/10/23
- [PATCH v7 03/17] fuzz: Add PCI features to the generic fuzzer, Alexander Bulekov, 2020/10/23
- [PATCH v7 10/17] scripts/oss-fuzz: Add script to reorder a generic-fuzzer trace, Alexander Bulekov, 2020/10/23
- [PATCH v7 04/17] fuzz: Add DMA support to the generic-fuzzer, Alexander Bulekov, 2020/10/23