[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[PATCH v9 00/23] Add virtual device fuzzing support
From: |
Alexander Bulekov |
Subject: |
[PATCH v9 00/23] Add virtual device fuzzing support |
Date: |
Tue, 11 Feb 2020 15:34:47 -0500 |
Hello,
This series adds a framework for coverage-guided fuzzing of
virtual-devices. Fuzzing targets are based on qtest and can make use of
the libqos abstractions.
V9:
* Fix bug in the virtio-scsi fuzzer. Virtqueues were being kicked only
if free_head != 0 (which it never was).
* Move vl.c and main.c into a new directory: softmmu/
* virtio-net-fuzz: refactor the looop over used descriptor.
* Improve comments for i440fx and virtio-scsi fuzzers.
V8:
* Small fixes to the virtio-net.
* Keep rcu_atfork when not using qtest.
V7:
* virtio-net: add virtio-net-check-used which waits for inputs on
the tx/ctrl vq by watching the used vring.
* virtio-net: add virtio-net-socket which uses the socket backend and can
exercise the rx components of virtio-net.
* virtio-net: add virtio-net-slirp which uses the user backend and exercises
slirp. This may lead to real traffic emitted by qemu so it is best to
run in an isolated network environment.
* build should succeed after each commit
V5/V6:
* added virtio-scsi fuzzer
* add support for using fork-based fuzzers with multiple libfuzzer
workers
* misc fixes addressing V4 comments
* cleanup in-process handlers/globals in libqtest.c
* small fixes to fork-based fuzzing and support for multiple workers
* changes to the virtio-net fuzzer to kick after each vq add
V4:
* add/transfer license headers to new files
* restructure the added QTestClientTransportOps struct
* restructure the FuzzTarget struct and fuzzer skeleton
* fork-based fuzzer now directly mmaps shm over the coverage bitmaps
* fixes to i440 and virtio-net fuzz targets
* undo the changes to qtest_memwrite
* possible to build /fuzz and /all in the same build-dir
* misc fixes to address V3 comments
V3:
* rebased onto v4.1.0+
* add the fuzzer as a new build-target type in the build-system
* add indirection to qtest client/server communication functions
* remove ramfile and snapshot-based fuzzing support
* add i440fx fuzz-target as a reference for developers.
* add linker-script to assist with fork-based fuzzer
V2:
* split off changes to qos virtio-net and qtest server to other patches
* move vl:main initialization into new func: qemu_init
* moved useful functions from qos-test.c to a separate object
* use struct of function pointers for add_fuzz_target(), instead of
arguments
* move ramfile to migration/qemu-file
* rewrite fork-based fuzzer pending patch to libfuzzer
* pass check-patch
Alexander Bulekov (23):
checkpatch: replace vl.c in the top of repo check
softmmu: move vl.c to softmmu/
softmmu: split off vl.c:main() into main.c
module: check module wasn't already initialized
fuzz: add FUZZ_TARGET module type
qtest: add qtest_server_send abstraction
libqtest: add a layer of abstraction to send/recv
libqtest: make bufwrite rely on the TransportOps
qtest: add in-process incoming command handler
libqos: rename i2c_send and i2c_recv
libqos: split qos-test and libqos makefile vars
libqos: move useful qos-test funcs to qos_external
fuzz: add fuzzer skeleton
exec: keep ram block across fork when using qtest
main: keep rcu_atfork callback enabled for qtest
fuzz: support for fork-based fuzzing.
fuzz: add support for qos-assisted fuzz targets
fuzz: add target/fuzz makefile rules
fuzz: add configure flag --enable-fuzzing
fuzz: add i440fx fuzz targets
fuzz: add virtio-net fuzz target
fuzz: add virtio-scsi fuzz target
fuzz: add documentation to docs/devel/
Makefile | 15 +-
Makefile.objs | 2 -
Makefile.target | 19 ++-
configure | 39 +++++
docs/devel/fuzzing.txt | 116 ++++++++++++++
exec.c | 12 +-
include/qemu/module.h | 4 +-
include/sysemu/qtest.h | 4 +
include/sysemu/sysemu.h | 4 +
qtest.c | 31 +++-
scripts/checkpatch.pl | 2 +-
softmmu/Makefile.objs | 3 +
softmmu/main.c | 53 +++++++
vl.c => softmmu/vl.c | 48 +++---
tests/qtest/Makefile.include | 72 ++++-----
tests/qtest/fuzz/Makefile.include | 18 +++
tests/qtest/fuzz/fork_fuzz.c | 55 +++++++
tests/qtest/fuzz/fork_fuzz.h | 23 +++
tests/qtest/fuzz/fork_fuzz.ld | 37 +++++
tests/qtest/fuzz/fuzz.c | 179 +++++++++++++++++++++
tests/qtest/fuzz/fuzz.h | 95 +++++++++++
tests/qtest/fuzz/i440fx_fuzz.c | 193 +++++++++++++++++++++++
tests/qtest/fuzz/qos_fuzz.c | 234 ++++++++++++++++++++++++++++
tests/qtest/fuzz/qos_fuzz.h | 33 ++++
tests/qtest/fuzz/virtio_net_fuzz.c | 198 +++++++++++++++++++++++
tests/qtest/fuzz/virtio_scsi_fuzz.c | 214 +++++++++++++++++++++++++
tests/qtest/libqos/i2c.c | 10 +-
tests/qtest/libqos/i2c.h | 4 +-
tests/qtest/libqos/qos_external.c | 168 ++++++++++++++++++++
tests/qtest/libqos/qos_external.h | 28 ++++
tests/qtest/libqtest.c | 119 ++++++++++++--
tests/qtest/libqtest.h | 4 +
tests/qtest/pca9552-test.c | 10 +-
tests/qtest/qos-test.c | 132 +---------------
util/module.c | 7 +
35 files changed, 1958 insertions(+), 227 deletions(-)
create mode 100644 docs/devel/fuzzing.txt
create mode 100644 softmmu/Makefile.objs
create mode 100644 softmmu/main.c
rename vl.c => softmmu/vl.c (99%)
create mode 100644 tests/qtest/fuzz/Makefile.include
create mode 100644 tests/qtest/fuzz/fork_fuzz.c
create mode 100644 tests/qtest/fuzz/fork_fuzz.h
create mode 100644 tests/qtest/fuzz/fork_fuzz.ld
create mode 100644 tests/qtest/fuzz/fuzz.c
create mode 100644 tests/qtest/fuzz/fuzz.h
create mode 100644 tests/qtest/fuzz/i440fx_fuzz.c
create mode 100644 tests/qtest/fuzz/qos_fuzz.c
create mode 100644 tests/qtest/fuzz/qos_fuzz.h
create mode 100644 tests/qtest/fuzz/virtio_net_fuzz.c
create mode 100644 tests/qtest/fuzz/virtio_scsi_fuzz.c
create mode 100644 tests/qtest/libqos/qos_external.c
create mode 100644 tests/qtest/libqos/qos_external.h
--
2.25.0
- [PATCH v9 00/23] Add virtual device fuzzing support,
Alexander Bulekov <=
- [PATCH v9 01/23] checkpatch: replace vl.c in the top of repo check, Alexander Bulekov, 2020/02/11
- [PATCH v9 02/23] softmmu: move vl.c to softmmu/, Alexander Bulekov, 2020/02/11
- [PATCH v9 04/23] module: check module wasn't already initialized, Alexander Bulekov, 2020/02/11
- [PATCH v9 03/23] softmmu: split off vl.c:main() into main.c, Alexander Bulekov, 2020/02/11
- [PATCH v9 05/23] fuzz: add FUZZ_TARGET module type, Alexander Bulekov, 2020/02/11
- [PATCH v9 06/23] qtest: add qtest_server_send abstraction, Alexander Bulekov, 2020/02/11
- [PATCH v9 11/23] libqos: split qos-test and libqos makefile vars, Alexander Bulekov, 2020/02/11
- [PATCH v9 09/23] qtest: add in-process incoming command handler, Alexander Bulekov, 2020/02/11