[PATCH v10 00/22] Add virtual device fuzzing support

Alexander Bulekov posted 22 patches 4 years, 1 month ago
Test docker-quick@centos7 passed
Test FreeBSD passed
Test docker-mingw@fedora passed
Test checkpatch passed
Patches applied successfully (tree, apply log)
git fetch https://github.com/patchew-project/qemu tags/patchew/20200220041118.23264-1-alxndr@bu.edu
Maintainers: Thomas Huth <thuth@redhat.com>, Laurent Vivier <lvivier@redhat.com>, Stefan Hajnoczi <stefanha@redhat.com>, Paolo Bonzini <pbonzini@redhat.com>, Richard Henderson <rth@twiddle.net>, Alexander Bulekov <alxndr@bu.edu>, Bandan Das <bsd@redhat.com>
MAINTAINERS                         |  11 +-
Makefile                            |  15 +-
Makefile.objs                       |   2 -
Makefile.target                     |  19 ++-
configure                           |  39 +++++
docs/devel/fuzzing.txt              | 116 ++++++++++++++
exec.c                              |  12 +-
include/qemu/module.h               |   4 +-
include/sysemu/qtest.h              |   4 +
include/sysemu/sysemu.h             |   4 +
qtest.c                             |  31 +++-
scripts/checkpatch.pl               |   2 +-
scripts/get_maintainer.pl           |   3 +-
softmmu/Makefile.objs               |   3 +
softmmu/main.c                      |  53 +++++++
vl.c => softmmu/vl.c                |  48 +++---
tests/qtest/Makefile.include        |  72 ++++-----
tests/qtest/fuzz/Makefile.include   |  18 +++
tests/qtest/fuzz/fork_fuzz.c        |  55 +++++++
tests/qtest/fuzz/fork_fuzz.h        |  23 +++
tests/qtest/fuzz/fork_fuzz.ld       |  37 +++++
tests/qtest/fuzz/fuzz.c             | 179 +++++++++++++++++++++
tests/qtest/fuzz/fuzz.h             |  95 +++++++++++
tests/qtest/fuzz/i440fx_fuzz.c      | 193 +++++++++++++++++++++++
tests/qtest/fuzz/qos_fuzz.c         | 234 ++++++++++++++++++++++++++++
tests/qtest/fuzz/qos_fuzz.h         |  33 ++++
tests/qtest/fuzz/virtio_net_fuzz.c  | 198 +++++++++++++++++++++++
tests/qtest/fuzz/virtio_scsi_fuzz.c | 213 +++++++++++++++++++++++++
tests/qtest/libqos/i2c.c            |  10 +-
tests/qtest/libqos/i2c.h            |   4 +-
tests/qtest/libqos/qos_external.c   | 168 ++++++++++++++++++++
tests/qtest/libqos/qos_external.h   |  28 ++++
tests/qtest/libqtest.c              | 119 ++++++++++++--
tests/qtest/libqtest.h              |   4 +
tests/qtest/pca9552-test.c          |  10 +-
tests/qtest/qos-test.c              | 132 +---------------
util/module.c                       |   7 +
37 files changed, 1969 insertions(+), 229 deletions(-)
create mode 100644 docs/devel/fuzzing.txt
create mode 100644 softmmu/Makefile.objs
create mode 100644 softmmu/main.c
rename vl.c => softmmu/vl.c (99%)
create mode 100644 tests/qtest/fuzz/Makefile.include
create mode 100644 tests/qtest/fuzz/fork_fuzz.c
create mode 100644 tests/qtest/fuzz/fork_fuzz.h
create mode 100644 tests/qtest/fuzz/fork_fuzz.ld
create mode 100644 tests/qtest/fuzz/fuzz.c
create mode 100644 tests/qtest/fuzz/fuzz.h
create mode 100644 tests/qtest/fuzz/i440fx_fuzz.c
create mode 100644 tests/qtest/fuzz/qos_fuzz.c
create mode 100644 tests/qtest/fuzz/qos_fuzz.h
create mode 100644 tests/qtest/fuzz/virtio_net_fuzz.c
create mode 100644 tests/qtest/fuzz/virtio_scsi_fuzz.c
create mode 100644 tests/qtest/libqos/qos_external.c
create mode 100644 tests/qtest/libqos/qos_external.h
[PATCH v10 00/22] Add virtual device fuzzing support
Posted by Alexander Bulekov 4 years, 1 month ago
Hello,

This series adds a framework for coverage-guided fuzzing of
virtual-devices. Fuzzing targets are based on qtest and can make use of
libqos. Fuzzing can help discover device bugs, such as
assertion-failures, timeouts, and overflows, triggerable from within
guests.

V10:
 * Update MAINTAINERS for vl.c, main.c and tests/qtest/fuzz
 * Fix changes to checkpatch
 * Fix typos in virtio-scsi fuzzer

V9:
 * Fix bug in the virtio-scsi fuzzer. Virtqueues were being kicked only
   if free_head != 0 (which it never was).
 * Move vl.c and main.c into a new directory: softmmu/
 * virtio-net-fuzz: refactor the looop over used descriptor.
 * Improve comments for i440fx and virtio-scsi fuzzers.

V8:
 * Small fixes to the virtio-net.
 * Keep rcu_atfork when not using qtest.

V7:
 * virtio-net: add virtio-net-check-used which waits for inputs on
 the tx/ctrl vq by watching the used vring.
 * virtio-net: add virtio-net-socket which uses the socket backend and can
 exercise the rx components of virtio-net.
 * virtio-net: add virtio-net-slirp which uses the user backend and exercises
 slirp. This may lead to real traffic emitted by qemu so it is best to
 run in an isolated network environment.
 * build should succeed after each commit

V5/V6:
 * added virtio-scsi fuzzer
 * add support for using fork-based fuzzers with multiple libfuzzer
   workers
 * misc fixes addressing V4 comments
 * cleanup in-process handlers/globals in libqtest.c
 * small fixes to fork-based fuzzing and support for multiple workers
 * changes to the virtio-net fuzzer to kick after each vq add

V4:
 * add/transfer license headers to new files
 * restructure the added QTestClientTransportOps struct
 * restructure the FuzzTarget struct and fuzzer skeleton
 * fork-based fuzzer now directly mmaps shm over the coverage bitmaps
 * fixes to i440 and virtio-net fuzz targets
 * undo the changes to qtest_memwrite
 * possible to build /fuzz and /all in the same build-dir
 * misc fixes to address V3 comments

V3:
 * rebased onto v4.1.0+
 * add the fuzzer as a new build-target type in the build-system
 * add indirection to qtest client/server communication functions
 * remove ramfile and snapshot-based fuzzing support
 * add i440fx fuzz-target as a reference for developers.
 * add linker-script to assist with fork-based fuzzer

V2:
 * split off changes to qos virtio-net and qtest server to other patches
 * move vl:main initialization into new func: qemu_init
 * moved useful functions from qos-test.c to a separate object
 * use struct of function pointers for add_fuzz_target(), instead of
   arguments
 * move ramfile to migration/qemu-file
 * rewrite fork-based fuzzer pending patch to libfuzzer
 * pass check-patch

Alexander Bulekov (22):
  softmmu: move vl.c to softmmu/
  softmmu: split off vl.c:main() into main.c
  module: check module wasn't already initialized
  fuzz: add FUZZ_TARGET module type
  qtest: add qtest_server_send abstraction
  libqtest: add a layer of abstraction to send/recv
  libqtest: make bufwrite rely on the TransportOps
  qtest: add in-process incoming command handler
  libqos: rename i2c_send and i2c_recv
  libqos: split qos-test and libqos makefile vars
  libqos: move useful qos-test funcs to qos_external
  fuzz: add fuzzer skeleton
  exec: keep ram block across fork when using qtest
  main: keep rcu_atfork callback enabled for qtest
  fuzz: support for fork-based fuzzing.
  fuzz: add support for qos-assisted fuzz targets
  fuzz: add target/fuzz makefile rules
  fuzz: add configure flag --enable-fuzzing
  fuzz: add i440fx fuzz targets
  fuzz: add virtio-net fuzz target
  fuzz: add virtio-scsi fuzz target
  fuzz: add documentation to docs/devel/

 MAINTAINERS                         |  11 +-
 Makefile                            |  15 +-
 Makefile.objs                       |   2 -
 Makefile.target                     |  19 ++-
 configure                           |  39 +++++
 docs/devel/fuzzing.txt              | 116 ++++++++++++++
 exec.c                              |  12 +-
 include/qemu/module.h               |   4 +-
 include/sysemu/qtest.h              |   4 +
 include/sysemu/sysemu.h             |   4 +
 qtest.c                             |  31 +++-
 scripts/checkpatch.pl               |   2 +-
 scripts/get_maintainer.pl           |   3 +-
 softmmu/Makefile.objs               |   3 +
 softmmu/main.c                      |  53 +++++++
 vl.c => softmmu/vl.c                |  48 +++---
 tests/qtest/Makefile.include        |  72 ++++-----
 tests/qtest/fuzz/Makefile.include   |  18 +++
 tests/qtest/fuzz/fork_fuzz.c        |  55 +++++++
 tests/qtest/fuzz/fork_fuzz.h        |  23 +++
 tests/qtest/fuzz/fork_fuzz.ld       |  37 +++++
 tests/qtest/fuzz/fuzz.c             | 179 +++++++++++++++++++++
 tests/qtest/fuzz/fuzz.h             |  95 +++++++++++
 tests/qtest/fuzz/i440fx_fuzz.c      | 193 +++++++++++++++++++++++
 tests/qtest/fuzz/qos_fuzz.c         | 234 ++++++++++++++++++++++++++++
 tests/qtest/fuzz/qos_fuzz.h         |  33 ++++
 tests/qtest/fuzz/virtio_net_fuzz.c  | 198 +++++++++++++++++++++++
 tests/qtest/fuzz/virtio_scsi_fuzz.c | 213 +++++++++++++++++++++++++
 tests/qtest/libqos/i2c.c            |  10 +-
 tests/qtest/libqos/i2c.h            |   4 +-
 tests/qtest/libqos/qos_external.c   | 168 ++++++++++++++++++++
 tests/qtest/libqos/qos_external.h   |  28 ++++
 tests/qtest/libqtest.c              | 119 ++++++++++++--
 tests/qtest/libqtest.h              |   4 +
 tests/qtest/pca9552-test.c          |  10 +-
 tests/qtest/qos-test.c              | 132 +---------------
 util/module.c                       |   7 +
 37 files changed, 1969 insertions(+), 229 deletions(-)
 create mode 100644 docs/devel/fuzzing.txt
 create mode 100644 softmmu/Makefile.objs
 create mode 100644 softmmu/main.c
 rename vl.c => softmmu/vl.c (99%)
 create mode 100644 tests/qtest/fuzz/Makefile.include
 create mode 100644 tests/qtest/fuzz/fork_fuzz.c
 create mode 100644 tests/qtest/fuzz/fork_fuzz.h
 create mode 100644 tests/qtest/fuzz/fork_fuzz.ld
 create mode 100644 tests/qtest/fuzz/fuzz.c
 create mode 100644 tests/qtest/fuzz/fuzz.h
 create mode 100644 tests/qtest/fuzz/i440fx_fuzz.c
 create mode 100644 tests/qtest/fuzz/qos_fuzz.c
 create mode 100644 tests/qtest/fuzz/qos_fuzz.h
 create mode 100644 tests/qtest/fuzz/virtio_net_fuzz.c
 create mode 100644 tests/qtest/fuzz/virtio_scsi_fuzz.c
 create mode 100644 tests/qtest/libqos/qos_external.c
 create mode 100644 tests/qtest/libqos/qos_external.h

-- 
2.25.0


Re: [PATCH v10 00/22] Add virtual device fuzzing support
Posted by Stefan Hajnoczi 4 years, 1 month ago
On Wed, Feb 19, 2020 at 11:10:56PM -0500, Alexander Bulekov wrote:
> Hello,
> 
> This series adds a framework for coverage-guided fuzzing of
> virtual-devices. Fuzzing targets are based on qtest and can make use of
> libqos. Fuzzing can help discover device bugs, such as
> assertion-failures, timeouts, and overflows, triggerable from within
> guests.
> 
> V10:
>  * Update MAINTAINERS for vl.c, main.c and tests/qtest/fuzz
>  * Fix changes to checkpatch
>  * Fix typos in virtio-scsi fuzzer
> 
> V9:
>  * Fix bug in the virtio-scsi fuzzer. Virtqueues were being kicked only
>    if free_head != 0 (which it never was).
>  * Move vl.c and main.c into a new directory: softmmu/
>  * virtio-net-fuzz: refactor the looop over used descriptor.
>  * Improve comments for i440fx and virtio-scsi fuzzers.
> 
> V8:
>  * Small fixes to the virtio-net.
>  * Keep rcu_atfork when not using qtest.
> 
> V7:
>  * virtio-net: add virtio-net-check-used which waits for inputs on
>  the tx/ctrl vq by watching the used vring.
>  * virtio-net: add virtio-net-socket which uses the socket backend and can
>  exercise the rx components of virtio-net.
>  * virtio-net: add virtio-net-slirp which uses the user backend and exercises
>  slirp. This may lead to real traffic emitted by qemu so it is best to
>  run in an isolated network environment.
>  * build should succeed after each commit
> 
> V5/V6:
>  * added virtio-scsi fuzzer
>  * add support for using fork-based fuzzers with multiple libfuzzer
>    workers
>  * misc fixes addressing V4 comments
>  * cleanup in-process handlers/globals in libqtest.c
>  * small fixes to fork-based fuzzing and support for multiple workers
>  * changes to the virtio-net fuzzer to kick after each vq add
> 
> V4:
>  * add/transfer license headers to new files
>  * restructure the added QTestClientTransportOps struct
>  * restructure the FuzzTarget struct and fuzzer skeleton
>  * fork-based fuzzer now directly mmaps shm over the coverage bitmaps
>  * fixes to i440 and virtio-net fuzz targets
>  * undo the changes to qtest_memwrite
>  * possible to build /fuzz and /all in the same build-dir
>  * misc fixes to address V3 comments
> 
> V3:
>  * rebased onto v4.1.0+
>  * add the fuzzer as a new build-target type in the build-system
>  * add indirection to qtest client/server communication functions
>  * remove ramfile and snapshot-based fuzzing support
>  * add i440fx fuzz-target as a reference for developers.
>  * add linker-script to assist with fork-based fuzzer
> 
> V2:
>  * split off changes to qos virtio-net and qtest server to other patches
>  * move vl:main initialization into new func: qemu_init
>  * moved useful functions from qos-test.c to a separate object
>  * use struct of function pointers for add_fuzz_target(), instead of
>    arguments
>  * move ramfile to migration/qemu-file
>  * rewrite fork-based fuzzer pending patch to libfuzzer
>  * pass check-patch
> 
> Alexander Bulekov (22):
>   softmmu: move vl.c to softmmu/
>   softmmu: split off vl.c:main() into main.c
>   module: check module wasn't already initialized
>   fuzz: add FUZZ_TARGET module type
>   qtest: add qtest_server_send abstraction
>   libqtest: add a layer of abstraction to send/recv
>   libqtest: make bufwrite rely on the TransportOps
>   qtest: add in-process incoming command handler
>   libqos: rename i2c_send and i2c_recv
>   libqos: split qos-test and libqos makefile vars
>   libqos: move useful qos-test funcs to qos_external
>   fuzz: add fuzzer skeleton
>   exec: keep ram block across fork when using qtest
>   main: keep rcu_atfork callback enabled for qtest
>   fuzz: support for fork-based fuzzing.
>   fuzz: add support for qos-assisted fuzz targets
>   fuzz: add target/fuzz makefile rules
>   fuzz: add configure flag --enable-fuzzing
>   fuzz: add i440fx fuzz targets
>   fuzz: add virtio-net fuzz target
>   fuzz: add virtio-scsi fuzz target
>   fuzz: add documentation to docs/devel/
> 
>  MAINTAINERS                         |  11 +-
>  Makefile                            |  15 +-
>  Makefile.objs                       |   2 -
>  Makefile.target                     |  19 ++-
>  configure                           |  39 +++++
>  docs/devel/fuzzing.txt              | 116 ++++++++++++++
>  exec.c                              |  12 +-
>  include/qemu/module.h               |   4 +-
>  include/sysemu/qtest.h              |   4 +
>  include/sysemu/sysemu.h             |   4 +
>  qtest.c                             |  31 +++-
>  scripts/checkpatch.pl               |   2 +-
>  scripts/get_maintainer.pl           |   3 +-
>  softmmu/Makefile.objs               |   3 +
>  softmmu/main.c                      |  53 +++++++
>  vl.c => softmmu/vl.c                |  48 +++---
>  tests/qtest/Makefile.include        |  72 ++++-----
>  tests/qtest/fuzz/Makefile.include   |  18 +++
>  tests/qtest/fuzz/fork_fuzz.c        |  55 +++++++
>  tests/qtest/fuzz/fork_fuzz.h        |  23 +++
>  tests/qtest/fuzz/fork_fuzz.ld       |  37 +++++
>  tests/qtest/fuzz/fuzz.c             | 179 +++++++++++++++++++++
>  tests/qtest/fuzz/fuzz.h             |  95 +++++++++++
>  tests/qtest/fuzz/i440fx_fuzz.c      | 193 +++++++++++++++++++++++
>  tests/qtest/fuzz/qos_fuzz.c         | 234 ++++++++++++++++++++++++++++
>  tests/qtest/fuzz/qos_fuzz.h         |  33 ++++
>  tests/qtest/fuzz/virtio_net_fuzz.c  | 198 +++++++++++++++++++++++
>  tests/qtest/fuzz/virtio_scsi_fuzz.c | 213 +++++++++++++++++++++++++
>  tests/qtest/libqos/i2c.c            |  10 +-
>  tests/qtest/libqos/i2c.h            |   4 +-
>  tests/qtest/libqos/qos_external.c   | 168 ++++++++++++++++++++
>  tests/qtest/libqos/qos_external.h   |  28 ++++
>  tests/qtest/libqtest.c              | 119 ++++++++++++--
>  tests/qtest/libqtest.h              |   4 +
>  tests/qtest/pca9552-test.c          |  10 +-
>  tests/qtest/qos-test.c              | 132 +---------------
>  util/module.c                       |   7 +
>  37 files changed, 1969 insertions(+), 229 deletions(-)
>  create mode 100644 docs/devel/fuzzing.txt
>  create mode 100644 softmmu/Makefile.objs
>  create mode 100644 softmmu/main.c
>  rename vl.c => softmmu/vl.c (99%)
>  create mode 100644 tests/qtest/fuzz/Makefile.include
>  create mode 100644 tests/qtest/fuzz/fork_fuzz.c
>  create mode 100644 tests/qtest/fuzz/fork_fuzz.h
>  create mode 100644 tests/qtest/fuzz/fork_fuzz.ld
>  create mode 100644 tests/qtest/fuzz/fuzz.c
>  create mode 100644 tests/qtest/fuzz/fuzz.h
>  create mode 100644 tests/qtest/fuzz/i440fx_fuzz.c
>  create mode 100644 tests/qtest/fuzz/qos_fuzz.c
>  create mode 100644 tests/qtest/fuzz/qos_fuzz.h
>  create mode 100644 tests/qtest/fuzz/virtio_net_fuzz.c
>  create mode 100644 tests/qtest/fuzz/virtio_scsi_fuzz.c
>  create mode 100644 tests/qtest/libqos/qos_external.c
>  create mode 100644 tests/qtest/libqos/qos_external.h

Thomas Huth (tests/ maintainer) is away on leave and the device fuzzer
covers virtio-blk/scsi, so I will merge this.

Thanks, applied to my block tree:
https://github.com/stefanha/qemu/commits/block

Stefan