From nobody Wed Feb 11 00:58:55 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; arc=pass (i=1dmarc=pass fromdomain=bu.edu) ARC-Seal: i=2; a=rsa-sha256; t=1600655553; cv=pass; d=zohomail.com; s=zohoarc; b=HBr4RPk+RwLDiK0/kvvTuqxuL3sC9e57EXg8Lp57XeLXUJ6QzaueKo+fbqgt5d31UlFeA9oF0vLez/hT9jC4tOnQmEtSu2CeoASLoGPx33M91phhhBi8BVPDBPbAA/KFb5R37rpCQC/XpkBe9B/RZ/R62Z6d4Mg2lm4J/sGvssA= ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1600655553; h=Content-Type:Content-Transfer-Encoding:Cc:Date:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:To; bh=0L41r48jbdQFt8ebZgEjrCNHjMkZsCBEX+y/w5PK8Fs=; b=Qdwjcyj1jMIsUroZLf4o4UtgZ9jzYREve1B10qo5c9S7LCEAkeu2tvW+sruf80mY2By8W93lacoQKl+Bt2Gw1RDUA+wvhqrpo13bCj3cawQ4EJY7LIWUSwbx0NJDp/XL7T8qlzrqyqahO/dMNDokfuIMNAIoRWoewqQuQDpBKa4= ARC-Authentication-Results: i=2; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; arc=pass (i=1dmarc=pass fromdomain=bu.edu) Return-Path: Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1600655553539271.609226942565; Sun, 20 Sep 2020 19:32:33 -0700 (PDT) Received: from localhost ([::1]:56784 helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1kKBd2-0003QI-0f for importer@patchew.org; Sun, 20 Sep 2020 22:32:32 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]:41630) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1kKBWi-0003Xb-Lk for qemu-devel@nongnu.org; Sun, 20 Sep 2020 22:26:00 -0400 Received: from mail-dm6nam12on2117.outbound.protection.outlook.com ([40.107.243.117]:28256 helo=NAM12-DM6-obe.outbound.protection.outlook.com) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1kKBWg-0000b7-Od for qemu-devel@nongnu.org; Sun, 20 Sep 2020 22:26:00 -0400 Received: from SN6PR03MB3871.namprd03.prod.outlook.com (2603:10b6:805:6d::32) by SN2PR03MB2237.namprd03.prod.outlook.com (2603:10b6:804:e::27) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3391.11; Mon, 21 Sep 2020 02:25:49 +0000 Received: from SN6PR03MB3871.namprd03.prod.outlook.com ([fe80::61ae:93a8:b26c:77b8]) by SN6PR03MB3871.namprd03.prod.outlook.com ([fe80::61ae:93a8:b26c:77b8%4]) with mapi id 15.20.3391.024; Mon, 21 Sep 2020 02:25:49 +0000 Received: from stormtrooper.vrmnet (72.93.72.163) by BL0PR1501CA0034.namprd15.prod.outlook.com (2603:10b6:207:17::47) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3391.14 via Frontend Transport; Mon, 21 Sep 2020 02:25:48 +0000 ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=SQcCCo/0fn7hm6PViHOsr/X3dflpzN4d/TTMsQBOd6V3QA5CrIwFpFBg6gqOoq9ZtNSdrMt/9cOdSCdo65uKzR9yHb3Yn+YLyoOM1ToQBdO2mh+xKy9UL31VhhMEpNV2C56ZT5wq6wFcZEWVJYIauRn+XeYidFH5xhw3GDWrepx74lVm2m2+0iv/FAxRsblYhmZ5v7mriTERwDTmTpXPOp7u5EYl4kYIv1FkiSbDF+gzsiWGDbeswr/akLKKqIM5ktDg0UjT6BOpRPFQraaUUUA4hTmTRvjmt60y+Cve6MURObKIVY8oZpdU/AgPKyI0qpICn1KloDllPb6Su+XU9A== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=0L41r48jbdQFt8ebZgEjrCNHjMkZsCBEX+y/w5PK8Fs=; b=jcj2THz7fDXx6iEYus2VFTVsrzZ3XjinTzu3qu0IC2CRVsg9pCAyBsoYvO4MOgfwMRi27PQqGaQZTLYGnngEfIa/81Hrsl8GjFooHbRlkDfIcAiKfZYDLCo5q89lFyoKhuxOnouqd+tQRG2eC5KqUXy0u8zKHLEIANdWnqvJfiiVQF+jFhCMWZ273Jk/JhS64zdMimx3pxEuoZnkZSHPaSperIFmSAt84L2Xq9dG8J9tMRWnh0dTSDdXskts/4vaeJKEwcaILmUMu19aNLVg5iYt/0wzTpQAkkdHu5xkrD9KedUuuIfWcA38627oTvTpKH9gRwy6PY4SpH0nvkbSMg== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=bu.edu; dmarc=pass action=none header.from=bu.edu; dkim=pass header.d=bu.edu; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=bushare.onmicrosoft.com; s=selector2-bushare-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=0L41r48jbdQFt8ebZgEjrCNHjMkZsCBEX+y/w5PK8Fs=; b=8NpT0laHl/1u/4KB2XNN6HD3AxOkfP6lr4PS4Q/oDq95wnjzQ8pOzS0Jruq9o45kRRCTyZ3qFRJHPVWzkZrrxiUNGdQH0vb+BWBiJYlaUByE1PBAdorOPShlZsbWs0Vdo6TL2E1Meype/m34SXMGL1nkt9L6yiqzI7fdq9mw9tc= Authentication-Results: nongnu.org; dkim=none (message not signed) header.d=none;nongnu.org; dmarc=none action=none header.from=bu.edu; From: Alexander Bulekov To: qemu-devel@nongnu.org Subject: [PATCH v3 15/16] scripts/oss-fuzz: Add crash trace minimization script Date: Sun, 20 Sep 2020 22:25:05 -0400 Message-Id: <20200921022506.873303-16-alxndr@bu.edu> X-Mailer: git-send-email 2.28.0 In-Reply-To: <20200921022506.873303-1-alxndr@bu.edu> References: <20200921022506.873303-1-alxndr@bu.edu> Content-Transfer-Encoding: quoted-printable X-ClientProxiedBy: BL0PR1501CA0034.namprd15.prod.outlook.com (2603:10b6:207:17::47) To SN6PR03MB3871.namprd03.prod.outlook.com (2603:10b6:805:6d::32) MIME-Version: 1.0 X-MS-Exchange-MessageSentRepresentingType: 1 X-Mailer: git-send-email 2.28.0 X-Originating-IP: [72.93.72.163] X-MS-PublicTrafficType: Email X-MS-Office365-Filtering-Correlation-Id: 24670455-4b32-47de-7d59-08d85dd5a719 X-MS-TrafficTypeDiagnostic: SN2PR03MB2237: X-MS-Exchange-Transport-Forked: True X-Microsoft-Antispam-PRVS: X-MS-Oob-TLC-OOBClassifiers: OLM:1923; X-MS-Exchange-SenderADCheck: 1 X-Microsoft-Antispam: BCL:0; X-Microsoft-Antispam-Message-Info: DN7l+B9VK9ADUu+qAHOmh1O5g8EmQST7Hn2fDmyzrxDXYsQxosdnPi3F75Ar2NwrNJEEbmNet/bkqTfNj4ppGJb4tKyQXv8UhUe+AQwbryFJxl6zV3IFHPfj1/bBRI6nCXNq1YC0AaQ0qVlaZhTL4nAkLZBI/427ld21KE+vtsNOA9yHlts0boLH19ZHlgqDm6edN+qf4slIUiNYgGcO2As6qbXjJFsc/+PTQ9eZF3JCwvaf1ECrDdhsjgA6lL7v6vvUqHAp3Di5YJIgKica8rP7ABHeuop1lW0yUjUCKCJuJs5JFGWLyFik8eGdOAs+Z8cUg0/FDSEIHvZgdibftBXsCeLbSkEaBiyyjSfSFUW8+DPuxfeAAHkRCTX+qeyu X-Forefront-Antispam-Report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:SN6PR03MB3871.namprd03.prod.outlook.com; PTR:; CAT:NONE; SFS:(4636009)(396003)(366004)(376002)(136003)(346002)(39860400002)(2616005)(956004)(4326008)(54906003)(83380400001)(26005)(478600001)(16526019)(6666004)(8936002)(316002)(6486002)(66476007)(1076003)(6512007)(186003)(6916009)(86362001)(66946007)(5660300002)(36756003)(75432002)(2906002)(6506007)(8676002)(66556008)(52116002)(786003); DIR:OUT; SFP:1102; X-MS-Exchange-AntiSpam-MessageData: 0E2W45FJk8IcHLGlQbI8QLH52jBICrQbAbCJl5t6Fu9Qe19rwr9CAFQMSa8p6H/34YlQngoY/k1q2CHF8MQYr94UTLC6GIuRznNWcLWhDnrLfuOnQt8w2sSVXtEiast8ktm6Fs3qbw/KTypdjyR5td/g47OLu7wphT84X0sNtMKrG8VGakKb50JGbCOHvGTTLuEwjqLOv/WUVz+MojJptgqPmaToImbk73ZcTCE0azIxv9m/j9n6DBJ38t8xvODU92wjrTgwc5uhRuyaQ3lAQWPeWzNNpf9tU9DJ5amGn9uyhMXDQkBXVLgoir++tMzk4UvTKOCFrHnvwOYLhXtksqdPuWIiSmLaJwpJzbf36BvTnc9FMVTg6dnJHaS+/9gFe0D9pm2Ubu9MIQtYEJjhP2MFWG4yaKCiCr/bKhOfaElPnQO7ukAFjkc2UEFpSbD6sfG/r0lbdfd/s+ENJZF1VZR8oYoUgrSRhd1m42Fhat3fksyqDqCtfmG0O7dVHEiJjjXuUWv5tG9+4zLaIgYH4GCx0tfpz1iByD/bisp5cRNByCCVYFWL0f/2K1IEonMeQh1wOQwN444eDFYPpogh/FF/2HfVElnpnLeDqKnkzWZNgssm451eL8W8bDMa39Pnep4tuI4g8Z5CWvCCLT2xoA== X-OriginatorOrg: bu.edu X-MS-Exchange-CrossTenant-Network-Message-Id: 24670455-4b32-47de-7d59-08d85dd5a719 X-MS-Exchange-CrossTenant-AuthSource: SN6PR03MB3871.namprd03.prod.outlook.com X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 21 Sep 2020 02:25:48.9675 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: d57d32cc-c121-488f-b07b-dfe705680c71 X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: PO+nr0MYdC5P6CDDeVb8oVRxvcJNghTxPpt3a0hZXJra8JC4oXEwKJS80N4PNRvU X-MS-Exchange-Transport-CrossTenantHeadersStamped: SN2PR03MB2237 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists.gnu.org; Received-SPF: pass client-ip=40.107.243.117; envelope-from=alxndr@bu.edu; helo=NAM12-DM6-obe.outbound.protection.outlook.com X-detected-operating-system: by eggs.gnu.org: First seen = 2020/09/20 22:25:42 X-ACL-Warn: Detected OS = Windows NT kernel [generic] [fuzzy] X-Spam_score_int: -18 X-Spam_score: -1.9 X-Spam_bar: - X-Spam_report: (-1.9 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HK_RANDOM_ENVFROM=0.001, HK_RANDOM_FROM=0.001, MSGID_FROM_MTA_HEADER=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: Thomas Huth , Alexander Bulekov , darren.kenny@oracle.com, bsd@redhat.com, stefanha@redhat.com, Paolo Bonzini , philmd@redhat.com Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: "Qemu-devel" X-ZohoMail-DKIM: pass (identity @bushare.onmicrosoft.com) Content-Type: text/plain; charset="utf-8" Once we find a crash, we can convert it into a QTest trace. Usually this trace will contain many operations that are unneeded to reproduce the crash. This script tries to minimize the crashing trace, by removing operations and trimming QTest bufwrite(write addr len data...) commands. Signed-off-by: Alexander Bulekov Reviewed-by: Darren Kenny --- scripts/oss-fuzz/minimize_qtest_trace.py | 157 +++++++++++++++++++++++ 1 file changed, 157 insertions(+) create mode 100755 scripts/oss-fuzz/minimize_qtest_trace.py diff --git a/scripts/oss-fuzz/minimize_qtest_trace.py b/scripts/oss-fuzz/mi= nimize_qtest_trace.py new file mode 100755 index 0000000000..05596d6f9c --- /dev/null +++ b/scripts/oss-fuzz/minimize_qtest_trace.py @@ -0,0 +1,157 @@ +#!/usr/bin/env python3 +# -*- coding: utf-8 -*- + +""" +This takes a crashing qtest trace and tries to remove superflous operations +""" + +import sys +import os +import subprocess +import time +import struct + +QEMU_ARGS =3D None +QEMU_PATH =3D None +TIMEOUT =3D 5 +CRASH_TOKEN =3D None + +write_suffix_lookup =3D {"b": (1, "B"), + "w": (2, "H"), + "l": (4, "L"), + "q": (8, "Q")} + +def usage(): + sys.exit("""\ +Usage: QEMU_PATH=3D"/path/to/qemu" QEMU_ARGS=3D"args" {} input_trace outpu= t_trace +By default, will try to use the second-to-last line in the output to ident= ify +whether the crash occred. Optionally, manually set a string that idenitife= s the +crash by setting CRASH_TOKEN=3D +""".format((sys.argv[0]))) + +def check_if_trace_crashes(trace, path): + global CRASH_TOKEN + with open(path, "w") as tracefile: + tracefile.write("".join(trace)) + + rc =3D subprocess.Popen("timeout -s 9 {timeout}s {qemu_path} {qemu_arg= s} 2>&1\ + < {trace_path}".format(timeout=3DTIMEOUT, + qemu_path=3DQEMU_PATH, + qemu_args=3DQEMU_ARGS, + trace_path=3Dpath), + shell=3DTrue, + stdin=3Dsubprocess.PIPE, + stdout=3Dsubprocess.PIPE) + stdo =3D rc.communicate()[0] + output =3D stdo.decode('unicode_escape') + if rc.returncode =3D=3D 137: # Timed Out + return False + if len(output.splitlines()) < 2: + return False + + if CRASH_TOKEN is None: + CRASH_TOKEN =3D output.splitlines()[-2] + + return CRASH_TOKEN in output + + +def minimize_trace(inpath, outpath): + global TIMEOUT + with open(inpath) as f: + trace =3D f.readlines() + start =3D time.time() + if not check_if_trace_crashes(trace, outpath): + sys.exit("The input qtest trace didn't cause a crash...") + end =3D time.time() + print("Crashed in {} seconds".format(end-start)) + TIMEOUT =3D (end-start)*5 + print("Setting the timeout for {} seconds".format(TIMEOUT)) + print("Identifying Crashes by this string: {}".format(CRASH_TOKEN)) + + i =3D 0 + newtrace =3D trace[:] + # For each line + while i < len(newtrace): + # 1.) Try to remove it completely and reproduce the crash. If it w= orks, + # we're done. + prior =3D newtrace[i] + print("Trying to remove {}".format(newtrace[i])) + # Try to remove the line completely + newtrace[i] =3D "" + if check_if_trace_crashes(newtrace, outpath): + i +=3D 1 + continue + newtrace[i] =3D prior + + # 2.) Try to replace write{bwlq} commands with a write addr, len + # command. Since this can require swapping endianness, try both LE= and + # BE options. We do this, so we can "trim" the writes in (3) + if (newtrace[i].startswith("write") and not + newtrace[i].startswith("write ")): + suffix =3D newtrace[i].split()[0][-1] + assert(suffix in write_suffix_lookup) + addr =3D int(newtrace[i].split()[1], 16) + value =3D int(newtrace[i].split()[2], 16) + for endianness in ['<', '>']: + data =3D struct.pack("{end}{size}".format(end=3Dendianness, + size=3Dwrite_suffix_lookup[suffix][1]), + value) + newtrace[i] =3D "write {addr} {size} 0x{data}\n".format( + addr=3Dhex(addr), + size=3Dhex(write_suffix_lookup[suffix][0]), + data=3Ddata.hex()) + if(check_if_trace_crashes(newtrace, outpath)): + break + else: + newtrace[i] =3D prior + + # 3.) If it is a qtest write command: write addr len data, try to = split + # it into two separate write commands. If splitting the write down= the + # middle does not work, try to move the pivot "left" and retry, un= til + # there is no space left. The idea is to prune unneccessary bytes = from + # long writes, while accommodating arbitrary MemoryRegion access s= izes + # and alignments. + if newtrace[i].startswith("write "): + addr =3D int(newtrace[i].split()[1], 16) + length =3D int(newtrace[i].split()[2], 16) + data =3D newtrace[i].split()[3][2:] + if length > 1: + leftlength =3D int(length/2) + rightlength =3D length - leftlength + newtrace.insert(i+1, "") + while leftlength > 0: + newtrace[i] =3D "write {} {} 0x{}\n".format( + hex(addr), + hex(leftlength), + data[:leftlength*2]) + newtrace[i+1] =3D "write {} {} 0x{}\n".format( + hex(addr+leftlength), + hex(rightlength), + data[leftlength*2:]) + if check_if_trace_crashes(newtrace, outpath): + break + else: + leftlength -=3D 1 + rightlength +=3D 1 + if check_if_trace_crashes(newtrace, outpath): + i -=3D 1 + else: + newtrace[i] =3D prior + del newtrace[i+1] + i +=3D 1 + check_if_trace_crashes(newtrace, outpath) + + +if __name__ =3D=3D '__main__': + if len(sys.argv) < 3: + usage() + + QEMU_PATH =3D os.getenv("QEMU_PATH") + QEMU_ARGS =3D os.getenv("QEMU_ARGS") + if QEMU_PATH is None or QEMU_ARGS is None: + usage() + # if "accel" not in QEMU_ARGS: + # QEMU_ARGS +=3D " -accel qtest" + CRASH_TOKEN =3D os.getenv("CRASH_TOKEN") + QEMU_ARGS +=3D " -qtest stdio -monitor none -serial none " + minimize_trace(sys.argv[1], sys.argv[2]) --=20 2.28.0