On Wed, Feb 19, 2020 at 11:10:56PM -0500, Alexander Bulekov wrote: > Hello, > > This series adds a framework for coverage-guided fuzzing of > virtual-devices. Fuzzing targets are based on qtest and can make use of > libqos. Fuzzing can help discover device bugs, such as > assertion-failures, timeouts, and overflows, triggerable from within > guests. > > V10: > * Update MAINTAINERS for vl.c, main.c and tests/qtest/fuzz > * Fix changes to checkpatch > * Fix typos in virtio-scsi fuzzer > > V9: > * Fix bug in the virtio-scsi fuzzer. Virtqueues were being kicked only > if free_head != 0 (which it never was). > * Move vl.c and main.c into a new directory: softmmu/ > * virtio-net-fuzz: refactor the looop over used descriptor. > * Improve comments for i440fx and virtio-scsi fuzzers. > > V8: > * Small fixes to the virtio-net. > * Keep rcu_atfork when not using qtest. > > V7: > * virtio-net: add virtio-net-check-used which waits for inputs on > the tx/ctrl vq by watching the used vring. > * virtio-net: add virtio-net-socket which uses the socket backend and can > exercise the rx components of virtio-net. > * virtio-net: add virtio-net-slirp which uses the user backend and exercises > slirp. This may lead to real traffic emitted by qemu so it is best to > run in an isolated network environment. > * build should succeed after each commit > > V5/V6: > * added virtio-scsi fuzzer > * add support for using fork-based fuzzers with multiple libfuzzer > workers > * misc fixes addressing V4 comments > * cleanup in-process handlers/globals in libqtest.c > * small fixes to fork-based fuzzing and support for multiple workers > * changes to the virtio-net fuzzer to kick after each vq add > > V4: > * add/transfer license headers to new files > * restructure the added QTestClientTransportOps struct > * restructure the FuzzTarget struct and fuzzer skeleton > * fork-based fuzzer now directly mmaps shm over the coverage bitmaps > * fixes to i440 and virtio-net fuzz targets > * undo the changes to qtest_memwrite > * possible to build /fuzz and /all in the same build-dir > * misc fixes to address V3 comments > > V3: > * rebased onto v4.1.0+ > * add the fuzzer as a new build-target type in the build-system > * add indirection to qtest client/server communication functions > * remove ramfile and snapshot-based fuzzing support > * add i440fx fuzz-target as a reference for developers. > * add linker-script to assist with fork-based fuzzer > > V2: > * split off changes to qos virtio-net and qtest server to other patches > * move vl:main initialization into new func: qemu_init > * moved useful functions from qos-test.c to a separate object > * use struct of function pointers for add_fuzz_target(), instead of > arguments > * move ramfile to migration/qemu-file > * rewrite fork-based fuzzer pending patch to libfuzzer > * pass check-patch > > Alexander Bulekov (22): > softmmu: move vl.c to softmmu/ > softmmu: split off vl.c:main() into main.c > module: check module wasn't already initialized > fuzz: add FUZZ_TARGET module type > qtest: add qtest_server_send abstraction > libqtest: add a layer of abstraction to send/recv > libqtest: make bufwrite rely on the TransportOps > qtest: add in-process incoming command handler > libqos: rename i2c_send and i2c_recv > libqos: split qos-test and libqos makefile vars > libqos: move useful qos-test funcs to qos_external > fuzz: add fuzzer skeleton > exec: keep ram block across fork when using qtest > main: keep rcu_atfork callback enabled for qtest > fuzz: support for fork-based fuzzing. > fuzz: add support for qos-assisted fuzz targets > fuzz: add target/fuzz makefile rules > fuzz: add configure flag --enable-fuzzing > fuzz: add i440fx fuzz targets > fuzz: add virtio-net fuzz target > fuzz: add virtio-scsi fuzz target > fuzz: add documentation to docs/devel/ > > MAINTAINERS | 11 +- > Makefile | 15 +- > Makefile.objs | 2 - > Makefile.target | 19 ++- > configure | 39 +++++ > docs/devel/fuzzing.txt | 116 ++++++++++++++ > exec.c | 12 +- > include/qemu/module.h | 4 +- > include/sysemu/qtest.h | 4 + > include/sysemu/sysemu.h | 4 + > qtest.c | 31 +++- > scripts/checkpatch.pl | 2 +- > scripts/get_maintainer.pl | 3 +- > softmmu/Makefile.objs | 3 + > softmmu/main.c | 53 +++++++ > vl.c => softmmu/vl.c | 48 +++--- > tests/qtest/Makefile.include | 72 ++++----- > tests/qtest/fuzz/Makefile.include | 18 +++ > tests/qtest/fuzz/fork_fuzz.c | 55 +++++++ > tests/qtest/fuzz/fork_fuzz.h | 23 +++ > tests/qtest/fuzz/fork_fuzz.ld | 37 +++++ > tests/qtest/fuzz/fuzz.c | 179 +++++++++++++++++++++ > tests/qtest/fuzz/fuzz.h | 95 +++++++++++ > tests/qtest/fuzz/i440fx_fuzz.c | 193 +++++++++++++++++++++++ > tests/qtest/fuzz/qos_fuzz.c | 234 ++++++++++++++++++++++++++++ > tests/qtest/fuzz/qos_fuzz.h | 33 ++++ > tests/qtest/fuzz/virtio_net_fuzz.c | 198 +++++++++++++++++++++++ > tests/qtest/fuzz/virtio_scsi_fuzz.c | 213 +++++++++++++++++++++++++ > tests/qtest/libqos/i2c.c | 10 +- > tests/qtest/libqos/i2c.h | 4 +- > tests/qtest/libqos/qos_external.c | 168 ++++++++++++++++++++ > tests/qtest/libqos/qos_external.h | 28 ++++ > tests/qtest/libqtest.c | 119 ++++++++++++-- > tests/qtest/libqtest.h | 4 + > tests/qtest/pca9552-test.c | 10 +- > tests/qtest/qos-test.c | 132 +--------------- > util/module.c | 7 + > 37 files changed, 1969 insertions(+), 229 deletions(-) > create mode 100644 docs/devel/fuzzing.txt > create mode 100644 softmmu/Makefile.objs > create mode 100644 softmmu/main.c > rename vl.c => softmmu/vl.c (99%) > create mode 100644 tests/qtest/fuzz/Makefile.include > create mode 100644 tests/qtest/fuzz/fork_fuzz.c > create mode 100644 tests/qtest/fuzz/fork_fuzz.h > create mode 100644 tests/qtest/fuzz/fork_fuzz.ld > create mode 100644 tests/qtest/fuzz/fuzz.c > create mode 100644 tests/qtest/fuzz/fuzz.h > create mode 100644 tests/qtest/fuzz/i440fx_fuzz.c > create mode 100644 tests/qtest/fuzz/qos_fuzz.c > create mode 100644 tests/qtest/fuzz/qos_fuzz.h > create mode 100644 tests/qtest/fuzz/virtio_net_fuzz.c > create mode 100644 tests/qtest/fuzz/virtio_scsi_fuzz.c > create mode 100644 tests/qtest/libqos/qos_external.c > create mode 100644 tests/qtest/libqos/qos_external.h Thomas Huth (tests/ maintainer) is away on leave and the device fuzzer covers virtio-blk/scsi, so I will merge this. Thanks, applied to my block tree: https://github.com/stefanha/qemu/commits/block Stefan