Hello, This series adds a framework for coverage-guided fuzzing of virtual-devices. Fuzzing targets are based on qtest and can make use of libqos. Fuzzing can help discover device bugs, such as assertion-failures, timeouts, and overflows, triggerable from within guests.
V10: * Update MAINTAINERS for vl.c, main.c and tests/qtest/fuzz * Fix changes to checkpatch * Fix typos in virtio-scsi fuzzer V9: * Fix bug in the virtio-scsi fuzzer. Virtqueues were being kicked only if free_head != 0 (which it never was). * Move vl.c and main.c into a new directory: softmmu/ * virtio-net-fuzz: refactor the looop over used descriptor. * Improve comments for i440fx and virtio-scsi fuzzers. V8: * Small fixes to the virtio-net. * Keep rcu_atfork when not using qtest. V7: * virtio-net: add virtio-net-check-used which waits for inputs on the tx/ctrl vq by watching the used vring. * virtio-net: add virtio-net-socket which uses the socket backend and can exercise the rx components of virtio-net. * virtio-net: add virtio-net-slirp which uses the user backend and exercises slirp. This may lead to real traffic emitted by qemu so it is best to run in an isolated network environment. * build should succeed after each commit V5/V6: * added virtio-scsi fuzzer * add support for using fork-based fuzzers with multiple libfuzzer workers * misc fixes addressing V4 comments * cleanup in-process handlers/globals in libqtest.c * small fixes to fork-based fuzzing and support for multiple workers * changes to the virtio-net fuzzer to kick after each vq add V4: * add/transfer license headers to new files * restructure the added QTestClientTransportOps struct * restructure the FuzzTarget struct and fuzzer skeleton * fork-based fuzzer now directly mmaps shm over the coverage bitmaps * fixes to i440 and virtio-net fuzz targets * undo the changes to qtest_memwrite * possible to build /fuzz and /all in the same build-dir * misc fixes to address V3 comments V3: * rebased onto v4.1.0+ * add the fuzzer as a new build-target type in the build-system * add indirection to qtest client/server communication functions * remove ramfile and snapshot-based fuzzing support * add i440fx fuzz-target as a reference for developers. * add linker-script to assist with fork-based fuzzer V2: * split off changes to qos virtio-net and qtest server to other patches * move vl:main initialization into new func: qemu_init * moved useful functions from qos-test.c to a separate object * use struct of function pointers for add_fuzz_target(), instead of arguments * move ramfile to migration/qemu-file * rewrite fork-based fuzzer pending patch to libfuzzer * pass check-patch Alexander Bulekov (22): softmmu: move vl.c to softmmu/ softmmu: split off vl.c:main() into main.c module: check module wasn't already initialized fuzz: add FUZZ_TARGET module type qtest: add qtest_server_send abstraction libqtest: add a layer of abstraction to send/recv libqtest: make bufwrite rely on the TransportOps qtest: add in-process incoming command handler libqos: rename i2c_send and i2c_recv libqos: split qos-test and libqos makefile vars libqos: move useful qos-test funcs to qos_external fuzz: add fuzzer skeleton exec: keep ram block across fork when using qtest main: keep rcu_atfork callback enabled for qtest fuzz: support for fork-based fuzzing. fuzz: add support for qos-assisted fuzz targets fuzz: add target/fuzz makefile rules fuzz: add configure flag --enable-fuzzing fuzz: add i440fx fuzz targets fuzz: add virtio-net fuzz target fuzz: add virtio-scsi fuzz target fuzz: add documentation to docs/devel/ MAINTAINERS | 11 +- Makefile | 15 +- Makefile.objs | 2 - Makefile.target | 19 ++- configure | 39 +++++ docs/devel/fuzzing.txt | 116 ++++++++++++++ exec.c | 12 +- include/qemu/module.h | 4 +- include/sysemu/qtest.h | 4 + include/sysemu/sysemu.h | 4 + qtest.c | 31 +++- scripts/checkpatch.pl | 2 +- scripts/get_maintainer.pl | 3 +- softmmu/Makefile.objs | 3 + softmmu/main.c | 53 +++++++ vl.c => softmmu/vl.c | 48 +++--- tests/qtest/Makefile.include | 72 ++++----- tests/qtest/fuzz/Makefile.include | 18 +++ tests/qtest/fuzz/fork_fuzz.c | 55 +++++++ tests/qtest/fuzz/fork_fuzz.h | 23 +++ tests/qtest/fuzz/fork_fuzz.ld | 37 +++++ tests/qtest/fuzz/fuzz.c | 179 +++++++++++++++++++++ tests/qtest/fuzz/fuzz.h | 95 +++++++++++ tests/qtest/fuzz/i440fx_fuzz.c | 193 +++++++++++++++++++++++ tests/qtest/fuzz/qos_fuzz.c | 234 ++++++++++++++++++++++++++++ tests/qtest/fuzz/qos_fuzz.h | 33 ++++ tests/qtest/fuzz/virtio_net_fuzz.c | 198 +++++++++++++++++++++++ tests/qtest/fuzz/virtio_scsi_fuzz.c | 213 +++++++++++++++++++++++++ tests/qtest/libqos/i2c.c | 10 +- tests/qtest/libqos/i2c.h | 4 +- tests/qtest/libqos/qos_external.c | 168 ++++++++++++++++++++ tests/qtest/libqos/qos_external.h | 28 ++++ tests/qtest/libqtest.c | 119 ++++++++++++-- tests/qtest/libqtest.h | 4 + tests/qtest/pca9552-test.c | 10 +- tests/qtest/qos-test.c | 132 +--------------- util/module.c | 7 + 37 files changed, 1969 insertions(+), 229 deletions(-) create mode 100644 docs/devel/fuzzing.txt create mode 100644 softmmu/Makefile.objs create mode 100644 softmmu/main.c rename vl.c => softmmu/vl.c (99%) create mode 100644 tests/qtest/fuzz/Makefile.include create mode 100644 tests/qtest/fuzz/fork_fuzz.c create mode 100644 tests/qtest/fuzz/fork_fuzz.h create mode 100644 tests/qtest/fuzz/fork_fuzz.ld create mode 100644 tests/qtest/fuzz/fuzz.c create mode 100644 tests/qtest/fuzz/fuzz.h create mode 100644 tests/qtest/fuzz/i440fx_fuzz.c create mode 100644 tests/qtest/fuzz/qos_fuzz.c create mode 100644 tests/qtest/fuzz/qos_fuzz.h create mode 100644 tests/qtest/fuzz/virtio_net_fuzz.c create mode 100644 tests/qtest/fuzz/virtio_scsi_fuzz.c create mode 100644 tests/qtest/libqos/qos_external.c create mode 100644 tests/qtest/libqos/qos_external.h -- 2.25.0