2017-08-16 19:18:04 +00:00
|
|
|
// Copyright 2017 syzkaller project authors. All rights reserved.
|
|
|
|
// Use of this source code is governed by Apache 2 LICENSE that can be found in the LICENSE file.
|
|
|
|
|
|
|
|
package prog
|
|
|
|
|
|
|
|
// A hint is basically a tuple consisting of a pointer to an argument
|
|
|
|
// in one of the syscalls of a program and a value, which should be
|
|
|
|
// assigned to that argument (we call it a replacer).
|
|
|
|
|
|
|
|
// A simplified version of hints workflow looks like this:
|
|
|
|
// 1. Fuzzer launches a program (we call it a hint seed) and collects all
|
|
|
|
// the comparisons' data for every syscall in the program.
|
|
|
|
// 2. Next it tries to match the obtained comparison operands' values
|
|
|
|
// vs. the input arguments' values.
|
|
|
|
// 3. For every such match the fuzzer mutates the program by
|
|
|
|
// replacing the pointed argument with the saved value.
|
|
|
|
// 4. If a valid program is obtained, then fuzzer launches it and
|
|
|
|
// checks if new coverage is obtained.
|
|
|
|
// For more insights on particular mutations please see prog/hints_test.go.
|
|
|
|
|
2017-08-31 15:11:45 +00:00
|
|
|
import (
|
2017-12-08 09:45:11 +00:00
|
|
|
"bytes"
|
2017-08-31 15:11:45 +00:00
|
|
|
"encoding/binary"
|
2017-12-08 09:45:11 +00:00
|
|
|
"fmt"
|
2019-01-03 11:12:55 +00:00
|
|
|
"sort"
|
2017-08-31 15:11:45 +00:00
|
|
|
)
|
|
|
|
|
2017-08-16 19:18:04 +00:00
|
|
|
// Example: for comparisons {(op1, op2), (op1, op3), (op1, op4), (op2, op1)}
|
|
|
|
// this map will store the following:
|
|
|
|
// m = {
|
|
|
|
// op1: {map[op2]: true, map[op3]: true, map[op4]: true},
|
|
|
|
// op2: {map[op1]: true}
|
|
|
|
// }.
|
2019-01-03 11:12:55 +00:00
|
|
|
type CompMap map[uint64]map[uint64]bool
|
2017-08-16 19:18:04 +00:00
|
|
|
|
2017-08-31 15:11:45 +00:00
|
|
|
const (
|
|
|
|
maxDataLength = 100
|
|
|
|
)
|
|
|
|
|
2019-01-03 11:12:55 +00:00
|
|
|
var specialIntsSet map[uint64]bool
|
2017-08-16 19:18:04 +00:00
|
|
|
|
|
|
|
func (m CompMap) AddComp(arg1, arg2 uint64) {
|
|
|
|
if _, ok := m[arg1]; !ok {
|
2019-01-03 11:12:55 +00:00
|
|
|
m[arg1] = make(map[uint64]bool)
|
2017-08-16 19:18:04 +00:00
|
|
|
}
|
|
|
|
m[arg1][arg2] = true
|
|
|
|
}
|
|
|
|
|
2017-12-08 09:45:11 +00:00
|
|
|
func (m CompMap) String() string {
|
|
|
|
buf := new(bytes.Buffer)
|
|
|
|
for v, comps := range m {
|
|
|
|
if len(buf.Bytes()) != 0 {
|
|
|
|
fmt.Fprintf(buf, ", ")
|
|
|
|
}
|
|
|
|
fmt.Fprintf(buf, "0x%x:", v)
|
|
|
|
for c := range comps {
|
|
|
|
fmt.Fprintf(buf, " 0x%x", c)
|
|
|
|
}
|
|
|
|
}
|
|
|
|
return buf.String()
|
|
|
|
}
|
|
|
|
|
2017-08-24 15:52:57 +00:00
|
|
|
// Mutates the program using the comparison operands stored in compMaps.
|
|
|
|
// For each of the mutants executes the exec callback.
|
2017-12-08 11:27:39 +00:00
|
|
|
func (p *Prog) MutateWithHints(callIndex int, comps CompMap, exec func(p *Prog)) {
|
|
|
|
p = p.Clone()
|
|
|
|
c := p.Calls[callIndex]
|
|
|
|
execValidate := func() {
|
2020-03-14 15:42:00 +00:00
|
|
|
// Don't try to fix the candidate program.
|
|
|
|
// Assuming the original call was sanitized, we've got a bad call
|
|
|
|
// as the result of hint substitution, so just throw it away.
|
|
|
|
if p.Target.sanitize(c, false) != nil {
|
|
|
|
return
|
|
|
|
}
|
2018-08-01 17:45:15 +00:00
|
|
|
p.debugValidate()
|
2017-12-08 11:27:39 +00:00
|
|
|
exec(p)
|
|
|
|
}
|
2018-02-18 12:49:48 +00:00
|
|
|
ForeachArg(c, func(arg Arg, _ *ArgCtx) {
|
2018-05-03 13:48:26 +00:00
|
|
|
generateHints(comps, arg, execValidate)
|
2017-10-20 10:23:21 +00:00
|
|
|
})
|
2017-08-24 15:52:57 +00:00
|
|
|
}
|
|
|
|
|
2018-05-03 13:48:26 +00:00
|
|
|
func generateHints(compMap CompMap, arg Arg, exec func()) {
|
2018-02-18 12:49:48 +00:00
|
|
|
typ := arg.Type()
|
2020-04-26 12:14:14 +00:00
|
|
|
if typ == nil || arg.Dir() == DirOut {
|
2017-10-20 09:54:24 +00:00
|
|
|
return
|
|
|
|
}
|
2018-07-08 15:35:15 +00:00
|
|
|
switch t := typ.(type) {
|
2017-10-20 09:54:24 +00:00
|
|
|
case *ProcType:
|
|
|
|
// Random proc will not pass validation.
|
|
|
|
// We can mutate it, but only if the resulting value is within the legal range.
|
|
|
|
return
|
2019-09-13 09:15:34 +00:00
|
|
|
case *ConstType:
|
|
|
|
if IsPad(typ) {
|
|
|
|
return
|
|
|
|
}
|
2017-10-20 09:54:24 +00:00
|
|
|
case *CsumType:
|
|
|
|
// Csum will not pass validation and is always computed.
|
|
|
|
return
|
2018-07-08 15:35:15 +00:00
|
|
|
case *BufferType:
|
2020-01-05 10:46:35 +00:00
|
|
|
switch t.Kind {
|
|
|
|
case BufferFilename:
|
2018-07-08 15:35:15 +00:00
|
|
|
// This can generate escaping paths and is probably not too useful anyway.
|
|
|
|
return
|
2020-01-05 10:46:35 +00:00
|
|
|
case BufferString:
|
|
|
|
if len(t.Values) != 0 {
|
|
|
|
// These are frequently file names or complete enumerations.
|
|
|
|
// Mutating these may be useful iff we intercept strcmp
|
|
|
|
// (and filter out file names).
|
|
|
|
return
|
|
|
|
}
|
2018-07-08 15:35:15 +00:00
|
|
|
}
|
2017-10-20 09:54:24 +00:00
|
|
|
}
|
|
|
|
|
2017-08-24 15:52:57 +00:00
|
|
|
switch a := arg.(type) {
|
|
|
|
case *ConstArg:
|
2017-12-08 11:27:39 +00:00
|
|
|
checkConstArg(a, compMap, exec)
|
2017-08-31 15:11:45 +00:00
|
|
|
case *DataArg:
|
2017-12-08 11:27:39 +00:00
|
|
|
checkDataArg(a, compMap, exec)
|
2017-08-24 15:52:57 +00:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2017-12-08 11:27:39 +00:00
|
|
|
func checkConstArg(arg *ConstArg, compMap CompMap, exec func()) {
|
|
|
|
original := arg.Val
|
2019-01-03 11:12:55 +00:00
|
|
|
// Note: because shrinkExpand returns a map, order of programs is non-deterministic.
|
|
|
|
// This can affect test coverage reports.
|
2019-09-13 09:15:34 +00:00
|
|
|
for _, replacer := range shrinkExpand(original, compMap, arg.Type().TypeBitSize()) {
|
2017-12-08 11:27:39 +00:00
|
|
|
arg.Val = replacer
|
|
|
|
exec()
|
2017-08-24 15:52:57 +00:00
|
|
|
}
|
2017-12-08 11:27:39 +00:00
|
|
|
arg.Val = original
|
2017-08-24 15:52:57 +00:00
|
|
|
}
|
|
|
|
|
2017-12-08 11:27:39 +00:00
|
|
|
func checkDataArg(arg *DataArg, compMap CompMap, exec func()) {
|
2017-08-31 15:11:45 +00:00
|
|
|
bytes := make([]byte, 8)
|
2017-12-13 19:12:13 +00:00
|
|
|
data := arg.Data()
|
|
|
|
size := len(data)
|
|
|
|
if size > maxDataLength {
|
|
|
|
size = maxDataLength
|
|
|
|
}
|
|
|
|
for i := 0; i < size; i++ {
|
2017-12-08 11:27:39 +00:00
|
|
|
original := make([]byte, 8)
|
2017-12-13 19:12:13 +00:00
|
|
|
copy(original, data[i:])
|
2017-12-08 11:27:39 +00:00
|
|
|
val := binary.LittleEndian.Uint64(original)
|
2019-09-13 09:15:34 +00:00
|
|
|
for _, replacer := range shrinkExpand(val, compMap, 64) {
|
2017-08-31 15:11:45 +00:00
|
|
|
binary.LittleEndian.PutUint64(bytes, replacer)
|
2017-12-13 19:12:13 +00:00
|
|
|
copy(data[i:], bytes)
|
2017-12-08 11:27:39 +00:00
|
|
|
exec()
|
2017-08-31 15:11:45 +00:00
|
|
|
}
|
2017-12-13 19:12:13 +00:00
|
|
|
copy(data[i:], original)
|
2017-08-31 15:11:45 +00:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
// Shrink and expand mutations model the cases when the syscall arguments
|
|
|
|
// are casted to narrower (and wider) integer types.
|
2020-06-04 20:20:22 +00:00
|
|
|
//
|
2017-08-31 15:11:45 +00:00
|
|
|
// Motivation for shrink:
|
|
|
|
// void f(u16 x) {
|
|
|
|
// u8 y = (u8)x;
|
|
|
|
// if (y == 0xab) {...}
|
|
|
|
// }
|
|
|
|
// If we call f(0x1234), then we'll see a comparison 0x34 vs 0xab and we'll
|
|
|
|
// be unable to match the argument 0x1234 with any of the comparison operands.
|
|
|
|
// Thus we shrink 0x1234 to 0x34 and try to match 0x34.
|
|
|
|
// If there's a match for the shrank value, then we replace the corresponding
|
|
|
|
// bytes of the input (in the given example we'll get 0x12ab).
|
|
|
|
// Sometimes the other comparison operand will be wider than the shrank value
|
|
|
|
// (in the example above consider comparison if (y == 0xdeadbeef) {...}).
|
|
|
|
// In this case we ignore such comparison because we couldn't come up with
|
|
|
|
// any valid code example that does similar things. To avoid such comparisons
|
|
|
|
// we check the sizes with leastSize().
|
2020-06-04 20:20:22 +00:00
|
|
|
//
|
2017-08-31 15:11:45 +00:00
|
|
|
// Motivation for expand:
|
|
|
|
// void f(i8 x) {
|
|
|
|
// i16 y = (i16)x;
|
|
|
|
// if (y == -2) {...}
|
|
|
|
// }
|
|
|
|
// Suppose we call f(-1), then we'll see a comparison 0xffff vs 0xfffe and be
|
|
|
|
// unable to match input vs any operands. Thus we sign extend the input and
|
|
|
|
// check the extension.
|
|
|
|
// As with shrink we ignore cases when the other operand is wider.
|
|
|
|
// Note that executor sign extends all the comparison operands to int64.
|
2019-09-13 09:15:34 +00:00
|
|
|
func shrinkExpand(v uint64, compMap CompMap, bitsize uint64) []uint64 {
|
|
|
|
v = truncateToBitSize(v, bitsize)
|
|
|
|
limit := uint64(1<<bitsize - 1)
|
2019-01-03 11:12:55 +00:00
|
|
|
var replacers map[uint64]bool
|
2018-05-07 12:24:00 +00:00
|
|
|
for _, iwidth := range []int{8, 4, 2, 1, -4, -2, -1} {
|
|
|
|
var width int
|
2018-03-31 16:55:59 +00:00
|
|
|
var size, mutant uint64
|
2018-05-07 12:24:00 +00:00
|
|
|
if iwidth > 0 {
|
|
|
|
width = iwidth
|
|
|
|
size = uint64(width) * 8
|
2017-12-08 11:27:39 +00:00
|
|
|
mutant = v & ((1 << size) - 1)
|
|
|
|
} else {
|
2018-05-07 12:24:00 +00:00
|
|
|
width = -iwidth
|
|
|
|
size = uint64(width) * 8
|
2019-09-13 09:15:34 +00:00
|
|
|
if size > bitsize {
|
|
|
|
size = bitsize
|
|
|
|
}
|
|
|
|
if v&(1<<(size-1)) == 0 {
|
|
|
|
continue
|
|
|
|
}
|
2017-12-08 11:27:39 +00:00
|
|
|
mutant = v | ^((1 << size) - 1)
|
2017-08-31 15:11:45 +00:00
|
|
|
}
|
2018-04-01 13:28:01 +00:00
|
|
|
// Use big-endian match/replace for both blobs and ints.
|
|
|
|
// Sometimes we have unmarked blobs (no little/big-endian info);
|
|
|
|
// for ANYBLOBs we intentionally lose all marking;
|
|
|
|
// but even for marked ints we may need this too.
|
|
|
|
// Consider that kernel code does not convert the data
|
|
|
|
// (i.e. not ntohs(pkt->proto) == ETH_P_BATMAN),
|
|
|
|
// but instead converts the constant (i.e. pkt->proto == htons(ETH_P_BATMAN)).
|
|
|
|
// In such case we will see dynamic operand that does not match what we have in the program.
|
|
|
|
for _, bigendian := range []bool{false, true} {
|
|
|
|
if bigendian {
|
2018-05-07 12:24:00 +00:00
|
|
|
if width == 1 {
|
2018-04-01 13:28:01 +00:00
|
|
|
continue
|
|
|
|
}
|
2018-05-07 12:24:00 +00:00
|
|
|
mutant = swapInt(mutant, width)
|
2018-03-31 16:55:59 +00:00
|
|
|
}
|
2018-04-01 13:28:01 +00:00
|
|
|
for newV := range compMap[mutant] {
|
2020-07-11 15:09:04 +00:00
|
|
|
// Check the limit for negative numbers.
|
2019-09-13 09:15:34 +00:00
|
|
|
if newV > limit && ((^(limit >> 1) & newV) != ^(limit >> 1)) {
|
|
|
|
continue
|
|
|
|
}
|
2018-04-01 13:28:01 +00:00
|
|
|
mask := uint64(1<<size - 1)
|
|
|
|
newHi := newV & ^mask
|
|
|
|
newV = newV & mask
|
|
|
|
if newHi != 0 && newHi^^mask != 0 {
|
|
|
|
continue
|
|
|
|
}
|
|
|
|
if bigendian {
|
2018-05-07 12:24:00 +00:00
|
|
|
newV = swapInt(newV, width)
|
2018-04-01 13:28:01 +00:00
|
|
|
}
|
|
|
|
if specialIntsSet[newV] {
|
|
|
|
continue
|
|
|
|
}
|
|
|
|
// Replace size least significant bits of v with
|
|
|
|
// corresponding bits of newV. Leave the rest of v as it was.
|
|
|
|
replacer := (v &^ mask) | newV
|
2019-01-03 12:39:30 +00:00
|
|
|
if replacer == v {
|
|
|
|
continue
|
|
|
|
}
|
2019-09-13 09:15:34 +00:00
|
|
|
|
|
|
|
replacer = truncateToBitSize(replacer, bitsize)
|
2018-04-01 13:28:01 +00:00
|
|
|
// TODO(dvyukov): should we try replacing with arg+/-1?
|
|
|
|
// This could trigger some off-by-ones.
|
|
|
|
if replacers == nil {
|
2019-01-03 11:12:55 +00:00
|
|
|
replacers = make(map[uint64]bool)
|
2018-04-01 13:28:01 +00:00
|
|
|
}
|
|
|
|
replacers[replacer] = true
|
2018-03-31 16:55:59 +00:00
|
|
|
}
|
2017-08-31 15:11:45 +00:00
|
|
|
}
|
|
|
|
}
|
2019-01-03 11:12:55 +00:00
|
|
|
if replacers == nil {
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
res := make([]uint64, 0, len(replacers))
|
|
|
|
for v := range replacers {
|
|
|
|
res = append(res, v)
|
|
|
|
}
|
|
|
|
sort.Slice(res, func(i, j int) bool {
|
|
|
|
return res[i] < res[j]
|
|
|
|
})
|
|
|
|
return res
|
2017-08-31 15:11:45 +00:00
|
|
|
}
|
|
|
|
|
2017-08-16 19:18:04 +00:00
|
|
|
func init() {
|
2019-01-03 11:12:55 +00:00
|
|
|
specialIntsSet = make(map[uint64]bool)
|
2017-08-16 19:18:04 +00:00
|
|
|
for _, v := range specialInts {
|
|
|
|
specialIntsSet[v] = true
|
|
|
|
}
|
|
|
|
}
|