mirror of
https://github.com/reactos/syzkaller.git
synced 2025-02-05 19:27:05 +00:00
![Dmitry Vyukov](/assets/img/avatar_default.png)
1. mmap all memory always, without explicit mmap calls in the program. This makes lots of things much easier and removes lots of code. Makes mmap not a special syscall and allows to fuzz without mmap enabled. 2. Change address assignment algorithm. Current algorithm allocates unmapped addresses too frequently and allows collisions between arguments of a single syscall. The new algorithm analyzes actual allocations in the program and places new arguments at unused locations.
53 lines
1.4 KiB
Go
53 lines
1.4 KiB
Go
// Copyright 2017 syzkaller project authors. All rights reserved.
|
|
// Use of this source code is governed by Apache 2 LICENSE that can be found in the LICENSE file.
|
|
|
|
package akaros
|
|
|
|
import (
|
|
"github.com/google/syzkaller/prog"
|
|
)
|
|
|
|
func initTarget(target *prog.Target) {
|
|
arch := &arch{
|
|
mmapSyscall: target.SyscallMap["mmap"],
|
|
PROT_READ: target.ConstMap["PROT_READ"],
|
|
PROT_WRITE: target.ConstMap["PROT_WRITE"],
|
|
MAP_ANONYMOUS: target.ConstMap["MAP_ANONYMOUS"],
|
|
MAP_PRIVATE: target.ConstMap["MAP_PRIVATE"],
|
|
MAP_FIXED: target.ConstMap["MAP_FIXED"],
|
|
}
|
|
|
|
target.MakeMmap = arch.makeMmap
|
|
}
|
|
|
|
const (
|
|
invalidFD = ^uint64(0)
|
|
)
|
|
|
|
type arch struct {
|
|
mmapSyscall *prog.Syscall
|
|
|
|
PROT_READ uint64
|
|
PROT_WRITE uint64
|
|
MAP_ANONYMOUS uint64
|
|
MAP_PRIVATE uint64
|
|
MAP_FIXED uint64
|
|
}
|
|
|
|
// createMmapCall creates a "normal" mmap call that maps [start, start+npages) page range.
|
|
func (arch *arch) makeMmap(addr, size uint64) *prog.Call {
|
|
meta := arch.mmapSyscall
|
|
return &prog.Call{
|
|
Meta: meta,
|
|
Args: []prog.Arg{
|
|
prog.MakeVmaPointerArg(meta.Args[0], addr, size),
|
|
prog.MakeConstArg(meta.Args[1], size),
|
|
prog.MakeConstArg(meta.Args[2], arch.PROT_READ|arch.PROT_WRITE),
|
|
prog.MakeConstArg(meta.Args[3], arch.MAP_ANONYMOUS|arch.MAP_PRIVATE|arch.MAP_FIXED),
|
|
prog.MakeResultArg(meta.Args[4], nil, invalidFD),
|
|
prog.MakeConstArg(meta.Args[5], 0),
|
|
},
|
|
Ret: prog.MakeReturnArg(meta.Ret),
|
|
}
|
|
}
|