From: Darren Kenny <darren.kenny@oracle.com>
To: Alexander Bulekov <alxndr@bu.edu>, qemu-devel@nongnu.org
Cc: Thomas Huth <thuth@redhat.com>,
f4bug@amsat.org, Alexander Bulekov <alxndr@bu.edu>,
bsd@redhat.com, stefanha@redhat.com,
Paolo Bonzini <pbonzini@redhat.com>
Subject: Re: [PATCH v2 15/15] scripts/oss-fuzz: Add crash trace minimization script
Date: Thu, 03 Sep 2020 10:28:29 +0100 [thread overview]
Message-ID: <m2y2lrqkea.fsf@oracle.com> (raw)
In-Reply-To: <20200819061110.1320568-16-alxndr@bu.edu>
On Wednesday, 2020-08-19 at 02:11:10 -04, Alexander Bulekov wrote:
> Once we find a crash, we can convert it into a QTest trace. Usually this
> trace will contain many operations that are unneeded to reproduce the
> crash. This script tries to minimize the crashing trace, by removing
> operations and trimming QTest bufwrite(write addr len data...) commands.
>
> Signed-off-by: Alexander Bulekov <alxndr@bu.edu>
> ---
> scripts/oss-fuzz/minimize_qtest_trace.py | 118 +++++++++++++++++++++++
> 1 file changed, 118 insertions(+)
> create mode 100755 scripts/oss-fuzz/minimize_qtest_trace.py
>
> diff --git a/scripts/oss-fuzz/minimize_qtest_trace.py b/scripts/oss-fuzz/minimize_qtest_trace.py
> new file mode 100755
> index 0000000000..2f1f4f368e
> --- /dev/null
> +++ b/scripts/oss-fuzz/minimize_qtest_trace.py
> @@ -0,0 +1,118 @@
> +#!/usr/bin/env python3
> +# -*- coding: utf-8 -*-
> +
> +"""
> +This takes a crashing qtest trace and tries to remove superflous operations
> +"""
> +
> +import sys
> +import os
> +import subprocess
> +import time
> +
> +QEMU_ARGS = None
> +QEMU_PATH = None
> +TIMEOUT = 5
> +CRASH_TOKEN = None
> +
> +
> +def usage():
> + sys.exit("""\
> +Usage: QEMU_PATH="/path/to/qemu" QEMU_ARGS="args" {} input_trace output_trace
> +By default, will try to use the second-to-last line in the output to identify
> +whether the crash occred. Optionally, manually set a string that idenitifes the
> +crash by setting CRASH_TOKEN=
> +""".format((sys.argv[0])))
> +
> +
> +def check_if_trace_crashes(trace, path):
> + global CRASH_TOKEN
> + with open(path, "w") as tracefile:
> + tracefile.write("".join(trace))
> + rc = subprocess.Popen("timeout -s 9 {}s {} {} 2>&1 < {}".format(TIMEOUT,
> + QEMU_PATH, QEMU_ARGS, path),
> + shell=True, stdin=subprocess.PIPE,
> + stdout=subprocess.PIPE)
NIT: Similar comment to before, it is nicer to name the placeholders if
there are more than 1 and you can.
> + stdo = rc.communicate()[0]
> + output = stdo.decode('unicode_escape')
> + if rc.returncode == 137: # Timed Out
> + return False
> + if len(output.splitlines()) < 2:
> + return False
> +
> + if CRASH_TOKEN is None:
> + CRASH_TOKEN = output.splitlines()[-2]
> +
> + return CRASH_TOKEN in output
> +
> +
> +def minimize_trace(inpath, outpath):
> + global TIMEOUT
> + with open(inpath) as f:
> + trace = f.readlines()
> + start = time.time()
> + if not check_if_trace_crashes(trace, outpath):
> + sys.exit("The input qtest trace didn't cause a crash...")
> + end = time.time()
> + print("Crashed in {} seconds".format(end-start))
> + TIMEOUT = (end-start)*5
> + print("Setting the timeout for {} seconds".format(TIMEOUT))
> + print("Identifying Crashes by this string: {}".format(CRASH_TOKEN))
> +
> + i = 0
> + newtrace = trace[:]
> + while i < len(newtrace):
> + prior = newtrace[i]
> + print("Trying to remove {}".format(newtrace[i]))
> + # Try to remove the line completely
> + newtrace[i] = ""
> + if check_if_trace_crashes(newtrace, outpath):
> + i += 1
> + continue
> + newtrace[i] = prior
> + # Try to split up writes into multiple commands, each of which can be
> + # removed.
> + if newtrace[i].startswith("write "):
NIT: Would be good to document the assumptions here, just in case things
change in future.
> + addr = int(newtrace[i].split()[1], 16)
> + length = int(newtrace[i].split()[2], 16)
> + data = newtrace[i].split()[3][2:]
> + if length > 1:
> + leftlength = int(length/2)
> + rightlength = length - leftlength
> + newtrace.insert(i+1, "")
> + while leftlength > 0:
> + newtrace[i] = "write {} {} 0x{}\n".format(
> + hex(addr),
> + hex(leftlength),
> + data[:leftlength*2])
> + newtrace[i+1] = "write {} {} 0x{}\n".format(
> + hex(addr+leftlength),
> + hex(rightlength),
> + data[leftlength*2:])
NIT: Similar comment w.r.t. naming the placeholders.
> + if check_if_trace_crashes(newtrace, outpath):
> + break
> + else:
> + leftlength -= 1
> + rightlength += 1
> + if check_if_trace_crashes(newtrace, outpath):
> + i -= 1
> + else:
> + newtrace[i] = prior
> + del newtrace[i+1]
> + i += 1
> + check_if_trace_crashes(newtrace, outpath)
> +
> +
> +if __name__ == '__main__':
> + if len(sys.argv) < 3:
> + usage()
> +
> + QEMU_PATH = os.getenv("QEMU_PATH")
> + QEMU_ARGS = os.getenv("QEMU_ARGS")
> + if QEMU_PATH is None or QEMU_ARGS is None:
> + usage()
> + if "accel" not in QEMU_ARGS:
> + QEMU_ARGS += " -accel qtest"
> + CRASH_TOKEN = os.getenv("CRASH_TOKEN")
> + QEMU_ARGS += " -qtest stdio -monitor none -serial none "
> + minimize_trace(sys.argv[1], sys.argv[2])
Since all only nits:
Reviewed-by: Darren Kenny <darren.kenny@oracle.com>
Thanks,
Darren.
next prev parent reply other threads:[~2020-09-03 9:29 UTC|newest]
Thread overview: 37+ messages / expand[flat|nested] mbox.gz Atom feed top
2020-08-19 6:10 [PATCH v2 00/15] Add a General Virtual Device Fuzzer Alexander Bulekov
2020-08-19 6:10 ` [PATCH v2 01/15] fuzz: Change the way we write qtest log to stderr Alexander Bulekov
2020-08-19 6:10 ` [PATCH v2 02/15] fuzz: Add general virtual-device fuzzer Alexander Bulekov
2020-09-02 10:03 ` Darren Kenny
2020-09-07 15:39 ` Alexander Bulekov
2020-09-07 15:55 ` Darren Kenny
2020-08-19 6:10 ` [PATCH v2 03/15] fuzz: Add PCI features to the general fuzzer Alexander Bulekov
2020-09-02 11:01 ` Darren Kenny
2020-08-19 6:10 ` [PATCH v2 04/15] fuzz: Add DMA support to the generic-fuzzer Alexander Bulekov
2020-09-03 8:43 ` Darren Kenny
2020-09-07 15:45 ` Alexander Bulekov
2020-08-19 6:11 ` [PATCH v2 05/15] fuzz: Declare DMA Read callback function Alexander Bulekov
2020-09-03 8:44 ` Darren Kenny
2020-08-19 6:11 ` [PATCH v2 06/15] fuzz: Add fuzzer callbacks to DMA-read functions Alexander Bulekov
2020-09-03 8:46 ` Darren Kenny
2020-08-19 6:11 ` [PATCH v2 07/15] fuzz: Add support for custom crossover functions Alexander Bulekov
2020-09-03 8:50 ` Darren Kenny
2020-08-19 6:11 ` [PATCH v2 08/15] fuzz: add a DISABLE_PCI op to general-fuzzer Alexander Bulekov
2020-09-03 8:49 ` Darren Kenny
2020-08-19 6:11 ` [PATCH v2 09/15] fuzz: add a crossover function to generic-fuzzer Alexander Bulekov
2020-09-03 9:04 ` Darren Kenny
2020-08-19 6:11 ` [PATCH v2 10/15] scripts/oss-fuzz: Add wrapper program for generic fuzzer Alexander Bulekov
2020-09-03 9:07 ` Darren Kenny
2020-09-03 9:10 ` Darren Kenny
2020-08-19 6:11 ` [PATCH v2 11/15] scripts/oss-fuzz: Add general-fuzzer build script Alexander Bulekov
2020-09-03 9:15 ` Darren Kenny
2020-08-19 6:11 ` [PATCH v2 12/15] scripts/oss-fuzz: Add general-fuzzer configs for oss-fuzz Alexander Bulekov
2020-09-03 9:16 ` Darren Kenny
2020-08-19 6:11 ` [PATCH v2 13/15] scripts/oss-fuzz: build the general-fuzzer configs Alexander Bulekov
2020-09-03 9:17 ` Darren Kenny
2020-09-07 15:49 ` Alexander Bulekov
2020-08-19 6:11 ` [PATCH v2 14/15] scripts/oss-fuzz: Add script to reorder a general-fuzzer trace Alexander Bulekov
2020-09-03 9:20 ` Darren Kenny
2020-08-19 6:11 ` [PATCH v2 15/15] scripts/oss-fuzz: Add crash trace minimization script Alexander Bulekov
2020-09-03 9:28 ` Darren Kenny [this message]
2020-08-19 6:32 ` [PATCH v2 00/15] Add a General Virtual Device Fuzzer no-reply
2020-08-19 16:23 ` Alexander Bulekov
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=m2y2lrqkea.fsf@oracle.com \
--to=darren.kenny@oracle.com \
--cc=alxndr@bu.edu \
--cc=bsd@redhat.com \
--cc=f4bug@amsat.org \
--cc=pbonzini@redhat.com \
--cc=qemu-devel@nongnu.org \
--cc=stefanha@redhat.com \
--cc=thuth@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.