From: Alexander Bulekov <alxndr@bu.edu>
To: "qemu-devel@nongnu.org" <qemu-devel@nongnu.org>,
"pbonzini@redhat.com" <pbonzini@redhat.com>,
"bsd@redhat.com" <bsd@redhat.com>,
"stefanha@redhat.com" <stefanha@redhat.com>
Subject: Re: [PATCH v5 00/20] Add virtual device fuzzing support
Date: Thu, 14 Nov 2019 10:04:02 -0500 [thread overview]
Message-ID: <3374ef9f-0cf8-1bf7-1d49-7789d2789eb0@bu.edu> (raw)
In-Reply-To: <20191114105542.d56y5egnd3qm6yuf@starbug-mbp>
On 11/14/19 5:55 AM, Darren Kenny wrote:
> Hi Alexander,
>
> A quick comment on the fact that you omitted any Reviewed-by's that
> you have received so far.
>
> Was that intentional?
No - I'll find a way to add them.
sorry about that
-Alex
>
> Thanks,
>
> Darren.
>
> On Wed, Nov 13, 2019 at 10:50:41PM +0000, Oleinik, Alexander wrote:
>> This series adds a framework for coverage-guided fuzzing of
>> virtual-devices. Fuzzing targets are based on qtest and can make use of
>> the libqos abstractions.
>>
>> V5:
>> * misc fixes addressing V4 comments
>> * cleanup in-process handlers/globals in libqtest.c
>> * small fixes to fork-based fuzzing and support for multiple workers
>> * changes to the virtio-net fuzzer to kick after each vq add
>>
>> V4:
>> * add/transfer license headers to new files
>> * restructure the added QTestClientTransportOps struct
>> * restructure the FuzzTarget struct and fuzzer skeleton
>> * fork-based fuzzer now directly mmaps shm over the coverage bitmaps
>> * fixes to i440 and virtio-net fuzz targets
>> * undo the changes to qtest_memwrite
>> * possible to build /fuzz and /all in the same build-dir
>> * misc fixes to address V3 comments
>>
>> V3:
>> * rebased onto v4.1.0+
>> * add the fuzzer as a new build-target type in the build-system
>> * add indirection to qtest client/server communication functions
>> * remove ramfile and snapshot-based fuzzing support
>> * add i440fx fuzz-target as a reference for developers.
>> * add linker-script to assist with fork-based fuzzer
>>
>> V2:
>> * split off changes to qos virtio-net and qtest server to other patches
>> * move vl:main initialization into new func: qemu_init
>> * moved useful functions from qos-test.c to a separate object
>> * use struct of function pointers for add_fuzz_target(), instead of
>> arguments
>> * move ramfile to migration/qemu-file
>> * rewrite fork-based fuzzer pending patch to libfuzzer
>> * pass check-patch
>>
>> Alexander Bulekov (20):
>> softmmu: split off vl.c:main() into main.c
>> libqos: Rename i2c_send and i2c_recv
>> fuzz: Add FUZZ_TARGET module type
>> qtest: add qtest_server_send abstraction
>> libqtest: Add a layer of abstraciton to send/recv
>> module: check module wasn't already initialized
>> qtest: add in-process incoming command handler
>> tests: provide test variables to other targets
>> libqos: split qos-test and libqos makefile vars
>> libqos: move useful qos-test funcs to qos_external
>> libqtest: make bufwrite rely on the TransportOps
>> libqtest: add in-process qtest.c tx/rx handlers
>> fuzz: add configure flag --enable-fuzzing
>> fuzz: Add target/fuzz makefile rules
>> fuzz: add fuzzer skeleton
>> fuzz: add support for fork-based fuzzing.
>> fuzz: add support for qos-assisted fuzz targets
>> fuzz: add i440fx fuzz targets
>> fuzz: add virtio-net fuzz target
>> fuzz: add documentation to docs/devel/
>>
>> Makefile | 16 ++-
>> Makefile.objs | 4 +
>> Makefile.target | 18 ++-
>> configure | 39 ++++++
>> docs/devel/fuzzing.txt | 119 ++++++++++++++++++
>> exec.c | 12 +-
>> include/qemu/module.h | 4 +-
>> include/sysemu/qtest.h | 4 +
>> include/sysemu/sysemu.h | 4 +
>> main.c | 53 ++++++++
>> qtest.c | 31 ++++-
>> tests/Makefile.include | 75 +++++------
>> tests/fuzz/Makefile.include | 11 ++
>> tests/fuzz/fork_fuzz.c | 55 +++++++++
>> tests/fuzz/fork_fuzz.h | 23 ++++
>> tests/fuzz/fork_fuzz.ld | 37 ++++++
>> tests/fuzz/fuzz.c | 179 +++++++++++++++++++++++++++
>> tests/fuzz/fuzz.h | 94 ++++++++++++++
>> tests/fuzz/i440fx_fuzz.c | 176 ++++++++++++++++++++++++++
>> tests/fuzz/qos_fuzz.c | 232 +++++++++++++++++++++++++++++++++++
>> tests/fuzz/qos_fuzz.h | 33 +++++
>> tests/fuzz/virtio_net_fuzz.c | 100 +++++++++++++++
>> tests/libqos/i2c.c | 10 +-
>> tests/libqos/i2c.h | 4 +-
>> tests/libqos/qos_external.c | 168 +++++++++++++++++++++++++
>> tests/libqos/qos_external.h | 28 +++++
>> tests/libqtest.c | 108 ++++++++++++++--
>> tests/libqtest.h | 4 +
>> tests/pca9552-test.c | 10 +-
>> tests/qos-test.c | 140 +--------------------
>> util/module.c | 7 ++
>> vl.c | 38 ++----
>> 32 files changed, 1607 insertions(+), 229 deletions(-)
>> create mode 100644 docs/devel/fuzzing.txt
>> create mode 100644 main.c
>> create mode 100644 tests/fuzz/Makefile.include
>> create mode 100644 tests/fuzz/fork_fuzz.c
>> create mode 100644 tests/fuzz/fork_fuzz.h
>> create mode 100644 tests/fuzz/fork_fuzz.ld
>> create mode 100644 tests/fuzz/fuzz.c
>> create mode 100644 tests/fuzz/fuzz.h
>> create mode 100644 tests/fuzz/i440fx_fuzz.c
>> create mode 100644 tests/fuzz/qos_fuzz.c
>> create mode 100644 tests/fuzz/qos_fuzz.h
>> create mode 100644 tests/fuzz/virtio_net_fuzz.c
>> create mode 100644 tests/libqos/qos_external.c
>> create mode 100644 tests/libqos/qos_external.h
>>
>> --
>> 2.23.0
>>
>>
--
===
I recently changed my last name from Oleinik to Bulekov
===
prev parent reply other threads:[~2019-11-14 15:05 UTC|newest]
Thread overview: 23+ messages / expand[flat|nested] mbox.gz Atom feed top
2019-11-13 22:50 [PATCH v5 00/20] Add virtual device fuzzing support Oleinik, Alexander
2019-11-13 22:50 ` [PATCH v5 01/20] softmmu: split off vl.c:main() into main.c Oleinik, Alexander
2019-11-13 22:50 ` [PATCH v5 02/20] libqos: Rename i2c_send and i2c_recv Oleinik, Alexander
2019-11-13 22:50 ` [PATCH v5 03/20] fuzz: Add FUZZ_TARGET module type Oleinik, Alexander
2019-11-13 22:50 ` [PATCH v5 04/20] qtest: add qtest_server_send abstraction Oleinik, Alexander
2019-11-13 22:50 ` [PATCH v5 06/20] module: check module wasn't already initialized Oleinik, Alexander
2019-11-13 22:50 ` [PATCH v5 05/20] libqtest: Add a layer of abstraciton to send/recv Oleinik, Alexander
2019-11-13 22:50 ` [PATCH v5 07/20] qtest: add in-process incoming command handler Oleinik, Alexander
2019-11-13 22:50 ` [PATCH v5 08/20] tests: provide test variables to other targets Oleinik, Alexander
2019-11-13 22:50 ` [PATCH v5 09/20] libqos: split qos-test and libqos makefile vars Oleinik, Alexander
2019-11-13 22:50 ` [PATCH v5 10/20] libqos: move useful qos-test funcs to qos_external Oleinik, Alexander
2019-11-13 22:50 ` [PATCH v5 11/20] libqtest: make bufwrite rely on the TransportOps Oleinik, Alexander
2019-11-13 22:50 ` [PATCH v5 12/20] libqtest: add in-process qtest.c tx/rx handlers Oleinik, Alexander
2019-11-13 22:50 ` [PATCH v5 13/20] fuzz: add configure flag --enable-fuzzing Oleinik, Alexander
2019-11-13 22:50 ` [PATCH v5 14/20] fuzz: Add target/fuzz makefile rules Oleinik, Alexander
2019-11-13 22:50 ` [PATCH v5 15/20] fuzz: add fuzzer skeleton Oleinik, Alexander
2019-11-13 22:50 ` [PATCH v5 17/20] fuzz: add support for qos-assisted fuzz targets Oleinik, Alexander
2019-11-13 22:50 ` [PATCH v5 16/20] fuzz: add support for fork-based fuzzing Oleinik, Alexander
2019-11-13 22:50 ` [PATCH v5 19/20] fuzz: add virtio-net fuzz target Oleinik, Alexander
2019-11-13 22:50 ` [PATCH v5 18/20] fuzz: add i440fx fuzz targets Oleinik, Alexander
2019-11-13 22:50 ` [PATCH v5 20/20] fuzz: add documentation to docs/devel/ Oleinik, Alexander
2019-11-14 10:55 ` [PATCH v5 00/20] Add virtual device fuzzing support Darren Kenny
2019-11-14 15:04 ` Alexander Bulekov [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=3374ef9f-0cf8-1bf7-1d49-7789d2789eb0@bu.edu \
--to=alxndr@bu.edu \
--cc=bsd@redhat.com \
--cc=pbonzini@redhat.com \
--cc=qemu-devel@nongnu.org \
--cc=stefanha@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).