[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[PATCH v6 15/16] fuzz: register predefined generic-fuzz configs
From: |
Alexander Bulekov |
Subject: |
[PATCH v6 15/16] fuzz: register predefined generic-fuzz configs |
Date: |
Wed, 21 Oct 2020 17:09:21 -0400 |
We call get_generic_fuzz_configs, which fills an array with
predefined {name, args, objects} triples. For each of these, we add a
new FuzzTarget, that uses a small wrapper to set
QEMU_FUZZ_{ARGS,OBJECTS} to the corresponding predefined values.
Signed-off-by: Alexander Bulekov <alxndr@bu.edu>
---
tests/qtest/fuzz/generic_fuzz.c | 32 ++++++++++++++++++++++++++++++++
1 file changed, 32 insertions(+)
diff --git a/tests/qtest/fuzz/generic_fuzz.c b/tests/qtest/fuzz/generic_fuzz.c
index f739937827..bff98fe3c8 100644
--- a/tests/qtest/fuzz/generic_fuzz.c
+++ b/tests/qtest/fuzz/generic_fuzz.c
@@ -26,6 +26,7 @@
#include "hw/qdev-core.h"
#include "hw/pci/pci.h"
#include "hw/boards.h"
+#include "generic_fuzz_configs.h"
/*
* SEPARATOR is used to separate "operations" in the fuzz input
@@ -901,6 +902,17 @@ static GString *generic_fuzz_cmdline(FuzzTarget *t)
return cmd_line;
}
+static GString *generic_fuzz_predefined_config_cmdline(FuzzTarget *t)
+{
+ const generic_fuzz_config *config;
+ g_assert(t->opaque);
+
+ config = t->opaque;
+ setenv("QEMU_FUZZ_ARGS", config->args, 1);
+ setenv("QEMU_FUZZ_OBJECTS", config->objects, 1);
+ return generic_fuzz_cmdline(t);
+}
+
static void register_generic_fuzz_targets(void)
{
fuzz_add_target(&(FuzzTarget){
@@ -911,6 +923,26 @@ static void register_generic_fuzz_targets(void)
.fuzz = generic_fuzz,
.crossover = generic_fuzz_crossover
});
+
+ GString *name;
+ const generic_fuzz_config *config;
+
+ for (int i = 0;
+ i < sizeof(predefined_configs) / sizeof(generic_fuzz_config);
+ i++) {
+ config = predefined_configs + i;
+ name = g_string_new("generic-fuzz");
+ g_string_append_printf(name, "-%s", config->name);
+ fuzz_add_target(&(FuzzTarget){
+ .name = name->str,
+ .description = "Predefined generic-fuzz config.",
+ .get_init_cmdline = generic_fuzz_predefined_config_cmdline,
+ .pre_fuzz = generic_pre_fuzz,
+ .fuzz = generic_fuzz,
+ .crossover = generic_fuzz_crossover,
+ .opaque = (void *)config
+ });
+ }
}
fuzz_target_init(register_generic_fuzz_targets);
--
2.28.0
- [PATCH v6 06/16] fuzz: Add fuzzer callbacks to DMA-read functions, (continued)
- [PATCH v6 06/16] fuzz: Add fuzzer callbacks to DMA-read functions, Alexander Bulekov, 2020/10/21
- [PATCH v6 08/16] fuzz: add a DISABLE_PCI op to generic-fuzzer, Alexander Bulekov, 2020/10/21
- [PATCH v6 09/16] fuzz: add a crossover function to generic-fuzzer, Alexander Bulekov, 2020/10/21
- [PATCH v6 10/16] scripts/oss-fuzz: Add script to reorder a generic-fuzzer trace, Alexander Bulekov, 2020/10/21
- [PATCH v6 12/16] fuzz: Add instructions for using generic-fuzz, Alexander Bulekov, 2020/10/21
- [PATCH v6 11/16] scripts/oss-fuzz: Add crash trace minimization script, Alexander Bulekov, 2020/10/21
- [PATCH v6 13/16] fuzz: add an "opaque" to the FuzzTarget struct, Alexander Bulekov, 2020/10/21
- [PATCH v6 14/16] fuzz: add generic-fuzz configs for oss-fuzz, Alexander Bulekov, 2020/10/21
- [PATCH v6 15/16] fuzz: register predefined generic-fuzz configs,
Alexander Bulekov <=
- [PATCH v6 16/16] scripts/oss-fuzz: remove the generic-fuzz target, Alexander Bulekov, 2020/10/21