fuzz: explicitly keep or reject fuzzer corpus

When the main fuzzer function returns (), it is equivalent to
returning Corpus::Keep.

In some of the return paths, we want to reject the input so that the
libfuzzer won't spend more time mutating them.

The should make fuzzing more efficient. No functional change intended.

Signed-off-by: Wei Liu <liuwe@microsoft.com>
This commit is contained in:
Wei Liu
2024-12-30 23:15:22 +00:00
committed by Wei Liu
parent ef88b2778e
commit 6fd5b0f696
13 changed files with 79 additions and 53 deletions
+7 -5
View File
@@ -7,7 +7,7 @@
use std::os::unix::io::{AsRawFd, FromRawFd};
use std::sync::Arc;
use libfuzzer_sys::fuzz_target;
use libfuzzer_sys::{fuzz_target, Corpus};
use seccompiler::SeccompAction;
use virtio_devices::{VirtioDevice, VirtioInterrupt, VirtioInterruptType};
use virtio_queue::{Queue, QueueT};
@@ -52,11 +52,11 @@ const USED_RING_ADDR: u64 = align!(AVAIL_RING_ADDR + AVAIL_RING_SIZE, USED_RING_
// Virtio-queue size in bytes
const QUEUE_BYTES_SIZE: usize = (USED_RING_ADDR + USED_RING_SIZE - DESC_TABLE_ADDR) as usize;
fuzz_target!(|bytes| {
fuzz_target!(|bytes: &[u8]| -> Corpus {
if bytes.len() < (QUEUE_DATA_SIZE + QUEUE_BYTES_SIZE)
|| bytes.len() > (QUEUE_DATA_SIZE + QUEUE_BYTES_SIZE + MEM_SIZE)
{
return;
return Corpus::Reject;
}
let mut rng = virtio_devices::Rng::new(
@@ -86,10 +86,10 @@ fuzz_target!(|bytes| {
.write_slice(queue_bytes, GuestAddress(DESC_TABLE_ADDR))
.is_err()
{
return;
return Corpus::Reject;
}
if mem.write_slice(mem_bytes, GuestAddress(0 as u64)).is_err() {
return;
return Corpus::Reject;
}
let guest_memory = GuestMemoryAtomic::new(mem);
@@ -108,6 +108,8 @@ fuzz_target!(|bytes| {
// Wait for the events to finish and rng device worker thread to return
rng.wait_for_epoll_threads();
Corpus::Keep
});
pub struct NoopVirtioInterrupt {}