File
Blob: src/workerd/api/fuzzilli.c++
| 1 | #if defined(__linux__) && defined(WORKERD_FUZZILLI) |
| 2 | #include "fuzzilli.h" |
| 3 | |
| 4 | #include <workerd/api/util.h> |
| 5 | #include <workerd/jsg/jsg.h> |
| 6 | #include <workerd/util/immediate-crash.h> |
| 7 | |
| 8 | #include <errno.h> |
| 9 | #include <string.h> |
| 10 | |
| 11 | #include <kj/common.h> |
| 12 | #include <kj/debug.h> |
| 13 | #include <kj/exception.h> |
| 14 | |
| 15 | // Declare global structures used for coverage info in Fuzzilli |
| 16 | // as Fuzzilli is coverage guided it requires trace pc guard |
| 17 | // NOLINTBEGIN(edgeworker-mutable-globals) |
| 18 | struct shmem_data* __shmem; |
| 19 | uint32_t* __edges_start; |
| 20 | uint32_t* __edges_stop; |
| 21 | // NOLINTEND(edgeworker-mutable-globals) |
| 22 | |
| 23 | void perform_wild_write() { |
| 24 | // Access an invalid address. |
| 25 | // We want to use an "interesting" address for the access (instead of |
| 26 | // e.g. nullptr). In the (unlikely) case that the address is actually |
| 27 | // mapped, simply increment the pointer until it crashes. |
| 28 | // The cast ensures that this works correctly on both 32-bit and 64-bit. |
| 29 | uintptr_t addr = static_cast<uintptr_t>(0x414141414141ull); |
| 30 | char* ptr = reinterpret_cast<char*>(addr); |
| 31 | for (int i = 0; i < 1024; i++) { |
| 32 | *ptr = 'A'; |
| 33 | ptr += 1 * 1024 * 1024; |
| 34 | } |
| 35 | } |
| 36 | |
| 37 | void __sanitizer_cov_reset_edgeguards() { |
| 38 | uint64_t N = 0; |
| 39 | for (uint32_t* x = __edges_start; x < __edges_stop && N < MAX_EDGES; x++) *x = ++N; |
| 40 | } |
| 41 | |
| 42 | // setup trace pc guard to let fuzzilli get some coverage info |
| 43 | extern "C" void __sanitizer_cov_trace_pc_guard_init(uint32_t* start, uint32_t* stop) { |
| 44 | // Avoid duplicate initialization |
| 45 | if (start == stop || *start) return; |
| 46 | |
| 47 | if (__edges_start != NULL || __edges_stop != NULL) { |
| 48 | KJ_LOG(ERROR, "Coverage instrumentation is only supported for a single module\n"); |
| 49 | _exit(-1); |
| 50 | } |
| 51 | |
| 52 | __edges_start = start; |
| 53 | __edges_stop = stop; |
| 54 | |
| 55 | // Map the shared memory region |
| 56 | const char* shm_key = getenv("SHM_ID"); |
| 57 | if (!shm_key) { |
| 58 | KJ_LOG(INFO, "[COV] no shared memory bitmap available, skipping"); |
| 59 | __shmem = (struct shmem_data*)malloc(SHM_SIZE); |
| 60 | } else { |
| 61 | int fd = shm_open(shm_key, O_RDWR, S_IREAD | S_IWRITE); |
| 62 | if (fd <= -1) { |
| 63 | KJ_LOG(ERROR, "Failed to open shared memory region: %s\n", strerror(errno)); |
| 64 | _exit(-1); |
| 65 | } |
| 66 | |
| 67 | __shmem = (struct shmem_data*)mmap(0, SHM_SIZE, PROT_READ | PROT_WRITE, MAP_SHARED, fd, 0); |
| 68 | if (__shmem == MAP_FAILED) { |
| 69 | KJ_LOG(ERROR, "Failed to mmap shared memory region\n"); |
| 70 | _exit(-1); |
| 71 | } |
| 72 | } |
| 73 | |
| 74 | __sanitizer_cov_reset_edgeguards(); |
| 75 | __shmem->num_edges = stop - start; |
| 76 | } |
| 77 | |
| 78 | extern "C" void __sanitizer_cov_trace_pc_guard(uint32_t* guard) { |
| 79 | // There's a small race condition here: if this function executes in two threads for the same |
| 80 | // edge at the same time, the first thread might disable the edge (by setting the guard to zero) |
| 81 | // before the second thread fetches the guard value (and thus the index). However, our |
| 82 | // instrumentation ignores the first edge (see libcoverage.c) and so the race is unproblematic. |
| 83 | uint32_t index = *guard; |
| 84 | // If this function is called before coverage instrumentation is properly initialized we want to return early. |
| 85 | if (!index) return; |
| 86 | __shmem->edges[index / 8] |= 1 << (index % 8); |
| 87 | *guard = 0; |
| 88 | } |
| 89 | |
| 90 | void fuzzilli_handler(workerd::jsg::Lock& js, workerd::jsg::Arguments<workerd::jsg::Value>& args) { |
| 91 | if (args.size() == 0) { |
| 92 | // No arguments provided, just return |
| 93 | return; |
| 94 | } |
| 95 | |
| 96 | v8::Isolate* isolate = v8::Isolate::GetCurrent(); |
| 97 | v8::Local<v8::Value> value = v8::Local<v8::Value>::Cast(args[0].getHandle(isolate)); |
| 98 | v8::Local<v8::String> str = workerd::jsg::check(value->ToDetailString(js.v8Context())); |
| 99 | v8::String::Utf8Value operation(js.v8Isolate, str); |
| 100 | if (*operation == nullptr) { |
| 101 | return; |
| 102 | } |
| 103 | |
| 104 | if (strcmp(*operation, "FUZZILLI_CRASH") == 0) { |
| 105 | auto maybeArg = |
| 106 | v8::Local<v8::Int32>::Cast(args[1].getHandle(isolate))->Int32Value(js.v8Context()); |
| 107 | if (!maybeArg.IsJust()) { |
| 108 | KJ_LOG(ERROR, "Maybe arg is empty...\n"); |
| 109 | fflush(stdout); |
| 110 | return; |
| 111 | } |
| 112 | int32_t arg = maybeArg.FromJust(); |
| 113 | switch (arg) { |
| 114 | case 0: |
| 115 | IMMEDIATE_CRASH(); |
| 116 | break; |
| 117 | case 1: |
| 118 | assert(0); |
| 119 | //CHECK(false); |
| 120 | break; |
| 121 | case 2: |
| 122 | assert(0); |
| 123 | //DCHECK(false); |
| 124 | break; |
| 125 | case 3: { |
| 126 | perform_wild_write(); |
| 127 | break; |
| 128 | } |
| 129 | case 4: { |
| 130 | // Use-after-free, should be caught by ASan (if active). |
| 131 | auto* vec = new std::vector<int>(4); |
| 132 | delete vec; |
| 133 | USE(vec->at(0)); |
| 134 | #ifndef V8_USE_ADDRESS_SANITIZER |
| 135 | // The testcase must also crash on non-asan builds. |
| 136 | perform_wild_write(); |
| 137 | #endif // !V8_USE_ADDRESS_SANITIZER |
| 138 | break; |
| 139 | } |
| 140 | case 5: { |
| 141 | // Out-of-bounds access (1), likely only crashes in ASan or |
| 142 | // "hardened"/"safe" libc++ builds. |
| 143 | std::vector<int> vec(5); |
| 144 | USE(vec[5]); |
| 145 | break; |
| 146 | } |
| 147 | case 6: { |
| 148 | // Out-of-bounds access (2), likely only crashes in ASan builds. |
| 149 | std::vector<int> vec(6); |
| 150 | //linter complains about this... |
| 151 | // NOLINTNEXTLINE(edgeworker-ban-memset) |
| 152 | memset(vec.data(), 42, 0x100); |
| 153 | break; |
| 154 | } |
| 155 | default: |
| 156 | break; |
| 157 | } |
| 158 | } else if (strcmp(*operation, "FUZZILLI_PRINT") == 0) { |
| 159 | static FILE* fzliout = nullptr; |
| 160 | if (!fzliout) { |
| 161 | fzliout = fdopen(REPRL_DWFD, "w"); |
| 162 | if (!fzliout) { |
| 163 | KJ_LOG(ERROR, "Fuzzer output channel not available, printing to stdout instead\n"); |
| 164 | fzliout = stdout; |
| 165 | } |
| 166 | } |
| 167 | |
| 168 | value = v8::Local<v8::Value>::Cast(args[1].getHandle(isolate)); |
| 169 | str = workerd::jsg::check(value->ToDetailString(js.v8Context())); |
| 170 | v8::String::Utf8Value string(js.v8Isolate, str); |
| 171 | if (*string == nullptr) { |
| 172 | return; |
| 173 | } |
| 174 | fprintf(fzliout, "%s\n", *string); |
| 175 | fflush(fzliout); |
| 176 | } |
| 177 | } |
| 178 | |
| 179 | #endif |