Skip to content
File

Blob: src/workerd/api/fuzzilli.c++

5.6 KB
1#if defined(__linux__) && defined(WORKERD_FUZZILLI)
2#include "fuzzilli.h"
3 
4#include <workerd/api/util.h>
5#include <workerd/jsg/jsg.h>
6#include <workerd/util/immediate-crash.h>
7 
8#include <errno.h>
9#include <string.h>
10 
11#include <kj/common.h>
12#include <kj/debug.h>
13#include <kj/exception.h>
14 
15// Declare global structures used for coverage info in Fuzzilli
16// as Fuzzilli is coverage guided it requires trace pc guard
17// NOLINTBEGIN(edgeworker-mutable-globals)
18struct shmem_data* __shmem;
19uint32_t* __edges_start;
20uint32_t* __edges_stop;
21// NOLINTEND(edgeworker-mutable-globals)
22 
23void perform_wild_write() {
24 // Access an invalid address.
25 // We want to use an "interesting" address for the access (instead of
26 // e.g. nullptr). In the (unlikely) case that the address is actually
27 // mapped, simply increment the pointer until it crashes.
28 // The cast ensures that this works correctly on both 32-bit and 64-bit.
29 uintptr_t addr = static_cast<uintptr_t>(0x414141414141ull);
30 char* ptr = reinterpret_cast<char*>(addr);
31 for (int i = 0; i < 1024; i++) {
32 *ptr = 'A';
33 ptr += 1 * 1024 * 1024;
34 }
35}
36 
37void __sanitizer_cov_reset_edgeguards() {
38 uint64_t N = 0;
39 for (uint32_t* x = __edges_start; x < __edges_stop && N < MAX_EDGES; x++) *x = ++N;
40}
41 
42// setup trace pc guard to let fuzzilli get some coverage info
43extern "C" void __sanitizer_cov_trace_pc_guard_init(uint32_t* start, uint32_t* stop) {
44 // Avoid duplicate initialization
45 if (start == stop || *start) return;
46 
47 if (__edges_start != NULL || __edges_stop != NULL) {
48 KJ_LOG(ERROR, "Coverage instrumentation is only supported for a single module\n");
49 _exit(-1);
50 }
51 
52 __edges_start = start;
53 __edges_stop = stop;
54 
55 // Map the shared memory region
56 const char* shm_key = getenv("SHM_ID");
57 if (!shm_key) {
58 KJ_LOG(INFO, "[COV] no shared memory bitmap available, skipping");
59 __shmem = (struct shmem_data*)malloc(SHM_SIZE);
60 } else {
61 int fd = shm_open(shm_key, O_RDWR, S_IREAD | S_IWRITE);
62 if (fd <= -1) {
63 KJ_LOG(ERROR, "Failed to open shared memory region: %s\n", strerror(errno));
64 _exit(-1);
65 }
66 
67 __shmem = (struct shmem_data*)mmap(0, SHM_SIZE, PROT_READ | PROT_WRITE, MAP_SHARED, fd, 0);
68 if (__shmem == MAP_FAILED) {
69 KJ_LOG(ERROR, "Failed to mmap shared memory region\n");
70 _exit(-1);
71 }
72 }
73 
74 __sanitizer_cov_reset_edgeguards();
75 __shmem->num_edges = stop - start;
76}
77 
78extern "C" void __sanitizer_cov_trace_pc_guard(uint32_t* guard) {
79 // There's a small race condition here: if this function executes in two threads for the same
80 // edge at the same time, the first thread might disable the edge (by setting the guard to zero)
81 // before the second thread fetches the guard value (and thus the index). However, our
82 // instrumentation ignores the first edge (see libcoverage.c) and so the race is unproblematic.
83 uint32_t index = *guard;
84 // If this function is called before coverage instrumentation is properly initialized we want to return early.
85 if (!index) return;
86 __shmem->edges[index / 8] |= 1 << (index % 8);
87 *guard = 0;
88}
89 
90void fuzzilli_handler(workerd::jsg::Lock& js, workerd::jsg::Arguments<workerd::jsg::Value>& args) {
91 if (args.size() == 0) {
92 // No arguments provided, just return
93 return;
94 }
95 
96 v8::Isolate* isolate = v8::Isolate::GetCurrent();
97 v8::Local<v8::Value> value = v8::Local<v8::Value>::Cast(args[0].getHandle(isolate));
98 v8::Local<v8::String> str = workerd::jsg::check(value->ToDetailString(js.v8Context()));
99 v8::String::Utf8Value operation(js.v8Isolate, str);
100 if (*operation == nullptr) {
101 return;
102 }
103 
104 if (strcmp(*operation, "FUZZILLI_CRASH") == 0) {
105 auto maybeArg =
106 v8::Local<v8::Int32>::Cast(args[1].getHandle(isolate))->Int32Value(js.v8Context());
107 if (!maybeArg.IsJust()) {
108 KJ_LOG(ERROR, "Maybe arg is empty...\n");
109 fflush(stdout);
110 return;
111 }
112 int32_t arg = maybeArg.FromJust();
113 switch (arg) {
114 case 0:
115 IMMEDIATE_CRASH();
116 break;
117 case 1:
118 assert(0);
119 //CHECK(false);
120 break;
121 case 2:
122 assert(0);
123 //DCHECK(false);
124 break;
125 case 3: {
126 perform_wild_write();
127 break;
128 }
129 case 4: {
130 // Use-after-free, should be caught by ASan (if active).
131 auto* vec = new std::vector<int>(4);
132 delete vec;
133 USE(vec->at(0));
134#ifndef V8_USE_ADDRESS_SANITIZER
135 // The testcase must also crash on non-asan builds.
136 perform_wild_write();
137#endif // !V8_USE_ADDRESS_SANITIZER
138 break;
139 }
140 case 5: {
141 // Out-of-bounds access (1), likely only crashes in ASan or
142 // "hardened"/"safe" libc++ builds.
143 std::vector<int> vec(5);
144 USE(vec[5]);
145 break;
146 }
147 case 6: {
148 // Out-of-bounds access (2), likely only crashes in ASan builds.
149 std::vector<int> vec(6);
150 //linter complains about this...
151 // NOLINTNEXTLINE(edgeworker-ban-memset)
152 memset(vec.data(), 42, 0x100);
153 break;
154 }
155 default:
156 break;
157 }
158 } else if (strcmp(*operation, "FUZZILLI_PRINT") == 0) {
159 static FILE* fzliout = nullptr;
160 if (!fzliout) {
161 fzliout = fdopen(REPRL_DWFD, "w");
162 if (!fzliout) {
163 KJ_LOG(ERROR, "Fuzzer output channel not available, printing to stdout instead\n");
164 fzliout = stdout;
165 }
166 }
167 
168 value = v8::Local<v8::Value>::Cast(args[1].getHandle(isolate));
169 str = workerd::jsg::check(value->ToDetailString(js.v8Context()));
170 v8::String::Utf8Value string(js.v8Isolate, str);
171 if (*string == nullptr) {
172 return;
173 }
174 fprintf(fzliout, "%s\n", *string);
175 fflush(fzliout);
176 }
177}
178 
179#endif