From: Anshu Kumari <anskuma@redhat.com>
To: sbrivio@redhat.com, passt-dev@passt.top
Cc: lvivier@redhat.com, anskuma@redhat.com, abdobngad@gmail.com
Subject: [PATCH v2 0/7] Add AFL++ fuzzing support for passt
Date: Mon, 28 Sep 2026 10:47:20 +0530 [thread overview]
Message-ID: <20260928051727.2251281-1-anskuma@redhat.com> (raw)
This series adds integrated AFL++ fuzzing support for passt,
extending the earlier work by AbdAlRahman Gad with
persistent mode, bidirectional protocol fuzzing, and real
TCP connection coverage via a companion test server.
Each testcase is a flat buffer split into four regions:
epoll events, raw L2 tap frames, test-server payloads,
and getsockopt(TCP_INFO) overrides. AFL++ controls all
four through mutation of a 10-byte header.
Fuzz-injected epoll events are interleaved with real
kernel events so protocol handshakes can complete. A
standalone test server (fuzz-server) attaches to AFL++'s
shared memory and sends fuzzer-controlled payload on
every accepted TCP connection. AnyIP routing in a
rootless user+network namespace makes every destination
local, so the test server intercepts all outbound traffic
from passt without mocking recv().
Deterministic wrappers replace clock_gettime(),
getsockopt() and assert() to eliminate non-determinism
from kernel state. Sandboxing (seccomp, namespaces,
close_range, capabilities) is bypassed under FUZZING
builds since AFL++ needs its own fds and syscalls.
*** BLURB HERE ***
Anshu Kumari (7):
fuzz: Add AFL++ shared memory testcase buffer layout
fuzz: Add deterministic wrappers for assert, clock and getsockopt
fuzz: Guard protocol handlers against invalid fuzz-injected state
fuzz: Bypass sandboxing for fuzzing builds
fuzz: Add AFL++ persistent mode fuzz loop
fuzz: Add host-side test server for bidirectional fuzzing
fuzz: Add build targets, namespace setup and documentation
Makefile | 35 +++-
flow.c | 52 +++++
fuzz-server.c | 343 +++++++++++++++++++++++++++++++++
fuzz-testbuf.h | 135 +++++++++++++
fuzz.c | 102 ++++++++++
fuzz.h | 38 ++++
fuzzing/README.fuzzing.md | 129 +++++++++++++
fuzzing/fuzz-setup.sh | 24 +++
fuzzing/testcase_dir/empty.bin | Bin 0 -> 12 bytes
icmp.c | 8 +-
isolation.c | 23 +++
passt.c | 198 +++++++++++++++++++
tap.c | 13 ++
tcp.c | 18 +-
tcp_buf.c | 1 +
tcp_splice.c | 4 +-
udp.c | 29 ++-
udp_flow.c | 3 +-
util.c | 1 +
19 files changed, 1131 insertions(+), 25 deletions(-)
create mode 100644 fuzz-server.c
create mode 100644 fuzz-testbuf.h
create mode 100644 fuzz.c
create mode 100644 fuzz.h
create mode 100644 fuzzing/README.fuzzing.md
create mode 100755 fuzzing/fuzz-setup.sh
create mode 100644 fuzzing/testcase_dir/empty.bin
--
2.55.0
next reply other threads:[~2026-09-28 5:17 UTC|newest]
Thread overview: 8+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-28 5:17 Anshu Kumari [this message]
2026-09-28 5:17 ` [PATCH v2 1/7] fuzz: Add AFL++ shared memory testcase buffer layout Anshu Kumari
2026-09-28 5:17 ` [PATCH v2 2/7] fuzz: Add deterministic wrappers for assert, clock and getsockopt Anshu Kumari
2026-09-28 5:17 ` [PATCH v2 3/7] fuzz: Guard protocol handlers against invalid fuzz-injected state Anshu Kumari
2026-09-28 5:17 ` [PATCH v2 4/7] fuzz: Bypass sandboxing for fuzzing builds Anshu Kumari
2026-09-28 5:17 ` [PATCH v2 5/7] fuzz: Add AFL++ persistent mode fuzz loop Anshu Kumari
2026-09-28 5:17 ` [PATCH v2 6/7] fuzz: Add host-side test server for bidirectional fuzzing Anshu Kumari
2026-09-28 5:17 ` [PATCH v2 7/7] fuzz: Add build targets, namespace setup and documentation Anshu Kumari
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260928051727.2251281-1-anskuma@redhat.com \
--to=anskuma@redhat.com \
--cc=abdobngad@gmail.com \
--cc=lvivier@redhat.com \
--cc=passt-dev@passt.top \
--cc=sbrivio@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
Code repositories for project(s) associated with this public inbox
https://passt.top/passt
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for IMAP folder(s).