From mboxrd@z Thu Jan 1 00:00:00 1970 Authentication-Results: passt.top; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: passt.top; dkim=pass (1024-bit key; unprotected) header.d=redhat.com header.i=@redhat.com header.a=rsa-sha256 header.s=mimecast20190719 header.b=dCTgxwEb; dkim-atps=neutral Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) by passt.top (Postfix) with ESMTPS id CB8B65A0269 for ; Mon, 28 Sep 2026 07:17:36 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1790572655; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=gJzSA/gL6I0KzgxlmtZgAkkVA1y59NHfKOZxMDT4jY0=; b=dCTgxwEbaT8YE2l6IwR8UQQYLFKfg53ZJp2WE0I/UcdavKOrAi444bseZwwbcPcBI+HkHc 7xEUkRX55wgkH9qQZKt+jYWPHWfSsXZky0VurgHSDBGgF5NkNZibJxPOo3QVGyw/t/Jzt3 GRz1jFN8Tad/ZUi8sjagOueDK1G0tLg= Received: from mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-159-mfNzcqkaNxCCsCZ20M4ZDw-1; Mon, 28 Sep 2026 01:17:33 -0400 X-MC-Unique: mfNzcqkaNxCCsCZ20M4ZDw-1 X-Mimecast-MFC-AGG-ID: mfNzcqkaNxCCsCZ20M4ZDw_1790572653 Received: from mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.17]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id BC6C819772F2; Mon, 28 Sep 2026 05:17:32 +0000 (UTC) Received: from anskuma-thinkpadp1gen7.bengluru.csb (unknown [10.74.80.83]) by mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 5D7A119560AB; Mon, 28 Sep 2026 05:17:30 +0000 (UTC) From: Anshu Kumari To: sbrivio@redhat.com, passt-dev@passt.top Subject: [PATCH v2 0/7] Add AFL++ fuzzing support for passt Date: Mon, 28 Sep 2026 10:47:20 +0530 Message-ID: <20260928051727.2251281-1-anskuma@redhat.com> MIME-Version: 1.0 X-Scanned-By: MIMEDefang 3.0 on 10.30.177.17 X-Mimecast-Spam-Score: 0 X-Mimecast-MFC-PROC-ID: 8swWCyDWwBSo-wllWJRbGE4HeM7l25627kmUUpcu734_1790572653 X-Mimecast-Originator: redhat.com Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: 8bit Message-ID-Hash: QBTJQRR4VIG5NAXM36O7E25BBJ5C3PCD X-Message-ID-Hash: QBTJQRR4VIG5NAXM36O7E25BBJ5C3PCD X-MailFrom: anskuma@redhat.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header CC: lvivier@redhat.com, anskuma@redhat.com, abdobngad@gmail.com X-Mailman-Version: 3.3.8 Precedence: list List-Id: Development discussion and patches for passt Archived-At: Archived-At: List-Archive: List-Archive: List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: This series adds integrated AFL++ fuzzing support for passt, extending the earlier work by AbdAlRahman Gad with persistent mode, bidirectional protocol fuzzing, and real TCP connection coverage via a companion test server. Each testcase is a flat buffer split into four regions: epoll events, raw L2 tap frames, test-server payloads, and getsockopt(TCP_INFO) overrides. AFL++ controls all four through mutation of a 10-byte header. Fuzz-injected epoll events are interleaved with real kernel events so protocol handshakes can complete. A standalone test server (fuzz-server) attaches to AFL++'s shared memory and sends fuzzer-controlled payload on every accepted TCP connection. AnyIP routing in a rootless user+network namespace makes every destination local, so the test server intercepts all outbound traffic from passt without mocking recv(). Deterministic wrappers replace clock_gettime(), getsockopt() and assert() to eliminate non-determinism from kernel state. Sandboxing (seccomp, namespaces, close_range, capabilities) is bypassed under FUZZING builds since AFL++ needs its own fds and syscalls. *** BLURB HERE *** Anshu Kumari (7): fuzz: Add AFL++ shared memory testcase buffer layout fuzz: Add deterministic wrappers for assert, clock and getsockopt fuzz: Guard protocol handlers against invalid fuzz-injected state fuzz: Bypass sandboxing for fuzzing builds fuzz: Add AFL++ persistent mode fuzz loop fuzz: Add host-side test server for bidirectional fuzzing fuzz: Add build targets, namespace setup and documentation Makefile | 35 +++- flow.c | 52 +++++ fuzz-server.c | 343 +++++++++++++++++++++++++++++++++ fuzz-testbuf.h | 135 +++++++++++++ fuzz.c | 102 ++++++++++ fuzz.h | 38 ++++ fuzzing/README.fuzzing.md | 129 +++++++++++++ fuzzing/fuzz-setup.sh | 24 +++ fuzzing/testcase_dir/empty.bin | Bin 0 -> 12 bytes icmp.c | 8 +- isolation.c | 23 +++ passt.c | 198 +++++++++++++++++++ tap.c | 13 ++ tcp.c | 18 +- tcp_buf.c | 1 + tcp_splice.c | 4 +- udp.c | 29 ++- udp_flow.c | 3 +- util.c | 1 + 19 files changed, 1131 insertions(+), 25 deletions(-) create mode 100644 fuzz-server.c create mode 100644 fuzz-testbuf.h create mode 100644 fuzz.c create mode 100644 fuzz.h create mode 100644 fuzzing/README.fuzzing.md create mode 100755 fuzzing/fuzz-setup.sh create mode 100644 fuzzing/testcase_dir/empty.bin -- 2.55.0