public inbox for passt-dev@passt.top
 help / color / mirror / code / Atom feed
From: Anshu Kumari <anskuma@redhat.com>
To: sbrivio@redhat.com, passt-dev@passt.top
Cc: lvivier@redhat.com, anskuma@redhat.com, abdobngad@gmail.com
Subject: [PATCH v2 2/7] fuzz: Add deterministic wrappers for assert, clock and getsockopt
Date: Mon, 28 Sep 2026 10:47:22 +0530	[thread overview]
Message-ID: <20260928051727.2251281-3-anskuma@redhat.com> (raw)
In-Reply-To: <20260928051727.2251281-1-anskuma@redhat.com>

Add fuzz_assert() macro that calls _exit(0) instead of abort()
so AFL++ treats assertion failures as normal exits rather than
crashes.

Add deterministic replacements for clock_gettime() and
getsockopt() that eliminate non-determinism from kernel state:

- fuzz_clock_gettime(): returns a monotonically incrementing
  timestamp from a fixed baseline, reset each AFL++ iteration
- fuzz_getsockopt(): returns fuzzer-controlled TCP_INFO from
  AFL++ shared memory (region d), and fixed values for
  SO_ERROR/SO_RCVBUF/SO_SNDBUF

Signed-off-by: Anshu Kumari <anskuma@redhat.com>
---
 Makefile |  17 ++++++----
 fuzz.c   | 102 +++++++++++++++++++++++++++++++++++++++++++++++++++++++
 fuzz.h   |  37 ++++++++++++++++++++
 3 files changed, 149 insertions(+), 7 deletions(-)
 create mode 100644 fuzz.c
 create mode 100644 fuzz.h

diff --git a/Makefile b/Makefile
index 97c27f7c..cce9ffd0 100644
--- a/Makefile
+++ b/Makefile
@@ -39,6 +39,9 @@ PASST_SRCS = arch.c arp.c bitmap.c checksum.c conf.c dhcp.c dhcpv6.c \
 	parse.c passt.c pasta.c pcap.c pif.c repair.c serialise.c tap.c tcp.c \
 	tcp_buf.c tcp_splice.c tcp_vu.c udp.c udp_flow.c udp_vu.c util.c \
 	vhost_user.c virtio.c vu_common.c
+ifneq ($(findstring FUZZING,$(CPPFLAGS)),)
+PASST_SRCS += fuzz.c
+endif
 PASST_REPAIR_SRCS = passt-repair.c
 PESTO_SRCS = pesto.c bitmap.c fwd_rule.c inany.c ip.c lineread.c parse.c \
 	serialise.c
@@ -47,13 +50,13 @@ SRCS = $(PASST_SRCS) $(PASST_REPAIR_SRCS) $(PESTO_SRCS)
 MANPAGES = passt.1 pasta.1 pesto.1 passt-repair.1
 
 PASST_HEADERS = arch.h arp.h bitmap.h checksum.h conf.h dhcp.h dhcpv6.h \
-	epoll_ctl.h flow.h fwd.h fwd_rule.h flow_table.h fuzz-testbuf.h \
-	icmp.h icmp_flow.h inany.h iov.h ip.h isolation.h lineread.h \
-	linux_dep.h log.h migrate.h ndp.h netlink.h packet.h parse.h \
-	passt.h pasta.h pcap.h pif.h repair.h serialise.h siphash.h tap.h \
-	tcp.h tcp_buf.h tcp_conn.h tcp_internal.h tcp_splice.h tcp_vu.h \
-	udp.h udp_flow.h udp_internal.h udp_vu.h util.h vhost_user.h \
-	virtio.h vu_common.h
+	epoll_ctl.h flow.h fwd.h fwd_rule.h flow_table.h fuzz.h \
+	fuzz-testbuf.h icmp.h icmp_flow.h inany.h iov.h ip.h isolation.h \
+	lineread.h linux_dep.h log.h migrate.h ndp.h netlink.h packet.h \
+	parse.h passt.h pasta.h pcap.h pif.h repair.h serialise.h siphash.h \
+	tap.h tcp.h tcp_buf.h tcp_conn.h tcp_internal.h tcp_splice.h \
+	tcp_vu.h udp.h udp_flow.h udp_internal.h udp_vu.h util.h \
+	vhost_user.h virtio.h vu_common.h
 PASST_REPAIR_HEADERS = linux_dep.h
 PESTO_HEADERS = bitmap.h common.h fwd_rule.h inany.h ip.h log.h parse.h \
 	pesto.h serialise.h
diff --git a/fuzz.c b/fuzz.c
new file mode 100644
index 00000000..89a47d76
--- /dev/null
+++ b/fuzz.c
@@ -0,0 +1,102 @@
+// SPDX-License-Identifier: GPL-2.0-or-later
+
+/* fuzz.c - AFL++ fuzzing support: deterministic wrappers for
+ *          clock_gettime() and getsockopt()
+ *
+ * Copyright Red Hat
+ * Author: Anshu Kumari <anskuma@redhat.com>
+ */
+
+#include <string.h>
+#include <time.h>
+#include <errno.h>
+#include <netinet/tcp.h>
+#include "passt.h"
+#include "fuzz.h"
+
+/* Undo macros so definitions here call the real syscalls */
+#undef clock_gettime
+#undef getsockopt
+
+#define FUZZ_CLOCK_BASE_SEC	10000
+
+static struct timespec fuzz_clock;
+
+/**
+ * fuzz_clock_reset() - Reset clock to fixed baseline
+ *
+ * Called at the start of every __AFL_LOOP iteration so
+ * the clock is identical regardless of iteration number.
+ */
+void fuzz_clock_reset(void)
+{
+	fuzz_clock.tv_sec = FUZZ_CLOCK_BASE_SEC;
+	fuzz_clock.tv_nsec = 0;
+}
+
+/**
+ * fuzz_clock_gettime() - Return deterministic time
+ * @clk:	Clock ID
+ * @tp:		Output timespec
+ *
+ * Return: 0 (always succeeds)
+ */
+int fuzz_clock_gettime(clockid_t clk, struct timespec *tp)
+{
+	(void)clk;
+	*tp = fuzz_clock;
+
+	/* increment the timestamp by 1 micro sec monotonically */
+	fuzz_clock.tv_nsec += 1000;
+	if (fuzz_clock.tv_nsec >= 1000000000) {
+		fuzz_clock.tv_sec++;
+		fuzz_clock.tv_nsec -= 1000000000;
+	}
+	return 0;
+}
+
+/**
+ * fuzz_getsockopt() - Deterministic getsockopt wrapper
+ * @fd:		Socket file descriptor
+ * @level:	Protocol level
+ * @optname:	Option name
+ * @optval:	Output buffer
+ * @optlen:	In/out option length
+ *
+ * For TCP_INFO: populates optval from the AFL++ shared memory buffer.
+ * For SO_RCVBUF, SO_SNDBUF: returns deterministic values.
+ *
+ * Return: 0 on success, -1 on error
+ */
+int fuzz_getsockopt(int fd, int level, int optname, void *optval,
+		    socklen_t *optlen)
+{
+	if (level == SOL_SOCKET) {
+		if (optname == SO_RCVBUF || optname == SO_SNDBUF) {
+			*(int *)optval = 212992; /* default linux buff size */
+			*optlen = sizeof(int);
+			return 0;
+		}
+	}
+
+	if (level == SOL_TCP && optname == TCP_INFO) {
+		size_t fill = *optlen;
+		size_t copy_len;
+
+		memset(optval, 0, fill);
+
+		if (fuzz_sockopt_data && fuzz_sockopt_data_len > 0) {
+			copy_len = MIN(fill, (size_t)fuzz_sockopt_data_len);
+			memcpy(optval, fuzz_sockopt_data, copy_len);
+			fuzz_sockopt_data += copy_len;
+			fuzz_sockopt_data_len -= copy_len;
+			*optlen = copy_len;
+		} else {
+			*optlen = 0;
+		}
+
+		return 0;
+	}
+
+	return getsockopt(fd, level, optname, optval, optlen);
+}
diff --git a/fuzz.h b/fuzz.h
new file mode 100644
index 00000000..311d7e79
--- /dev/null
+++ b/fuzz.h
@@ -0,0 +1,37 @@
+//SPDX-License-Identifier: GPL-2.0-or-later
+
+/* fuzz.h - AFL++ fuzzing support for passt
+ *
+ * Copyright Red Hat
+ * Author: Anshu Kumari <anskuma@redhat.com>
+ */
+
+#ifndef FUZZ_H
+#define FUZZ_H
+
+#ifdef FUZZING
+
+#include <time.h>
+#include <unistd.h>
+#include <sys/socket.h>
+#include "fuzz-testbuf.h"
+
+int fuzz_clock_gettime(clockid_t clk, struct timespec *tp);
+void fuzz_clock_reset(void);
+int fuzz_getsockopt(int fd, int level, int optname, void *optval,
+		    socklen_t *optlen);
+
+extern const unsigned char *fuzz_sockopt_data;
+extern int fuzz_sockopt_data_len;
+
+#define clock_gettime(clk, tp)	fuzz_clock_gettime(clk, tp)
+#define getsockopt(fd, level, name, val, len) \
+	fuzz_getsockopt(fd, level, name, val, len)
+
+#define fuzz_assert(expr)	do { if (!(expr)) _exit(0); } while (0)
+#else /* !FUZZING */
+#include <assert.h>
+#define fuzz_assert(expr)	assert(expr)
+#endif /* FUZZING */
+
+#endif /* FUZZ_H */
-- 
2.55.0


  parent reply	other threads:[~2026-09-28  5:17 UTC|newest]

Thread overview: 8+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-28  5:17 [PATCH v2 0/7] Add AFL++ fuzzing support for passt Anshu Kumari
2026-09-28  5:17 ` [PATCH v2 1/7] fuzz: Add AFL++ shared memory testcase buffer layout Anshu Kumari
2026-09-28  5:17 ` Anshu Kumari [this message]
2026-09-28  5:17 ` [PATCH v2 3/7] fuzz: Guard protocol handlers against invalid fuzz-injected state Anshu Kumari
2026-09-28  5:17 ` [PATCH v2 4/7] fuzz: Bypass sandboxing for fuzzing builds Anshu Kumari
2026-09-28  5:17 ` [PATCH v2 5/7] fuzz: Add AFL++ persistent mode fuzz loop Anshu Kumari
2026-09-28  5:17 ` [PATCH v2 6/7] fuzz: Add host-side test server for bidirectional fuzzing Anshu Kumari
2026-09-28  5:17 ` [PATCH v2 7/7] fuzz: Add build targets, namespace setup and documentation Anshu Kumari

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260928051727.2251281-3-anskuma@redhat.com \
    --to=anskuma@redhat.com \
    --cc=abdobngad@gmail.com \
    --cc=lvivier@redhat.com \
    --cc=passt-dev@passt.top \
    --cc=sbrivio@redhat.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
Code repositories for project(s) associated with this public inbox

	https://passt.top/passt

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for IMAP folder(s).