From mboxrd@z Thu Jan 1 00:00:00 1970 Authentication-Results: passt.top; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: passt.top; dkim=pass (1024-bit key; unprotected) header.d=redhat.com header.i=@redhat.com header.a=rsa-sha256 header.s=mimecast20190719 header.b=hwbhHixO; dkim-atps=neutral Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) by passt.top (Postfix) with ESMTPS id 96F3A5A0275 for ; Mon, 28 Sep 2026 07:17:50 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1790572669; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=47beMeM5vqTfzEMCSdRr18EpsfEYDmVMy4L0fjS86HA=; b=hwbhHixOetWmVCNJF03wEpG98Feno3XeuVP92TSD7HQxlyNeg4BRd+zOc3ThwgpydaWaW6 KtG5Vep56ar8RgBs0EEJDVvhiWkaT4tqGiWLYmOSTyjlQLtdBrwj0O8BnbIM4JgTPYgP6b qNWdOOPRAwvu1eYnMaRlh24T1SdSR7c= Received: from mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-575--XwmDvT8Orq23vueL93eGg-1; Mon, 28 Sep 2026 01:17:45 -0400 X-MC-Unique: -XwmDvT8Orq23vueL93eGg-1 X-Mimecast-MFC-AGG-ID: -XwmDvT8Orq23vueL93eGg_1790572664 Received: from mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.17]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 6CDAA184557D; Mon, 28 Sep 2026 05:17:44 +0000 (UTC) Received: from anskuma-thinkpadp1gen7.bengluru.csb (unknown [10.74.80.83]) by mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 1661819560AB; Mon, 28 Sep 2026 05:17:41 +0000 (UTC) From: Anshu Kumari To: sbrivio@redhat.com, passt-dev@passt.top Subject: [PATCH v2 4/7] fuzz: Bypass sandboxing for fuzzing builds Date: Mon, 28 Sep 2026 10:47:24 +0530 Message-ID: <20260928051727.2251281-5-anskuma@redhat.com> In-Reply-To: <20260928051727.2251281-1-anskuma@redhat.com> References: <20260928051727.2251281-1-anskuma@redhat.com> MIME-Version: 1.0 X-Scanned-By: MIMEDefang 3.0 on 10.30.177.17 X-Mimecast-Spam-Score: 0 X-Mimecast-MFC-PROC-ID: XnZAsKSWnPb2Y5qmMwJs-4uiaTxIGwCTL1Ss1-CKgjc_1790572664 X-Mimecast-Originator: redhat.com Content-Transfer-Encoding: 8bit content-type: text/plain; charset="US-ASCII"; x-default=true Message-ID-Hash: WI5V47HK4LUYSS25DM4FRU57RQG753MA X-Message-ID-Hash: WI5V47HK4LUYSS25DM4FRU57RQG753MA X-MailFrom: anskuma@redhat.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header CC: lvivier@redhat.com, anskuma@redhat.com, abdobngad@gmail.com X-Mailman-Version: 3.3.8 Precedence: list List-Id: Development discussion and patches for passt Archived-At: Archived-At: List-Archive: List-Archive: List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: Skip isolation steps that prevent AFL++ from operating: - close_range(): AFL++ needs its shared memory fds open - User namespace and setuid/setgid: the fuzzer runs in a separate rootless namespace, not passt's own - Capability dropping: not needed without real isolation - Seccomp BPF filters: the fuzz loop uses syscalls (epoll_create1, fork, execl). Signed-off-by: Anshu Kumari --- isolation.c | 23 +++++++++++++++++++++++ 1 file changed, 23 insertions(+) diff --git a/isolation.c b/isolation.c index a30b329f..0d1e6423 100644 --- a/isolation.c +++ b/isolation.c @@ -275,6 +275,7 @@ int isolate_fds(int argc, char **argv) fd = close_from++; } +#ifndef FUZZING if (close_range(close_from, ~0U, CLOSE_RANGE_UNSHARE)) { if (errno == ENOSYS || errno == EINVAL) { /* This probably means close_range() or the @@ -288,6 +289,9 @@ int isolate_fds(int argc, char **argv) die_perror("Failed to close files leaked by parent"); } } +#else + (void)close_from; +#endif /* !FUZZING */ return fd; } @@ -311,6 +315,7 @@ void isolate_user(const struct ctx *c, uid_t uid, gid_t gid, bool use_userns, { uint64_t ns_caps = 0; +#ifndef FUZZING /* First set our UID & GID in the original namespace */ if (setgroups(0, NULL)) { /* If we don't have CAP_SETGID, this will EPERM */ @@ -340,6 +345,10 @@ void isolate_user(const struct ctx *c, uid_t uid, gid_t gid, bool use_userns, if (unshare(CLONE_NEWUSER) != 0) die_perror("Couldn't create user namespace"); } +#else + (void)uid; + (void)gid; +#endif /* !FUZZING */ /* Joining a new userns gives us full capabilities; drop the * ones we don't need. With --netns-only we haven't changed @@ -371,7 +380,11 @@ void isolate_user(const struct ctx *c, uid_t uid, gid_t gid, bool use_userns, ns_caps |= BIT(CAP_SYS_PTRACE); } +#ifndef FUZZING drop_caps_ep_except(ns_caps); +#else + (void)ns_caps; +#endif /* !FUZZING */ } /** @@ -389,6 +402,7 @@ void isolate_user(const struct ctx *c, uid_t uid, gid_t gid, bool use_userns, */ int isolate_prefork(const struct ctx *c) { +#ifndef FUZZING int flags = CLONE_NEWIPC | CLONE_NEWNS | CLONE_NEWUTS; uint64_t ns_caps = 0; @@ -452,6 +466,9 @@ int isolate_prefork(const struct ctx *c) clamp_caps(); drop_caps_ep_except(ns_caps); +#else + (void)c; +#endif /* !FUZZING */ return 0; } @@ -466,10 +483,13 @@ int isolate_prefork(const struct ctx *c) */ void isolate_postfork(const struct ctx *c) { +#ifndef FUZZING struct sock_fprog prog; +#endif /* !FUZZING */ prctl(PR_SET_DUMPABLE, 0); +#ifndef FUZZING switch (c->mode) { case MODE_PASST: prog.len = (unsigned short)ARRAY_SIZE(filter_passt); @@ -490,4 +510,7 @@ void isolate_postfork(const struct ctx *c) if (prctl(PR_SET_NO_NEW_PRIVS, 1, 0, 0, 0) || prctl(PR_SET_SECCOMP, SECCOMP_MODE_FILTER, &prog)) die_perror("Failed to apply seccomp filter"); +#else + (void)c; +#endif /* !FUZZING */ } -- 2.55.0