diff options
| author | Julia Hansbrough <flowerhack@google.com> | 2018-03-21 02:26:33 -0700 |
|---|---|---|
| committer | Dmitry Vyukov <dvyukov@google.com> | 2018-03-21 10:26:33 +0100 |
| commit | f63eeee99fd125d095eaacf0c0739ac14a6e473d (patch) | |
| tree | cbb0378ae75802910ece7e082e26b05e7bb5658e /executor | |
| parent | 040e73d644ee4124adfc744cbb81075b863c2b19 (diff) | |
fuchsia: Update syzkaller to build with current Fuchsia API. (#543)
* fuchsia: Fix the `extractor` tool.
The include path in Zircon has changed; updated syz-extract/fuchsia.go
to include this, and re-ran extract to get updated *.const files.
* fuchsia: Update syzkaller to build with current Fuchsia API.
Fuchsia doesn't have a stable API right now, so alas, this will probably
continue to change until that's nailed down.
But, useful to get this up-to-date at least.
Relevant notes:
* zx_channel_call_finish and _retry aren't technically public; leave
them out until we have a less-cludgy way to expose them
* musl supports setjmp/longjmp but not _setjmp/_longjump
* remove some unsupported syscalls
* update the build invocation
Diffstat (limited to 'executor')
| -rw-r--r-- | executor/common_fuchsia.h | 48 | ||||
| -rw-r--r-- | executor/syscalls_fuchsia.h | 22 |
2 files changed, 23 insertions, 47 deletions
diff --git a/executor/common_fuchsia.h b/executor/common_fuchsia.h index 608ce91aa..1c5762199 100644 --- a/executor/common_fuchsia.h +++ b/executor/common_fuchsia.h @@ -55,7 +55,7 @@ static void segv_handler() { if (__atomic_load_n(&skip_segv, __ATOMIC_RELAXED)) { debug("recover: skipping\n"); - _longjmp(segv_env, 1); + longjmp(segv_env, 1); } debug("recover: exiting\n"); doexit(1); @@ -72,7 +72,7 @@ static void* ex_handler(void* arg) continue; } debug("got exception packet: type=%d status=%d tid=%llu\n", - packet.type, packet.status, packet.exception.tid); + packet.type, packet.status, static_cast<unsigned long long>(packet.exception.tid)); zx_handle_t thread; status = zx_object_get_child(zx_process_self(), packet.exception.tid, ZX_RIGHT_SAME_RIGHTS, &thread); @@ -80,16 +80,21 @@ static void* ex_handler(void* arg) debug("zx_object_get_child failed: %d\n", status); continue; } - uint32 bytes_read; - zx_x86_64_general_regs_t regs; - status = zx_thread_read_state(thread, ZX_THREAD_STATE_REGSET0, - ®s, sizeof(regs), &bytes_read); - if (status != ZX_OK || bytes_read != sizeof(regs)) { - debug("zx_thread_read_state failed: %d/%d (%d)\n", - bytes_read, (int)sizeof(regs), status); + zx_thread_state_general_regs_t regs; + status = zx_thread_read_state(thread, ZX_THREAD_STATE_GENERAL_REGS, + ®s, sizeof(regs)); + if (status != ZX_OK) { + debug("zx_thread_read_state failed: %d (%d)\n", + (int)sizeof(regs), status); } else { +#if defined(__x86_64__) regs.rip = (uint64)(void*)&segv_handler; - status = zx_thread_write_state(thread, ZX_THREAD_STATE_REGSET0, ®s, sizeof(regs)); +#elif defined(__aarch64__) + regs.pc = (uint64)(void*)&segv_handler; +#else +#error "unsupported arch" +#endif + status = zx_thread_write_state(thread, ZX_THREAD_STATE_GENERAL_REGS, ®s, sizeof(regs)); if (status != ZX_OK) debug("zx_thread_write_state failed: %d\n", status); } @@ -118,7 +123,7 @@ static void install_segv_handler() #define NONFAILING(...) \ { \ __atomic_fetch_add(&skip_segv, 1, __ATOMIC_SEQ_CST); \ - if (_setjmp(segv_env) == 0) { \ + if (sigsetjmp(segv_env, 0) == 0) { \ __VA_ARGS__; \ } \ __atomic_fetch_sub(&skip_segv, 1, __ATOMIC_SEQ_CST); \ @@ -216,26 +221,7 @@ long syz_future_time(long when) default: delta_ms = 10000; } - zx_time_t now = zx_time_get(ZX_CLOCK_MONOTONIC); + zx_time_t now = zx_clock_get(ZX_CLOCK_MONOTONIC); return now + delta_ms * 1000 * 1000; } #endif - -#if defined(SYZ_EXECUTOR) || defined(__NR_zx_channel_call_finish) || defined(zx_channel_call_noretry) -#include "kernel/lib/vdso/vdso-code.h" -#define UNEXPORTED(name) ((syscall_t)((long)&zx_handle_close - VDSO_SYSCALL_zx_handle_close + VDSO_SYSCALL_##name)) -#endif - -#if defined(SYZ_EXECUTOR) || defined(__NR_zx_channel_call_finish) -zx_status_t zx_channel_call_finish(long a0, long a1, long a2, long a3, long a4, long a5, long a6, long a7, long a8) -{ - return UNEXPORTED(zx_channel_call_finish)(a0, a1, a2, a3, a4, a5, a6, a7, a8); -} -#endif - -#if defined(SYZ_EXECUTOR) || defined(__NR_zx_channel_call_noretry) -zx_status_t zx_channel_call_noretry(long a0, long a1, long a2, long a3, long a4, long a5, long a6, long a7, long a8) -{ - return UNEXPORTED(zx_channel_call_noretry)(a0, a1, a2, a3, a4, a5, a6, a7, a8); -} -#endif diff --git a/executor/syscalls_fuchsia.h b/executor/syscalls_fuchsia.h index c7c7448cf..0da680b07 100644 --- a/executor/syscalls_fuchsia.h +++ b/executor/syscalls_fuchsia.h @@ -2,11 +2,11 @@ #if defined(__x86_64__) || 0 #define GOARCH "amd64" -#define SYZ_REVISION "7b78fbcff5be58d55fce6250972288b9c5141689" +#define SYZ_REVISION "9bdbf38bbd8f8ae5ac1db5c26f4309fd7cab884b" #define SYZ_PAGE_SIZE 4096 #define SYZ_NUM_PAGES 4096 #define SYZ_DATA_OFFSET 536870912 -unsigned syscall_count = 164; +unsigned syscall_count = 159; call_t syscalls[] = { {"chdir", 0, (syscall_t)chdir}, {"chmod", 0, (syscall_t)chmod}, @@ -17,17 +17,14 @@ call_t syscalls[] = { {"dup2", 0, (syscall_t)dup2}, {"dup3", 0, (syscall_t)dup3}, {"faccessat", 0, (syscall_t)faccessat}, - {"fchdir", 0, (syscall_t)fchdir}, {"fchmod", 0, (syscall_t)fchmod}, {"fchmodat", 0, (syscall_t)fchmodat}, {"fchown", 0, (syscall_t)fchown}, {"fchownat", 0, (syscall_t)fchownat}, {"fdatasync", 0, (syscall_t)fdatasync}, - {"flock", 0, (syscall_t)flock}, {"fstat", 0, (syscall_t)fstat}, {"fsync", 0, (syscall_t)fsync}, {"ftruncate", 0, (syscall_t)ftruncate}, - {"futimesat", 0, (syscall_t)futimesat}, {"getcwd", 0, (syscall_t)getcwd}, {"getgid", 0, (syscall_t)getgid}, {"getpid", 0, (syscall_t)getpid}, @@ -72,11 +69,10 @@ call_t syscalls[] = { {"write", 0, (syscall_t)write}, {"writev", 0, (syscall_t)writev}, {"zx_channel_call", 0, (syscall_t)zx_channel_call}, - {"zx_channel_call_finish", 0, (syscall_t)zx_channel_call_finish}, - {"zx_channel_call_noretry", 0, (syscall_t)zx_channel_call_noretry}, {"zx_channel_create", 0, (syscall_t)zx_channel_create}, {"zx_channel_read", 0, (syscall_t)zx_channel_read}, {"zx_channel_write", 0, (syscall_t)zx_channel_write}, + {"zx_clock_get", 0, (syscall_t)zx_clock_get}, {"zx_cprng_add_entropy", 0, (syscall_t)zx_cprng_add_entropy}, {"zx_cprng_draw", 0, (syscall_t)zx_cprng_draw}, {"zx_event_create", 0, (syscall_t)zx_event_create}, @@ -148,7 +144,6 @@ call_t syscalls[] = { {"zx_thread_write_state$0", 0, (syscall_t)zx_thread_write_state}, {"zx_ticks_get", 0, (syscall_t)zx_ticks_get}, {"zx_ticks_per_second", 0, (syscall_t)zx_ticks_per_second}, - {"zx_time_get", 0, (syscall_t)zx_time_get}, {"zx_timer_cancel", 0, (syscall_t)zx_timer_cancel}, {"zx_timer_create", 0, (syscall_t)zx_timer_create}, {"zx_timer_set", 0, (syscall_t)zx_timer_set}, @@ -178,11 +173,11 @@ call_t syscalls[] = { #if defined(__aarch64__) || 0 #define GOARCH "arm64" -#define SYZ_REVISION "545421122ef05f52e8f98342789ed868018b192b" +#define SYZ_REVISION "ebd125b38ce1b3617ba0e9db31c2becdb3213fc2" #define SYZ_PAGE_SIZE 4096 #define SYZ_NUM_PAGES 4096 #define SYZ_DATA_OFFSET 536870912 -unsigned syscall_count = 164; +unsigned syscall_count = 159; call_t syscalls[] = { {"chdir", 0, (syscall_t)chdir}, {"chmod", 0, (syscall_t)chmod}, @@ -193,17 +188,14 @@ call_t syscalls[] = { {"dup2", 0, (syscall_t)dup2}, {"dup3", 0, (syscall_t)dup3}, {"faccessat", 0, (syscall_t)faccessat}, - {"fchdir", 0, (syscall_t)fchdir}, {"fchmod", 0, (syscall_t)fchmod}, {"fchmodat", 0, (syscall_t)fchmodat}, {"fchown", 0, (syscall_t)fchown}, {"fchownat", 0, (syscall_t)fchownat}, {"fdatasync", 0, (syscall_t)fdatasync}, - {"flock", 0, (syscall_t)flock}, {"fstat", 0, (syscall_t)fstat}, {"fsync", 0, (syscall_t)fsync}, {"ftruncate", 0, (syscall_t)ftruncate}, - {"futimesat", 0, (syscall_t)futimesat}, {"getcwd", 0, (syscall_t)getcwd}, {"getgid", 0, (syscall_t)getgid}, {"getpid", 0, (syscall_t)getpid}, @@ -248,11 +240,10 @@ call_t syscalls[] = { {"write", 0, (syscall_t)write}, {"writev", 0, (syscall_t)writev}, {"zx_channel_call", 0, (syscall_t)zx_channel_call}, - {"zx_channel_call_finish", 0, (syscall_t)zx_channel_call_finish}, - {"zx_channel_call_noretry", 0, (syscall_t)zx_channel_call_noretry}, {"zx_channel_create", 0, (syscall_t)zx_channel_create}, {"zx_channel_read", 0, (syscall_t)zx_channel_read}, {"zx_channel_write", 0, (syscall_t)zx_channel_write}, + {"zx_clock_get", 0, (syscall_t)zx_clock_get}, {"zx_cprng_add_entropy", 0, (syscall_t)zx_cprng_add_entropy}, {"zx_cprng_draw", 0, (syscall_t)zx_cprng_draw}, {"zx_event_create", 0, (syscall_t)zx_event_create}, @@ -324,7 +315,6 @@ call_t syscalls[] = { {"zx_thread_write_state$0", 0, (syscall_t)zx_thread_write_state}, {"zx_ticks_get", 0, (syscall_t)zx_ticks_get}, {"zx_ticks_per_second", 0, (syscall_t)zx_ticks_per_second}, - {"zx_time_get", 0, (syscall_t)zx_time_get}, {"zx_timer_cancel", 0, (syscall_t)zx_timer_cancel}, {"zx_timer_create", 0, (syscall_t)zx_timer_create}, {"zx_timer_set", 0, (syscall_t)zx_timer_set}, |
