1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
|
// Copyright 2017 syzkaller project authors. All rights reserved.
// Use of this source code is governed by Apache 2 LICENSE that can be found in the LICENSE file.
// +build
#define SYZ_EXECUTOR
#include "common_akaros.h"
#include "executor_posix.h"
#include "syscalls_akaros.h"
#include "executor.h"
#include <sys/mman.h>
uint32 output;
static void child();
int main(int argc, char** argv)
{
if (argc == 2 && strcmp(argv[1], "version") == 0) {
puts(GOOS " " GOARCH " " SYZ_REVISION " " GIT_REVISION);
return 0;
}
if (argc == 2 && strcmp(argv[1], "child") == 0) {
child();
doexit(0);
}
use_temporary_dir();
main_init();
reply_handshake();
for (;;) {
char cwdbuf[128] = "/syz-tmpXXXXXX";
mkdtemp(cwdbuf);
int pid = fork();
if (pid < 0)
fail("fork failed");
if (pid == 0) {
if (chdir(cwdbuf))
fail("chdir failed");
execl(argv[0], argv[0], "child", NULL);
fail("execl failed");
return 0;
}
int status = 0;
while (waitpid(pid, &status, 0) != pid) {
}
status = WEXITSTATUS(status);
if (status == kFailStatus)
fail("child failed");
if (status == kErrorStatus)
error("child errored");
remove_dir(cwdbuf);
reply_execute(0);
}
return 0;
}
static void child()
{
install_segv_handler();
if (mmap((void*)SYZ_DATA_OFFSET, SYZ_NUM_PAGES * SYZ_PAGE_SIZE, PROT_READ | PROT_WRITE,
MAP_ANON | MAP_PRIVATE | MAP_FIXED, -1, 0) != (void*)SYZ_DATA_OFFSET)
fail("mmap of data segment failed");
receive_execute();
close(kInPipeFd);
execute_one();
}
long execute_syscall(const call_t* c, long a0, long a1, long a2, long a3, long a4, long a5, long a6, long a7, long a8)
{
return syscall(c->sys_nr, a0, a1, a2, a3, a4, a5, a6, a7, a8);
}
void cover_open()
{
}
void cover_enable(thread_t* th)
{
}
void cover_reset(thread_t* th)
{
}
uint32 cover_read_size(thread_t* th)
{
return 0;
}
bool cover_check(uint32 pc)
{
return true;
}
bool cover_check(uint64 pc)
{
return true;
}
uint32* write_output(uint32 v)
{
return &output;
}
void write_completed(uint32 completed)
{
}
bool kcov_comparison_t::ignore() const
{
return false;
}
|