diff --git a/analysis/test_data/pairwise_unique_coverage_heatmap-failed-diff.png b/analysis/test_data/pairwise_unique_coverage_heatmap-failed-diff.png index 5dc618e..7eb634b 100644 Binary files a/analysis/test_data/pairwise_unique_coverage_heatmap-failed-diff.png and b/analysis/test_data/pairwise_unique_coverage_heatmap-failed-diff.png differ diff --git a/benchmarks/bloaty_fuzz_target/benchmark.yaml b/benchmarks/bloaty_fuzz_target/benchmark.yaml index 66a0b5e..49e7e1a 100644 --- a/benchmarks/bloaty_fuzz_target/benchmark.yaml +++ b/benchmarks/bloaty_fuzz_target/benchmark.yaml @@ -26,3 +26,9 @@ unsupported_fuzzers: - symqemu_aflplusplus - fuzzolic_aflplusplus_fuzzy - fuzzolic_aflplusplus_z3dict + - dgfuzz + - dgfuzz_4aacb8 + - dgfuzz_c286e5 + - dgfuzz_3f8f81 + - dgfuzz_0e010d + - dgfuzz_ab0800 diff --git a/benchmarks/bloaty_fuzz_target_52948c/benchmark.yaml b/benchmarks/bloaty_fuzz_target_52948c/benchmark.yaml index 968c43d..cc23bf7 100644 --- a/benchmarks/bloaty_fuzz_target_52948c/benchmark.yaml +++ b/benchmarks/bloaty_fuzz_target_52948c/benchmark.yaml @@ -28,3 +28,9 @@ unsupported_fuzzers: - symqemu_aflplusplus - fuzzolic_aflplusplus_fuzzy - fuzzolic_aflplusplus_z3dict + - dgfuzz + - dgfuzz_4aacb8 + - dgfuzz_c286e5 + - dgfuzz_3f8f81 + - dgfuzz_0e010d + - dgfuzz_ab0800 diff --git a/benchmarks/curl_curl_fuzzer_http/benchmark.yaml b/benchmarks/curl_curl_fuzzer_http/benchmark.yaml index 48d6a2e..06017cd 100644 --- a/benchmarks/curl_curl_fuzzer_http/benchmark.yaml +++ b/benchmarks/curl_curl_fuzzer_http/benchmark.yaml @@ -23,3 +23,9 @@ unsupported_fuzzers: - libfuzzer_dataflow_store - centipede - centipede_function_filter + - dgfuzz + - dgfuzz_4aacb8 + - dgfuzz_c286e5 + - dgfuzz_3f8f81 + - dgfuzz_0e010d + - dgfuzz_ab0800 diff --git a/benchmarks/freetype2_ftfuzzer/benchmark.yaml b/benchmarks/freetype2_ftfuzzer/benchmark.yaml index 0bdd0a0..f15fe79 100644 --- a/benchmarks/freetype2_ftfuzzer/benchmark.yaml +++ b/benchmarks/freetype2_ftfuzzer/benchmark.yaml @@ -16,3 +16,10 @@ commit: cd02d359a6d0455e9d16b87bf9665961c4699538 commit_date: 2023-01-28T16:04:38+00:00 fuzz_target: ftfuzzer project: freetype2 +unsupported_fuzzers: + - dgfuzz + - dgfuzz_4aacb8 + - dgfuzz_c286e5 + - dgfuzz_3f8f81 + - dgfuzz_0e010d + - dgfuzz_ab0800 diff --git a/benchmarks/jsoncpp_jsoncpp_fuzzer/benchmark.yaml b/benchmarks/jsoncpp_jsoncpp_fuzzer/benchmark.yaml index e988f0a..b20d186 100644 --- a/benchmarks/jsoncpp_jsoncpp_fuzzer/benchmark.yaml +++ b/benchmarks/jsoncpp_jsoncpp_fuzzer/benchmark.yaml @@ -26,3 +26,9 @@ unsupported_fuzzers: - symqemu_aflplusplus - fuzzolic_aflplusplus_fuzzy - fuzzolic_aflplusplus_z3dict + - dgfuzz + - dgfuzz_4aacb8 + - dgfuzz_c286e5 + - dgfuzz_3f8f81 + - dgfuzz_0e010d + - dgfuzz_ab0800 diff --git a/benchmarks/libjpeg-turbo_libjpeg_turbo_fuzzer/benchmark.yaml b/benchmarks/libjpeg-turbo_libjpeg_turbo_fuzzer/benchmark.yaml index cfdb389..d7545cf 100644 --- a/benchmarks/libjpeg-turbo_libjpeg_turbo_fuzzer/benchmark.yaml +++ b/benchmarks/libjpeg-turbo_libjpeg_turbo_fuzzer/benchmark.yaml @@ -18,3 +18,9 @@ fuzz_target: libjpeg_turbo_fuzzer project: libjpeg-turbo unsupported_fuzzers: - aflcc + - dgfuzz + - dgfuzz_4aacb8 + - dgfuzz_c286e5 + - dgfuzz_3f8f81 + - dgfuzz_0e010d + - dgfuzz_ab0800 diff --git a/benchmarks/libpng_libpng_read_fuzzer/benchmark.yaml b/benchmarks/libpng_libpng_read_fuzzer/benchmark.yaml index f1df594..74d19db 100644 --- a/benchmarks/libpng_libpng_read_fuzzer/benchmark.yaml +++ b/benchmarks/libpng_libpng_read_fuzzer/benchmark.yaml @@ -16,3 +16,10 @@ commit: cd0ea2a7f53b603d3d9b5b891c779c430047b39a commit_date: 2023-01-09T13:17:31+00:00 fuzz_target: libpng_read_fuzzer project: libpng +unsupported_fuzzers: + - dgfuzz + - dgfuzz_4aacb8 + - dgfuzz_c286e5 + - dgfuzz_3f8f81 + - dgfuzz_0e010d + - dgfuzz_ab0800 diff --git a/benchmarks/libxml2_xml/benchmark.yaml b/benchmarks/libxml2_xml/benchmark.yaml index e12fc3b..c2866dd 100644 --- a/benchmarks/libxml2_xml/benchmark.yaml +++ b/benchmarks/libxml2_xml/benchmark.yaml @@ -16,3 +16,10 @@ commit: c7260a47f19e01f4f663b6a56fbdc2dafd8a6e7e commit_date: 2023-01-23T09:19:59+00:00 fuzz_target: xml project: libxml2 +unsupported_fuzzers: + - dgfuzz + - dgfuzz_4aacb8 + - dgfuzz_c286e5 + - dgfuzz_3f8f81 + - dgfuzz_0e010d + - dgfuzz_ab0800 diff --git a/benchmarks/libxml2_xml_e85b9b/benchmark.yaml b/benchmarks/libxml2_xml_e85b9b/benchmark.yaml index 51296d5..48439af 100644 --- a/benchmarks/libxml2_xml_e85b9b/benchmark.yaml +++ b/benchmarks/libxml2_xml_e85b9b/benchmark.yaml @@ -18,3 +18,10 @@ commit_date: 2022-10-19T00:47:30+0000 fuzz_target: xml project: libxml2 type: bug +unsupported_fuzzers: + - dgfuzz + - dgfuzz_4aacb8 + - dgfuzz_c286e5 + - dgfuzz_3f8f81 + - dgfuzz_0e010d + - dgfuzz_ab0800 diff --git a/benchmarks/libxslt_xpath/benchmark.yaml b/benchmarks/libxslt_xpath/benchmark.yaml index e2c3754..20d8bf0 100644 --- a/benchmarks/libxslt_xpath/benchmark.yaml +++ b/benchmarks/libxslt_xpath/benchmark.yaml @@ -42,3 +42,9 @@ unsupported_fuzzers: - symqemu_aflplusplus - fuzzolic_aflplusplus_fuzzy - fuzzolic_aflplusplus_z3dict + - dgfuzz + - dgfuzz_4aacb8 + - dgfuzz_c286e5 + - dgfuzz_3f8f81 + - dgfuzz_0e010d + - dgfuzz_ab0800 diff --git a/benchmarks/openh264_decoder_fuzzer/benchmark.yaml b/benchmarks/openh264_decoder_fuzzer/benchmark.yaml index 42ea7d6..5e0c018 100644 --- a/benchmarks/openh264_decoder_fuzzer/benchmark.yaml +++ b/benchmarks/openh264_decoder_fuzzer/benchmark.yaml @@ -21,3 +21,9 @@ unsupported_fuzzers: - fuzzolic_aflplusplus_fuzzy - fuzzolic_aflplusplus_z3dict - tortoisefuzz + - dgfuzz + - dgfuzz_4aacb8 + - dgfuzz_c286e5 + - dgfuzz_3f8f81 + - dgfuzz_0e010d + - dgfuzz_ab0800 diff --git a/benchmarks/openssl_x509/benchmark.yaml b/benchmarks/openssl_x509/benchmark.yaml index 883e263..cc7a424 100644 --- a/benchmarks/openssl_x509/benchmark.yaml +++ b/benchmarks/openssl_x509/benchmark.yaml @@ -21,3 +21,9 @@ unsupported_fuzzers: - cfctx_dataflow_svf - cfctx_dataflow_svf_llc - tortoisefuzz + - dgfuzz + - dgfuzz_4aacb8 + - dgfuzz_c286e5 + - dgfuzz_3f8f81 + - dgfuzz_0e010d + - dgfuzz_ab0800 diff --git a/benchmarks/php_php-fuzz-parser_0dbedb/benchmark.yaml b/benchmarks/php_php-fuzz-parser_0dbedb/benchmark.yaml index e38fbb2..e0338d1 100644 --- a/benchmarks/php_php-fuzz-parser_0dbedb/benchmark.yaml +++ b/benchmarks/php_php-fuzz-parser_0dbedb/benchmark.yaml @@ -52,3 +52,9 @@ unsupported_fuzzers: - symqemu_aflplusplus - fuzzolic_aflplusplus_fuzzy - fuzzolic_aflplusplus_z3dict + - dgfuzz + - dgfuzz_4aacb8 + - dgfuzz_c286e5 + - dgfuzz_3f8f81 + - dgfuzz_0e010d + - dgfuzz_ab0800 diff --git a/benchmarks/proj4_proj_crs_to_crs_fuzzer/benchmark.yaml b/benchmarks/proj4_proj_crs_to_crs_fuzzer/benchmark.yaml index e93b0d3..add33c4 100644 --- a/benchmarks/proj4_proj_crs_to_crs_fuzzer/benchmark.yaml +++ b/benchmarks/proj4_proj_crs_to_crs_fuzzer/benchmark.yaml @@ -16,3 +16,10 @@ commit: a7482d3775f2e346f3680363dd2d641add3e68b2 commit_date: 2023-02-06T16:46:19+0000 fuzz_target: proj_crs_to_crs_fuzzer project: proj4 +unsupported_fuzzers: + - dgfuzz + - dgfuzz_4aacb8 + - dgfuzz_c286e5 + - dgfuzz_3f8f81 + - dgfuzz_0e010d + - dgfuzz_ab0800 diff --git a/benchmarks/re2_fuzzer/benchmark.yaml b/benchmarks/re2_fuzzer/benchmark.yaml index 55cf244..f38a507 100644 --- a/benchmarks/re2_fuzzer/benchmark.yaml +++ b/benchmarks/re2_fuzzer/benchmark.yaml @@ -16,3 +16,10 @@ commit: b025c6a3ae05995660e3b882eb3277f4399ced1a commit_date: 2023-01-30T18:31:10+0000 fuzz_target: fuzzer project: re2 +unsupported_fuzzers: + - dgfuzz + - dgfuzz_4aacb8 + - dgfuzz_c286e5 + - dgfuzz_3f8f81 + - dgfuzz_0e010d + - dgfuzz_ab0800 diff --git a/benchmarks/sqlite3_ossfuzz/benchmark.yaml b/benchmarks/sqlite3_ossfuzz/benchmark.yaml index 4eb2eff..c95f0c8 100644 --- a/benchmarks/sqlite3_ossfuzz/benchmark.yaml +++ b/benchmarks/sqlite3_ossfuzz/benchmark.yaml @@ -20,3 +20,9 @@ unsupported_fuzzers: - symcc_afl - symcc_afl_single - symcc_aflplusplus + - dgfuzz + - dgfuzz_4aacb8 + - dgfuzz_c286e5 + - dgfuzz_3f8f81 + - dgfuzz_0e010d + - dgfuzz_ab0800 diff --git a/benchmarks/systemd_fuzz-link-parser/benchmark.yaml b/benchmarks/systemd_fuzz-link-parser/benchmark.yaml index 2d04855..15cc252 100644 --- a/benchmarks/systemd_fuzz-link-parser/benchmark.yaml +++ b/benchmarks/systemd_fuzz-link-parser/benchmark.yaml @@ -5,3 +5,9 @@ project: systemd unsupported_fuzzers: - centipede - wingfuzz + - dgfuzz + - dgfuzz_4aacb8 + - dgfuzz_c286e5 + - dgfuzz_3f8f81 + - dgfuzz_0e010d + - dgfuzz_ab0800 diff --git a/benchmarks/woff2_convert_woff2ttf_fuzzer/benchmark.yaml b/benchmarks/woff2_convert_woff2ttf_fuzzer/benchmark.yaml index fd30aa2..477a715 100644 --- a/benchmarks/woff2_convert_woff2ttf_fuzzer/benchmark.yaml +++ b/benchmarks/woff2_convert_woff2ttf_fuzzer/benchmark.yaml @@ -16,3 +16,10 @@ commit: 8109a2cc2b27436962ac1cfe40ad0e8a0dca26c8 commit_date: 2017-01-04T06:37:49+1100 fuzz_target: convert_woff2ttf_fuzzer project: woff2 +unsupported_fuzzers: + - dgfuzz + - dgfuzz_4aacb8 + - dgfuzz_c286e5 + - dgfuzz_3f8f81 + - dgfuzz_0e010d + - dgfuzz_ab0800 diff --git a/fuzzers/dgfuzz_0e010d/builder.Dockerfile b/fuzzers/dgfuzz_0e010d/builder.Dockerfile new file mode 100644 index 0000000..f316815 --- /dev/null +++ b/fuzzers/dgfuzz_0e010d/builder.Dockerfile @@ -0,0 +1,86 @@ +# Copyright 2020 Google LLC +# +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. + +ARG parent_image +FROM $parent_image + +# Uninstall old Rust & Install the latest one. +RUN if which rustup; then rustup self uninstall -y; fi && \ + curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs > /rustup.sh && \ + sh /rustup.sh -y && \ + /root/.cargo/bin/rustup toolchain install nightly && \ + rm /rustup.sh + +RUN apt-get update && \ + apt-get install -y \ + build-essential \ + cargo && \ + apt-get install -y wget libstdc++5 libtool-bin automake flex bison \ + libglib2.0-dev libpixman-1-dev python3-setuptools unzip \ + apt-utils apt-transport-https ca-certificates joe curl && \ + PATH="/root/.cargo/bin/:$PATH" cargo install cargo-make + + +# Download DGFuzz. +RUN git clone https://github.com/DanBlackwell/DGFuzz /dgfuzz + +# Checkout a current commit +RUN cd /dgfuzz && git pull && git checkout 0e010d256ec3f191545b21cbecf6cb50886134ff || true + +# apply a patch (local testing only) +# COPY ./patch /dgfuzz/patch +# RUN cd /dgfuzz && git apply ./patch + +# Compile DGFuzz. +RUN cd /dgfuzz && \ + unset CFLAGS CXXFLAGS && \ + export CC=clang AFL_NO_X86 && \ + cd ./fuzzers/fuzzbench_dataflow_guided && \ + PATH="/root/.cargo/bin/:$PATH" cargo +nightly build --profile release-fuzzbench --features no_link_main + +# Auxiliary weak references. +RUN cd /dgfuzz/fuzzers/fuzzbench_dataflow_guided && \ + clang -c stub_rt.c && \ + ar r /stub_rt.a stub_rt.o + +# install AFL++ dependencies +RUN apt-get update && \ + apt-get install -y \ + build-essential \ + python3-dev \ + python3-setuptools \ + automake \ + cmake \ + git \ + flex \ + bison \ + libglib2.0-dev \ + libpixman-1-dev \ + cargo \ + libgtk-3-dev \ + # for QEMU mode + ninja-build \ + gcc-$(gcc --version|head -n1|sed 's/\..*//'|sed 's/.* //')-plugin-dev \ + libstdc++-$(gcc --version|head -n1|sed 's/\..*//'|sed 's/.* //')-dev + +# compile afl-clang-dgfuzz +RUN cd /dgfuzz/fuzzers/fuzzbench_dataflow_guided/afl-cc && \ + unset CFLAGS CXXFLAGS && \ + export CC=clang AFL_NO_X86=1 && \ + PYTHON_INCLUDE=/ make && \ + cd utils/aflpp_driver/ && \ + PYTHON_INCLUDE=/ make && \ + cp ./libAFLDriver.a / + + diff --git a/fuzzers/dgfuzz_0e010d/description.md b/fuzzers/dgfuzz_0e010d/description.md new file mode 100644 index 0000000..452b0e3 --- /dev/null +++ b/fuzzers/dgfuzz_0e010d/description.md @@ -0,0 +1,8 @@ +# PrescientFuzz + +based on libafl fuzzer instance + - persistent mode + +[builder.Dockerfile](builder.Dockerfile) +[fuzzer.py](fuzzer.py) +[runner.Dockerfile](runner.Dockerfile) diff --git a/fuzzers/dgfuzz_0e010d/fuzzer.py b/fuzzers/dgfuzz_0e010d/fuzzer.py new file mode 100755 index 0000000..074224e --- /dev/null +++ b/fuzzers/dgfuzz_0e010d/fuzzer.py @@ -0,0 +1,140 @@ +# Copyright 2020 Google LLC +# +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. +# +"""Integration code for a LibAFL-based fuzzer.""" + +import os +import sys +import subprocess +from pathlib import Path + +from fuzzers import utils + + +def prepare_fuzz_environment(input_corpus): + """Prepare to fuzz with a LibAFL-based fuzzer.""" + os.environ['ASAN_OPTIONS'] = 'abort_on_error=1:detect_leaks=0:'\ + 'malloc_context_size=0:symbolize=0:'\ + 'allocator_may_return_null=1:'\ + 'detect_odr_violation=0:handle_segv=0:'\ + 'handle_sigbus=0:handle_abort=0:'\ + 'handle_sigfpe=0:handle_sigill=0' + os.environ['UBSAN_OPTIONS'] = 'abort_on_error=1:'\ + 'allocator_release_to_os_interval_ms=500:'\ + 'handle_abort=0:handle_segv=0:'\ + 'handle_sigbus=0:handle_sigfpe=0:'\ + 'handle_sigill=0:print_stacktrace=0:'\ + 'symbolize=0:symbolize_inline_frames=0' + # Create at least one non-empty seed to start. + utils.create_seed_file_for_empty_corpus(input_corpus) + + +def build_dfsan(): + """Build benchmark with dfsan.""" + new_env = os.environ.copy() + new_env['CC'] = ('/dgfuzz/fuzzers/fuzzbench_dataflow_guided/afl-cc/' + 'afl-clang-dgfuzz') + new_env['CXX'] = ('/dgfuzz/fuzzers/fuzzbench_dataflow_guided/afl-cc/' + 'afl-clang-dgfuzz++') + + new_env['ASAN_OPTIONS'] = 'abort_on_error=0:allocator_may_return_null=1' + new_env['UBSAN_OPTIONS'] = 'abort_on_error=0' + new_env['AFL_QUIET'] = '1' + + new_env['FUZZER_LIB'] = '/libAFLDriver.a' + + build_directory = new_env['OUT'] + dfsan_build_directory = os.path.join(build_directory, 'dfsan') + os.mkdir(dfsan_build_directory) + new_env['OUT'] = dfsan_build_directory + + cfg_file = os.path.join(build_directory, 'aflpp_cfg.bin') + new_env['AFL_LLVM_CFG_FILE'] = cfg_file + if os.path.isfile(cfg_file): + os.remove(cfg_file) + Path(cfg_file).touch() + + src = os.getenv('SRC') + work = os.getenv('WORK') + + with utils.restore_directory(src), utils.restore_directory(work): + # Restore SRC to its initial state so we can build again without any + # trouble. For some OSS-Fuzz projects, build_benchmark cannot be run + # twice in the same directory without this. + utils.build_benchmark(env=new_env) + + fuzz_target = os.getenv('FUZZ_TARGET') + exec_path = os.path.join(dfsan_build_directory, fuzz_target) + new_path = os.path.join(dfsan_build_directory, fuzz_target + '_dfsan') + os.rename(exec_path, new_path) + + +def build(): + """Build benchmark.""" + + # first build it with DFSan enabled + build_dfsan() + + os.environ['CC'] = ('/dgfuzz/fuzzers/fuzzbench_dataflow_guided/target/' + 'release-fuzzbench/libafl_cc') + os.environ['CXX'] = ('/dgfuzz/fuzzers/fuzzbench_dataflow_guided/target/' + 'release-fuzzbench/libafl_cxx') + + os.environ['ASAN_OPTIONS'] = 'abort_on_error=0:allocator_may_return_null=1' + os.environ['UBSAN_OPTIONS'] = 'abort_on_error=0' + + cflags = ['--libafl'] + utils.append_flags('CFLAGS', cflags) + utils.append_flags('CXXFLAGS', cflags) + utils.append_flags('LDFLAGS', cflags) + + os.environ['FUZZER_LIB'] = '/stub_rt.a' + build_directory = os.environ['OUT'] + cfg_file = os.path.join(build_directory, 'libafl_cfg.bin') + os.environ['AFL_LLVM_CFG_FILE'] = cfg_file + if os.path.isfile(cfg_file): + os.remove(cfg_file) + Path(cfg_file).touch() + utils.build_benchmark() + + +def fuzz(input_corpus, output_corpus, target_binary): + """Run fuzzer.""" + prepare_fuzz_environment(input_corpus) + dictionary_path = utils.get_dictionary_path(target_binary) + command = [target_binary] + if dictionary_path: + command += (['-x', dictionary_path]) + + # Add the control flow graph file + build_directory = os.environ['OUT'] + cfg_file = os.path.join(build_directory, 'libafl_cfg.bin') + if os.path.exists(cfg_file): + command += (['-c', cfg_file]) + else: + sys.exit(1) + + # get the dfsan binary + dfsan_build_directory = os.path.join(build_directory, 'dfsan') + fuzz_target = os.getenv('FUZZ_TARGET') + dfsan_fuzz_target = os.path.join(dfsan_build_directory, + fuzz_target + '_dfsan') + command += (['-d', dfsan_fuzz_target]) + + # Add the input and output corpus + command += (['-o', output_corpus, '-i', input_corpus]) + fuzzer_env = os.environ.copy() + fuzzer_env['LD_PRELOAD'] = '/usr/lib/x86_64-linux-gnu/libjemalloc.so.2' + print(command) + subprocess.check_call(command, cwd=os.environ['OUT'], env=fuzzer_env) diff --git a/fuzzers/dgfuzz_0e010d/runner.Dockerfile b/fuzzers/dgfuzz_0e010d/runner.Dockerfile new file mode 100644 index 0000000..f87abba --- /dev/null +++ b/fuzzers/dgfuzz_0e010d/runner.Dockerfile @@ -0,0 +1,25 @@ +# Copyright 2020 Google LLC +# +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. + +FROM gcr.io/fuzzbench/base-image + +RUN apt install libjemalloc2 + +# This makes interactive docker runs painless: +ENV LD_LIBRARY_PATH="$LD_LIBRARY_PATH:/out" +ENV AFL_MAP_SIZE=1310720 +ENV PATH="$PATH:/out" +ENV AFL_SKIP_CPUFREQ=1 +ENV AFL_I_DONT_CARE_ABOUT_MISSING_CRASHES=1 +ENV AFL_TESTCACHE_SIZE=2 diff --git a/fuzzers/dgfuzz_3f8f81/builder.Dockerfile b/fuzzers/dgfuzz_3f8f81/builder.Dockerfile new file mode 100644 index 0000000..900c993 --- /dev/null +++ b/fuzzers/dgfuzz_3f8f81/builder.Dockerfile @@ -0,0 +1,86 @@ +# Copyright 2020 Google LLC +# +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. + +ARG parent_image +FROM $parent_image + +# Uninstall old Rust & Install the latest one. +RUN if which rustup; then rustup self uninstall -y; fi && \ + curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs > /rustup.sh && \ + sh /rustup.sh -y && \ + /root/.cargo/bin/rustup toolchain install nightly && \ + rm /rustup.sh + +RUN apt-get update && \ + apt-get install -y \ + build-essential \ + cargo && \ + apt-get install -y wget libstdc++5 libtool-bin automake flex bison \ + libglib2.0-dev libpixman-1-dev python3-setuptools unzip \ + apt-utils apt-transport-https ca-certificates joe curl && \ + PATH="/root/.cargo/bin/:$PATH" cargo install cargo-make + + +# Download DGFuzz. +RUN git clone https://github.com/DanBlackwell/DGFuzz /dgfuzz + +# Checkout a current commit +RUN cd /dgfuzz && git pull && git checkout 3f8f819cd357ddbb2b793778de0246f2eb4335b2 || true + +# apply a patch (local testing only) +# COPY ./patch /dgfuzz/patch +# RUN cd /dgfuzz && git apply ./patch + +# Compile DGFuzz. +RUN cd /dgfuzz && \ + unset CFLAGS CXXFLAGS && \ + export CC=clang AFL_NO_X86 && \ + cd ./fuzzers/fuzzbench_dataflow_guided && \ + PATH="/root/.cargo/bin/:$PATH" cargo +nightly build --profile release-fuzzbench --features no_link_main + +# Auxiliary weak references. +RUN cd /dgfuzz/fuzzers/fuzzbench_dataflow_guided && \ + clang -c stub_rt.c && \ + ar r /stub_rt.a stub_rt.o + +# install AFL++ dependencies +RUN apt-get update && \ + apt-get install -y \ + build-essential \ + python3-dev \ + python3-setuptools \ + automake \ + cmake \ + git \ + flex \ + bison \ + libglib2.0-dev \ + libpixman-1-dev \ + cargo \ + libgtk-3-dev \ + # for QEMU mode + ninja-build \ + gcc-$(gcc --version|head -n1|sed 's/\..*//'|sed 's/.* //')-plugin-dev \ + libstdc++-$(gcc --version|head -n1|sed 's/\..*//'|sed 's/.* //')-dev + +# compile afl-clang-dgfuzz +RUN cd /dgfuzz/fuzzers/fuzzbench_dataflow_guided/afl-cc && \ + unset CFLAGS CXXFLAGS && \ + export CC=clang AFL_NO_X86=1 && \ + PYTHON_INCLUDE=/ make && \ + cd utils/aflpp_driver/ && \ + PYTHON_INCLUDE=/ make && \ + cp ./libAFLDriver.a / + + diff --git a/fuzzers/dgfuzz_3f8f81/description.md b/fuzzers/dgfuzz_3f8f81/description.md new file mode 100644 index 0000000..452b0e3 --- /dev/null +++ b/fuzzers/dgfuzz_3f8f81/description.md @@ -0,0 +1,8 @@ +# PrescientFuzz + +based on libafl fuzzer instance + - persistent mode + +[builder.Dockerfile](builder.Dockerfile) +[fuzzer.py](fuzzer.py) +[runner.Dockerfile](runner.Dockerfile) diff --git a/fuzzers/dgfuzz_3f8f81/fuzzer.py b/fuzzers/dgfuzz_3f8f81/fuzzer.py new file mode 100755 index 0000000..074224e --- /dev/null +++ b/fuzzers/dgfuzz_3f8f81/fuzzer.py @@ -0,0 +1,140 @@ +# Copyright 2020 Google LLC +# +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. +# +"""Integration code for a LibAFL-based fuzzer.""" + +import os +import sys +import subprocess +from pathlib import Path + +from fuzzers import utils + + +def prepare_fuzz_environment(input_corpus): + """Prepare to fuzz with a LibAFL-based fuzzer.""" + os.environ['ASAN_OPTIONS'] = 'abort_on_error=1:detect_leaks=0:'\ + 'malloc_context_size=0:symbolize=0:'\ + 'allocator_may_return_null=1:'\ + 'detect_odr_violation=0:handle_segv=0:'\ + 'handle_sigbus=0:handle_abort=0:'\ + 'handle_sigfpe=0:handle_sigill=0' + os.environ['UBSAN_OPTIONS'] = 'abort_on_error=1:'\ + 'allocator_release_to_os_interval_ms=500:'\ + 'handle_abort=0:handle_segv=0:'\ + 'handle_sigbus=0:handle_sigfpe=0:'\ + 'handle_sigill=0:print_stacktrace=0:'\ + 'symbolize=0:symbolize_inline_frames=0' + # Create at least one non-empty seed to start. + utils.create_seed_file_for_empty_corpus(input_corpus) + + +def build_dfsan(): + """Build benchmark with dfsan.""" + new_env = os.environ.copy() + new_env['CC'] = ('/dgfuzz/fuzzers/fuzzbench_dataflow_guided/afl-cc/' + 'afl-clang-dgfuzz') + new_env['CXX'] = ('/dgfuzz/fuzzers/fuzzbench_dataflow_guided/afl-cc/' + 'afl-clang-dgfuzz++') + + new_env['ASAN_OPTIONS'] = 'abort_on_error=0:allocator_may_return_null=1' + new_env['UBSAN_OPTIONS'] = 'abort_on_error=0' + new_env['AFL_QUIET'] = '1' + + new_env['FUZZER_LIB'] = '/libAFLDriver.a' + + build_directory = new_env['OUT'] + dfsan_build_directory = os.path.join(build_directory, 'dfsan') + os.mkdir(dfsan_build_directory) + new_env['OUT'] = dfsan_build_directory + + cfg_file = os.path.join(build_directory, 'aflpp_cfg.bin') + new_env['AFL_LLVM_CFG_FILE'] = cfg_file + if os.path.isfile(cfg_file): + os.remove(cfg_file) + Path(cfg_file).touch() + + src = os.getenv('SRC') + work = os.getenv('WORK') + + with utils.restore_directory(src), utils.restore_directory(work): + # Restore SRC to its initial state so we can build again without any + # trouble. For some OSS-Fuzz projects, build_benchmark cannot be run + # twice in the same directory without this. + utils.build_benchmark(env=new_env) + + fuzz_target = os.getenv('FUZZ_TARGET') + exec_path = os.path.join(dfsan_build_directory, fuzz_target) + new_path = os.path.join(dfsan_build_directory, fuzz_target + '_dfsan') + os.rename(exec_path, new_path) + + +def build(): + """Build benchmark.""" + + # first build it with DFSan enabled + build_dfsan() + + os.environ['CC'] = ('/dgfuzz/fuzzers/fuzzbench_dataflow_guided/target/' + 'release-fuzzbench/libafl_cc') + os.environ['CXX'] = ('/dgfuzz/fuzzers/fuzzbench_dataflow_guided/target/' + 'release-fuzzbench/libafl_cxx') + + os.environ['ASAN_OPTIONS'] = 'abort_on_error=0:allocator_may_return_null=1' + os.environ['UBSAN_OPTIONS'] = 'abort_on_error=0' + + cflags = ['--libafl'] + utils.append_flags('CFLAGS', cflags) + utils.append_flags('CXXFLAGS', cflags) + utils.append_flags('LDFLAGS', cflags) + + os.environ['FUZZER_LIB'] = '/stub_rt.a' + build_directory = os.environ['OUT'] + cfg_file = os.path.join(build_directory, 'libafl_cfg.bin') + os.environ['AFL_LLVM_CFG_FILE'] = cfg_file + if os.path.isfile(cfg_file): + os.remove(cfg_file) + Path(cfg_file).touch() + utils.build_benchmark() + + +def fuzz(input_corpus, output_corpus, target_binary): + """Run fuzzer.""" + prepare_fuzz_environment(input_corpus) + dictionary_path = utils.get_dictionary_path(target_binary) + command = [target_binary] + if dictionary_path: + command += (['-x', dictionary_path]) + + # Add the control flow graph file + build_directory = os.environ['OUT'] + cfg_file = os.path.join(build_directory, 'libafl_cfg.bin') + if os.path.exists(cfg_file): + command += (['-c', cfg_file]) + else: + sys.exit(1) + + # get the dfsan binary + dfsan_build_directory = os.path.join(build_directory, 'dfsan') + fuzz_target = os.getenv('FUZZ_TARGET') + dfsan_fuzz_target = os.path.join(dfsan_build_directory, + fuzz_target + '_dfsan') + command += (['-d', dfsan_fuzz_target]) + + # Add the input and output corpus + command += (['-o', output_corpus, '-i', input_corpus]) + fuzzer_env = os.environ.copy() + fuzzer_env['LD_PRELOAD'] = '/usr/lib/x86_64-linux-gnu/libjemalloc.so.2' + print(command) + subprocess.check_call(command, cwd=os.environ['OUT'], env=fuzzer_env) diff --git a/fuzzers/dgfuzz_3f8f81/runner.Dockerfile b/fuzzers/dgfuzz_3f8f81/runner.Dockerfile new file mode 100644 index 0000000..f87abba --- /dev/null +++ b/fuzzers/dgfuzz_3f8f81/runner.Dockerfile @@ -0,0 +1,25 @@ +# Copyright 2020 Google LLC +# +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. + +FROM gcr.io/fuzzbench/base-image + +RUN apt install libjemalloc2 + +# This makes interactive docker runs painless: +ENV LD_LIBRARY_PATH="$LD_LIBRARY_PATH:/out" +ENV AFL_MAP_SIZE=1310720 +ENV PATH="$PATH:/out" +ENV AFL_SKIP_CPUFREQ=1 +ENV AFL_I_DONT_CARE_ABOUT_MISSING_CRASHES=1 +ENV AFL_TESTCACHE_SIZE=2 diff --git a/fuzzers/dgfuzz_4aacb8/builder.Dockerfile b/fuzzers/dgfuzz_4aacb8/builder.Dockerfile new file mode 100644 index 0000000..ed194fc --- /dev/null +++ b/fuzzers/dgfuzz_4aacb8/builder.Dockerfile @@ -0,0 +1,86 @@ +# Copyright 2020 Google LLC +# +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. + +ARG parent_image +FROM $parent_image + +# Uninstall old Rust & Install the latest one. +RUN if which rustup; then rustup self uninstall -y; fi && \ + curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs > /rustup.sh && \ + sh /rustup.sh -y && \ + /root/.cargo/bin/rustup toolchain install nightly && \ + rm /rustup.sh + +RUN apt-get update && \ + apt-get install -y \ + build-essential \ + cargo && \ + apt-get install -y wget libstdc++5 libtool-bin automake flex bison \ + libglib2.0-dev libpixman-1-dev python3-setuptools unzip \ + apt-utils apt-transport-https ca-certificates joe curl && \ + PATH="/root/.cargo/bin/:$PATH" cargo install cargo-make + + +# Download DGFuzz. +RUN git clone https://github.com/DanBlackwell/DGFuzz /dgfuzz + +# Checkout a current commit +RUN cd /dgfuzz && git pull && git checkout 4aacb8c751ac26b686cf08633c31b0d6067b32f2 || true + +# apply a patch (local testing only) +# COPY ./patch /dgfuzz/patch +# RUN cd /dgfuzz && git apply ./patch + +# Compile DGFuzz. +RUN cd /dgfuzz && \ + unset CFLAGS CXXFLAGS && \ + export CC=clang AFL_NO_X86 && \ + cd ./fuzzers/fuzzbench_dataflow_guided && \ + PATH="/root/.cargo/bin/:$PATH" cargo +nightly build --profile release-fuzzbench --features no_link_main + +# Auxiliary weak references. +RUN cd /dgfuzz/fuzzers/fuzzbench_dataflow_guided && \ + clang -c stub_rt.c && \ + ar r /stub_rt.a stub_rt.o + +# install AFL++ dependencies +RUN apt-get update && \ + apt-get install -y \ + build-essential \ + python3-dev \ + python3-setuptools \ + automake \ + cmake \ + git \ + flex \ + bison \ + libglib2.0-dev \ + libpixman-1-dev \ + cargo \ + libgtk-3-dev \ + # for QEMU mode + ninja-build \ + gcc-$(gcc --version|head -n1|sed 's/\..*//'|sed 's/.* //')-plugin-dev \ + libstdc++-$(gcc --version|head -n1|sed 's/\..*//'|sed 's/.* //')-dev + +# compile afl-clang-dgfuzz +RUN cd /dgfuzz/fuzzers/fuzzbench_dataflow_guided/afl-cc && \ + unset CFLAGS CXXFLAGS && \ + export CC=clang AFL_NO_X86=1 && \ + PYTHON_INCLUDE=/ make && \ + cd utils/aflpp_driver/ && \ + PYTHON_INCLUDE=/ make && \ + cp ./libAFLDriver.a / + + diff --git a/fuzzers/dgfuzz_4aacb8/description.md b/fuzzers/dgfuzz_4aacb8/description.md new file mode 100644 index 0000000..452b0e3 --- /dev/null +++ b/fuzzers/dgfuzz_4aacb8/description.md @@ -0,0 +1,8 @@ +# PrescientFuzz + +based on libafl fuzzer instance + - persistent mode + +[builder.Dockerfile](builder.Dockerfile) +[fuzzer.py](fuzzer.py) +[runner.Dockerfile](runner.Dockerfile) diff --git a/fuzzers/dgfuzz_4aacb8/fuzzer.py b/fuzzers/dgfuzz_4aacb8/fuzzer.py new file mode 100755 index 0000000..074224e --- /dev/null +++ b/fuzzers/dgfuzz_4aacb8/fuzzer.py @@ -0,0 +1,140 @@ +# Copyright 2020 Google LLC +# +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. +# +"""Integration code for a LibAFL-based fuzzer.""" + +import os +import sys +import subprocess +from pathlib import Path + +from fuzzers import utils + + +def prepare_fuzz_environment(input_corpus): + """Prepare to fuzz with a LibAFL-based fuzzer.""" + os.environ['ASAN_OPTIONS'] = 'abort_on_error=1:detect_leaks=0:'\ + 'malloc_context_size=0:symbolize=0:'\ + 'allocator_may_return_null=1:'\ + 'detect_odr_violation=0:handle_segv=0:'\ + 'handle_sigbus=0:handle_abort=0:'\ + 'handle_sigfpe=0:handle_sigill=0' + os.environ['UBSAN_OPTIONS'] = 'abort_on_error=1:'\ + 'allocator_release_to_os_interval_ms=500:'\ + 'handle_abort=0:handle_segv=0:'\ + 'handle_sigbus=0:handle_sigfpe=0:'\ + 'handle_sigill=0:print_stacktrace=0:'\ + 'symbolize=0:symbolize_inline_frames=0' + # Create at least one non-empty seed to start. + utils.create_seed_file_for_empty_corpus(input_corpus) + + +def build_dfsan(): + """Build benchmark with dfsan.""" + new_env = os.environ.copy() + new_env['CC'] = ('/dgfuzz/fuzzers/fuzzbench_dataflow_guided/afl-cc/' + 'afl-clang-dgfuzz') + new_env['CXX'] = ('/dgfuzz/fuzzers/fuzzbench_dataflow_guided/afl-cc/' + 'afl-clang-dgfuzz++') + + new_env['ASAN_OPTIONS'] = 'abort_on_error=0:allocator_may_return_null=1' + new_env['UBSAN_OPTIONS'] = 'abort_on_error=0' + new_env['AFL_QUIET'] = '1' + + new_env['FUZZER_LIB'] = '/libAFLDriver.a' + + build_directory = new_env['OUT'] + dfsan_build_directory = os.path.join(build_directory, 'dfsan') + os.mkdir(dfsan_build_directory) + new_env['OUT'] = dfsan_build_directory + + cfg_file = os.path.join(build_directory, 'aflpp_cfg.bin') + new_env['AFL_LLVM_CFG_FILE'] = cfg_file + if os.path.isfile(cfg_file): + os.remove(cfg_file) + Path(cfg_file).touch() + + src = os.getenv('SRC') + work = os.getenv('WORK') + + with utils.restore_directory(src), utils.restore_directory(work): + # Restore SRC to its initial state so we can build again without any + # trouble. For some OSS-Fuzz projects, build_benchmark cannot be run + # twice in the same directory without this. + utils.build_benchmark(env=new_env) + + fuzz_target = os.getenv('FUZZ_TARGET') + exec_path = os.path.join(dfsan_build_directory, fuzz_target) + new_path = os.path.join(dfsan_build_directory, fuzz_target + '_dfsan') + os.rename(exec_path, new_path) + + +def build(): + """Build benchmark.""" + + # first build it with DFSan enabled + build_dfsan() + + os.environ['CC'] = ('/dgfuzz/fuzzers/fuzzbench_dataflow_guided/target/' + 'release-fuzzbench/libafl_cc') + os.environ['CXX'] = ('/dgfuzz/fuzzers/fuzzbench_dataflow_guided/target/' + 'release-fuzzbench/libafl_cxx') + + os.environ['ASAN_OPTIONS'] = 'abort_on_error=0:allocator_may_return_null=1' + os.environ['UBSAN_OPTIONS'] = 'abort_on_error=0' + + cflags = ['--libafl'] + utils.append_flags('CFLAGS', cflags) + utils.append_flags('CXXFLAGS', cflags) + utils.append_flags('LDFLAGS', cflags) + + os.environ['FUZZER_LIB'] = '/stub_rt.a' + build_directory = os.environ['OUT'] + cfg_file = os.path.join(build_directory, 'libafl_cfg.bin') + os.environ['AFL_LLVM_CFG_FILE'] = cfg_file + if os.path.isfile(cfg_file): + os.remove(cfg_file) + Path(cfg_file).touch() + utils.build_benchmark() + + +def fuzz(input_corpus, output_corpus, target_binary): + """Run fuzzer.""" + prepare_fuzz_environment(input_corpus) + dictionary_path = utils.get_dictionary_path(target_binary) + command = [target_binary] + if dictionary_path: + command += (['-x', dictionary_path]) + + # Add the control flow graph file + build_directory = os.environ['OUT'] + cfg_file = os.path.join(build_directory, 'libafl_cfg.bin') + if os.path.exists(cfg_file): + command += (['-c', cfg_file]) + else: + sys.exit(1) + + # get the dfsan binary + dfsan_build_directory = os.path.join(build_directory, 'dfsan') + fuzz_target = os.getenv('FUZZ_TARGET') + dfsan_fuzz_target = os.path.join(dfsan_build_directory, + fuzz_target + '_dfsan') + command += (['-d', dfsan_fuzz_target]) + + # Add the input and output corpus + command += (['-o', output_corpus, '-i', input_corpus]) + fuzzer_env = os.environ.copy() + fuzzer_env['LD_PRELOAD'] = '/usr/lib/x86_64-linux-gnu/libjemalloc.so.2' + print(command) + subprocess.check_call(command, cwd=os.environ['OUT'], env=fuzzer_env) diff --git a/fuzzers/dgfuzz_4aacb8/runner.Dockerfile b/fuzzers/dgfuzz_4aacb8/runner.Dockerfile new file mode 100644 index 0000000..f87abba --- /dev/null +++ b/fuzzers/dgfuzz_4aacb8/runner.Dockerfile @@ -0,0 +1,25 @@ +# Copyright 2020 Google LLC +# +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. + +FROM gcr.io/fuzzbench/base-image + +RUN apt install libjemalloc2 + +# This makes interactive docker runs painless: +ENV LD_LIBRARY_PATH="$LD_LIBRARY_PATH:/out" +ENV AFL_MAP_SIZE=1310720 +ENV PATH="$PATH:/out" +ENV AFL_SKIP_CPUFREQ=1 +ENV AFL_I_DONT_CARE_ABOUT_MISSING_CRASHES=1 +ENV AFL_TESTCACHE_SIZE=2 diff --git a/fuzzers/dgfuzz_ab0800/builder.Dockerfile b/fuzzers/dgfuzz_ab0800/builder.Dockerfile new file mode 100644 index 0000000..ee0c232 --- /dev/null +++ b/fuzzers/dgfuzz_ab0800/builder.Dockerfile @@ -0,0 +1,86 @@ +# Copyright 2020 Google LLC +# +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. + +ARG parent_image +FROM $parent_image + +# Uninstall old Rust & Install the latest one. +RUN if which rustup; then rustup self uninstall -y; fi && \ + curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs > /rustup.sh && \ + sh /rustup.sh -y && \ + /root/.cargo/bin/rustup toolchain install nightly && \ + rm /rustup.sh + +RUN apt-get update && \ + apt-get install -y \ + build-essential \ + cargo && \ + apt-get install -y wget libstdc++5 libtool-bin automake flex bison \ + libglib2.0-dev libpixman-1-dev python3-setuptools unzip \ + apt-utils apt-transport-https ca-certificates joe curl && \ + PATH="/root/.cargo/bin/:$PATH" cargo install cargo-make + + +# Download DGFuzz. +RUN git clone https://github.com/DanBlackwell/DGFuzz /dgfuzz + +# Checkout a current commit +RUN cd /dgfuzz && git pull && git checkout ab08000af3b5a9491f9a143cec6d3f12e3040724 || true + +# apply a patch (local testing only) +# COPY ./patch /dgfuzz/patch +# RUN cd /dgfuzz && git apply ./patch + +# Compile DGFuzz. +RUN cd /dgfuzz && \ + unset CFLAGS CXXFLAGS && \ + export CC=clang AFL_NO_X86 && \ + cd ./fuzzers/fuzzbench_dataflow_guided && \ + PATH="/root/.cargo/bin/:$PATH" cargo +nightly build --profile release-fuzzbench --features no_link_main + +# Auxiliary weak references. +RUN cd /dgfuzz/fuzzers/fuzzbench_dataflow_guided && \ + clang -c stub_rt.c && \ + ar r /stub_rt.a stub_rt.o + +# install AFL++ dependencies +RUN apt-get update && \ + apt-get install -y \ + build-essential \ + python3-dev \ + python3-setuptools \ + automake \ + cmake \ + git \ + flex \ + bison \ + libglib2.0-dev \ + libpixman-1-dev \ + cargo \ + libgtk-3-dev \ + # for QEMU mode + ninja-build \ + gcc-$(gcc --version|head -n1|sed 's/\..*//'|sed 's/.* //')-plugin-dev \ + libstdc++-$(gcc --version|head -n1|sed 's/\..*//'|sed 's/.* //')-dev + +# compile afl-clang-dgfuzz +RUN cd /dgfuzz/fuzzers/fuzzbench_dataflow_guided/afl-cc && \ + unset CFLAGS CXXFLAGS && \ + export CC=clang AFL_NO_X86=1 && \ + PYTHON_INCLUDE=/ make && \ + cd utils/aflpp_driver/ && \ + PYTHON_INCLUDE=/ make && \ + cp ./libAFLDriver.a / + + diff --git a/fuzzers/dgfuzz_ab0800/description.md b/fuzzers/dgfuzz_ab0800/description.md new file mode 100644 index 0000000..452b0e3 --- /dev/null +++ b/fuzzers/dgfuzz_ab0800/description.md @@ -0,0 +1,8 @@ +# PrescientFuzz + +based on libafl fuzzer instance + - persistent mode + +[builder.Dockerfile](builder.Dockerfile) +[fuzzer.py](fuzzer.py) +[runner.Dockerfile](runner.Dockerfile) diff --git a/fuzzers/dgfuzz_ab0800/fuzzer.py b/fuzzers/dgfuzz_ab0800/fuzzer.py new file mode 100755 index 0000000..074224e --- /dev/null +++ b/fuzzers/dgfuzz_ab0800/fuzzer.py @@ -0,0 +1,140 @@ +# Copyright 2020 Google LLC +# +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. +# +"""Integration code for a LibAFL-based fuzzer.""" + +import os +import sys +import subprocess +from pathlib import Path + +from fuzzers import utils + + +def prepare_fuzz_environment(input_corpus): + """Prepare to fuzz with a LibAFL-based fuzzer.""" + os.environ['ASAN_OPTIONS'] = 'abort_on_error=1:detect_leaks=0:'\ + 'malloc_context_size=0:symbolize=0:'\ + 'allocator_may_return_null=1:'\ + 'detect_odr_violation=0:handle_segv=0:'\ + 'handle_sigbus=0:handle_abort=0:'\ + 'handle_sigfpe=0:handle_sigill=0' + os.environ['UBSAN_OPTIONS'] = 'abort_on_error=1:'\ + 'allocator_release_to_os_interval_ms=500:'\ + 'handle_abort=0:handle_segv=0:'\ + 'handle_sigbus=0:handle_sigfpe=0:'\ + 'handle_sigill=0:print_stacktrace=0:'\ + 'symbolize=0:symbolize_inline_frames=0' + # Create at least one non-empty seed to start. + utils.create_seed_file_for_empty_corpus(input_corpus) + + +def build_dfsan(): + """Build benchmark with dfsan.""" + new_env = os.environ.copy() + new_env['CC'] = ('/dgfuzz/fuzzers/fuzzbench_dataflow_guided/afl-cc/' + 'afl-clang-dgfuzz') + new_env['CXX'] = ('/dgfuzz/fuzzers/fuzzbench_dataflow_guided/afl-cc/' + 'afl-clang-dgfuzz++') + + new_env['ASAN_OPTIONS'] = 'abort_on_error=0:allocator_may_return_null=1' + new_env['UBSAN_OPTIONS'] = 'abort_on_error=0' + new_env['AFL_QUIET'] = '1' + + new_env['FUZZER_LIB'] = '/libAFLDriver.a' + + build_directory = new_env['OUT'] + dfsan_build_directory = os.path.join(build_directory, 'dfsan') + os.mkdir(dfsan_build_directory) + new_env['OUT'] = dfsan_build_directory + + cfg_file = os.path.join(build_directory, 'aflpp_cfg.bin') + new_env['AFL_LLVM_CFG_FILE'] = cfg_file + if os.path.isfile(cfg_file): + os.remove(cfg_file) + Path(cfg_file).touch() + + src = os.getenv('SRC') + work = os.getenv('WORK') + + with utils.restore_directory(src), utils.restore_directory(work): + # Restore SRC to its initial state so we can build again without any + # trouble. For some OSS-Fuzz projects, build_benchmark cannot be run + # twice in the same directory without this. + utils.build_benchmark(env=new_env) + + fuzz_target = os.getenv('FUZZ_TARGET') + exec_path = os.path.join(dfsan_build_directory, fuzz_target) + new_path = os.path.join(dfsan_build_directory, fuzz_target + '_dfsan') + os.rename(exec_path, new_path) + + +def build(): + """Build benchmark.""" + + # first build it with DFSan enabled + build_dfsan() + + os.environ['CC'] = ('/dgfuzz/fuzzers/fuzzbench_dataflow_guided/target/' + 'release-fuzzbench/libafl_cc') + os.environ['CXX'] = ('/dgfuzz/fuzzers/fuzzbench_dataflow_guided/target/' + 'release-fuzzbench/libafl_cxx') + + os.environ['ASAN_OPTIONS'] = 'abort_on_error=0:allocator_may_return_null=1' + os.environ['UBSAN_OPTIONS'] = 'abort_on_error=0' + + cflags = ['--libafl'] + utils.append_flags('CFLAGS', cflags) + utils.append_flags('CXXFLAGS', cflags) + utils.append_flags('LDFLAGS', cflags) + + os.environ['FUZZER_LIB'] = '/stub_rt.a' + build_directory = os.environ['OUT'] + cfg_file = os.path.join(build_directory, 'libafl_cfg.bin') + os.environ['AFL_LLVM_CFG_FILE'] = cfg_file + if os.path.isfile(cfg_file): + os.remove(cfg_file) + Path(cfg_file).touch() + utils.build_benchmark() + + +def fuzz(input_corpus, output_corpus, target_binary): + """Run fuzzer.""" + prepare_fuzz_environment(input_corpus) + dictionary_path = utils.get_dictionary_path(target_binary) + command = [target_binary] + if dictionary_path: + command += (['-x', dictionary_path]) + + # Add the control flow graph file + build_directory = os.environ['OUT'] + cfg_file = os.path.join(build_directory, 'libafl_cfg.bin') + if os.path.exists(cfg_file): + command += (['-c', cfg_file]) + else: + sys.exit(1) + + # get the dfsan binary + dfsan_build_directory = os.path.join(build_directory, 'dfsan') + fuzz_target = os.getenv('FUZZ_TARGET') + dfsan_fuzz_target = os.path.join(dfsan_build_directory, + fuzz_target + '_dfsan') + command += (['-d', dfsan_fuzz_target]) + + # Add the input and output corpus + command += (['-o', output_corpus, '-i', input_corpus]) + fuzzer_env = os.environ.copy() + fuzzer_env['LD_PRELOAD'] = '/usr/lib/x86_64-linux-gnu/libjemalloc.so.2' + print(command) + subprocess.check_call(command, cwd=os.environ['OUT'], env=fuzzer_env) diff --git a/fuzzers/dgfuzz_ab0800/runner.Dockerfile b/fuzzers/dgfuzz_ab0800/runner.Dockerfile new file mode 100644 index 0000000..f87abba --- /dev/null +++ b/fuzzers/dgfuzz_ab0800/runner.Dockerfile @@ -0,0 +1,25 @@ +# Copyright 2020 Google LLC +# +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. + +FROM gcr.io/fuzzbench/base-image + +RUN apt install libjemalloc2 + +# This makes interactive docker runs painless: +ENV LD_LIBRARY_PATH="$LD_LIBRARY_PATH:/out" +ENV AFL_MAP_SIZE=1310720 +ENV PATH="$PATH:/out" +ENV AFL_SKIP_CPUFREQ=1 +ENV AFL_I_DONT_CARE_ABOUT_MISSING_CRASHES=1 +ENV AFL_TESTCACHE_SIZE=2 diff --git a/fuzzers/dgfuzz_c286e5/builder.Dockerfile b/fuzzers/dgfuzz_c286e5/builder.Dockerfile new file mode 100644 index 0000000..cfa19ba --- /dev/null +++ b/fuzzers/dgfuzz_c286e5/builder.Dockerfile @@ -0,0 +1,86 @@ +# Copyright 2020 Google LLC +# +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. + +ARG parent_image +FROM $parent_image + +# Uninstall old Rust & Install the latest one. +RUN if which rustup; then rustup self uninstall -y; fi && \ + curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs > /rustup.sh && \ + sh /rustup.sh -y && \ + /root/.cargo/bin/rustup toolchain install nightly && \ + rm /rustup.sh + +RUN apt-get update && \ + apt-get install -y \ + build-essential \ + cargo && \ + apt-get install -y wget libstdc++5 libtool-bin automake flex bison \ + libglib2.0-dev libpixman-1-dev python3-setuptools unzip \ + apt-utils apt-transport-https ca-certificates joe curl && \ + PATH="/root/.cargo/bin/:$PATH" cargo install cargo-make + + +# Download DGFuzz. +RUN git clone https://github.com/DanBlackwell/DGFuzz /dgfuzz + +# Checkout a current commit +RUN cd /dgfuzz && git pull && git checkout c286e569e9e28de0fb2d90e8585665b6c27b565c || true + +# apply a patch (local testing only) +# COPY ./patch /dgfuzz/patch +# RUN cd /dgfuzz && git apply ./patch + +# Compile DGFuzz. +RUN cd /dgfuzz && \ + unset CFLAGS CXXFLAGS && \ + export CC=clang AFL_NO_X86 && \ + cd ./fuzzers/fuzzbench_dataflow_guided && \ + PATH="/root/.cargo/bin/:$PATH" cargo +nightly build --profile release-fuzzbench --features no_link_main + +# Auxiliary weak references. +RUN cd /dgfuzz/fuzzers/fuzzbench_dataflow_guided && \ + clang -c stub_rt.c && \ + ar r /stub_rt.a stub_rt.o + +# install AFL++ dependencies +RUN apt-get update && \ + apt-get install -y \ + build-essential \ + python3-dev \ + python3-setuptools \ + automake \ + cmake \ + git \ + flex \ + bison \ + libglib2.0-dev \ + libpixman-1-dev \ + cargo \ + libgtk-3-dev \ + # for QEMU mode + ninja-build \ + gcc-$(gcc --version|head -n1|sed 's/\..*//'|sed 's/.* //')-plugin-dev \ + libstdc++-$(gcc --version|head -n1|sed 's/\..*//'|sed 's/.* //')-dev + +# compile afl-clang-dgfuzz +RUN cd /dgfuzz/fuzzers/fuzzbench_dataflow_guided/afl-cc && \ + unset CFLAGS CXXFLAGS && \ + export CC=clang AFL_NO_X86=1 && \ + PYTHON_INCLUDE=/ make && \ + cd utils/aflpp_driver/ && \ + PYTHON_INCLUDE=/ make && \ + cp ./libAFLDriver.a / + + diff --git a/fuzzers/dgfuzz_c286e5/description.md b/fuzzers/dgfuzz_c286e5/description.md new file mode 100644 index 0000000..452b0e3 --- /dev/null +++ b/fuzzers/dgfuzz_c286e5/description.md @@ -0,0 +1,8 @@ +# PrescientFuzz + +based on libafl fuzzer instance + - persistent mode + +[builder.Dockerfile](builder.Dockerfile) +[fuzzer.py](fuzzer.py) +[runner.Dockerfile](runner.Dockerfile) diff --git a/fuzzers/dgfuzz_c286e5/fuzzer.py b/fuzzers/dgfuzz_c286e5/fuzzer.py new file mode 100755 index 0000000..074224e --- /dev/null +++ b/fuzzers/dgfuzz_c286e5/fuzzer.py @@ -0,0 +1,140 @@ +# Copyright 2020 Google LLC +# +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. +# +"""Integration code for a LibAFL-based fuzzer.""" + +import os +import sys +import subprocess +from pathlib import Path + +from fuzzers import utils + + +def prepare_fuzz_environment(input_corpus): + """Prepare to fuzz with a LibAFL-based fuzzer.""" + os.environ['ASAN_OPTIONS'] = 'abort_on_error=1:detect_leaks=0:'\ + 'malloc_context_size=0:symbolize=0:'\ + 'allocator_may_return_null=1:'\ + 'detect_odr_violation=0:handle_segv=0:'\ + 'handle_sigbus=0:handle_abort=0:'\ + 'handle_sigfpe=0:handle_sigill=0' + os.environ['UBSAN_OPTIONS'] = 'abort_on_error=1:'\ + 'allocator_release_to_os_interval_ms=500:'\ + 'handle_abort=0:handle_segv=0:'\ + 'handle_sigbus=0:handle_sigfpe=0:'\ + 'handle_sigill=0:print_stacktrace=0:'\ + 'symbolize=0:symbolize_inline_frames=0' + # Create at least one non-empty seed to start. + utils.create_seed_file_for_empty_corpus(input_corpus) + + +def build_dfsan(): + """Build benchmark with dfsan.""" + new_env = os.environ.copy() + new_env['CC'] = ('/dgfuzz/fuzzers/fuzzbench_dataflow_guided/afl-cc/' + 'afl-clang-dgfuzz') + new_env['CXX'] = ('/dgfuzz/fuzzers/fuzzbench_dataflow_guided/afl-cc/' + 'afl-clang-dgfuzz++') + + new_env['ASAN_OPTIONS'] = 'abort_on_error=0:allocator_may_return_null=1' + new_env['UBSAN_OPTIONS'] = 'abort_on_error=0' + new_env['AFL_QUIET'] = '1' + + new_env['FUZZER_LIB'] = '/libAFLDriver.a' + + build_directory = new_env['OUT'] + dfsan_build_directory = os.path.join(build_directory, 'dfsan') + os.mkdir(dfsan_build_directory) + new_env['OUT'] = dfsan_build_directory + + cfg_file = os.path.join(build_directory, 'aflpp_cfg.bin') + new_env['AFL_LLVM_CFG_FILE'] = cfg_file + if os.path.isfile(cfg_file): + os.remove(cfg_file) + Path(cfg_file).touch() + + src = os.getenv('SRC') + work = os.getenv('WORK') + + with utils.restore_directory(src), utils.restore_directory(work): + # Restore SRC to its initial state so we can build again without any + # trouble. For some OSS-Fuzz projects, build_benchmark cannot be run + # twice in the same directory without this. + utils.build_benchmark(env=new_env) + + fuzz_target = os.getenv('FUZZ_TARGET') + exec_path = os.path.join(dfsan_build_directory, fuzz_target) + new_path = os.path.join(dfsan_build_directory, fuzz_target + '_dfsan') + os.rename(exec_path, new_path) + + +def build(): + """Build benchmark.""" + + # first build it with DFSan enabled + build_dfsan() + + os.environ['CC'] = ('/dgfuzz/fuzzers/fuzzbench_dataflow_guided/target/' + 'release-fuzzbench/libafl_cc') + os.environ['CXX'] = ('/dgfuzz/fuzzers/fuzzbench_dataflow_guided/target/' + 'release-fuzzbench/libafl_cxx') + + os.environ['ASAN_OPTIONS'] = 'abort_on_error=0:allocator_may_return_null=1' + os.environ['UBSAN_OPTIONS'] = 'abort_on_error=0' + + cflags = ['--libafl'] + utils.append_flags('CFLAGS', cflags) + utils.append_flags('CXXFLAGS', cflags) + utils.append_flags('LDFLAGS', cflags) + + os.environ['FUZZER_LIB'] = '/stub_rt.a' + build_directory = os.environ['OUT'] + cfg_file = os.path.join(build_directory, 'libafl_cfg.bin') + os.environ['AFL_LLVM_CFG_FILE'] = cfg_file + if os.path.isfile(cfg_file): + os.remove(cfg_file) + Path(cfg_file).touch() + utils.build_benchmark() + + +def fuzz(input_corpus, output_corpus, target_binary): + """Run fuzzer.""" + prepare_fuzz_environment(input_corpus) + dictionary_path = utils.get_dictionary_path(target_binary) + command = [target_binary] + if dictionary_path: + command += (['-x', dictionary_path]) + + # Add the control flow graph file + build_directory = os.environ['OUT'] + cfg_file = os.path.join(build_directory, 'libafl_cfg.bin') + if os.path.exists(cfg_file): + command += (['-c', cfg_file]) + else: + sys.exit(1) + + # get the dfsan binary + dfsan_build_directory = os.path.join(build_directory, 'dfsan') + fuzz_target = os.getenv('FUZZ_TARGET') + dfsan_fuzz_target = os.path.join(dfsan_build_directory, + fuzz_target + '_dfsan') + command += (['-d', dfsan_fuzz_target]) + + # Add the input and output corpus + command += (['-o', output_corpus, '-i', input_corpus]) + fuzzer_env = os.environ.copy() + fuzzer_env['LD_PRELOAD'] = '/usr/lib/x86_64-linux-gnu/libjemalloc.so.2' + print(command) + subprocess.check_call(command, cwd=os.environ['OUT'], env=fuzzer_env) diff --git a/fuzzers/dgfuzz_c286e5/runner.Dockerfile b/fuzzers/dgfuzz_c286e5/runner.Dockerfile new file mode 100644 index 0000000..f87abba --- /dev/null +++ b/fuzzers/dgfuzz_c286e5/runner.Dockerfile @@ -0,0 +1,25 @@ +# Copyright 2020 Google LLC +# +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. + +FROM gcr.io/fuzzbench/base-image + +RUN apt install libjemalloc2 + +# This makes interactive docker runs painless: +ENV LD_LIBRARY_PATH="$LD_LIBRARY_PATH:/out" +ENV AFL_MAP_SIZE=1310720 +ENV PATH="$PATH:/out" +ENV AFL_SKIP_CPUFREQ=1 +ENV AFL_I_DONT_CARE_ABOUT_MISSING_CRASHES=1 +ENV AFL_TESTCACHE_SIZE=2 diff --git a/fuzzers/dgfuzz_control/builder.Dockerfile b/fuzzers/dgfuzz_control/builder.Dockerfile new file mode 100644 index 0000000..2ab506c --- /dev/null +++ b/fuzzers/dgfuzz_control/builder.Dockerfile @@ -0,0 +1,86 @@ +# Copyright 2020 Google LLC +# +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. + +ARG parent_image +FROM $parent_image + +# Uninstall old Rust & Install the latest one. +RUN if which rustup; then rustup self uninstall -y; fi && \ + curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs > /rustup.sh && \ + sh /rustup.sh -y && \ + /root/.cargo/bin/rustup toolchain install nightly && \ + rm /rustup.sh + +RUN apt-get update && \ + apt-get install -y \ + build-essential \ + cargo && \ + apt-get install -y wget libstdc++5 libtool-bin automake flex bison \ + libglib2.0-dev libpixman-1-dev python3-setuptools unzip \ + apt-utils apt-transport-https ca-certificates joe curl && \ + PATH="/root/.cargo/bin/:$PATH" cargo install cargo-make + + +# Download DGFuzz. +RUN git clone https://github.com/DanBlackwell/DGFuzz /dgfuzz + +# Checkout a current commit +RUN cd /dgfuzz && git pull && git checkout ee618fde3b3ff779481198892998dc3d6fb834a4 || true + +# apply a patch (local testing only) +# COPY ./patch /dgfuzz/patch +# RUN cd /dgfuzz && git apply ./patch + +# Compile DGFuzz. +RUN cd /dgfuzz && \ + unset CFLAGS CXXFLAGS && \ + export CC=clang AFL_NO_X86 && \ + cd ./fuzzers/fuzzbench_dataflow_guided && \ + PATH="/root/.cargo/bin/:$PATH" cargo +nightly build --profile release-fuzzbench --features no_link_main + +# Auxiliary weak references. +RUN cd /dgfuzz/fuzzers/fuzzbench_dataflow_guided && \ + clang -c stub_rt.c && \ + ar r /stub_rt.a stub_rt.o + +# install AFL++ dependencies +RUN apt-get update && \ + apt-get install -y \ + build-essential \ + python3-dev \ + python3-setuptools \ + automake \ + cmake \ + git \ + flex \ + bison \ + libglib2.0-dev \ + libpixman-1-dev \ + cargo \ + libgtk-3-dev \ + # for QEMU mode + ninja-build \ + gcc-$(gcc --version|head -n1|sed 's/\..*//'|sed 's/.* //')-plugin-dev \ + libstdc++-$(gcc --version|head -n1|sed 's/\..*//'|sed 's/.* //')-dev + +# compile afl-clang-dgfuzz +RUN cd /dgfuzz/fuzzers/fuzzbench_dataflow_guided/afl-cc && \ + unset CFLAGS CXXFLAGS && \ + export CC=clang AFL_NO_X86=1 && \ + PYTHON_INCLUDE=/ make && \ + cd utils/aflpp_driver/ && \ + PYTHON_INCLUDE=/ make && \ + cp ./libAFLDriver.a / + + diff --git a/fuzzers/dgfuzz_control/description.md b/fuzzers/dgfuzz_control/description.md new file mode 100644 index 0000000..452b0e3 --- /dev/null +++ b/fuzzers/dgfuzz_control/description.md @@ -0,0 +1,8 @@ +# PrescientFuzz + +based on libafl fuzzer instance + - persistent mode + +[builder.Dockerfile](builder.Dockerfile) +[fuzzer.py](fuzzer.py) +[runner.Dockerfile](runner.Dockerfile) diff --git a/fuzzers/dgfuzz_control/fuzzer.py b/fuzzers/dgfuzz_control/fuzzer.py new file mode 100755 index 0000000..e13ad64 --- /dev/null +++ b/fuzzers/dgfuzz_control/fuzzer.py @@ -0,0 +1,90 @@ +# Copyright 2020 Google LLC +# +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. +# +"""Integration code for a LibAFL-based fuzzer.""" + +import os +import sys +import subprocess +from pathlib import Path + +from fuzzers import utils + + +def prepare_fuzz_environment(input_corpus): + """Prepare to fuzz with a LibAFL-based fuzzer.""" + os.environ['ASAN_OPTIONS'] = 'abort_on_error=1:detect_leaks=0:'\ + 'malloc_context_size=0:symbolize=0:'\ + 'allocator_may_return_null=1:'\ + 'detect_odr_violation=0:handle_segv=0:'\ + 'handle_sigbus=0:handle_abort=0:'\ + 'handle_sigfpe=0:handle_sigill=0' + os.environ['UBSAN_OPTIONS'] = 'abort_on_error=1:'\ + 'allocator_release_to_os_interval_ms=500:'\ + 'handle_abort=0:handle_segv=0:'\ + 'handle_sigbus=0:handle_sigfpe=0:'\ + 'handle_sigill=0:print_stacktrace=0:'\ + 'symbolize=0:symbolize_inline_frames=0' + # Create at least one non-empty seed to start. + utils.create_seed_file_for_empty_corpus(input_corpus) + + +def build(): + """Build benchmark.""" + + os.environ['CC'] = ('/dgfuzz/fuzzers/fuzzbench_dataflow_guided/target/' + 'release-fuzzbench/libafl_cc') + os.environ['CXX'] = ('/dgfuzz/fuzzers/fuzzbench_dataflow_guided/target/' + 'release-fuzzbench/libafl_cxx') + + os.environ['ASAN_OPTIONS'] = 'abort_on_error=0:allocator_may_return_null=1' + os.environ['UBSAN_OPTIONS'] = 'abort_on_error=0' + + cflags = ['--libafl'] + utils.append_flags('CFLAGS', cflags) + utils.append_flags('CXXFLAGS', cflags) + utils.append_flags('LDFLAGS', cflags) + + os.environ['FUZZER_LIB'] = '/stub_rt.a' + build_directory = os.environ['OUT'] + cfg_file = os.path.join(build_directory, 'libafl_cfg.bin') + os.environ['AFL_LLVM_CFG_FILE'] = cfg_file + if os.path.isfile(cfg_file): + os.remove(cfg_file) + Path(cfg_file).touch() + utils.build_benchmark() + + +def fuzz(input_corpus, output_corpus, target_binary): + """Run fuzzer.""" + prepare_fuzz_environment(input_corpus) + dictionary_path = utils.get_dictionary_path(target_binary) + command = [target_binary] + if dictionary_path: + command += (['-x', dictionary_path]) + + # Add the control flow graph file + build_directory = os.environ['OUT'] + cfg_file = os.path.join(build_directory, 'libafl_cfg.bin') + if os.path.exists(cfg_file): + command += (['-c', cfg_file]) + else: + sys.exit(1) + + # Add the input and output corpus + command += (['-o', output_corpus, '-i', input_corpus]) + fuzzer_env = os.environ.copy() + fuzzer_env['LD_PRELOAD'] = '/usr/lib/x86_64-linux-gnu/libjemalloc.so.2' + print(command) + subprocess.check_call(command, cwd=os.environ['OUT'], env=fuzzer_env) diff --git a/fuzzers/dgfuzz_control/runner.Dockerfile b/fuzzers/dgfuzz_control/runner.Dockerfile new file mode 100644 index 0000000..f87abba --- /dev/null +++ b/fuzzers/dgfuzz_control/runner.Dockerfile @@ -0,0 +1,25 @@ +# Copyright 2020 Google LLC +# +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. + +FROM gcr.io/fuzzbench/base-image + +RUN apt install libjemalloc2 + +# This makes interactive docker runs painless: +ENV LD_LIBRARY_PATH="$LD_LIBRARY_PATH:/out" +ENV AFL_MAP_SIZE=1310720 +ENV PATH="$PATH:/out" +ENV AFL_SKIP_CPUFREQ=1 +ENV AFL_I_DONT_CARE_ABOUT_MISSING_CRASHES=1 +ENV AFL_TESTCACHE_SIZE=2