Skip to content
Permalink
Tree: 55e0c07757
Commits on Jul 22, 2019
  1. sys/linux: extract USB HID ids (#1294)

    xairy committed Jul 22, 2019
    * sys/linux: extract USB HID ids
    
    As it turns out the HID kernel subsystem registers only one USB driver that
    checks that the interface of the connected device has HID class and then looks
    up its own list of vendor/device ids to find a matching driver. This means
    that we currently don't generate proper vendor/device ids for USB HID devices.
    
    This patch updates the syz-usbgen tool to also extract USB HID vendor/device
    ids from a running kernel and makes the generated descriptions for HID devices
    to be patched using the extracted ids.
    
    This patch also contains some minor improvements to USB descriptions
    (better HID descriptions and more replies for some USB classes/drivers).
    
    * sys/linux: run make generate
  2. sys/linux: use AT_FDCWD only for directories

    dvyukov committed Jul 22, 2019
    Currently we use AT_FDCWD as a special value for all file descriptors,
    but it does not make sense for almost all of them (sockets, bpf, etc).
    Use it as a special value only for fd_dir.
  3. executor: drop CAP_SYS_NICE

    dvyukov committed Jul 22, 2019
    A process with CAP_SYS_NICE can bring kernel down by asking for too high SCHED_DEADLINE priority,
    as the result rcu and other system services that use kernel threads will stop functioning.
    Some parameters for SCHED_DEADLINE should be OK, but we don't have means to enforce
    values of indirect syscall arguments. Peter Zijlstra proposed sysctl_deadline_period_{min,max}
    which could be used to enfore safe limits without droppping CAP_SYS_NICE, but we don't have it yet.
    See the following bug for details:
    https://groups.google.com/forum/#!topic/syzkaller-bugs/G6Wl_PKPIWI
  4. sys/linux: improve sched_attr description

    dvyukov committed Jul 22, 2019
    Today we have means to properly describe parent size.
  5. executor: drop CAP_SYS_PTRACE with sandbox=none

    dvyukov committed Jul 22, 2019
    We only drop CAP_SYS_PTRACE for sandbox=namespace,
    but it can equally affect testing with sandbox=none.
    Drop it for sandbox=none, add a test.
  6. pkg/csource: test sys/*/test programs

    dvyukov committed Jul 22, 2019
    Running sys/*/test programs requires real machines and kernels for each OS.
    We can't do that in unit tests, but at least try to deserialize these programs
    so that they don't get rotten.
  7. pkg/mgrconfig: add example for "enable_syscalls"

    dvyukov committed Jul 22, 2019
  8. docs: fix description of ptr type

    dvyukov committed Jul 22, 2019
    ptr has direction as the first argument.
  9. pkg/report: support older format of "bad usercopy"

    dvyukov committed Jul 22, 2019
  10. tools/syz-execprog: remove unused parameter

    blackgnezdo authored and dvyukov committed Jul 21, 2019
  11. sys/openbsd: prevent swap partition device nodes from being created

    mptre authored and dvyukov committed Jul 21, 2019
    Writing to the swap partition during fuzzing can lead to all kinds of
    corruptions[1].
    
    [1] https://syzkaller.appspot.com/bug?id=a2eca15e6e0be4be3ed1b0b2bab3332edc317b1c
Commits on Jul 19, 2019
  1. fuzz.yaml: rename to fuzzbuzz.yaml

    dvyukov committed Jul 19, 2019
    Newsletter says we need to change the name.
  2. Update found_bugs.md

    evdenis authored and dvyukov committed Jul 18, 2019
  3. tools/syz-env: restrict Makefile parallelism based on RAM

    dvyukov committed Jul 19, 2019
    Ensure that we have at least 1GB per Makefile job.
    Go compiler/linker can consume significant amount of memory
    (observed to consume at least 600MB). See #1276 for context.
    Update #1276
Commits on Jul 18, 2019
  1. syz-manager: fix argument order in generateCoverHTML

    dvyukov committed Jul 18, 2019
  2. pkg/cover: fix objdump process hang

    dvyukov committed Jul 18, 2019
    One instance we observed that objdump hanged due to stdout
    pipe overflow due to panic in archCallInsn.
    The reason for the original panic is still unclear,
    but fix the objdump hang. We need to terminate objdump
    and propagate the panic.
    Also extend the panic messages.
  3. tools/syz-cover: skip empty lines in coverage file

    dvyukov committed Jul 18, 2019
    If it's constructed manually, it's easy to add an empty line at the end.
Commits on Jul 17, 2019
  1. pkg/cover: fix prefix computation

    R3x authored and dvyukov committed Jul 17, 2019
    * pkg/cover: Modify parsing logic
    1. Remove prefix computation
    2. Add a mgrconfig for kernel build directory
    
    * pkg/report: shorten reports with kernelBuildSrc instead of kernelSrc
    
    * pkg/report: Fix failing tests
    
    * pkg/report: fix formating issues
    
    * tools/syz-cover: Fix unintended redefinition
    
    * make changes to fix failing ci build
    
    * pkg/report: fix issues
  2. sys/fuchsia: update zx_clock_get syscall (#1292)

    mvanotti committed Jul 17, 2019
    * sys/fuchsia: update zx_clock_get.
    
    zx_clock_get was deprecated and replaced by zx_clock_get_new. In a
    recent CL[0], they replaced the zx_clock_get by zx_clock_get_new and
    moved all client. This commit updates syzkaller to use the new function.
    
    [0]: https://fuchsia-review.googlesource.com/c/fuchsia/+/298575
    
    * run make extract && make generate
Commits on Jul 16, 2019
  1. pkg/report: support new format of "held lock freed" linux bugs

    dvyukov committed Jul 16, 2019
  2. sys/syz-extract: fix too long line

    dvyukov committed Jul 16, 2019
  3. sys/fuchsia: remove RESIZEABLE flags from vmo ops.

    mvanotti authored and dvyukov committed Jul 9, 2019
    This change removes the ZX_VMO_NON_RESIZABLE flag for vmo create and the
    ZX_VMO_CHILD_NON_RESIZEABLE flag from vmo create child.
    
    The flags were removed upstream in cl:
    https://fuchsia-review.googlesource.com/c/fuchsia/+/293991
  4. sys/syz-extract: Add "DefineGlibcUse" flag.

    mvanotti authored and dvyukov committed Jul 9, 2019
    Instead of defining the __GLIBC_USE macro on every OS, we are just
    defining it based on a parameter. That parameter is set to false for all
    OSs except for fuchsia.
  5. sys/fuchsia: rename vmo_clone to vmo_create_child.

    mvanotti authored and dvyukov committed Jun 13, 2019
    This commit modifies the vmo_clone definition, renaming it to
    vmo_create_child. This change happened in fuchsia a few weeks ago[0].
    
    [0]: https://fuchsia-review.googlesource.com/c/fuchsia/+/272268/
  6. sys/syz-extract: define __GLIBC_USE if not defined.

    mvanotti authored and dvyukov committed Jun 13, 2019
    When I try to run `make extract` for fuchsia, the clang compiler
    complains that __GLIBC_USE is undefined.
    
    This CL just defines it to be an always false function-like macro if it
    was not defined.
  7. sys/fuchsia: update paths for fdio and driver libs.

    mvanotti authored and dvyukov committed Jun 13, 2019
    This commit updates the targets for fuchsia, modifying the clang flags
    so that it uses the correct path to link against libfdio and libdriver.
  8. sys/fuchsia: remove power fidl definitions.

    mvanotti authored and dvyukov committed Jun 13, 2019
    This commit removes the fuchsia-power fidl definitions. The interface
    doesn't have a service implementing it in fuchsia, and it is causing
    issues in make extract.
  9. prog: fix updating triedPaths when minimizing resources

    xairy authored and dvyukov committed Jul 9, 2019
  10. dashboard: fix usb config extraction script

    xairy authored and dvyukov committed Jul 16, 2019
    Fix extracting more configs that are actually enabled.
    Regenerate upsteam-usb.config and sys/linux/init_vusb_ids.go.
  11. dashboard/app: add ConstFilter helper

    dvyukov committed Jul 16, 2019
    Handy to use in configs if lots of filter just need to return a const.
  12. sys/linux, executor: improve USB descriptions

    xairy committed Jul 16, 2019
    1. Change HID descriptions to allow devices to have two interrupt endpoints.
    2. Remove unneeded responses to OUT control requests from descriptions.
    3. Add some debugging code to detect and report missing descriptions.
  13. dashboard/app: add an empty test file

    dvyukov committed Jul 16, 2019
    blaze+tricoder fail when all test files are excluded by tags.
    Work around the bug by adding an empty test file.
  14. sys/linux: update fs-verity descriptions

    ebiggers authored and dvyukov committed Jul 9, 2019
    The fs-verity API was redesigned, and we're planning to re-add the
    fs-verity patches to linux-next soon.  Get the syzkaller descriptions up
    to date with the new API [1]
    
    [1] https://lkml.kernel.org/linux-fsdevel/20190701153237.1777-4-ebiggers@kernel.org
  15. sys/linux: update BPF constants

    pchaigno authored and dvyukov committed Jul 12, 2019
    Signed-off-by: Paul Chaignon <paul.chaignon@orange.com>
Older
You can’t perform that action at this time.