268 lines
13 KiB
Plaintext
268 lines
13 KiB
Plaintext
import csv
|
|
import os
|
|
def_flags="--release --no-default-features --features std,snapshot_fast,restarting,do_hash_notify_state,fuzz_int,trace_job_response_times"
|
|
remote="remote/"
|
|
RUNTIME=86400
|
|
NUM_ITERS=12
|
|
|
|
rule build_default:
|
|
input:
|
|
"../Cargo.toml",
|
|
"../src"
|
|
output:
|
|
directory("bins/target_default")
|
|
shell:
|
|
"cargo build --target-dir {output} {def_flags}"
|
|
|
|
rule build_showmap:
|
|
input:
|
|
"bins/target_default"
|
|
output:
|
|
directory("bins/target_showmap")
|
|
shell:
|
|
"cp -r -a --reflink=auto {input} {output} && cargo build --target-dir {output} {def_flags},config_stg"
|
|
|
|
rule build_random:
|
|
input:
|
|
"bins/target_default"
|
|
output:
|
|
directory("bins/target_random")
|
|
shell:
|
|
"cp -r -a --reflink=auto {input} {output} && cargo build --target-dir {output} {def_flags},feed_longest"
|
|
|
|
rule build_frafl:
|
|
input:
|
|
"bins/target_default"
|
|
output:
|
|
directory("bins/target_frafl")
|
|
shell:
|
|
"cp -r -a --reflink=auto {input} {output} && cargo build --target-dir {output} {def_flags},config_frafl,feed_longest"
|
|
|
|
rule build_afl:
|
|
input:
|
|
"bins/target_default"
|
|
output:
|
|
directory("bins/target_afl")
|
|
shell:
|
|
"cp -r -a --reflink=auto {input} {output} && cargo build --target-dir {output} {def_flags},config_afl"
|
|
|
|
rule build_stg:
|
|
input:
|
|
"bins/target_default"
|
|
output:
|
|
directory("bins/target_stg")
|
|
shell:
|
|
"cp -r -a --reflink=auto {input} {output} && cargo build --target-dir {output} {def_flags},config_stg"
|
|
|
|
rule build_stg_abbpath:
|
|
input:
|
|
"bins/target_default"
|
|
output:
|
|
directory("bins/target_stg_abbpath")
|
|
shell:
|
|
"cp -r -a --reflink=auto {input} {output} && cargo build --target-dir {output} {def_flags},config_stg_abbpath"
|
|
|
|
rule build_stg_edge:
|
|
input:
|
|
"bins/target_default"
|
|
output:
|
|
directory("bins/target_stg_edge")
|
|
shell:
|
|
"cp -r -a --reflink=auto {input} {output} && cargo build --target-dir {output} {def_flags},config_stg_edge"
|
|
|
|
rule build_feedgeneration1:
|
|
input:
|
|
"bins/target_default"
|
|
output:
|
|
directory("bins/target_feedgeneration1")
|
|
shell:
|
|
"cp -r -a --reflink=auto {input} {output} && cargo build --target-dir {output} {def_flags},feed_genetic,gensize_1"
|
|
|
|
rule build_feedgeneration10:
|
|
input:
|
|
"bins/target_default"
|
|
output:
|
|
directory("bins/target_feedgeneration10")
|
|
shell:
|
|
"cp -r -a --reflink=auto {input} {output} && cargo build --target-dir {output} {def_flags},feed_genetic,gensize_10"
|
|
|
|
rule build_feedgeneration100:
|
|
input:
|
|
"bins/target_default"
|
|
output:
|
|
directory("bins/target_feedgeneration100")
|
|
shell:
|
|
"cp -r -a --reflink=auto {input} {output} && cargo build --target-dir {output} {def_flags},config_genetic,gensize_100"
|
|
|
|
rule build_genetic100:
|
|
input:
|
|
"bins/target_default"
|
|
output:
|
|
directory("bins/target_genetic100")
|
|
shell:
|
|
"cp -r -a --reflink=auto {input} {output} && cargo build --target-dir {output} {def_flags},config_genetic,mutate_stg,gensize_100"
|
|
|
|
rule build_feedgeneration1000:
|
|
input:
|
|
"bins/target_default"
|
|
output:
|
|
directory("bins/target_feedgeneration1000")
|
|
shell:
|
|
"cp -r -a --reflink=auto {input} {output} && cargo build --target-dir {output} {def_flags},config_genetic,gensize_1000"
|
|
|
|
rule build_genetic1000:
|
|
input:
|
|
"bins/target_default"
|
|
output:
|
|
directory("bins/target_genetic1000")
|
|
shell:
|
|
"cp -r -a --reflink=auto {input} {output} && cargo build --target-dir {output} {def_flags},config_genetic,mutate_stg,gensize_1000"
|
|
|
|
rule run_bench:
|
|
input:
|
|
"build/{target}.elf",
|
|
"bins/target_{fuzzer}"
|
|
output:
|
|
multiext("timedump/{fuzzer}/{target}#{num}", ".time", ".log") # , ".case"
|
|
run:
|
|
with open('target_symbols.csv') as csvfile:
|
|
reader = csv.DictReader(csvfile)
|
|
line = next((x for x in reader if x['\ufeffkernel']==wildcards.target), None)
|
|
if line == None:
|
|
return False
|
|
kernel=line['\ufeffkernel']
|
|
fuzz_main=line['main_function']
|
|
fuzz_input=line['input_symbol']
|
|
fuzz_len=line['input_size']
|
|
bkp=line['return_function']
|
|
select_task=line['select_task']
|
|
if wildcards.fuzzer.find('random') >= 0:
|
|
script="""
|
|
export RUST_BACKTRACE=1
|
|
mkdir -p $(dirname {output[0]})
|
|
set +e
|
|
echo $(pwd)/{input[1]}/release/fret -n $(pwd)/timedump/{wildcards.fuzzer}/{wildcards.target}#{wildcards.num} -s {select_task} -t -a -g -k {input[0]} -c ./target_symbols.csv fuzz --random -t {RUNTIME} -s {wildcards.num}
|
|
$(pwd)/{input[1]}/release/fret -n $(pwd)/timedump/{wildcards.fuzzer}/{wildcards.target}#{wildcards.num} -s {select_task} -t -a -g -k {input[0]} -c ./target_symbols.csv fuzz --random -t {RUNTIME} -s {wildcards.num} > {output[1]} 2>&1
|
|
exit 0
|
|
"""
|
|
else:
|
|
script="""
|
|
export RUST_BACKTRACE=1
|
|
mkdir -p $(dirname {output[0]})
|
|
set +e
|
|
echo $(pwd)/{input[1]}/release/fret -n $(pwd)/timedump/{wildcards.fuzzer}/{wildcards.target}#{wildcards.num} -s {select_task} -t -a -g -k {input[0]} -c ./target_symbols.csv fuzz -t {RUNTIME} -s {wildcards.num}
|
|
$(pwd)/{input[1]}/release/fret -n $(pwd)/timedump/{wildcards.fuzzer}/{wildcards.target}#{wildcards.num} -s {select_task} -t -a -g -k {input[0]} -c ./target_symbols.csv fuzz -t {RUNTIME} -s {wildcards.num} > {output[1]} 2>&1
|
|
exit 0
|
|
"""
|
|
shell(script)
|
|
|
|
rule run_showmap:
|
|
input:
|
|
"{remote}build/{target}.elf",
|
|
"bins/target_showmap",
|
|
"{remote}timedump/{fuzzer}/{target}#{num}.case"
|
|
output:
|
|
"{remote}timedump/{fuzzer}/{target}#{num}_case.trace.ron",
|
|
"{remote}timedump/{fuzzer}/{target}#{num}_case.time",
|
|
run:
|
|
with open('target_symbols.csv') as csvfile:
|
|
reader = csv.DictReader(csvfile)
|
|
line = next((x for x in reader if x['\ufeffkernel']==wildcards.target), None)
|
|
if line == None:
|
|
return False
|
|
kernel=line['\ufeffkernel']
|
|
fuzz_main=line['main_function']
|
|
fuzz_input=line['input_symbol']
|
|
fuzz_len=line['input_size']
|
|
bkp=line['return_function']
|
|
select_task=line['select_task']
|
|
script="""
|
|
export FUZZER=$(pwd)/{input[1]}/release/fret
|
|
mkdir -p $(dirname {output})
|
|
set +e
|
|
echo $FUZZER -n $(pwd)/{remote}/timedump/{wildcards.fuzzer}/{wildcards.target}#{wildcards.num}_case -s {select_task} -t -a -r -g -k {input[0]} -c ./target_symbols.csv showmap -i {input[2]}
|
|
$FUZZER -n $(pwd)/{remote}/timedump/{wildcards.fuzzer}/{wildcards.target}#{wildcards.num}_case -s {select_task} -t -a -r -g -k {input[0]} -c ./target_symbols.csv showmap -i {input[2]}
|
|
exit 0
|
|
"""
|
|
if wildcards.fuzzer.find('random') >= 0:
|
|
script="export FUZZ_RANDOM=1\n"+script
|
|
shell(script)
|
|
|
|
rule tarnsform_trace:
|
|
input:
|
|
"{remote}timedump/{fuzzer}/{target}#{num}_case.trace.ron",
|
|
output:
|
|
"{remote}timedump/{fuzzer}/{target}#{num}_case.jobs.csv",
|
|
"{remote}timedump/{fuzzer}/{target}#{num}_case.resp.csv",
|
|
"{remote}timedump/{fuzzer}/{target}#{num}_case.abbs.csv"
|
|
run:
|
|
with open('target_symbols.csv') as csvfile:
|
|
reader = csv.DictReader(csvfile)
|
|
line = next((x for x in reader if x['\ufeffkernel']==wildcards.target), None)
|
|
if line == None:
|
|
return False
|
|
kernel=line['\ufeffkernel']
|
|
fuzz_main=line['main_function']
|
|
fuzz_input=line['input_symbol']
|
|
fuzz_len=line['input_size']
|
|
bkp=line['return_function']
|
|
select_task=line['select_task']
|
|
script="""
|
|
echo $(pwd)/../../../../state2gantt/target/debug/state2gantt -i {input} -a {output[0]} -r {output[1]} -p {output[2]} -t {select_task}
|
|
$(pwd)/../../../../state2gantt/target/debug/state2gantt -i {input} -a {output[0]} -r {output[1]} -p {output[2]} -t {select_task}
|
|
"""
|
|
shell(script)
|
|
|
|
rule trace2gantt:
|
|
input:
|
|
"{remote}timedump/{fuzzer}/{target}#{num}_case.jobs.csv",
|
|
"{remote}timedump/{fuzzer}/{target}#{num}_case.resp.csv"
|
|
output:
|
|
"{remote}timedump/{fuzzer}/{target}#{num}_case.jobs.html",
|
|
shell:
|
|
"Rscript $(pwd)/../../../../state2gantt/plot_response.r {input[0]} {input[1]} html"
|
|
|
|
rule quicktest:
|
|
input:
|
|
expand("timedump/{fuzzer}/{target}{variant}#{num}.time", fuzzer=['feedgeneration100', 'stg'], target=['release', 'waters', 'copter'], variant=['_full'], num=range(0,int( NUM_ITERS ))),
|
|
expand("timedump/{fuzzer}/{target}{variant}#{num}.time", fuzzer=['feedgeneration100', 'stg'], target=['waters'], variant=['_bytes', '_int'], num=range(0,int( NUM_ITERS ))),
|
|
#expand("timedump/{fuzzer}/{target}{variant}#{num}.time", fuzzer=['genetic100', 'frafl'], target=['release', 'waters', 'copter'], variant=['_full'], num=range(0,int( NUM_ITERS ))),
|
|
#expand("timedump/{fuzzer}/{target}{variant}#{num}.time", fuzzer=['genetic100', 'frafl'], target=['waters'], variant=['_bytes', '_int'], num=range(0,int( NUM_ITERS ))),
|
|
expand("timedump/{fuzzer}/{target}{variant}#{num}.time", fuzzer=['random'], target=['release', 'waters', 'copter'], variant=['_full'], num=range(0,int( 1 ))),
|
|
expand("timedump/{fuzzer}/{target}{variant}#{num}.time", fuzzer=['random'], target=['waters'], variant=['_bytes', '_int'], num=range(0,int( 1 ))),
|
|
|
|
rule critical_set:
|
|
input:
|
|
expand("timedump/{fuzzer}/{target}{variant}#{num}.time", fuzzer=['feedgeneration100', 'stg'], target=['release', 'waters', 'copter'], variant=['_seq_full'], num=range(0,int( 10 ))),
|
|
expand("timedump/{fuzzer}/{target}{variant}#{num}.time", fuzzer=['random'], target=['release', 'waters', 'copter'], variant=['_seq_full'], num=range(0,int( 1 ))),
|
|
|
|
rule extended_set:
|
|
input:
|
|
expand("timedump/{fuzzer}/{target}{variant}#{num}.time", fuzzer=['feedgeneration100', 'stg'], target=['release', 'waters', 'copter'], variant=['_seq_full'], num=range(0,int( 10 ))),
|
|
expand("timedump/{fuzzer}/{target}{variant}#{num}.time", fuzzer=['feedgeneration100', 'stg'], target=['waters'], variant=['_seq_int','_seq_bytes'], num=range(0,int( 10 ))),
|
|
expand("timedump/{fuzzer}/{target}{variant}#{num}.time", fuzzer=['feedgeneration100', 'stg'], target=['copter'], variant=['_seq_bytes'], num=range(0,int( 10 ))),
|
|
expand("timedump/{fuzzer}/{target}{variant}#{num}.time", fuzzer=['random'], target=['copter', 'release', 'waters'], variant=['_seq_full'], num=range(0,int( 1 ))),
|
|
expand("timedump/{fuzzer}/{target}{variant}#{num}.time", fuzzer=['random'], target=['copter', 'waters'], variant=['_seq_full','_seq_int','_seq_bytes'], num=range(0,int( 1 ))),
|
|
|
|
rule emergency_copter:
|
|
input:
|
|
expand("timedump/{fuzzer}/{target}{variant}#{num}.time", fuzzer=['feedgeneration100', 'stg', 'frafl'], target=['copter'], variant=['_seq_stateless_full'], num=range(0,int( 10 ))),
|
|
expand("timedump/{fuzzer}/{target}{variant}#{num}.time", fuzzer=['feedgeneration100', 'stg', 'frafl'], target=['copter'], variant=['_seq_full'], num=range(0,int( 10 ))),
|
|
expand("timedump/{fuzzer}/{target}{variant}#{num}.time", fuzzer=['random'], target=['copter'], variant=['_seq_full'], num=range(0,int( 10 ))),
|
|
expand("timedump/{fuzzer}/{target}{variant}#{num}.time", fuzzer=['random'], target=['copter'], variant=['_seq_stateless_full'], num=range(0,int( 10 ))),
|
|
|
|
rule full_set:
|
|
input:
|
|
expand("timedump/{fuzzer}/{target}{variant}#{num}.time", fuzzer=[ 'frafl'], target=['release', 'waters', 'copter'], variant=['_seq_full'], num=range(0,int( 10 ))),
|
|
expand("timedump/{fuzzer}/{target}{variant}#{num}.time", fuzzer=['frafl'], target=['release', 'waters'], variant=['_seq_int'], num=range(0,int( 10 ))),
|
|
expand("timedump/{fuzzer}/{target}{variant}#{num}.time", fuzzer=['frafl'], target=['waters', 'copter'], variant=['_seq_bytes'], num=range(0,int( 10 ))),
|
|
expand("timedump/{fuzzer}/{target}{variant}#{num}.time", fuzzer=['frafl'], target=['copter'], variant=['_seq_int'], num=range(0,int( 10 ))),
|
|
expand("timedump/{fuzzer}/{target}{variant}#{num}.time", fuzzer=['afl'], target=['release', 'waters', 'copter'], variant=['_seq_full'], num=range(0,int( 10 ))),
|
|
expand("timedump/{fuzzer}/{target}{variant}#{num}.time", fuzzer=['afl'], target=['copter'], variant=['_seq_int'], num=range(0,int( 10 ))),
|
|
expand("timedump/{fuzzer}/{target}{variant}#{num}.time", fuzzer=['afl'], target=['copter'], variant=['_seq_bytes'], num=range(0,int( 8 ))),
|
|
#expand("timedump/{fuzzer}/{target}{variant}#{num}.time", fuzzer=['feedgeneration100', 'stg', 'random', 'frafl'], target=['release'], variant=['_seq_bytes'], num=range(0,int( 10 ))),
|
|
|
|
rule all_bins:
|
|
input:
|
|
expand("bins/target_{target}",target=['random','frafl','stg','feedgeneration100','feedgeneration1000','genetic100','genetic1000'])
|