From 9e2fc019a60909b3ab0f96a4b4489bce888a77a9 Mon Sep 17 00:00:00 2001 From: Etienne Perot Date: Wed, 21 Feb 2024 13:46:06 -0800 Subject: [PATCH] Delete test against golden `seccomp-bpf` program. PiperOrigin-RevId: 609109522 --- runsc/boot/filter/BUILD | 5 - runsc/boot/filter/filter_fuzz_golden.bpf | Bin 6040 -> 0 bytes runsc/boot/filter/filter_fuzz_golden_test.go | 98 ------------------- 3 files changed, 103 deletions(-) delete mode 100644 runsc/boot/filter/filter_fuzz_golden.bpf delete mode 100644 runsc/boot/filter/filter_fuzz_golden_test.go diff --git a/runsc/boot/filter/BUILD b/runsc/boot/filter/BUILD index 0b7feae07..a40503a60 100644 --- a/runsc/boot/filter/BUILD +++ b/runsc/boot/filter/BUILD @@ -54,18 +54,13 @@ secbench_test( go_test( name = "filter_fuzz_test", srcs = [ - "filter_fuzz_golden_test.go", "filter_fuzz_test.go", ], - data = ["filter_fuzz_golden.bpf"], deps = [ "//pkg/abi/linux", - "//pkg/bpf", "//pkg/seccomp", "//pkg/sentry/platform/systrap", - "//pkg/test/testutil", "//runsc/boot/filter/config", "//test/secfuzz", - "@org_golang_x_sys//unix:go_default_library", ], ) diff --git a/runsc/boot/filter/filter_fuzz_golden.bpf b/runsc/boot/filter/filter_fuzz_golden.bpf deleted file mode 100644 index 488198f8339f42c6273669b443cbcd0071b90b52..0000000000000000000000000000000000000000 GIT binary patch literal 0 HcmV?d00001 literal 6040 zcmY#jU|?WjU|paS%(Cftewdfq_Alfq@Z3vobI+JYr;E0MX$L z3=AN30$}|N%pe-X7lH5@LHZ%){jUd!gXBdS7`WM?`k?AKLFz#AAS}wj0Fnlqs{%0x zWEGgN0pT;l)ayX_xa?tObb`1KY7Z`T>@2A2;Pye?!wk|0Vnf{n;xb_I7cIk?nu zGoY#?+5e6V0^sl<;D2^jRC~zv7dtlrb2y;!Ng#Z<<)P}J@jQ2c_#LGd8UzyP)w5>Bir_JSf7WNsQ0B>#c*g7ksR5oI9G zJdhq(eg|0u;^Rv1Fmo!;cgC2-;500(0DaPi+@nM1jRpy2B}Yissn{HBtHMwgVH^yyauTQ z(I9nEP<4S&`$73wl>wA$K>3LQ6s%x(g4C-rurmDr4=ML0Amuc(bO^-%p!_C^l71lS zNHvd<%H}aq**q31o5xIL^F*j@o-mcobLzyMUO?&b79%L#F*EQ(%V!V`62A^@pP;5^ zMg~4;`n}AET26w>4UoPIDB{cvpmYmL{~#J956e&J=7Q2KNd5#P#J!+=YYJ&rF^DoC z@&zbQgUkb!pRjxe(svN-4@L%QsQdP#xx*alKM)O4Uj|jD2hE2d_kqd{kh?&3K=T(! zDL6lZ#6%ewnAM@`LGHtr|A;jQt$YGm3orjcb`fh1s6GIxr_?>51|v1h0i^?6=70jT z2OLk#44`la#UqFYiHk$y0~Dtq{U8hqZwF|3kIjD|eN9mF)S&STqCw)YdKnb3ATt>l zAmy<#R2_&0sjI?~&O!ErK{-!4l)ZGpP*<5 zrzdFo0yz&`yu;hegw%m543PQQ)PdX)2M!-b27Rb|Vxaj8qz4qf2?WwJOdY6x1F><% zLm<>1P`wJW*B@#R$p4^x121*8rnkINsfVDp(7yrAI>qCxh+(hn#g zk>lAGst!bh)WOmhx;h)EIuH#~XMrOM4E(&{_=Nfk)NBLuL4HB@H#FQp zR)FPU?GRYFU~A8S6sv*#&B)*ZwO<8lKP=op2?}Hvwr~T9!_>jb2}0^X;RDi#O&!QR zB4GD0Gekqf4Mc;)VHl(z5f6+EzEF4bqU0Aw22i>K>ES{VXJ(LKg!Gd^G)TS+svne} zLGFV32UJ{v!x8FEkWw(8*l_&~Zci~Y+=u!DM1u^0xtH4Zy@lGh3u+&T2H6LzuTaB{ znPDna9f$_06NZKZy1HJdIuH#~_W-I6=6+DVLQaR!bP7@m4lhucg319{I)tWEkTvjf z38eTc*!_$Q%~10%GoaT0)1cxPP{f%TZbRJ%qCw_JLe+sRKu#y8pyDT>e34R4TfaCd|B zuLkR9W_Se+9}o=^2l)p?gAzE%ewcY7{&wK_!e$;U96|aPK+Sy)H5WvK#6jr+M1vdx zQxEE&Jb|hM(IEL5Q2(H+V`O*)6`z6s$x^~^wQsQcjMJJfyb4$ydqx({R&*!`e(0CK)E0lO2qzyH4;q&N#K z&di_;bq|OJiK{~00}3C6f0!8*pz1(0NF69WfM}2!kUL@N1(wc1^62eUka|$L4T^tR zsCgh7Bp!j)UPcBpwrR{}>sRp!$8F;RSUkD4B!93+hgg6To~>K0ppX zT=~!mY(6uCI@BK^8e|A4oq=f7@MB~E)t?}7Yp6Rweu3D-0k#(!&me6m`PCF`4B$9ZKZpjI4>AWtgWLhK1Lj|l!5}`l{sox}iZ@fJeIOcS53GKG*#`|jc=$rY z52O_APmmiR{zmk-u%#0*sK1S&{sy@lq!*h0nbFce$a^T^2Fg#MaWp%qejc=N^MLvT jM1vd$!ytn|X&TaQXJl}P>Ib!Bki~tV;>hYD@(c_Ba-&^s diff --git a/runsc/boot/filter/filter_fuzz_golden_test.go b/runsc/boot/filter/filter_fuzz_golden_test.go deleted file mode 100644 index 2f9d049ec..000000000 --- a/runsc/boot/filter/filter_fuzz_golden_test.go +++ /dev/null @@ -1,98 +0,0 @@ -// Copyright 2023 The gVisor Authors. -// -// Licensed under the Apache License, Version 2.0 (the "License"); -// you may not use this file except in compliance with the License. -// You may obtain a copy of the License at -// -// http://www.apache.org/licenses/LICENSE-2.0 -// -// Unless required by applicable law or agreed to in writing, software -// distributed under the License is distributed on an "AS IS" BASIS, -// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -// See the License for the specific language governing permissions and -// limitations under the License. - -//go:build !false -// +build !false - -package filter_fuzz_test - -import ( - "os" - "testing" - - "gvisor.dev/gvisor/pkg/abi/linux" - "gvisor.dev/gvisor/pkg/bpf" - "gvisor.dev/gvisor/pkg/seccomp" - "gvisor.dev/gvisor/pkg/sentry/platform/systrap" - "gvisor.dev/gvisor/pkg/test/testutil" - "gvisor.dev/gvisor/runsc/boot/filter/config" - "gvisor.dev/gvisor/test/secfuzz" -) - -// FuzzFilterAgainstGolden tests that the behavior of the generated -// seccomp-bpf program has not changed. -// This is useful when modifying the way that the seccomp-bpf program -// is built, not when modifying what rules the program is meant to enforce. -// If you are modifying the seccomp-bpf rules in such a way that you -// are expecting the set of allowed/disallowed syscalls to change, -// you can update the reference program using: -// -// $ make seccomp-sentry-filters ARGS='--deny-action=errno --default-action=kill_thread --bad-arch-action=kill_process --output=bytecode --out=runsc/boot/filter/filter_fuzz_golden.bpf' -func FuzzFilterAgainstGolden(f *testing.F) { - goldenProgPath, err := testutil.FindFile("runsc/boot/filter/filter_fuzz_golden.bpf") - if err != nil { - f.Fatalf("failed to find golden program: %v", err) - } - goldenProg, err := os.ReadFile(goldenProgPath) - if err != nil { - f.Fatalf("failed to read golden program: %v", err) - } - goldenInstructions, err := bpf.ParseBytecode(goldenProg) - if err != nil { - f.Fatalf("failed to parse golden program bytecode: %v", err) - } - goldenFuzzee := secfuzz.Fuzzee{ - Name: "golden", - Instructions: goldenInstructions, - // TODO(b/298726675): Enforce full coverage with the optimized program - // once confident that it works well. - // This will ensure that the generated fuzz corpus is sufficient to - // fully exhaust the golden program. - EnforceFullCoverage: false, - } - - filterOpts := config.Options{ - Platform: (&systrap.Systrap{}).SeccompInfo(), - } - rules, denyRules := config.Rules(filterOpts) - ruleSets := []seccomp.RuleSet{ - { - Rules: denyRules, - Action: linux.SECCOMP_RET_ERRNO, - }, - { - Rules: rules, - Action: linux.SECCOMP_RET_ALLOW, - }, - } - opts := config.SeccompOptions(filterOpts) - // We use unique actions here to be able to tell them apart. - opts.DefaultAction = linux.SECCOMP_RET_KILL_THREAD - opts.BadArchAction = linux.SECCOMP_RET_KILL_PROCESS - current, _, err := seccomp.BuildProgram(ruleSets, opts) - if err != nil { - f.Fatalf("failed to build seccomp-bpf program: %v", err) - } - currentFuzzee := secfuzz.Fuzzee{ - Name: "current", - Instructions: current, - EnforceFullCoverage: true, - } - df, err := secfuzz.NewDiffFuzzer(f, &goldenFuzzee, ¤tFuzzee) - if err != nil { - f.Fatalf("failed to create diff fuzzer: %v", err) - } - df.DeriveCorpusFromRuleSets(ruleSets) - df.Fuzz() -}