fuzzer and performance optimisations
This commit is contained in:
parent
d5ea2e2974
commit
a4650fd589
11 changed files with 897 additions and 146 deletions
52
README.md
52
README.md
|
|
@ -98,6 +98,21 @@ roadmap.
|
|||
Services run as `root` by default; `user`/`group` trigger a full privilege
|
||||
drop (supplementary groups, then gid, then uid) before exec.
|
||||
|
||||
### imports
|
||||
|
||||
Configs can be split across files with `@import PATH` (column 0, before any
|
||||
section in that file):
|
||||
|
||||
```rc
|
||||
@import extra-services.rc
|
||||
```
|
||||
|
||||
The path resolves relative to the importing file's directory (absolute paths
|
||||
pass through). A file reached by several imports is only parsed once;
|
||||
self/cyclic imports are reported as errors. Imported files may import other
|
||||
files and define services and actions like any other rc. `reload` re-parses
|
||||
the whole import tree, so imported changes take effect on `bctl reload`.
|
||||
|
||||
## control
|
||||
|
||||
A running init listens on an abstract unix socket (`@bajia`). The bundled
|
||||
|
|
@ -150,3 +165,40 @@ policy with `checkpolicy`/`audit2allow`, then flip to `enforcing=1`.
|
|||
Limitations: uses the dynamic libselinux (no static build on Fedora), so the
|
||||
`--selinux` init is dynamically linked and the loader + libs (`libselinux`,
|
||||
`libpcre2-8`, glibc) are bundled into the initramfs.
|
||||
|
||||
## development & testing
|
||||
|
||||
Host-side unit tests (no framework, no dependencies) cover the rc parser, the
|
||||
`@import` machinery, and the pure supervisor helpers:
|
||||
|
||||
```sh
|
||||
make test # builds build/unit_tests and runs it
|
||||
```
|
||||
|
||||
The parser is also fuzz-tested with libFuzzer (needs clang):
|
||||
|
||||
```sh
|
||||
python3 tools/fuzz.py --seconds 300
|
||||
```
|
||||
|
||||
This drives random bytes through the same `parse_rc_stream` path the real init
|
||||
uses, with `@import` rejected so fuzz input can never open real files (e.g.
|
||||
`/dev/zero`). Crashes are saved under `build/fuzz-`; seeds accumulate in
|
||||
`build/fuzz-corpus` and grow between runs. A grammar dictionary (auto-seeded
|
||||
at `build/fuzz.dict`, overridable via `--dict`, disabled with `--no-dict`)
|
||||
guides coverage toward real rc keywords. Leak detection is on by default:
|
||||
`tools/lsan.supp` silences the spurious `strdup` that a torsocks `LD_PRELOAD`
|
||||
on the dev host allocates at startup, so any real leak in `parse_rc_stream` is
|
||||
saved as a `leak-*` artifact; pass `--no-detect-leaks` to disable it on a
|
||||
clean host. Peak fuzz RSS is driven mostly by ASan's freed-memory quarantine
|
||||
(256MiB default); fuzz.py pins it to 64MiB (`--quarantine-mb N`, 0 to
|
||||
disable), which roughly halves peak RSS.
|
||||
|
||||
To leak-check the host-side unit tests under ASan/LSan instead:
|
||||
|
||||
```sh
|
||||
make test-asan
|
||||
```
|
||||
|
||||
(clang++ and a `leak:tsocks_once` suppression are used automatically; the
|
||||
default `make test` runs the same assertions without the sanitizer).
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue