From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-ed1-f48.google.com (mail-ed1-f48.google.com [209.85.208.48]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 9FE5930F931 for ; Mon, 12 Jan 2026 19:28:41 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.208.48 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1768246123; cv=none; b=p7K5AL1m7s3ZR3Y74R0jcVPpPfcE9QvEij4/xvAqu9JHvZ7QdaG0FJYvr4aOMhPbwW4XkGYvYbAPVHDpCsNHYS6StYjJeHPb8qSvreRyaN/bC8nu87rgGNVyEOyU7kpjZcLrLoCfj4bkJMQaLJmYV7q2tKPc2Rf3NtHg0ZWxlHg= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1768246123; c=relaxed/simple; bh=P/xCm9B+5KAEyQ1qfcZ8mgBzb6s/VqdCC9Btij3XqM0=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=iQPrBSinrijvGecZJABgOcTvqNbVYmvDmscywj8N5BYJcXK/2QvpVhDHxws56HmWYpIgvVTPupTRQQpkPar9UW3LcrXHgcOZPq5JXPMWsPXHMuQUwAeCQjJMPNZkF2S9SHO9+BX33sfZIuluoRHiYQTHmL9aT/NGQUTC934pF4A= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=aUFgUo1r; arc=none smtp.client-ip=209.85.208.48 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="aUFgUo1r" Received: by mail-ed1-f48.google.com with SMTP id 4fb4d7f45d1cf-64b9dfc146fso1716095a12.0 for ; Mon, 12 Jan 2026 11:28:41 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1768246120; x=1768850920; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to; bh=a8RC3/jOXChgUFu7fWCHeysuCImlO6A97UJW0JalKx0=; b=aUFgUo1rZFLwFw2/7/udF0DHXW9dv40/a9g59x+kYJLVjJOl7aQjPzVQ/pXhQEavFt 0qEaa/mfJFJ1tFA0oGfhCS9ci7e43TS9PsvglK1lN2tCHRZ56jDAObDLfVkQHKLs+zMg QUe3bC03UYEBDQpw8jnDLjsHVud0twk3vKt4bpqtAf2OGf7oK2kdv9gopBTqKJSPhy43 50kLGl/KjIxTAMnSuJDh0DFZfC4DhhvxXjTCZKcNAk8BrUnjqSnLoJbIBaenEQhHVhvJ bs0NFLawVWDlSYJIUFE2TAEYWk0WG7Lv/4uciqM+9PtEAYacBBWdFtuOsp++vT/g1RJG AMFA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1768246120; x=1768850920; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=a8RC3/jOXChgUFu7fWCHeysuCImlO6A97UJW0JalKx0=; b=ND3yDyYySP692X2iuDnFpWfILl3W+Q/UA/EezxLr7zKsIwcK5D6fjrIhOdJRnUMlol j8JikcuKLLxG8R59vqc35rCCMPQz7otjp2oKMX/SnQOzVbT0Pn4rDwokZh/Kl7luH4ct ppyyABTSfgTkmOcM1RLmBD+d3ldoUx3XjcdtGxmLlVEBBF66lwCtMjQGSEBzrOG8RhIl c/DVpUEKvXnC8pzBEsA8HJH5BwvaC0AlvUo7A+1AVQowCdn/xEoprwIbbw5DVN1M/P/+ qI5NN42U1LdSZoPufpm27xoMtwMQZX3uKtZe8/x65a0UZuFJYjkXzEKL7oxdwedZD7rP QIsQ== X-Forwarded-Encrypted: i=1; AJvYcCUL2uJ7f92tOIQu7Jd0hZYPWITYPsNw6oPiGEwXtLE4gHVg8aZmWmKJrym+BEoF8kIoAuLD1y7H7XLbnm8=@vger.kernel.org X-Gm-Message-State: AOJu0Yw0q5Q/1X0EwsFWeoXZdunb/VVLSBolDOLIpEs2S1yECLn35G/O e2Q+dWI2dO3rN2E+Sra7gj8Jexh5JAgaySHmUGjtPcM7GUnNe4r43PJS X-Gm-Gg: AY/fxX6tc2OFl4MXwFZdWtijl6l7ZenOBlb0zxWieZb+/TJFFPaWVJ64G4tQEt4Rmlh pSZTm425/jX4vbAgkIrh9NPbYaW4EQtYXB0vPc+OLBa7CchClJbQEcPBIt9/9cz6+oA5ShaCLr+ mYMLW34sPXz5Ajxwsj1zJWQr5zDRiML5cYzD3llrl8gXimytBVxliFmlWAsYAkOOqKCsbuq2Rj+ JO5BN2vpxQkJUXPU1hKG6KQgP6qJqspkUJnqM2yDCm6B2v3PxXbEL7D3QzK04eLVyRP7vAMqF5g bF1MhT/CO/0S9Ajqi1/eNvq6hRXMsN4ebUQ2eJeoGKjSMST4vZRKIgX1Wv34sqieYcDbPBZHoQv st/V90RJj061DUEmUvtovZnMb3MSoIeDFLNmKU0WO9nut/MSjMSSHlGB7XInOizoRI0D+M8lX2k m0XUg+CbG4CL7/5P/N+DXaNn0dRPsP6RS4HLNk4sGgTTdXZg8yzg== X-Received: by 2002:a05:6402:326:b0:641:88ff:10ad with SMTP id 4fb4d7f45d1cf-652e58769e9mr330944a12.14.1768246119781; Mon, 12 Jan 2026 11:28:39 -0800 (PST) Received: from ethan-tp (xdsl-31-164-106-179.adslplus.ch. [31.164.106.179]) by smtp.gmail.com with ESMTPSA id 4fb4d7f45d1cf-6507bf667fcsm18108959a12.29.2026.01.12.11.28.37 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 12 Jan 2026 11:28:38 -0800 (PST) From: Ethan Graham To: ethan.w.s.graham@gmail.com, glider@google.com Cc: akpm@linux-foundation.org, andreyknvl@gmail.com, andy@kernel.org, andy.shevchenko@gmail.com, brauner@kernel.org, brendan.higgins@linux.dev, davem@davemloft.net, davidgow@google.com, dhowells@redhat.com, dvyukov@google.com, ebiggers@kernel.org, elver@google.com, gregkh@linuxfoundation.org, herbert@gondor.apana.org.au, ignat@cloudflare.com, jack@suse.cz, jannh@google.com, johannes@sipsolutions.net, kasan-dev@googlegroups.com, kees@kernel.org, kunit-dev@googlegroups.com, linux-crypto@vger.kernel.org, linux-kernel@vger.kernel.org, linux-mm@kvack.org, lukas@wunner.de, mcgrof@kernel.org, rmoar@google.com, shuah@kernel.org, sj@kernel.org, skhan@linuxfoundation.org, tarasmadan@google.com, wentaoz5@illinois.edu Subject: [PATCH v4 0/6] KFuzzTest: a new kernel fuzzing framework Date: Mon, 12 Jan 2026 20:28:21 +0100 Message-ID: <20260112192827.25989-1-ethan.w.s.graham@gmail.com> X-Mailer: git-send-email 2.51.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit This patch series introduces KFuzzTest, a lightweight framework for creating in-kernel fuzz targets for internal kernel functions. The primary motivation for KFuzzTest is to simplify the fuzzing of low-level, relatively stateless functions (e.g., data parsers, format converters) that are difficult to exercise effectively from the syscall boundary. It is intended for in-situ fuzzing of kernel code without requiring that it be built as a separate userspace library or that its dependencies be stubbed out. Following feedback from the Linux Plumbers Conference and mailing list discussions, this version of the framework has been significantly simplified. It now focuses exclusively on handling raw binary inputs, removing the complexity of the custom serialization format and DWARF parsing found in previous iterations. The core design consists of two main parts: 1. The `FUZZ_TEST_SIMPLE(name)` macro, which allows developers to define a fuzz test that accepts a buffer and its length. 2. A simplified debugfs interface that allows userspace fuzzers (or simple command-line tools) to pass raw binary blobs directly to the target function. To validate the framework's end-to-end effectiveness, we performed an experiment by manually introducing an off-by-one buffer over-read into pkcs7_parse_message, like so: - ret = asn1_ber_decoder(&pkcs7_decoder, ctx, data, datalen); + ret = asn1_ber_decoder(&pkcs7_decoder, ctx, data, datalen + 1); A syzkaller instance fuzzing the new test_pkcs7_parse_message target introduced in patch 7 successfully triggered the bug inside of asn1_ber_decoder in under 30 seconds from a cold start. Similar experiments on the other new fuzz targets (patches 8-9) also successfully identified injected bugs, proving that KFuzzTest is effective when paired with a coverage-guided fuzzing engine. This patch series is structured as follows: - Patch 1 introduces the core KFuzzTest API, including the main FUZZ_TEST_SIMPLE macro. - Patch 2 adds the runtime implementation for the framework - Patch 3 adds documentation. - Patch 4 provides sample fuzz targets. - Patch 5 defines fuzz targets for several functions in crypto/. - Patch 6 adds maintainer information for KFuzzTest. Changes since PR v3: - Major simplification of the architecture, removing the complex `FUZZ_TEST` macro, the custom serialization format, domain constraints, annotations, and associated DWARF metadata regions. - The framework now only supports `FUZZ_TEST_SIMPLE` targets, which accept raw binary data. - Removed the userspace bridge tool as it is no longer required for serializing inputs. - Updated documentation and samples to reflect the "simple-only" approach. Ethan Graham (6): kfuzztest: add user-facing API and data structures kfuzztest: implement core module and input processing kfuzztest: add ReST documentation kfuzztest: add KFuzzTest sample fuzz targets crypto: implement KFuzzTest targets for PKCS7 and RSA parsing MAINTAINERS: add maintainer information for KFuzzTest Documentation/dev-tools/index.rst | 1 + Documentation/dev-tools/kfuzztest.rst | 152 ++++++++++++++++++ MAINTAINERS | 7 + crypto/asymmetric_keys/Makefile | 2 + crypto/asymmetric_keys/tests/Makefile | 4 + crypto/asymmetric_keys/tests/pkcs7_kfuzz.c | 18 +++ .../asymmetric_keys/tests/rsa_helper_kfuzz.c | 24 +++ include/asm-generic/vmlinux.lds.h | 14 +- include/linux/kfuzztest.h | 90 +++++++++++ lib/Kconfig.debug | 1 + lib/Makefile | 2 + lib/kfuzztest/Kconfig | 16 ++ lib/kfuzztest/Makefile | 4 + lib/kfuzztest/input.c | 47 ++++++ lib/kfuzztest/main.c | 142 ++++++++++++++++ samples/Kconfig | 7 + samples/Makefile | 1 + samples/kfuzztest/Makefile | 3 + samples/kfuzztest/underflow_on_buffer.c | 52 ++++++ 19 files changed, 586 insertions(+), 1 deletion(-) create mode 100644 Documentation/dev-tools/kfuzztest.rst create mode 100644 crypto/asymmetric_keys/tests/Makefile create mode 100644 crypto/asymmetric_keys/tests/pkcs7_kfuzz.c create mode 100644 crypto/asymmetric_keys/tests/rsa_helper_kfuzz.c create mode 100644 include/linux/kfuzztest.h create mode 100644 lib/kfuzztest/Kconfig create mode 100644 lib/kfuzztest/Makefile create mode 100644 lib/kfuzztest/input.c create mode 100644 lib/kfuzztest/main.c create mode 100644 samples/kfuzztest/Makefile create mode 100644 samples/kfuzztest/underflow_on_buffer.c -- 2.51.0