Industry Practice of Directed Kernel Fuzzing for Open-source Linux Distribution
Abstract
Directed grey-box fuzzing is a widely used automatic testing technique that has helped developers test specific code space in the target program. Although many directed fuzzers are designed to test the Linux kernel, challenges still remain due to the complexity of industrial requirements and deployment environments. In this paper, we collaborate with developers from Alibaba and the OpenAnolis community to conduct an industry practice of directed kernel fuzzing for open-source Linux distribution. We highlight typical challenges in deploying directed kernel fuzzing, including target-related kernel configuration options being disabled, unrelated initial seeds limiting fuzzing startup performance, no support for kernel feature interface fuzzing, independent fuzzer execution limiting fuzzing effectiveness, much manual work to triage and analyze crashes, and hard to integrate into the existing fuzzing framework. We provide solutions to these challenges, which allowed us to discover 11 previously unknown kernel bugs related to cloud-native features, io_uring, and other components in the OpenAnolis Linux distribution.
BibTeX
@inproceedings{Shi-al:ASE24,
author = {Heyuan Shi and
Shijun Chen and
Runzhe Wang and
Yuhan Chen and
Weibo Zhang and
Qiang Zhang and
Yuheng Shen and
Xiaohai Shi and
Chao Hu and
Yu Jiang},
title = {Industry Practice of Directed Kernel Fuzzing for Open-source Linux Distribution},
booktitle = {ASE},
pages = {2159--2169},
publisher = {{ACM}},
year = {2024},
}