Skip to content

Commit 2e3a715

Browse files
committed
ipc4: helper: unlock module instance verbs on native_sim
ipc4_get_comp_drv() returned NULL unconditionally on native_sim because the RIMAGE_MANIFEST guard (Intel ADSP ACE/CAVS only) was the sole path to a driver UUID lookup. Every INIT_INSTANCE call therefore failed with IPC4_MOD_NOT_INITIALIZED before creating any comp_dev, making the entire module instance verb surface (CONFIG_GET/SET, LARGE_CONFIG on real modules, BIND, UNBIND, DELETE_INSTANCE) unreachable from the fuzzer. Add a CONFIG_ARCH_POSIX_LIBFUZZER branch that mirrors the existing IPC3 whitebox hack in posix/ipc.c: treat module_id as a 1-based index into the runtime comp_driver list. module_id 0 (BaseFW, handled separately and having no create callback) is excluded. Drivers without an ops.create callback are skipped during the index walk so the fuzzer's module_id space only maps to instantiable components, otherwise a module_id that lands on such a driver would cause a NULL function pointer call. Return the resolved driver directly instead of a redundant UUID re-lookup. The change is inactive in all non-fuzz builds. Measured impact (UBSan IPC4, seed=1, 20 s, small corpus): cov ~558 -> ~3974 (~7x lift from previously dead module instance paths) Signed-off-by: Tomasz Leman <tomasz.m.leman@intel.com>
1 parent 1469c18 commit 2e3a715

1 file changed

Lines changed: 47 additions & 0 deletions

File tree

‎src/ipc/ipc4/helper.c‎

Lines changed: 47 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1361,6 +1361,53 @@ __cold const struct comp_driver *ipc4_get_comp_drv(uint32_t module_id)
13611361

13621362
#ifdef RIMAGE_MANIFEST
13631363
desc = (const struct sof_man_fw_desc *)IMR_BOOT_LDR_MANIFEST_BASE;
1364+
#elif defined(CONFIG_ARCH_POSIX_LIBFUZZER)
1365+
/*
1366+
* native_sim fuzz builds have no rimage manifest so ipc4_get_comp_drv()
1367+
* would always return NULL, making every module instance verb
1368+
* (INIT_INSTANCE, CONFIG_GET/SET, LARGE_CONFIG, BIND, UNBIND,
1369+
* DELETE_INSTANCE) unreachable from the fuzzer.
1370+
*
1371+
* Mirror the IPC3 whitebox hack in posix/ipc.c: treat module_id as a
1372+
* 1-based index into the runtime comp_driver list. module_id 0 (BaseFW)
1373+
* has no comp_driver entry and is handled separately above via
1374+
* ipc4_get_drv(); non-zero ids map to registered drivers so the fuzzer
1375+
* can create real module instances with valid driver UUIDs.
1376+
*/
1377+
if (module_id) {
1378+
struct comp_driver_list *dlist = comp_drivers_get();
1379+
struct list_item *iter;
1380+
uint32_t idx = 0;
1381+
1382+
list_for_item(iter, &dlist->list) {
1383+
struct comp_driver_info *inf =
1384+
container_of(iter, struct comp_driver_info, list);
1385+
1386+
/* Only count drivers that can be instantiated —
1387+
* skip BaseFW and other query-only entries that
1388+
* have no create op.
1389+
*/
1390+
if (!inf->drv->ops.create)
1391+
continue;
1392+
1393+
/*
1394+
* A real signed manifest only lists module-adapter
1395+
* modules. The internal gateway drivers (SOF_COMP_HOST,
1396+
* SOF_COMP_DAI) are registered for IPC3 but are never
1397+
* IPC4 modules: on the IPC4 path they receive no params()
1398+
* pass and cannot be configured (e.g. their DMA buffer is
1399+
* never allocated). Skip non-module-adapter drivers here
1400+
* so the fuzzer's module_id space matches a real manifest
1401+
* and cannot map to an unconfigurable component.
1402+
*/
1403+
if (inf->drv->type != SOF_COMP_MODULE_ADAPTER)
1404+
continue;
1405+
1406+
if (++idx == module_id)
1407+
return inf->drv;
1408+
}
1409+
}
1410+
return NULL;
13641411
#else
13651412
/* Non-rimage platforms have no component facility yet.
13661413
* This needs to move to the platform layer.

0 commit comments

Comments
 (0)