Skip to content

Commit 58a8d62

Browse files
tmlemankv2019i
authored andcommitted
ipc4: helper: unlock module instance verbs on native_sim
ipc4_get_comp_drv() returned NULL unconditionally on native_sim because the RIMAGE_MANIFEST guard (Intel ADSP ACE/CAVS only) was the sole path to a driver UUID lookup. Every INIT_INSTANCE call therefore failed with IPC4_MOD_NOT_INITIALIZED before creating any comp_dev, making the entire module instance verb surface (CONFIG_GET/SET, LARGE_CONFIG on real modules, BIND, UNBIND, DELETE_INSTANCE) unreachable from the fuzzer. Resolve module drivers on native_sim from a small fuzzer-only helper, ipc4_get_fuzzer_drv(), called from the CONFIG_ARCH_POSIX_LIBFUZZER branch of ipc4_get_comp_drv() so the heavily-used manifest lookup path is left untouched. It mirrors the IPC3 whitebox hack in posix/ipc.c: module_id is a 1-based index into the runtime component driver list, counting only instantiable module-adapter drivers so the fuzzer's module_id space matches what a real signed manifest exposes. Drivers with no ops.create, and internal gateway drivers (SOF_COMP_HOST/DAI) that are never IPC4 modules, are skipped (otherwise a module_id could land on an unconfigurable component or a NULL create op). module_id 0 (BaseFW) intentionally resolves to NULL: BaseFW is never created as a pipeline component, its messages are dispatched directly by base_fw.c. A tr_err() logs any module_id that maps to no driver to help developers and agents triage. The change is inactive in all non-fuzz builds. Measured impact (UBSan IPC4, seed=1, 20 s, small corpus): cov ~558 -> ~3974 (~7x lift from previously dead module instance paths) Signed-off-by: Tomasz Leman <tomasz.m.leman@intel.com>
1 parent ffa52df commit 58a8d62

1 file changed

Lines changed: 64 additions & 0 deletions

File tree

‎src/ipc/ipc4/helper.c‎

Lines changed: 64 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1344,6 +1344,68 @@ __cold static const struct comp_driver *ipc4_get_drv(const void *uuid)
13441344
return drv;
13451345
}
13461346

1347+
#if defined(CONFIG_ARCH_POSIX_LIBFUZZER) && !defined(RIMAGE_MANIFEST)
1348+
/*
1349+
* ipc4_get_fuzzer_drv - resolve a module driver for native_sim fuzz builds.
1350+
*
1351+
* native_sim fuzz builds have no rimage manifest, so the manifest lookup in
1352+
* ipc4_get_comp_drv() can never resolve a driver and every module instance
1353+
* verb (INIT_INSTANCE, CONFIG_GET/SET, LARGE_CONFIG, BIND, UNBIND,
1354+
* DELETE_INSTANCE) would be unreachable from the fuzzer.
1355+
*
1356+
* Mirror the IPC3 whitebox hack in posix/ipc.c and treat module_id as a
1357+
* 1-based index into the runtime component driver list, counting only
1358+
* instantiable module-adapter drivers so the fuzzer's module_id space matches
1359+
* what a real signed manifest would expose.
1360+
*
1361+
* module_id 0 (BaseFW) is deliberately not mapped: BaseFW is never created as
1362+
* a pipeline component - its messages are dispatched directly by base_fw.c -
1363+
* so returning NULL for it here is correct.
1364+
*/
1365+
static const struct comp_driver *ipc4_get_fuzzer_drv(uint32_t module_id)
1366+
{
1367+
struct comp_driver_list *dlist = comp_drivers_get();
1368+
struct list_item *iter;
1369+
uint32_t idx = 0;
1370+
1371+
if (!module_id)
1372+
return NULL;
1373+
1374+
list_for_item(iter, &dlist->list) {
1375+
struct comp_driver_info *inf =
1376+
container_of(iter, struct comp_driver_info, list);
1377+
1378+
/*
1379+
* Skip query-only entries (e.g. BaseFW) that cannot be
1380+
* instantiated because they have no create op.
1381+
*/
1382+
if (!inf->drv->ops.create)
1383+
continue;
1384+
1385+
/*
1386+
* A real signed manifest only lists module-adapter modules.
1387+
* The internal gateway drivers (SOF_COMP_HOST, SOF_COMP_DAI)
1388+
* are registered for IPC3 but are never IPC4 modules: on the
1389+
* IPC4 path they receive no params() pass and cannot be
1390+
* configured (e.g. their DMA buffer is never allocated). Skip
1391+
* non-module-adapter drivers so the fuzzer's module_id space
1392+
* matches a real manifest and cannot map to an unconfigurable
1393+
* component.
1394+
*/
1395+
if (inf->drv->type != SOF_COMP_MODULE_ADAPTER)
1396+
continue;
1397+
1398+
if (++idx == module_id)
1399+
return inf->drv;
1400+
}
1401+
1402+
tr_err(&comp_tr,
1403+
"no instantiable driver at module_id %u (%u available)",
1404+
module_id, idx);
1405+
return NULL;
1406+
}
1407+
#endif
1408+
13471409
/*
13481410
* Called from
13491411
* - ipc4_get_large_config_module_instance()
@@ -1361,6 +1423,8 @@ __cold const struct comp_driver *ipc4_get_comp_drv(uint32_t module_id)
13611423

13621424
#ifdef RIMAGE_MANIFEST
13631425
desc = (const struct sof_man_fw_desc *)IMR_BOOT_LDR_MANIFEST_BASE;
1426+
#elif defined(CONFIG_ARCH_POSIX_LIBFUZZER)
1427+
return ipc4_get_fuzzer_drv(module_id);
13641428
#else
13651429
/* Non-rimage platforms have no component facility yet.
13661430
* This needs to move to the platform layer.

0 commit comments

Comments
 (0)