Kexec & Btrfs Subvolumes for Kernel Testing
As part of his Doctorate, a researcher is recreating prior academic work in the fuzzing domain. Kernel/embedded system fuzzing often requires a custom kernel, patches, and other specific setups. Containers can help with packaging userland components, but some kernel-based fuzzing frameworks need bare metal installations for specific hardware features.
This blog post addresses the gap by using btrfs subvolumes as "workspaces" and kexec to load arbitrary kernels for projects. The workflow consists of loading a new kernel with kexec, a "soft reboot" that kills running processes but does not boot back to the bootloader, making it faster than powering off and on a machine. Kexec enables leveraging hardware tracing technologies on bare-metal installs of Linux distributions like Arch Linux.
Hardware tracing, such as Intel's Processor Trace (PT), allows userland processes to receive trace information about a program’s execution at an incredibly fast rate. This data helps a fuzzer determine if new code was reached, speeding up the fuzzing loop. However, running a virtual machine for specific kernels is not ideal due to performance issues caused by nested virtualization.
Btrfs subvolumes can create near-instant snapshotting of data, allowing easy restoration of workspaces after changes or use as a clean base for fuzzing workflows.
Written by urgent.news from Lobsters's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.