|
24 | 24 |
|
25 | 25 | import yaml
|
26 | 26 |
|
| 27 | +from experiment import benchmark as benchmarklib |
| 28 | + |
27 | 29 | logger = logging.getLogger(__name__)
|
28 | 30 |
|
29 | 31 | BUILD_DIR: str = 'build'
|
30 | 32 | GLOBAL_TEMP_DIR: str = ''
|
| 33 | +ENABLE_CACHING = bool(int(os.getenv('OFG_USE_CACHING', '0'))) |
31 | 34 | # Assume OSS-Fuzz is at repo root dir by default.
|
32 | 35 | # This will change if temp_dir is used.
|
33 | 36 | OSS_FUZZ_DIR: str = os.path.join(
|
@@ -174,3 +177,173 @@ def get_project_repository(project: str) -> str:
|
174 | 177 | with open(project_yaml_path, 'r') as benchmark_file:
|
175 | 178 | data = yaml.safe_load(benchmark_file)
|
176 | 179 | return data.get('main_repo', '')
|
| 180 | + |
| 181 | + |
| 182 | +def _get_project_cache_name(project: str) -> str: |
| 183 | + """Gets name of cached container for a project.""" |
| 184 | + return f'gcr.io.oss-fuzz.{project}_cache' |
| 185 | + |
| 186 | + |
| 187 | +def _get_project_cache_image_name(project: str, sanitizer: str) -> str: |
| 188 | + """Gets name of cached Docker image for a project and a respective |
| 189 | + sanitizer.""" |
| 190 | + return f'gcr.io/oss-fuzz/{project}_{sanitizer}_cache' |
| 191 | + |
| 192 | + |
| 193 | +def _has_cache_build_script(project: str) -> bool: |
| 194 | + """Checks if a project has cached fuzzer build script.""" |
| 195 | + cached_build_script = os.path.join('fuzzer_build_script', project) |
| 196 | + return os.path.isfile(cached_build_script) |
| 197 | + |
| 198 | + |
| 199 | +def _prepare_image_cache(project: str) -> bool: |
| 200 | + """Prepares cached images of fuzzer build containers.""" |
| 201 | + # Only create a cached image if we have a post-build build script |
| 202 | + if not _has_cache_build_script(project): |
| 203 | + logger.info('No cached script for %s', project) |
| 204 | + return False |
| 205 | + logger.info('%s has a cached build script', project) |
| 206 | + |
| 207 | + cached_container_name = _get_project_cache_name(project) |
| 208 | + adjusted_env = os.environ | { |
| 209 | + 'OSS_FUZZ_SAVE_CONTAINERS_NAME': cached_container_name |
| 210 | + } |
| 211 | + |
| 212 | + logger.info('Creating a cached images') |
| 213 | + for sanitizer in ['address', 'coverage']: |
| 214 | + # Create cached image by building using OSS-Fuzz with set variable |
| 215 | + command = [ |
| 216 | + 'python3', 'infra/helper.py', 'build_fuzzers', project, '--sanitizer', |
| 217 | + sanitizer |
| 218 | + ] |
| 219 | + try: |
| 220 | + sp.run(command, cwd=OSS_FUZZ_DIR, env=adjusted_env, check=True) |
| 221 | + except sp.CalledProcessError: |
| 222 | + logger.info('Failed to build fuzzer for %s.', project) |
| 223 | + return False |
| 224 | + |
| 225 | + # Commit the container to an image |
| 226 | + cached_image_name = _get_project_cache_image_name(project, sanitizer) |
| 227 | + |
| 228 | + command = ['docker', 'commit', cached_container_name, cached_image_name] |
| 229 | + try: |
| 230 | + sp.run(command, check=True) |
| 231 | + except sp.CalledProcessError: |
| 232 | + logger.info('Could not rename image.') |
| 233 | + return False |
| 234 | + logger.info('Created cached image %s', cached_image_name) |
| 235 | + |
| 236 | + # Delete the container we created |
| 237 | + command = ['docker', 'container', 'rm', cached_container_name] |
| 238 | + try: |
| 239 | + sp.run(command, check=True) |
| 240 | + except sp.CalledProcessError: |
| 241 | + logger.info('Could not rename image.') |
| 242 | + return True |
| 243 | + |
| 244 | + |
| 245 | +def prepare_cached_images( |
| 246 | + experiment_targets: list[benchmarklib.Benchmark]) -> None: |
| 247 | + """Builds cached Docker images for a set of targets.""" |
| 248 | + all_projects = set() |
| 249 | + for benchmark in experiment_targets: |
| 250 | + all_projects.add(benchmark.project) |
| 251 | + |
| 252 | + logger.info('Preparing cache for %d projects', len(all_projects)) |
| 253 | + |
| 254 | + for project in all_projects: |
| 255 | + _prepare_image_cache(project) |
| 256 | + |
| 257 | + |
| 258 | +def is_image_cached(project_name: str, sanitizer: str) -> bool: |
| 259 | + """Checks whether a project has a cached Docker image post fuzzer |
| 260 | + building.""" |
| 261 | + cached_image_name = _get_project_cache_image_name(project_name, sanitizer) |
| 262 | + try: |
| 263 | + sp.run( |
| 264 | + ['docker', 'inspect', '--type=image', cached_image_name], |
| 265 | + check=True, |
| 266 | + stdin=sp.DEVNULL, |
| 267 | + stdout=sp.DEVNULL, |
| 268 | + stderr=sp.STDOUT, |
| 269 | + ) |
| 270 | + return True |
| 271 | + except sp.CalledProcessError: |
| 272 | + return False |
| 273 | + |
| 274 | + |
| 275 | +def rewrite_project_to_cached_project(project_name: str, generated_project: str, |
| 276 | + sanitizer: str) -> None: |
| 277 | + """Rewrites Dockerfile of a project to enable cached build scripts.""" |
| 278 | + cached_image_name = _get_project_cache_image_name(project_name, sanitizer) |
| 279 | + |
| 280 | + generated_project_folder = os.path.join(OSS_FUZZ_DIR, 'projects', |
| 281 | + generated_project) |
| 282 | + |
| 283 | + cached_dockerfile = os.path.join(generated_project_folder, |
| 284 | + f'Dockerfile_{sanitizer}_cached') |
| 285 | + if os.path.isfile(cached_dockerfile): |
| 286 | + logger.info('Already converted') |
| 287 | + return |
| 288 | + |
| 289 | + # Check if there is an original Dockerfile, because we should use that in |
| 290 | + # case,as otherwise the "Dockerfile" may be a copy of another sanitizer. |
| 291 | + original_dockerfile = os.path.join(generated_project_folder, |
| 292 | + 'Dockerfile_original') |
| 293 | + if not os.path.isfile(original_dockerfile): |
| 294 | + dockerfile = os.path.join(generated_project_folder, 'Dockerfile') |
| 295 | + shutil.copy(dockerfile, original_dockerfile) |
| 296 | + |
| 297 | + with open(original_dockerfile, 'r') as f: |
| 298 | + docker_content = f.read() |
| 299 | + |
| 300 | + docker_content = docker_content.replace( |
| 301 | + 'FROM gcr.io/oss-fuzz-base/base-builder', f'FROM {cached_image_name}') |
| 302 | + docker_content += '\n' + 'COPY adjusted_build.sh $SRC/build.sh\n' |
| 303 | + |
| 304 | + # Now comment out everything except the first FROM and the last two Dockers |
| 305 | + from_line = -1 |
| 306 | + copy_fuzzer_line = -1 |
| 307 | + copy_build_line = -1 |
| 308 | + |
| 309 | + for line_idx, line in enumerate(docker_content.split('\n')): |
| 310 | + if line.startswith('FROM') and from_line == -1: |
| 311 | + from_line = line_idx |
| 312 | + if line.startswith('COPY'): |
| 313 | + copy_fuzzer_line = copy_build_line |
| 314 | + copy_build_line = line_idx |
| 315 | + |
| 316 | + lines_to_keep = {from_line, copy_fuzzer_line, copy_build_line} |
| 317 | + new_content = '' |
| 318 | + for line_idx, line in enumerate(docker_content.split('\n')): |
| 319 | + if line_idx not in lines_to_keep: |
| 320 | + new_content += f'# {line}\n' |
| 321 | + else: |
| 322 | + new_content += f'{line}\n' |
| 323 | + |
| 324 | + # Overwrite the existing one |
| 325 | + with open(cached_dockerfile, 'w') as f: |
| 326 | + f.write(new_content) |
| 327 | + |
| 328 | + # Copy over adjusted build script |
| 329 | + shutil.copy(os.path.join('fuzzer_build_script', project_name), |
| 330 | + os.path.join(generated_project_folder, 'adjusted_build.sh')) |
| 331 | + |
| 332 | + |
| 333 | +def prepare_build(project_name, sanitizer, generated_project): |
| 334 | + """Prepares the correct Dockerfile to be used for cached builds.""" |
| 335 | + generated_project_folder = os.path.join(OSS_FUZZ_DIR, 'projects', |
| 336 | + generated_project) |
| 337 | + if not ENABLE_CACHING: |
| 338 | + return |
| 339 | + dockerfile_to_use = os.path.join(generated_project_folder, 'Dockerfile') |
| 340 | + original_dockerfile = os.path.join(generated_project_folder, |
| 341 | + 'Dockerfile_original') |
| 342 | + if is_image_cached(project_name, sanitizer): |
| 343 | + logger.info('Using cached dockerfile') |
| 344 | + cached_dockerfile = os.path.join(generated_project_folder, |
| 345 | + f'Dockerfile_{sanitizer}_cached') |
| 346 | + shutil.copy(cached_dockerfile, dockerfile_to_use) |
| 347 | + else: |
| 348 | + logger.info('Using original dockerfile') |
| 349 | + shutil.copy(original_dockerfile, dockerfile_to_use) |
0 commit comments