Example #1
0
    def test_hide_nested_list(self) -> None:
        def hider(secret_data: SecretData) -> None:
            if not isinstance(secret_data.secret, SecretAddress):
                secret_data.secret = SecretAddress(url="blah blah")

        job_template_index = JobTemplateIndex(
            name="test",
            template=JobTemplate(
                os=OS.linux,
                job=JobConfig(name="test",
                              build="test",
                              project="test",
                              duration=1),
                tasks=[],
                notifications=[
                    JobTemplateNotification(
                        container_type=ContainerType.unique_inputs,
                        notification=NotificationConfig(config=TeamsTemplate(
                            url=SecretData(secret="http://test"))),
                    )
                ],
                user_fields=[],
            ),
        )
        ORMMixin.hide_secrets(job_template_index, hider)
        notification = job_template_index.template.notifications[
            0].notification
        if isinstance(notification.config, TeamsTemplate):
            self.assertIsInstance(notification.config.url, SecretData)
            self.assertIsInstance(notification.config.url.secret,
                                  SecretAddress)
        else:
            self.fail(f"Invalid config type {type(notification.config)}")
    def test_path_resolution(self) -> None:
        helper = JobHelper(
            Onefuzz(),
            logging.getLogger(),
            "a",
            "b",
            "c",
            False,
            target_exe=File("README.md"),
            job=Job(
                job_id=UUID("0" * 32),
                state=JobState.init,
                config=JobConfig(project="a", name="a", build="a", duration=1),
            ),
        )
        values = {
            (File("filename.txt"), None): "filename.txt",
            (File("dir/filename.txt"), None): "filename.txt",
            (File("./filename.txt"), None): "filename.txt",
            (File("./filename.txt"), Directory(".")): "filename.txt",
            (File("dir/filename.txt"), Directory("dir")): "filename.txt",
            (File("dir/filename.txt"), Directory("dir/")): "filename.txt",
            (File("dir/filename.txt"), Directory("./dir")): "filename.txt",
            (File("./dir/filename.txt"), Directory("./dir/")): "filename.txt",
        }

        expected = "filename.txt"
        if sys.platform == "linux":
            filename = File("/unused/filename.txt")
            values[(filename, None)] = expected
            values[(filename, Directory("/unused"))] = expected
            values[(filename, Directory("/unused/"))] = expected

        if sys.platform == "windows":
            for filename in [
                    File("c:/unused/filename.txt"),
                    File("c:\\unused/filename.txt"),
                    File("c:\\unused\\filename.txt"),
            ]:
                values[(filename, None)] = expected
                values[(filename, Directory("c:/unused"))] = expected
                values[(filename, Directory("c:/unused/"))] = expected
                values[(filename, Directory("c:\\unused\\"))] = expected
                values[(filename, Directory("c:\\unused\\"))] = expected

        for (args, expected) in values.items():
            self.assertEqual(helper.target_exe_blob_name(*args), expected)

        with self.assertRaises(ValueError):
            helper.target_exe_blob_name(File("dir/filename.txt"),
                                        Directory("other_dir"))
Example #3
0
    def test_sample(self) -> None:
        expected_path = Path(__file__).parent / "data" / "ado-rendered.json"
        with open(expected_path, "r") as handle:
            expected_document = json.load(handle)

        report_path = Path(__file__).parent / "data" / "crash-report-with-html.json"
        with open(report_path, "r") as handle:
            report_raw = json.load(handle)

        ado_path = Path(__file__).parent / "data" / "ado-config.json"
        with open(ado_path, "r") as handle:
            ado_raw = json.load(handle)

        report = Report.parse_obj(report_raw)
        config = ADOTemplate.parse_obj(ado_raw)

        container = Container("containername")
        filename = "test.json"

        job = Job(
            config=JobConfig(project="project", name="name", build="build", duration=1)
        )
        task = Task(
            config=TaskConfig(
                job_id=job.job_id,
                tags={},
                containers=[],
                task=TaskDetails(type=TaskType.libfuzzer_fuzz, duration=1),
            ),
            job_id=job.job_id,
            os=OS.linux,
        )

        renderer = Render(
            container,
            filename,
            report,
            task=task,
            job=job,
            target_url="https://contoso.com/1",
            input_url="https://contoso.com/2",
            report_url="https://contoso.com/3",
        )

        ado = ADO(container, filename, config, report, renderer=renderer)
        work_item_type, document = ado.render_new()
        self.assertEqual(work_item_type, "Bug")

        as_obj = [x.as_dict() for x in document]

        self.assertEqual(as_obj, expected_document)
Example #4
0
from onefuzztypes.primitives import Container, PoolName

from .common import (
    DURATION_HELP,
    POOL_HELP,
    REBOOT_HELP,
    RETRY_COUNT_HELP,
    TAGS_HELP,
    TARGET_EXE_HELP,
    TARGET_OPTIONS_HELP,
    VM_COUNT_HELP,
)

afl_linux = JobTemplate(
    os=OS.linux,
    job=JobConfig(project="", name=Container(""), build="", duration=1),
    tasks=[
        TaskConfig(
            job_id=(UUID(int=0)),
            task=TaskDetails(
                type=TaskType.generic_supervisor,
                duration=1,
                target_exe="fuzz.exe",
                target_env={},
                target_options=[],
                supervisor_exe="",
                supervisor_options=[],
                supervisor_input_marker="@@",
            ),
            pool=TaskPool(count=1, pool_name=PoolName("")),
            containers=[
Example #5
0
from onefuzztypes.enums import ContainerType, TaskType
from onefuzztypes.models import (
    JobConfig,
    TaskConfig,
    TaskContainers,
    TaskDetails,
    TaskPool,
)

from .enums import UserFieldOperation, UserFieldType
from .models import OnefuzzTemplate, UserField, UserFieldLocation

TEMPLATES = {
    "afl_basic":
    OnefuzzTemplate(
        job=JobConfig(project="", name="", build="", duration=1),
        tasks=[
            TaskConfig(
                job_id=(UUID(int=0)),
                task=TaskDetails(
                    type=TaskType.generic_supervisor,
                    duration=1,
                    target_exe="fuzz.exe",
                    target_env={},
                    target_options=[],
                    supervisor_exe="{tools_dir}/afl-fuzz",
                    supervisor_options=[
                        "-d",
                        "-i",
                        "{input_corpus}",
                        "-o",
Example #6
0
def main() -> None:
    if len(sys.argv) < 2:
        print(f"usage: {__file__} [OUTPUT_FILE]")
        sys.exit(1)
    filename = sys.argv[1]

    task_config = TaskConfig(
        job_id=UUID(int=0),
        task=TaskDetails(
            type=TaskType.libfuzzer_fuzz,
            duration=1,
            target_exe="fuzz.exe",
            target_env={},
            target_options=[],
        ),
        containers=[
            TaskContainers(name=Container("my-setup"),
                           type=ContainerType.setup),
            TaskContainers(name=Container("my-inputs"),
                           type=ContainerType.inputs),
            TaskContainers(name=Container("my-crashes"),
                           type=ContainerType.crashes),
        ],
        tags={},
    )
    report = Report(
        input_blob=BlobRef(
            account="contoso-storage-account",
            container=Container("crashes"),
            name="input.txt",
        ),
        executable="fuzz.exe",
        crash_type="example crash report type",
        crash_site="example crash site",
        call_stack=["#0 line", "#1 line", "#2 line"],
        call_stack_sha256=ZERO_SHA256,
        input_sha256=EMPTY_SHA256,
        asan_log="example asan log",
        task_id=UUID(int=0),
        job_id=UUID(int=0),
        scariness_score=10,
        scariness_description="example-scariness",
        tool_name="libfuzzer",
        tool_version="1.2.3",
        onefuzz_version="1.2.3",
    )
    examples: List[Event] = [
        EventPing(ping_id=UUID(int=0)),
        EventTaskCreated(
            job_id=UUID(int=0),
            task_id=UUID(int=0),
            config=task_config,
            user_info=UserInfo(
                application_id=UUID(int=0),
                object_id=UUID(int=0),
                upn="*****@*****.**",
            ),
        ),
        EventTaskStopped(
            job_id=UUID(int=0),
            task_id=UUID(int=0),
            user_info=UserInfo(
                application_id=UUID(int=0),
                object_id=UUID(int=0),
                upn="*****@*****.**",
            ),
            config=task_config,
        ),
        EventTaskFailed(
            job_id=UUID(int=0),
            task_id=UUID(int=0),
            error=Error(code=ErrorCode.TASK_FAILED,
                        errors=["example error message"]),
            user_info=UserInfo(
                application_id=UUID(int=0),
                object_id=UUID(int=0),
                upn="*****@*****.**",
            ),
            config=task_config,
        ),
        EventTaskStateUpdated(
            job_id=UUID(int=0),
            task_id=UUID(int=0),
            state=TaskState.init,
            config=task_config,
        ),
        EventProxyCreated(region=Region("eastus"), proxy_id=UUID(int=0)),
        EventProxyDeleted(region=Region("eastus"), proxy_id=UUID(int=0)),
        EventProxyFailed(
            region=Region("eastus"),
            proxy_id=UUID(int=0),
            error=Error(code=ErrorCode.PROXY_FAILED,
                        errors=["example error message"]),
        ),
        EventProxyStateUpdated(
            region=Region("eastus"),
            proxy_id=UUID(int=0),
            state=VmState.init,
        ),
        EventPoolCreated(
            pool_name=PoolName("example"),
            os=OS.linux,
            arch=Architecture.x86_64,
            managed=True,
        ),
        EventPoolDeleted(pool_name=PoolName("example")),
        EventScalesetCreated(
            scaleset_id=UUID(int=0),
            pool_name=PoolName("example"),
            vm_sku="Standard_D2s_v3",
            image="Canonical:UbuntuServer:18.04-LTS:latest",
            region=Region("eastus"),
            size=10,
        ),
        EventScalesetFailed(
            scaleset_id=UUID(int=0),
            pool_name=PoolName("example"),
            error=Error(code=ErrorCode.UNABLE_TO_RESIZE,
                        errors=["example error message"]),
        ),
        EventScalesetDeleted(scaleset_id=UUID(int=0),
                             pool_name=PoolName("example")),
        EventScalesetStateUpdated(
            scaleset_id=UUID(int=0),
            pool_name=PoolName("example"),
            state=ScalesetState.init,
        ),
        EventScalesetResizeScheduled(scaleset_id=UUID(int=0),
                                     pool_name=PoolName("example"),
                                     size=0),
        EventJobCreated(
            job_id=UUID(int=0),
            config=JobConfig(
                project="example project",
                name="example name",
                build="build 1",
                duration=24,
            ),
        ),
        EventJobStopped(
            job_id=UUID(int=0),
            config=JobConfig(
                project="example project",
                name="example name",
                build="build 1",
                duration=24,
            ),
            task_info=[
                JobTaskStopped(
                    task_id=UUID(int=0),
                    task_type=TaskType.libfuzzer_fuzz,
                    error=Error(code=ErrorCode.TASK_FAILED,
                                errors=["example error message"]),
                ),
                JobTaskStopped(
                    task_id=UUID(int=1),
                    task_type=TaskType.coverage,
                ),
            ],
        ),
        EventNodeCreated(machine_id=UUID(int=0),
                         pool_name=PoolName("example")),
        EventNodeDeleted(machine_id=UUID(int=0),
                         pool_name=PoolName("example")),
        EventNodeStateUpdated(
            machine_id=UUID(int=0),
            pool_name=PoolName("example"),
            state=NodeState.setting_up,
        ),
        EventRegressionReported(
            regression_report=RegressionReport(
                crash_test_result=CrashTestResult(crash_report=report),
                original_crash_test_result=CrashTestResult(
                    crash_report=report),
            ),
            container=Container("container-name"),
            filename="example.json",
        ),
        EventCrashReported(
            container=Container("container-name"),
            filename="example.json",
            report=report,
        ),
        EventFileAdded(container=Container("container-name"),
                       filename="example.txt"),
        EventNodeHeartbeat(machine_id=UUID(int=0),
                           pool_name=PoolName("example")),
        EventTaskHeartbeat(task_id=UUID(int=0),
                           job_id=UUID(int=0),
                           config=task_config),
        EventInstanceConfigUpdated(config=InstanceConfig(
            admins=[UUID(int=0)], allowed_aad_tenants=[UUID(int=0)])),
    ]

    # works around `mypy` not handling that Union has `__args__`
    for event in getattr(Event, "__args__", []):
        seen = False
        for value in examples:
            if isinstance(value, event):
                seen = True
                break
        assert seen, "missing event type definition: %s" % event.__name__

    event_types = [get_event_type(x) for x in examples]

    for event_type in EventType:
        assert event_type in event_types, (
            "missing event type definition: %s" % event_type.name)

    message = WebhookMessage(
        webhook_id=UUID(int=0),
        event_id=UUID(int=0),
        event_type=EventType.ping,
        event=EventPing(ping_id=UUID(int=0)),
        instance_id=UUID(int=0),
        instance_name="example",
    )

    message_event_grid = WebhookMessageEventGrid(
        dataVersion="1.0.0",
        subject="example",
        eventType=EventType.ping,
        eventTime=datetime.datetime.min,
        id=UUID(int=0),
        data=EventPing(ping_id=UUID(int=0)),
    )

    message_event_grid_json = json.dumps(
        [
            json.loads(
                message_event_grid.json(
                    indent=4, exclude_none=True, sort_keys=True))
        ],
        indent=4,
        sort_keys=True,
    )

    result = ""
    result += layer(
        1,
        "Webhook Events",
        "This document describes the basic webhook event subscriptions "
        "available in OneFuzz",
    )
    result += layer(
        2,
        "Payload",
        "Each event will be submitted via HTTP POST to the user provided URL.",
    )

    result += typed(
        3,
        "Example",
        message.json(indent=4, exclude_none=True, sort_keys=True),
        "json",
    )

    result += layer(
        2,
        "Event Grid Payload format",
        "If webhook is set to have Event Grid message format then "
        "the payload will look as follows:",
    )

    result += typed(
        3,
        "Example",
        message_event_grid_json,
        "json",
    )

    result += layer(2, "Event Types (EventType)")

    event_map = {get_event_type(x).name: x for x in examples}

    for name in sorted(event_map.keys()):
        result += f"* [{name}](#{name})\n"

    result += "\n"

    for name in sorted(event_map.keys()):
        example = event_map[name]
        result += layer(3, name)
        result += typed(
            4,
            "Example",
            example.json(indent=4, exclude_none=True, sort_keys=True),
            "json",
        )
        result += typed(4, "Schema",
                        example.schema_json(indent=4, sort_keys=True), "json")

    result += typed(2, "Full Event Schema",
                    message.schema_json(indent=4, sort_keys=True), "json")

    with open(filename, "w", newline="\n", encoding="utf8") as handle:
        handle.write(result)
Example #7
0
def main() -> None:
    task_config = TaskConfig(
        job_id=UUID(int=0),
        task=TaskDetails(
            type=TaskType.libfuzzer_fuzz,
            duration=1,
            target_exe="fuzz.exe",
            target_env={},
            target_options=[],
        ),
        containers=[
            TaskContainers(name=Container("my-setup"), type=ContainerType.setup),
            TaskContainers(name=Container("my-inputs"), type=ContainerType.inputs),
            TaskContainers(name=Container("my-crashes"), type=ContainerType.crashes),
        ],
        tags={},
    )
    examples: List[Event] = [
        EventPing(ping_id=UUID(int=0)),
        EventTaskCreated(
            job_id=UUID(int=0),
            task_id=UUID(int=0),
            config=task_config,
            user_info=UserInfo(
                application_id=UUID(int=0),
                object_id=UUID(int=0),
                upn="*****@*****.**",
            ),
        ),
        EventTaskStopped(
            job_id=UUID(int=0),
            task_id=UUID(int=0),
            user_info=UserInfo(
                application_id=UUID(int=0),
                object_id=UUID(int=0),
                upn="*****@*****.**",
            ),
            config=task_config,
        ),
        EventTaskFailed(
            job_id=UUID(int=0),
            task_id=UUID(int=0),
            error=Error(code=ErrorCode.TASK_FAILED, errors=["example error message"]),
            user_info=UserInfo(
                application_id=UUID(int=0),
                object_id=UUID(int=0),
                upn="*****@*****.**",
            ),
            config=task_config,
        ),
        EventTaskStateUpdated(
            job_id=UUID(int=0),
            task_id=UUID(int=0),
            state=TaskState.init,
            config=task_config,
        ),
        EventProxyCreated(region=Region("eastus")),
        EventProxyDeleted(region=Region("eastus")),
        EventProxyFailed(
            region=Region("eastus"),
            error=Error(code=ErrorCode.PROXY_FAILED, errors=["example error message"]),
        ),
        EventPoolCreated(
            pool_name=PoolName("example"),
            os=OS.linux,
            arch=Architecture.x86_64,
            managed=True,
        ),
        EventPoolDeleted(pool_name=PoolName("example")),
        EventScalesetCreated(
            scaleset_id=UUID(int=0),
            pool_name=PoolName("example"),
            vm_sku="Standard_D2s_v3",
            image="Canonical:UbuntuServer:18.04-LTS:latest",
            region=Region("eastus"),
            size=10,
        ),
        EventScalesetFailed(
            scaleset_id=UUID(int=0),
            pool_name=PoolName("example"),
            error=Error(
                code=ErrorCode.UNABLE_TO_RESIZE, errors=["example error message"]
            ),
        ),
        EventScalesetDeleted(scaleset_id=UUID(int=0), pool_name=PoolName("example")),
        EventJobCreated(
            job_id=UUID(int=0),
            config=JobConfig(
                project="example project",
                name="example name",
                build="build 1",
                duration=24,
            ),
        ),
        EventJobStopped(
            job_id=UUID(int=0),
            config=JobConfig(
                project="example project",
                name="example name",
                build="build 1",
                duration=24,
            ),
            task_info=[
                JobTaskStopped(
                    task_id=UUID(int=0),
                    task_type=TaskType.libfuzzer_fuzz,
                    error=Error(
                        code=ErrorCode.TASK_FAILED, errors=["example error message"]
                    ),
                ),
                JobTaskStopped(
                    task_id=UUID(int=1),
                    task_type=TaskType.libfuzzer_coverage,
                ),
            ],
        ),
        EventNodeCreated(machine_id=UUID(int=0), pool_name=PoolName("example")),
        EventNodeDeleted(machine_id=UUID(int=0), pool_name=PoolName("example")),
        EventNodeStateUpdated(
            machine_id=UUID(int=0),
            pool_name=PoolName("example"),
            state=NodeState.setting_up,
        ),
        EventCrashReported(
            container=Container("container-name"),
            filename="example.json",
            report=Report(
                input_blob=BlobRef(
                    account="contoso-storage-account",
                    container=Container("crashes"),
                    name="input.txt",
                ),
                executable="fuzz.exe",
                crash_type="example crash report type",
                crash_site="example crash site",
                call_stack=["#0 line", "#1 line", "#2 line"],
                call_stack_sha256=ZERO_SHA256,
                input_sha256=EMPTY_SHA256,
                asan_log="example asan log",
                task_id=UUID(int=0),
                job_id=UUID(int=0),
                scariness_score=10,
                scariness_description="example-scariness",
            ),
        ),
        EventFileAdded(container=Container("container-name"), filename="example.txt"),
        EventNodeHeartbeat(machine_id=UUID(int=0), pool_name=PoolName("example")),
        EventTaskHeartbeat(task_id=UUID(int=0), job_id=UUID(int=0), config=task_config),
    ]

    # works around `mypy` not handling that Union has `__args__`
    for event in getattr(Event, "__args__", []):
        seen = False
        for value in examples:
            if isinstance(value, event):
                seen = True
                break
        assert seen, "missing event type definition: %s" % event.__name__

    event_types = [get_event_type(x) for x in examples]

    for event_type in EventType:
        assert event_type in event_types, (
            "missing event type definition: %s" % event_type.name
        )

    message = WebhookMessage(
        webhook_id=UUID(int=0),
        event_id=UUID(int=0),
        event_type=EventType.ping,
        event=EventPing(ping_id=UUID(int=0)),
        instance_id=UUID(int=0),
        instance_name="example",
    )

    layer(
        1,
        "Webhook Events",
        "This document describes the basic webhook event subscriptions "
        "available in OneFuzz",
    )
    layer(
        2,
        "Payload",
        "Each event will be submitted via HTTP POST to the user provided URL.",
    )

    typed(
        3, "Example", message.json(indent=4, exclude_none=True, sort_keys=True), "json"
    )
    layer(2, "Event Types (EventType)")

    event_map = {get_event_type(x).name: x for x in examples}

    for name in sorted(event_map.keys()):
        print(f"* [{name}](#{name})")

    print()

    for name in sorted(event_map.keys()):
        example = event_map[name]
        layer(3, name)
        typed(
            4,
            "Example",
            example.json(indent=4, exclude_none=True, sort_keys=True),
            "json",
        )
        typed(4, "Schema", example.schema_json(indent=4, sort_keys=True), "json")

    typed(2, "Full Event Schema", message.schema_json(indent=4, sort_keys=True), "json")