-
Notifications
You must be signed in to change notification settings - Fork 1
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
- Loading branch information
1 parent
02227c3
commit 515f6a6
Showing
1 changed file
with
266 additions
and
0 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,266 @@ | ||
<!DOCTYPE HTML> | ||
<html lang="en" class="light" dir="ltr"> | ||
<head> | ||
<!-- Book generated using mdBook --> | ||
<meta charset="UTF-8"> | ||
<title>How does Phink work - Phink Book</title> | ||
|
||
|
||
<!-- Custom HTML head --> | ||
|
||
<meta name="description" content="Documentation for Phink fuzzer"> | ||
<meta name="viewport" content="width=device-width, initial-scale=1"> | ||
<meta name="theme-color" content="#ffffff"> | ||
|
||
<link rel="icon" href="favicon.svg"> | ||
<link rel="shortcut icon" href="favicon.png"> | ||
<link rel="stylesheet" href="css/variables.css"> | ||
<link rel="stylesheet" href="css/general.css"> | ||
<link rel="stylesheet" href="css/chrome.css"> | ||
<link rel="stylesheet" href="css/print.css" media="print"> | ||
|
||
<!-- Fonts --> | ||
<link rel="stylesheet" href="FontAwesome/css/font-awesome.css"> | ||
<link rel="stylesheet" href="fonts/fonts.css"> | ||
|
||
<!-- Highlight.js Stylesheets --> | ||
<link rel="stylesheet" href="highlight.css"> | ||
<link rel="stylesheet" href="tomorrow-night.css"> | ||
<link rel="stylesheet" href="ayu-highlight.css"> | ||
|
||
<!-- Custom theme stylesheets --> | ||
|
||
</head> | ||
<body class="sidebar-visible no-js"> | ||
<div id="body-container"> | ||
<!-- Provide site root to javascript --> | ||
<script> | ||
var path_to_root = ""; | ||
var default_theme = window.matchMedia("(prefers-color-scheme: dark)").matches ? "navy" : "light"; | ||
</script> | ||
|
||
<!-- Work around some values being stored in localStorage wrapped in quotes --> | ||
<script> | ||
try { | ||
var theme = localStorage.getItem('mdbook-theme'); | ||
var sidebar = localStorage.getItem('mdbook-sidebar'); | ||
|
||
if (theme.startsWith('"') && theme.endsWith('"')) { | ||
localStorage.setItem('mdbook-theme', theme.slice(1, theme.length - 1)); | ||
} | ||
|
||
if (sidebar.startsWith('"') && sidebar.endsWith('"')) { | ||
localStorage.setItem('mdbook-sidebar', sidebar.slice(1, sidebar.length - 1)); | ||
} | ||
} catch (e) { } | ||
</script> | ||
|
||
<!-- Set the theme before any content is loaded, prevents flash --> | ||
<script> | ||
var theme; | ||
try { theme = localStorage.getItem('mdbook-theme'); } catch(e) { } | ||
if (theme === null || theme === undefined) { theme = default_theme; } | ||
var html = document.querySelector('html'); | ||
html.classList.remove('light') | ||
html.classList.add(theme); | ||
var body = document.querySelector('body'); | ||
body.classList.remove('no-js') | ||
body.classList.add('js'); | ||
</script> | ||
|
||
<input type="checkbox" id="sidebar-toggle-anchor" class="hidden"> | ||
|
||
<!-- Hide / unhide sidebar before it is displayed --> | ||
<script> | ||
var body = document.querySelector('body'); | ||
var sidebar = null; | ||
var sidebar_toggle = document.getElementById("sidebar-toggle-anchor"); | ||
if (document.body.clientWidth >= 1080) { | ||
try { sidebar = localStorage.getItem('mdbook-sidebar'); } catch(e) { } | ||
sidebar = sidebar || 'visible'; | ||
} else { | ||
sidebar = 'hidden'; | ||
} | ||
sidebar_toggle.checked = sidebar === 'visible'; | ||
body.classList.remove('sidebar-visible'); | ||
body.classList.add("sidebar-" + sidebar); | ||
</script> | ||
|
||
<nav id="sidebar" class="sidebar" aria-label="Table of contents"> | ||
<div class="sidebar-scrollbox"> | ||
<ol class="chapter"><li class="chapter-item expanded affix "><a href="INTRO.html">Introduction</a></li><li class="chapter-item expanded affix "><li class="part-title">User guide</li><li class="chapter-item expanded "><a href="START.html"><strong aria-hidden="true">1.</strong> Installation</a></li><li class="chapter-item expanded "><a href="CONFIG.html"><strong aria-hidden="true">2.</strong> Configuration</a></li><li class="chapter-item expanded "><a href="CAMPAIGN.html"><strong aria-hidden="true">3.</strong> Starting a campaign</a></li><li class="chapter-item expanded "><a href="RUNTIME.html"><strong aria-hidden="true">4.</strong> Plug-in your runtime</a></li><li class="chapter-item expanded "><a href="SEEDS.html"><strong aria-hidden="true">5.</strong> Seeds</a></li><li class="chapter-item expanded affix "><li class="part-title">Concepts and understanding</li><li class="chapter-item expanded "><a href="CONCEPT.html"><strong aria-hidden="true">6.</strong> Concept and terminology</a></li><li class="chapter-item expanded "><a href="TECH.html" class="active"><strong aria-hidden="true">7.</strong> How does Phink work</a></li><li class="chapter-item expanded "><a href="TROUBLESHOTING.html"><strong aria-hidden="true">8.</strong> Troubleshoting</a></li></ol> | ||
</div> | ||
<div id="sidebar-resize-handle" class="sidebar-resize-handle"> | ||
<div class="sidebar-resize-indicator"></div> | ||
</div> | ||
</nav> | ||
|
||
<!-- Track and set sidebar scroll position --> | ||
<script> | ||
var sidebarScrollbox = document.querySelector('#sidebar .sidebar-scrollbox'); | ||
sidebarScrollbox.addEventListener('click', function(e) { | ||
if (e.target.tagName === 'A') { | ||
sessionStorage.setItem('sidebar-scroll', sidebarScrollbox.scrollTop); | ||
} | ||
}, { passive: true }); | ||
var sidebarScrollTop = sessionStorage.getItem('sidebar-scroll'); | ||
sessionStorage.removeItem('sidebar-scroll'); | ||
if (sidebarScrollTop) { | ||
// preserve sidebar scroll position when navigating via links within sidebar | ||
sidebarScrollbox.scrollTop = sidebarScrollTop; | ||
} else { | ||
// scroll sidebar to current active section when navigating via "next/previous chapter" buttons | ||
var activeSection = document.querySelector('#sidebar .active'); | ||
if (activeSection) { | ||
activeSection.scrollIntoView({ block: 'center' }); | ||
} | ||
} | ||
</script> | ||
|
||
<div id="page-wrapper" class="page-wrapper"> | ||
|
||
<div class="page"> | ||
<div id="menu-bar-hover-placeholder"></div> | ||
<div id="menu-bar" class="menu-bar sticky"> | ||
<div class="left-buttons"> | ||
<label id="sidebar-toggle" class="icon-button" for="sidebar-toggle-anchor" title="Toggle Table of Contents" aria-label="Toggle Table of Contents" aria-controls="sidebar"> | ||
<i class="fa fa-bars"></i> | ||
</label> | ||
<button id="theme-toggle" class="icon-button" type="button" title="Change theme" aria-label="Change theme" aria-haspopup="true" aria-expanded="false" aria-controls="theme-list"> | ||
<i class="fa fa-paint-brush"></i> | ||
</button> | ||
<ul id="theme-list" class="theme-popup" aria-label="Themes" role="menu"> | ||
<li role="none"><button role="menuitem" class="theme" id="light">Light</button></li> | ||
<li role="none"><button role="menuitem" class="theme" id="rust">Rust</button></li> | ||
<li role="none"><button role="menuitem" class="theme" id="coal">Coal</button></li> | ||
<li role="none"><button role="menuitem" class="theme" id="navy">Navy</button></li> | ||
<li role="none"><button role="menuitem" class="theme" id="ayu">Ayu</button></li> | ||
</ul> | ||
<button id="search-toggle" class="icon-button" type="button" title="Search. (Shortkey: s)" aria-label="Toggle Searchbar" aria-expanded="false" aria-keyshortcuts="S" aria-controls="searchbar"> | ||
<i class="fa fa-search"></i> | ||
</button> | ||
</div> | ||
|
||
<h1 class="menu-title">Phink Book</h1> | ||
|
||
<div class="right-buttons"> | ||
<a href="print.html" title="Print this book" aria-label="Print this book"> | ||
<i id="print-button" class="fa fa-print"></i> | ||
</a> | ||
<a href="https://github.com/srlabs/phink/" title="Git repository" aria-label="Git repository"> | ||
<i id="git-repository-button" class="fa fa-github"></i> | ||
</a> | ||
<a href="https://github.com/srlabs/phink/blob/main/src/src/TECH.md" title="Suggest an edit" aria-label="Suggest an edit"> | ||
<i id="git-edit-button" class="fa fa-edit"></i> | ||
</a> | ||
|
||
</div> | ||
</div> | ||
|
||
<div id="search-wrapper" class="hidden"> | ||
<form id="searchbar-outer" class="searchbar-outer"> | ||
<input type="search" id="searchbar" name="searchbar" placeholder="Search this book ..." aria-controls="searchresults-outer" aria-describedby="searchresults-header"> | ||
</form> | ||
<div id="searchresults-outer" class="searchresults-outer hidden"> | ||
<div id="searchresults-header" class="searchresults-header"></div> | ||
<ul id="searchresults"> | ||
</ul> | ||
</div> | ||
</div> | ||
|
||
<!-- Apply ARIA attributes after the sidebar and the sidebar toggle button are added to the DOM --> | ||
<script> | ||
document.getElementById('sidebar-toggle').setAttribute('aria-expanded', sidebar === 'visible'); | ||
document.getElementById('sidebar').setAttribute('aria-hidden', sidebar !== 'visible'); | ||
Array.from(document.querySelectorAll('#sidebar a')).forEach(function(link) { | ||
link.setAttribute('tabIndex', sidebar === 'visible' ? 0 : -1); | ||
}); | ||
</script> | ||
|
||
<div id="content" class="content"> | ||
<main> | ||
<h1 id="how-phink-works"><a class="header" href="#how-phink-works">How Phink Works</a></h1> | ||
<p>Phink is built on top of AFL++, leveraging its capabilities to provide effective fuzz testing for ink! smart contracts. | ||
Here’s an overview of how it operates:</p> | ||
<h2 id="afl-integration"><a class="header" href="#afl-integration">AFL++ Integration</a></h2> | ||
<p>Phink utilizes AFL++ through two key components:</p> | ||
<ul> | ||
<li><strong>ziggy</strong>: A multifuzzing crate that enables integration with multiple fuzzers.</li> | ||
<li><strong>afl.rs</strong>: A crate that spawns AFL++ fuzzers, facilitating seamless mutation and coverage tracking.</li> | ||
</ul> | ||
<h3 id="afl-mechanics"><a class="header" href="#afl-mechanics">AFL++ Mechanics</a></h3> | ||
<p>AFL++ mutates the input bytes and evaluates whether these mutations increase code coverage. If a mutation results in new | ||
execution paths, the modified seed is retained in the corpus. This iterative process enhances the likelihood of | ||
discovering hidden vulnerabilities.</p> | ||
<h3 id="monitoring-execution"><a class="header" href="#monitoring-execution">Monitoring Execution</a></h3> | ||
<p>Users can monitor the execution logs using familiar AFL++ tools. For instance, by using <code>tail</code>, you can view real-time | ||
fuzzer logs and activity:</p> | ||
<pre><code class="language-bash">tail -f output/phink/logs/afl.log | ||
tail -f output/phink/logs/afl_1.log #if multi-threaded | ||
</code></pre> | ||
<p>Additionally, tools like <code>afl_showmap</code> allow developers to debug and visualize the coverage maps.</p> | ||
<h2 id="coverage-guided-strategy"><a class="header" href="#coverage-guided-strategy">Coverage-Guided Strategy</a></h2> | ||
<p>Currently, Phink employs a partially coverage-guided approach. While full coverage feedback from low-level | ||
instrumentation is not available yet, plans are underway to integrate this capability | ||
via <a href="https://github.com/wasmi-labs/wasmi">WASMI</a> or <a href="https://github.com/koute/polkavm">PolkaVM</a> in future | ||
versions.</p> | ||
<h2 id="execution-and-validation"><a class="header" href="#execution-and-validation">Execution and Validation</a></h2> | ||
<p>For each generated seed, Phink executes the associated input on a mock-emulated ‘node’. | ||
This setup ensures that invariants are verified : known selectors are checked to ensure that | ||
invariants hold across different message calls.</p> | ||
<h2 id="contract-instrumentation"><a class="header" href="#contract-instrumentation">Contract Instrumentation</a></h2> | ||
<p>Phink instruments contracts using the <code>syn</code> crate, allowing for precise modification and analysis of the smart contract | ||
code. This instrumentation is crucial for identifying potential vulnerabilities and ensuring the integrity of the fuzz | ||
testing process.</p> | ||
|
||
</main> | ||
|
||
<nav class="nav-wrapper" aria-label="Page navigation"> | ||
<!-- Mobile navigation buttons --> | ||
<a rel="prev" href="CONCEPT.html" class="mobile-nav-chapters previous" title="Previous chapter" aria-label="Previous chapter" aria-keyshortcuts="Left"> | ||
<i class="fa fa-angle-left"></i> | ||
</a> | ||
|
||
<a rel="next prefetch" href="TROUBLESHOTING.html" class="mobile-nav-chapters next" title="Next chapter" aria-label="Next chapter" aria-keyshortcuts="Right"> | ||
<i class="fa fa-angle-right"></i> | ||
</a> | ||
|
||
<div style="clear: both"></div> | ||
</nav> | ||
</div> | ||
</div> | ||
|
||
<nav class="nav-wide-wrapper" aria-label="Page navigation"> | ||
<a rel="prev" href="CONCEPT.html" class="nav-chapters previous" title="Previous chapter" aria-label="Previous chapter" aria-keyshortcuts="Left"> | ||
<i class="fa fa-angle-left"></i> | ||
</a> | ||
|
||
<a rel="next prefetch" href="TROUBLESHOTING.html" class="nav-chapters next" title="Next chapter" aria-label="Next chapter" aria-keyshortcuts="Right"> | ||
<i class="fa fa-angle-right"></i> | ||
</a> | ||
</nav> | ||
|
||
</div> | ||
|
||
|
||
|
||
|
||
<script> | ||
window.playground_copyable = true; | ||
</script> | ||
|
||
|
||
<script src="elasticlunr.min.js"></script> | ||
<script src="mark.min.js"></script> | ||
<script src="searcher.js"></script> | ||
|
||
<script src="clipboard.min.js"></script> | ||
<script src="highlight.js"></script> | ||
<script src="book.js"></script> | ||
|
||
<!-- Custom JS scripts --> | ||
|
||
|
||
</div> | ||
</body> | ||
</html> |