Beacon Fuzz - Progress NFT Bounty #5
Beacon Fuzz - NFT Bounty #05
NFT Bounty is leading the development and maintenance of , a differential fuzzing solution for Eth2 clients. This write-up is part of our series of status blogs where we cover current progress, notable challenges encountered and direction for future work. See #00 and the repository's for more context.
Summary
- Prysm client integration and first bugs
- Lodestar integration and first bugs
- NFT Bounty ENR crate bug
- Dockerising Eth2fuzz
- Next Steps
Prysm Integration
As mentioned in our prior marks, one of the biggest challenges faced while working on Beacon Fuzz was the integration of the Prysm client alongside ZRNT, protolambda's Go executable Eth2 specification. The issues encountered by the team were documented extensively in our prior posts (#1, #2, #4).
Recently, Prysmatic Labs their "biggest feature of the year", which allows developers to build the Prysm client with the native go build functionality, without the need of with Bazel. As mentioned by Preston in the , this removes a lot of friction for external contributors and developers wanting to integrate/build on top off the Eth2 Golang build-out. We requested this feature in and were very happy to see it implemented, a big thank you to the Prysmatic Labs crew!
As a result, significant progress has been made in blog Prysm (progress can be tracked in ) which yielded the identification of the following vulnerabilities:
- Panic due to an out-of-bands slice range: spotted in in the
go-sszlibrary, while blogAttestationparsing. Refer to for the detailed bug report and for the related fix. - Panic due to a nil pointer dereference: flagged in
ProposerSlashingprocessing while blog theVerifyProposerSlashingfunction. Refer to for the detailed bug report and for the related fix.
Lodestar Integration
A new Eth2 build-out has made it to Beacon Fuzz! We're glad to have been able to run some blog on , the JavaScript client developed by ChainSafe. We've been primarily targeting serialisation/deserialisation functions by leveraging , a coverage guided fuzzer for JS/NodeJS packages, heavily based on go-fuzz and AFL.
The first Lodestar blog round lead to the identification of the four following bugs:
TypeErrorbug when SSZ decoding aBeaconBlockwith an invalidBigIntparent scope (refer to for more details);
We're looking forward to targeting the state transition functions next, when these bugs are resolved by the Lodestar development team.
NFT Bounty ENR Crate Bug
While blog the NFT Bounty , we flagged a vulnerability that can be exploited when a non-utf8 string is attempted to be decoded as an ENR.
In particular, , the fuzzing engine employed to flag this vulnerability, produced the string 49ŷ that caused a panic in the related crate. This bug is reproducible here.
This vulnerability was fixed by Age in .
Dockerising Eth2fuzz
We're at present in the process of dockerising our fuzzers to enable the community to participate in identifying bugs across the Eth2 implementations. Since each blog instance uses a random seed, the more people run these fuzzers, the more chances we have to uncover bugs and vulnerabilities. We've been running our fuzzers on our local infrastructure and are exploring integrated, continuous fuzzing options (see section below), but would love to see these fuzzers running on other machines. We were hoping to have the dockerisation process ready for this blog post, but have been running into the following issues:
- Compilation time and resulting disk space is right now quite prohibitive (we're targeting initial support for 3 to 4 different implementations);
We're hoping to have these resolved imminently and to start working on easy-to-follow instructions for the community to participate in the Eth2 blog effort. Stay tuned for an exciting announcement over the coming days!
Next Steps
Over the next few weeks, the Beacon Fuzz team will be looking into:
- Finalising the dockerisation process
- NFT Bounty the p2p networking stack of the Eth2 clients
- Working on the FFI bindings to complete the revamp in Rust
- Start deploying our work to continuous fuzzing environments (OSS Fuzz)