Automated firmware testing using firmware-hardware interaction patterns

Automated firmware testing using firmware-hardware interaction patterns
复制标题

使用固件-硬件交互模式进行自动化固件测试

DOI:
10.1145/2656075.2656080
复制
发表时间:
2014
期刊:
2014 International Conference on Hardware/Software Codesign and System Synthesis (CODES+ISSS)
影响因子:
--
通讯作者:
S. Malik
S. Malik
中科院分区:
--
文献类型:
--
作者:
Sunha Ahn;S. Malik

文献摘要

被引文献

相似文献

固件是可以直接访问硬件的低级软件,通常与硬件平台一起提供。系统的这一组成部分的规模和重要性不断增加,因此固件验证是系统验证的关键部分。固件验证依赖于交互硬件组件,这些组件通常要到设计后期才可用。这通常通过共同模拟基于C/C++的固件代码和HDL硬件模型(包括SystemC)来解决。然而,这往往是缓慢的,并且由于并发固件和硬件线程之间的大量可能的交织而进一步加剧。通常,在协同仿真中,诸如SystemC调度器的调度器将仅探索单个或最多少量的可能的固件-硬件交织,并且因此可能错过关键错误。在本文中,我们提出了一种替代方法,固件验证,是基于自动生成一个测试集的固件的目标是完整的路径覆盖,同时考虑其与硬件和其他固件线程的相互作用。它使用基于服务功能的事务级模型(TLM),该模型过去曾用于固件-硬件协同设计。测试生成基于concolic测试,concolic测试已成功地应用于软件测试生成。然而,现有的concolic测试工具用于顺序代码的测试生成,并且不能在测试生成期间直接考虑其他硬件/固件线程与目标固件线程的交互。我们通过利用可以从TLM分析的固件和硬件线程之间的特定交互模式来解决此限制。我们将展示这些模式,沿着与固件和硬件线程被用来自动生成一个顺序的程序,测试相当于目标固件事务,可以使用一个标准的顺序程序concolic测试生成器。生成的测试可以(i)直接用于固件事务,以及(ii)考虑多线程交互。这些交互模式实际上是相关的,因为它们在实践中经常出现在真实的固件基准测试中,例如Linux设备驱动程序代码及其交互的QEMU仿真硬件代码。最后,我们通过一个实际的实现,是自动化的,并建立在上面的框架-C,静态代码分析器,和KLEE,concolic测试工具,这些基准证明了我们的技术的有效性。
Firmware is low-level software which can directly access hardware and is often shipped with the hardware platform. This component of the system is increasing in scale and importance, and thus firmware validation is a critical part of system validation. Firmware validation relies on the interacting hardware components which are usually not available until the late design stages. This is generally addressed through co-simulating C/C++ based firmware code and HDL hardware models (including SystemC). However, this tends to be slow, and is further exacerbated by the large number of possible interleavings between the concurrent firmware and hardware threads. Typically, in the co-simulation, the scheduler, such as the SystemC scheduler, will only explore a single, or at best a small number of possible firmware-hardware interleavings and thus may miss critical bugs. In this paper we present an alternative approach to firmware validation that is based on automatically generating a test-set for the firmware with the goal of complete path coverage while considering its interactions with hardware and other firmware threads. It uses a service-function based Transaction Level Model (TLM) which has been used in the past for firmware-hardware codesign. The test generation is based on concolic testing which has been used successfully in software test generation. However, existing concolic testing tools are used for test-generation of sequential code, and cannot directly consider the interaction of other hardware/firmware threads with the target firmware thread during test generation. We address this limitation by exploiting specific interaction patterns between the firmware and hardware threads that can be analyzed from the TLM. We show how these patterns, along with the firmware and hardware threads are used to automatically generate a sequential program that is test-equivalent to the target firmware transaction and that can be used with a standard sequential program concolic test generator. The tests generated can be (i) directly used for the firmware transaction and (ii) account for the multi-threaded interactions. These interaction patterns are practically relevant as they occur often in practice in real firmware benchmarks such as Linux device driver code, and its interacting QEMU emulated hardware code. Finally, we demonstrate the efficacy of our techniques for these benchmarks through a practical implementation that is automated and built on top of Frama-C, a static code analyzer, and KLEE, a concolic testing tool.