发表机构
University of Illinois Chicago; Indiana University Bloomington(伊利诺伊大学芝加哥分校; 印第安纳大学布鲁明顿分校)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本SoK系统化Linux内核缺陷从发现到部署的生命周期,划分五个阶段,通过测量syzbot修复缺陷揭示崩溃到补丁差距的结构性原因,指出修复技术应把复现器等产物视为输出而非前提。
AI 中文摘要
自动化内核缺陷发现已取得快速发展。持续模糊测试和静态分析系统(如 syzbot)现在以超出下游流程吸收能力的规模暴露 Linux 内核缺陷。然而,崩溃报告仅仅是个开始。在缺陷被消除之前,它必须经过分类、理解、修补、验证、审查、集成,并经常进行向后移植。这些后续阶段自动化程度远低,导致缺陷发现与补丁部署之间持续存在差距。本 SoK 系统化了从发现到部署的 Linux 内核缺陷生命周期。我们将先前工作和生产系统组织为五个阶段:发现、分类、补丁生成、补丁验证和集成。我们通过内核特有挑战(如并发、隐式不变量、跨系统调用状态、硬件依赖性、缺乏故障隔离以及架构/配置多样性)解释了由此产生的自动化梯度。我们进一步基于对真实 syzbot 修复缺陷的测量来夯实分析。数据表明,崩溃到补丁的差距不仅仅是未修复报告的积压,而是修复管道的结构性故障模式:即使在修复后,缺陷通常仍会开放数周,需要审查驱动的补丁修订,或缺乏当前修复和验证系统所假设的复现器。这暴露了内核安全自动化成熟之处与缺陷关闭实际中断之处之间的不匹配。这些发现揭示了更深层的不匹配:当今的修复和验证技术通常假设可靠的复现器、局部化的根本原因和可检查的正确性预言机,然而这些正是许多真实内核缺陷报告中所缺失的产物。因此,缩小崩溃到补丁的差距需要将这些产物视为要生成的输出,而非要假设的前提。
英文摘要
Automated kernel bug discovery has advanced rapidly. Continuous fuzzing and static analysis systems, such as syzbot, now expose Linux kernel bugs at a scale that downstream processes struggle to absorb. Yet a crash report is only the beginning. Before a bug is eliminated, it must be triaged, understood, patched, validated, reviewed, integrated, and often backported. These later stages remain far less automated, creating a persistent gap between bug discovery and patch deployment. This SoK systematizes the Linux kernel bug lifecycle from discovery to deployment. We organize prior work and production systems into five stages: discovery, triage, patch generation, patch validation, and integration. We explain the resulting automation gradient through kernel-specific challenges such as concurrency, implicit invariants, cross-syscall state, hardware dependence, lack of fault isolation, and architecture/configuration multiplicity. We further ground the analysis in a measurement of real syzbot-fixed bugs. The data shows that the crash-to-patch gap is not merely a backlog of unfixed reports but a structural failure mode of the repair pipeline: even after being fixed, bugs often remain open for weeks, require review-driven patch revisions, or lack reproducers that current repair and validation systems assume. This exposes a mismatch between where kernel-security automation is mature and where bug closure actually breaks down. These findings expose a deeper mismatch: today's repair and validation techniques often assume reliable reproducers, localized root causes, and checkable correctness oracles, yet these are precisely the artifacts missing from many real kernel bug reports. Closing the crash-to-patch gap, therefore, requires treating such artifacts as outputs to be produced, not prerequisites to be assumed.