diff options
author | Ben Wiederhake <BenWiederhake.GitHub@gmx.de> | 2020-08-30 11:51:55 +0200 |
---|---|---|
committer | Andreas Kling <kling@serenityos.org> | 2020-09-12 00:13:29 +0200 |
commit | 98bfcb4b5754948c921ed94851102883121eab5d (patch) | |
tree | 5452433d2a22c41de5393dce7e68ad08eb1f6fce | |
parent | 5d3c437ccea82afbc3eb15da781c49056f1ea778 (diff) | |
download | serenity-98bfcb4b5754948c921ed94851102883121eab5d.zip |
Meta+LibGfx: Fuzz BMP parsing
-rw-r--r-- | Meta/Lagom/Fuzzers/CMakeLists.txt | 9 | ||||
-rw-r--r-- | Meta/Lagom/Fuzzers/FuzzBMP.cpp | 41 |
2 files changed, 50 insertions, 0 deletions
diff --git a/Meta/Lagom/Fuzzers/CMakeLists.txt b/Meta/Lagom/Fuzzers/CMakeLists.txt index cec56eccb6..a52bb14723 100644 --- a/Meta/Lagom/Fuzzers/CMakeLists.txt +++ b/Meta/Lagom/Fuzzers/CMakeLists.txt @@ -1,3 +1,12 @@ +add_executable(FuzzBMP FuzzBMP.cpp) +target_compile_options(FuzzBMP + PRIVATE $<$<C_COMPILER_ID:Clang>:-g -O1 -fsanitize=fuzzer> + ) +target_link_libraries(FuzzBMP + PUBLIC Lagom + PRIVATE $<$<C_COMPILER_ID:Clang>:-fsanitize=fuzzer> + ) + add_executable(FuzzELF FuzzELF.cpp) target_compile_options(FuzzELF PRIVATE $<$<C_COMPILER_ID:Clang>:-g -O1 -fsanitize=fuzzer> diff --git a/Meta/Lagom/Fuzzers/FuzzBMP.cpp b/Meta/Lagom/Fuzzers/FuzzBMP.cpp new file mode 100644 index 0000000000..40ebd22784 --- /dev/null +++ b/Meta/Lagom/Fuzzers/FuzzBMP.cpp @@ -0,0 +1,41 @@ +/* + * Copyright (c) 2020, the SerenityOS developers. + * All rights reserved. + * + * Redistribution and use in source and binary forms, with or without + * modification, are permitted provided that the following conditions are met: + * + * 1. Redistributions of source code must retain the above copyright notice, this + * list of conditions and the following disclaimer. + * + * 2. Redistributions in binary form must reproduce the above copyright notice, + * this list of conditions and the following disclaimer in the documentation + * and/or other materials provided with the distribution. + * + * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" + * AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE + * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE + * DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE + * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL + * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR + * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER + * CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, + * OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE + * OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. + */ + +#include <LibGfx/BMPLoader.h> +#include <stdio.h> + +extern "C" int LLVMFuzzerTestOneInput(const uint8_t* data, size_t size) +{ + Gfx::BMPImageDecoderPlugin loader { data, size }; + auto bitmap = loader.bitmap(); + if (!bitmap) + return 1; + if (bitmap->width() >= 100000 || bitmap->height() >= 100000) { + fprintf(stderr, "Silly bitmap: %dx%d pixels?!\n", bitmap->width(), bitmap->height()); + ASSERT_NOT_REACHED(); + } + return 0; +} |