diff options
Diffstat (limited to 'fuzz/xml_parse_fuzzer.c')
| -rw-r--r-- | fuzz/xml_parse_fuzzer.c | 64 |
1 files changed, 64 insertions, 0 deletions
diff --git a/fuzz/xml_parse_fuzzer.c b/fuzz/xml_parse_fuzzer.c new file mode 100644 index 000000000000..48b50212fa62 --- /dev/null +++ b/fuzz/xml_parse_fuzzer.c @@ -0,0 +1,64 @@ +/* + * Copyright (C) 2016 The Android Open Source Project + * + * Licensed under the Apache License, Version 2.0 (the "License"); + * you may not use this file except in compliance with the License. + * You may obtain a copy of the License at + * + * http://www.apache.org/licenses/LICENSE-2.0 + * + * Unless required by applicable law or agreed to in writing, software + * distributed under the License is distributed on an "AS IS" BASIS, + * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + * See the License for the specific language governing permissions and + * limitations under the License. + */ + +#include <assert.h> +#include <stdint.h> + +#include "expat.h" +#include "siphash.h" + +// Macros to convert preprocessor macros to string literals. See +// https://gcc.gnu.org/onlinedocs/gcc-3.4.3/cpp/Stringification.html +#define xstr(s) str(s) +#define str(s) #s + +// The encoder type that we wish to fuzz should come from the compile-time +// definition `ENCODING_FOR_FUZZING`. This allows us to have a separate fuzzer +// binary for +#ifndef ENCODING_FOR_FUZZING +# error "ENCODING_FOR_FUZZING was not provided to this fuzz target." +#endif + +// 16-byte deterministic hash key. +static unsigned char hash_key[16] = "FUZZING IS FUN!"; + +static void XMLCALL +start(void *userData, const XML_Char *name, const XML_Char **atts) { + (void)userData; + (void)name; + (void)atts; +} +static void XMLCALL +end(void *userData, const XML_Char *name) { + (void)userData; + (void)name; +} + +int +LLVMFuzzerTestOneInput(const uint8_t *data, size_t size) { + XML_Parser p = XML_ParserCreate(xstr(ENCODING_FOR_FUZZING)); + assert(p); + + // Set the hash salt using siphash to generate a deterministic hash. + struct sipkey *key = sip_keyof(hash_key); + XML_SetHashSalt(p, (unsigned long)siphash24(data, size, key)); + + XML_SetElementHandler(p, start, end); + XML_Parse(p, (const XML_Char *)data, size, 0); + XML_Parse(p, (const XML_Char *)data, size, 1); + XML_ParserFree(p); + return 0; +} |
