39 lines
1.2 KiB
C++
39 lines
1.2 KiB
C++
|
|
// fuzz_config.cpp - libFuzzer harness for the .rc parser.
|
||
|
|
//
|
||
|
|
// Built and driven by tools/fuzz.py with clang++ -fsanitize=fuzzer. The
|
||
|
|
// parser is exercised on raw bytes through the same `parse_rc_stream` path
|
||
|
|
// used by the real init. `@import` is rejected inside the harness (the
|
||
|
|
// opener throws) so fuzz input can never open real files such as /dev/zero.
|
||
|
|
#include "../src/config.cpp"
|
||
|
|
|
||
|
|
#include <cstddef>
|
||
|
|
#include <cstdint>
|
||
|
|
#include <memory>
|
||
|
|
#include <sstream>
|
||
|
|
#include <string>
|
||
|
|
#include <vector>
|
||
|
|
|
||
|
|
namespace {
|
||
|
|
|
||
|
|
struct NoImports {
|
||
|
|
std::unique_ptr<std::istream> operator()(const std::string&) const {
|
||
|
|
throw std::runtime_error("fuzz: @import disabled");
|
||
|
|
}
|
||
|
|
};
|
||
|
|
|
||
|
|
} // namespace
|
||
|
|
|
||
|
|
extern "C" int LLVMFuzzerTestOneInput(const uint8_t* data, size_t size) {
|
||
|
|
const std::string text(reinterpret_cast<const char*>(data), size);
|
||
|
|
bajia::Config cfg;
|
||
|
|
std::vector<std::string> chain;
|
||
|
|
std::vector<std::string> seen;
|
||
|
|
try {
|
||
|
|
std::istringstream in(text);
|
||
|
|
bajia::parse_rc_stream(cfg, in, "/fuzz/main.rc", chain, seen,
|
||
|
|
NoImports{});
|
||
|
|
} catch (const std::exception&) {
|
||
|
|
// every parse error is a valid outcome; crashes are the bugs.
|
||
|
|
}
|
||
|
|
return 0;
|
||
|
|
}
|