bajia/tests/fuzz_config.cpp

39 lines
1.2 KiB
C++
Raw Permalink Normal View History

2026-08-28 00:22:49 +01:00
// fuzz_config.cpp - libFuzzer harness for the .rc parser.
//
// Built and driven by tools/fuzz.py with clang++ -fsanitize=fuzzer. The
// parser is exercised on raw bytes through the same `parse_rc_stream` path
// used by the real init. `@import` is rejected inside the harness (the
// opener throws) so fuzz input can never open real files such as /dev/zero.
#include "../src/config.cpp"
#include <cstddef>
#include <cstdint>
#include <memory>
#include <sstream>
#include <string>
#include <vector>
namespace {
struct NoImports {
std::unique_ptr<std::istream> operator()(const std::string&) const {
throw std::runtime_error("fuzz: @import disabled");
}
};
} // namespace
extern "C" int LLVMFuzzerTestOneInput(const uint8_t* data, size_t size) {
const std::string text(reinterpret_cast<const char*>(data), size);
bajia::Config cfg;
std::vector<std::string> chain;
std::vector<std::string> seen;
try {
std::istringstream in(text);
bajia::parse_rc_stream(cfg, in, "/fuzz/main.rc", chain, seen,
NoImports{});
} catch (const std::exception&) {
// every parse error is a valid outcome; crashes are the bugs.
}
return 0;
}