fuzzer and performance optimisations
This commit is contained in:
parent
d5ea2e2974
commit
a4650fd589
11 changed files with 897 additions and 146 deletions
39
tests/fuzz_config.cpp
Normal file
39
tests/fuzz_config.cpp
Normal file
|
|
@ -0,0 +1,39 @@
|
|||
// fuzz_config.cpp - libFuzzer harness for the .rc parser.
|
||||
//
|
||||
// Built and driven by tools/fuzz.py with clang++ -fsanitize=fuzzer. The
|
||||
// parser is exercised on raw bytes through the same `parse_rc_stream` path
|
||||
// used by the real init. `@import` is rejected inside the harness (the
|
||||
// opener throws) so fuzz input can never open real files such as /dev/zero.
|
||||
#include "../src/config.cpp"
|
||||
|
||||
#include <cstddef>
|
||||
#include <cstdint>
|
||||
#include <memory>
|
||||
#include <sstream>
|
||||
#include <string>
|
||||
#include <vector>
|
||||
|
||||
namespace {
|
||||
|
||||
struct NoImports {
|
||||
std::unique_ptr<std::istream> operator()(const std::string&) const {
|
||||
throw std::runtime_error("fuzz: @import disabled");
|
||||
}
|
||||
};
|
||||
|
||||
} // namespace
|
||||
|
||||
extern "C" int LLVMFuzzerTestOneInput(const uint8_t* data, size_t size) {
|
||||
const std::string text(reinterpret_cast<const char*>(data), size);
|
||||
bajia::Config cfg;
|
||||
std::vector<std::string> chain;
|
||||
std::vector<std::string> seen;
|
||||
try {
|
||||
std::istringstream in(text);
|
||||
bajia::parse_rc_stream(cfg, in, "/fuzz/main.rc", chain, seen,
|
||||
NoImports{});
|
||||
} catch (const std::exception&) {
|
||||
// every parse error is a valid outcome; crashes are the bugs.
|
||||
}
|
||||
return 0;
|
||||
}
|
||||
Loading…
Add table
Add a link
Reference in a new issue