// fuzz_config.cpp - libFuzzer harness for the .rc parser. // // Built and driven by tools/fuzz.py with clang++ -fsanitize=fuzzer. The // parser is exercised on raw bytes through the same `parse_rc_stream` path // used by the real init. `@import` is rejected inside the harness (the // opener throws) so fuzz input can never open real files such as /dev/zero. #include "../src/config.cpp" #include #include #include #include #include #include namespace { struct NoImports { std::unique_ptr operator()(const std::string&) const { throw std::runtime_error("fuzz: @import disabled"); } }; } // namespace extern "C" int LLVMFuzzerTestOneInput(const uint8_t* data, size_t size) { const std::string text(reinterpret_cast(data), size); bajia::Config cfg; std::vector chain; std::vector seen; try { std::istringstream in(text); bajia::parse_rc_stream(cfg, in, "/fuzz/main.rc", chain, seen, NoImports{}); } catch (const std::exception&) { // every parse error is a valid outcome; crashes are the bugs. } return 0; }