/src/binutils-gdb/binutils/fuzz_dlltool.c
Line | Count | Source |
1 | | /* Copyright 2021 Google LLC |
2 | | Licensed under the Apache License, Version 2.0 (the "License"); |
3 | | you may not use this file except in compliance with the License. |
4 | | You may obtain a copy of the License at |
5 | | http://www.apache.org/licenses/LICENSE-2.0 |
6 | | Unless required by applicable law or agreed to in writing, software |
7 | | distributed under the License is distributed on an "AS IS" BASIS, |
8 | | WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. |
9 | | See the License for the specific language governing permissions and |
10 | | limitations under the License. |
11 | | */ |
12 | | |
13 | | /* |
14 | | * We convert dlltool.c into a header file to make convenient for fuzzing. |
15 | | * We do this for several of the binutils applications when creating |
16 | | * the binutils fuzzers. |
17 | | */ |
18 | | #include "fuzz_dlltool.h" |
19 | | |
20 | | void |
21 | 666 | init_dlltool_global_state() { |
22 | 666 | import_list = NULL; |
23 | 666 | as_name = NULL; |
24 | 666 | as_flags = ""; |
25 | 666 | tmp_prefix = NULL; |
26 | 666 | exp_name = NULL; |
27 | 666 | imp_name = NULL; |
28 | 666 | delayimp_name = NULL; |
29 | 666 | identify_imp_name = NULL; |
30 | 666 | identify_strict = false; |
31 | 666 | head_label = NULL; |
32 | 666 | imp_name_lab = NULL; |
33 | 666 | dll_name = NULL; |
34 | 666 | dll_name_set_by_exp_name = 0; |
35 | 666 | add_indirect = 0; |
36 | 666 | add_underscore = 0; |
37 | 666 | add_stdcall_underscore = 0; |
38 | 666 | leading_underscore = "_"; |
39 | 666 | dontdeltemps = 0; |
40 | 666 | do_default_excludes = true; |
41 | 666 | use_nul_prefixed_import_tables = false; |
42 | 666 | def_file = NULL; |
43 | 666 | } |
44 | | |
45 | | void callIntoDlltool(char *, char*, bool); |
46 | | void |
47 | 666 | callIntoDlltool(char *deffile, char *objfile, bool var_export_all_symbols) { |
48 | 666 | init_dlltool_global_state(); |
49 | 666 | program_name = "fuzz_dlltool"; |
50 | 666 | mname = "mcore-elf"; |
51 | 666 | export_all_symbols = var_export_all_symbols; |
52 | | |
53 | | // At the moment we focus on the def file processing |
54 | 666 | def_file = deffile; |
55 | 666 | process_def_file(deffile); |
56 | 666 | scan_obj_file(objfile); |
57 | 666 | } |
58 | | |
59 | | int LLVMFuzzerTestOneInput(const uint8_t *Data, size_t Size); |
60 | | int |
61 | | LLVMFuzzerTestOneInput(const uint8_t *data, size_t size) |
62 | 337 | { |
63 | 337 | if (size < 512 || size > 16384) |
64 | 4 | return 0; |
65 | | |
66 | | /* def file */ |
67 | 333 | char filename[256]; |
68 | 333 | sprintf(filename, "/tmp/libfuzzer.%d", getpid()); |
69 | 333 | FILE *fp = fopen(filename, "wb"); |
70 | 333 | if (!fp) { |
71 | 0 | return 0; |
72 | 0 | } |
73 | 333 | fwrite(data, 412, 1, fp); |
74 | 333 | fclose(fp); |
75 | | |
76 | 333 | data += 412; |
77 | 333 | size -= 412; |
78 | | |
79 | 333 | char filename2[256]; |
80 | 333 | sprintf(filename2, "/tmp/libfuzzer-2.%d", getpid()); |
81 | 333 | FILE *fp2 = fopen(filename2, "wb"); |
82 | 333 | if (!fp2) { |
83 | 0 | return 0; |
84 | 0 | } |
85 | | |
86 | 333 | fwrite(data, size, 1, fp2); |
87 | 333 | fclose(fp2); |
88 | | |
89 | 333 | callIntoDlltool(filename, filename2, true); |
90 | 333 | callIntoDlltool(filename, filename2, false); |
91 | | |
92 | 333 | unlink(filename); |
93 | 333 | unlink(filename2); |
94 | 333 | return 0; |
95 | 333 | } |