Coverage Report

Created: 2026-10-02 09:53

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/binutils-gdb/binutils/fuzz_dlltool.c
Line
Count
Source
1
/* Copyright 2021 Google LLC
2
Licensed under the Apache License, Version 2.0 (the "License");
3
you may not use this file except in compliance with the License.
4
You may obtain a copy of the License at
5
      http://www.apache.org/licenses/LICENSE-2.0
6
Unless required by applicable law or agreed to in writing, software
7
distributed under the License is distributed on an "AS IS" BASIS,
8
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
9
See the License for the specific language governing permissions and
10
limitations under the License.
11
*/
12
13
/*
14
 * We convert dlltool.c into a header file to make convenient for fuzzing.
15
 * We do this for several of the binutils applications when creating
16
 * the binutils fuzzers.
17
 */
18
#include "fuzz_dlltool.h"
19
20
void
21
666
init_dlltool_global_state() {
22
666
  import_list = NULL;
23
666
  as_name = NULL;
24
666
  as_flags = "";
25
666
  tmp_prefix = NULL;
26
666
  exp_name = NULL;
27
666
  imp_name = NULL;
28
666
  delayimp_name = NULL;
29
666
  identify_imp_name = NULL;
30
666
  identify_strict = false;
31
666
  head_label = NULL;
32
666
  imp_name_lab = NULL;
33
666
  dll_name = NULL;
34
666
  dll_name_set_by_exp_name = 0;
35
666
  add_indirect = 0;
36
666
  add_underscore = 0;
37
666
  add_stdcall_underscore = 0;
38
666
  leading_underscore = "_";
39
666
  dontdeltemps = 0;
40
666
  do_default_excludes = true;
41
666
  use_nul_prefixed_import_tables = false;
42
666
  def_file = NULL;
43
666
}
44
45
void callIntoDlltool(char *, char*, bool);
46
void
47
666
callIntoDlltool(char *deffile, char *objfile, bool var_export_all_symbols) {
48
666
  init_dlltool_global_state();
49
666
  program_name = "fuzz_dlltool";
50
666
  mname = "mcore-elf";
51
666
  export_all_symbols = var_export_all_symbols;
52
53
  // At the moment we focus on the def file processing
54
666
  def_file = deffile;
55
666
  process_def_file(deffile);
56
666
  scan_obj_file(objfile);
57
666
}
58
59
int LLVMFuzzerTestOneInput(const uint8_t *Data, size_t Size);
60
int
61
LLVMFuzzerTestOneInput(const uint8_t *data, size_t size)
62
337
{
63
337
  if (size < 512 || size > 16384)
64
4
    return 0;
65
66
  /* def file */
67
333
  char filename[256];
68
333
  sprintf(filename, "/tmp/libfuzzer.%d", getpid());
69
333
  FILE *fp = fopen(filename, "wb");
70
333
  if (!fp) {
71
0
    return 0;
72
0
  }
73
333
  fwrite(data, 412, 1, fp);
74
333
  fclose(fp);
75
76
333
  data += 412;
77
333
  size -= 412;
78
79
333
  char filename2[256];
80
333
  sprintf(filename2, "/tmp/libfuzzer-2.%d", getpid());
81
333
  FILE *fp2 = fopen(filename2, "wb");
82
333
  if (!fp2) {
83
0
    return 0;
84
0
  }
85
86
333
  fwrite(data, size, 1, fp2);
87
333
  fclose(fp2);
88
89
333
  callIntoDlltool(filename, filename2, true);
90
333
  callIntoDlltool(filename, filename2, false);
91
92
333
  unlink(filename);
93
333
  unlink(filename2);
94
333
  return 0;
95
333
}