/src/libpng/contrib/oss-fuzz/libpng_read_fuzzer.cc
Line | Count | Source (jump to first uncovered line) |
1 | | |
2 | | // libpng_read_fuzzer.cc |
3 | | // Copyright 2017-2018 Glenn Randers-Pehrson |
4 | | // Copyright 2015 The Chromium Authors. All rights reserved. |
5 | | // Use of this source code is governed by a BSD-style license that may |
6 | | // be found in the LICENSE file https://cs.chromium.org/chromium/src/LICENSE |
7 | | |
8 | | // The modifications in 2017 by Glenn Randers-Pehrson include |
9 | | // 1. addition of a PNG_CLEANUP macro, |
10 | | // 2. setting the option to ignore ADLER32 checksums, |
11 | | // 3. adding "#include <string.h>" which is needed on some platforms |
12 | | // to provide memcpy(). |
13 | | // 4. adding read_end_info() and creating an end_info structure. |
14 | | // 5. adding calls to png_set_*() transforms commonly used by browsers. |
15 | | |
16 | | #include <stddef.h> |
17 | | #include <stdint.h> |
18 | | #include <stdlib.h> |
19 | | #include <string.h> |
20 | | |
21 | | #include <vector> |
22 | | |
23 | | #define PNG_INTERNAL |
24 | | #include "png.h" |
25 | | |
26 | | #define PNG_CLEANUP \ |
27 | 25.8k | if(png_handler.png_ptr) \ |
28 | 25.8k | { \ |
29 | 25.8k | if (png_handler.row_ptr) \ |
30 | 25.8k | png_free(png_handler.png_ptr, png_handler.row_ptr); \ |
31 | 25.8k | if (png_handler.end_info_ptr) \ |
32 | 25.8k | png_destroy_read_struct(&png_handler.png_ptr, &png_handler.info_ptr,\ |
33 | 25.8k | &png_handler.end_info_ptr); \ |
34 | 25.8k | else if (png_handler.info_ptr) \ |
35 | 0 | png_destroy_read_struct(&png_handler.png_ptr, &png_handler.info_ptr,\ |
36 | 0 | nullptr); \ |
37 | 0 | else \ |
38 | 0 | png_destroy_read_struct(&png_handler.png_ptr, nullptr, nullptr); \ |
39 | 25.8k | png_handler.png_ptr = nullptr; \ |
40 | 25.8k | png_handler.row_ptr = nullptr; \ |
41 | 25.8k | png_handler.info_ptr = nullptr; \ |
42 | 25.8k | png_handler.end_info_ptr = nullptr; \ |
43 | 25.8k | } |
44 | | |
45 | | struct BufState { |
46 | | const uint8_t* data; |
47 | | size_t bytes_left; |
48 | | }; |
49 | | |
50 | | struct PngObjectHandler { |
51 | | png_infop info_ptr = nullptr; |
52 | | png_structp png_ptr = nullptr; |
53 | | png_infop end_info_ptr = nullptr; |
54 | | png_voidp row_ptr = nullptr; |
55 | | BufState* buf_state = nullptr; |
56 | | |
57 | 25.8k | ~PngObjectHandler() { |
58 | 25.8k | if (row_ptr) |
59 | 0 | png_free(png_ptr, row_ptr); |
60 | 25.8k | if (end_info_ptr) |
61 | 0 | png_destroy_read_struct(&png_ptr, &info_ptr, &end_info_ptr); |
62 | 25.8k | else if (info_ptr) |
63 | 0 | png_destroy_read_struct(&png_ptr, &info_ptr, nullptr); |
64 | 25.8k | else |
65 | 25.8k | png_destroy_read_struct(&png_ptr, nullptr, nullptr); |
66 | 25.8k | delete buf_state; |
67 | 25.8k | } |
68 | | }; |
69 | | |
70 | 3.32M | void user_read_data(png_structp png_ptr, png_bytep data, size_t length) { |
71 | 3.32M | BufState* buf_state = static_cast<BufState*>(png_get_io_ptr(png_ptr)); |
72 | 3.32M | if (length > buf_state->bytes_left) { |
73 | 6.31k | png_error(png_ptr, "read error"); |
74 | 6.31k | } |
75 | 3.31M | memcpy(data, buf_state->data, length); |
76 | 3.31M | buf_state->bytes_left -= length; |
77 | 3.31M | buf_state->data += length; |
78 | 3.31M | } |
79 | | |
80 | 151k | void* limited_malloc(png_structp, png_alloc_size_t size) { |
81 | | // libpng may allocate large amounts of memory that the fuzzer reports as |
82 | | // an error. In order to silence these errors, make libpng fail when trying |
83 | | // to allocate a large amount. This allocator used to be in the Chromium |
84 | | // version of this fuzzer. |
85 | | // This number is chosen to match the default png_user_chunk_malloc_max. |
86 | 151k | if (size > 8000000) |
87 | 2.33k | return nullptr; |
88 | | |
89 | 149k | return malloc(size); |
90 | 151k | } |
91 | | |
92 | 226k | void default_free(png_structp, png_voidp ptr) { |
93 | 226k | return free(ptr); |
94 | 226k | } |
95 | | |
96 | | static const int kPngHeaderSize = 8; |
97 | | |
98 | | // Entry point for LibFuzzer. |
99 | | // Roughly follows the libpng book example: |
100 | | // http://www.libpng.org/pub/png/book/chapter13.html |
101 | 25.9k | extern "C" int LLVMFuzzerTestOneInput(const uint8_t* data, size_t size) { |
102 | 25.9k | if (size < kPngHeaderSize) { |
103 | 4 | return 0; |
104 | 4 | } |
105 | | |
106 | 25.9k | std::vector<unsigned char> v(data, data + size); |
107 | 25.9k | if (png_sig_cmp(v.data(), 0, kPngHeaderSize)) { |
108 | | // not a PNG. |
109 | 70 | return 0; |
110 | 70 | } |
111 | | |
112 | 25.8k | PngObjectHandler png_handler; |
113 | 25.8k | png_handler.png_ptr = nullptr; |
114 | 25.8k | png_handler.row_ptr = nullptr; |
115 | 25.8k | png_handler.info_ptr = nullptr; |
116 | 25.8k | png_handler.end_info_ptr = nullptr; |
117 | | |
118 | 25.8k | png_handler.png_ptr = png_create_read_struct |
119 | 25.8k | (PNG_LIBPNG_VER_STRING, nullptr, nullptr, nullptr); |
120 | 25.8k | if (!png_handler.png_ptr) { |
121 | 0 | return 0; |
122 | 0 | } |
123 | | |
124 | 25.8k | png_handler.info_ptr = png_create_info_struct(png_handler.png_ptr); |
125 | 25.8k | if (!png_handler.info_ptr) { |
126 | 0 | PNG_CLEANUP |
127 | 0 | return 0; |
128 | 0 | } |
129 | | |
130 | 25.8k | png_handler.end_info_ptr = png_create_info_struct(png_handler.png_ptr); |
131 | 25.8k | if (!png_handler.end_info_ptr) { |
132 | 0 | PNG_CLEANUP |
133 | 0 | return 0; |
134 | 0 | } |
135 | | |
136 | | // Use a custom allocator that fails for large allocations to avoid OOM. |
137 | 25.8k | png_set_mem_fn(png_handler.png_ptr, nullptr, limited_malloc, default_free); |
138 | | |
139 | 25.8k | png_set_crc_action(png_handler.png_ptr, PNG_CRC_QUIET_USE, PNG_CRC_QUIET_USE); |
140 | 25.8k | #ifdef PNG_IGNORE_ADLER32 |
141 | 25.8k | png_set_option(png_handler.png_ptr, PNG_IGNORE_ADLER32, PNG_OPTION_ON); |
142 | 25.8k | #endif |
143 | | |
144 | | // Setting up reading from buffer. |
145 | 25.8k | png_handler.buf_state = new BufState(); |
146 | 25.8k | png_handler.buf_state->data = data + kPngHeaderSize; |
147 | 25.8k | png_handler.buf_state->bytes_left = size - kPngHeaderSize; |
148 | 25.8k | png_set_read_fn(png_handler.png_ptr, png_handler.buf_state, user_read_data); |
149 | 25.8k | png_set_sig_bytes(png_handler.png_ptr, kPngHeaderSize); |
150 | | |
151 | 25.8k | if (setjmp(png_jmpbuf(png_handler.png_ptr))) { |
152 | 19.8k | PNG_CLEANUP |
153 | 19.8k | return 0; |
154 | 19.8k | } |
155 | | |
156 | | // Reading. |
157 | 6.03k | png_read_info(png_handler.png_ptr, png_handler.info_ptr); |
158 | | |
159 | | // reset error handler to put png_deleter into scope. |
160 | 6.03k | if (setjmp(png_jmpbuf(png_handler.png_ptr))) { |
161 | 4.42k | PNG_CLEANUP |
162 | 4.42k | return 0; |
163 | 4.42k | } |
164 | | |
165 | 1.61k | png_uint_32 width, height; |
166 | 1.61k | int bit_depth, color_type, interlace_type, compression_type; |
167 | 1.61k | int filter_type; |
168 | | |
169 | 1.61k | if (!png_get_IHDR(png_handler.png_ptr, png_handler.info_ptr, &width, |
170 | 1.61k | &height, &bit_depth, &color_type, &interlace_type, |
171 | 1.61k | &compression_type, &filter_type)) { |
172 | 0 | PNG_CLEANUP |
173 | 0 | return 0; |
174 | 0 | } |
175 | | |
176 | | // This is going to be too slow. |
177 | 6.03k | if (width && height > 100000000 / width) { |
178 | 65 | PNG_CLEANUP |
179 | 65 | return 0; |
180 | 65 | } |
181 | | |
182 | | // Set several transforms that browsers typically use: |
183 | 1.54k | png_set_gray_to_rgb(png_handler.png_ptr); |
184 | 1.54k | png_set_expand(png_handler.png_ptr); |
185 | 1.54k | png_set_packing(png_handler.png_ptr); |
186 | 1.54k | png_set_scale_16(png_handler.png_ptr); |
187 | 1.54k | png_set_tRNS_to_alpha(png_handler.png_ptr); |
188 | | |
189 | 1.54k | int passes = png_set_interlace_handling(png_handler.png_ptr); |
190 | | |
191 | 1.54k | png_read_update_info(png_handler.png_ptr, png_handler.info_ptr); |
192 | | |
193 | 1.54k | png_handler.row_ptr = png_malloc( |
194 | 1.54k | png_handler.png_ptr, png_get_rowbytes(png_handler.png_ptr, |
195 | 1.54k | png_handler.info_ptr)); |
196 | | |
197 | 17.2k | for (int pass = 0; pass < passes; ++pass) { |
198 | 248k | for (png_uint_32 y = 0; y < height; ++y) { |
199 | 233k | png_read_row(png_handler.png_ptr, |
200 | 233k | static_cast<png_bytep>(png_handler.row_ptr), nullptr); |
201 | 233k | } |
202 | 15.7k | } |
203 | | |
204 | 1.54k | png_read_end(png_handler.png_ptr, png_handler.end_info_ptr); |
205 | | |
206 | 1.54k | PNG_CLEANUP |
207 | 1.54k | return 0; |
208 | 1.61k | } Line | Count | Source | 101 | 18.1k | extern "C" int LLVMFuzzerTestOneInput(const uint8_t* data, size_t size) { | 102 | 18.1k | if (size < kPngHeaderSize) { | 103 | 0 | return 0; | 104 | 0 | } | 105 | | | 106 | 18.1k | std::vector<unsigned char> v(data, data + size); | 107 | 18.1k | if (png_sig_cmp(v.data(), 0, kPngHeaderSize)) { | 108 | | // not a PNG. | 109 | 0 | return 0; | 110 | 0 | } | 111 | | | 112 | 18.1k | PngObjectHandler png_handler; | 113 | 18.1k | png_handler.png_ptr = nullptr; | 114 | 18.1k | png_handler.row_ptr = nullptr; | 115 | 18.1k | png_handler.info_ptr = nullptr; | 116 | 18.1k | png_handler.end_info_ptr = nullptr; | 117 | | | 118 | 18.1k | png_handler.png_ptr = png_create_read_struct | 119 | 18.1k | (PNG_LIBPNG_VER_STRING, nullptr, nullptr, nullptr); | 120 | 18.1k | if (!png_handler.png_ptr) { | 121 | 0 | return 0; | 122 | 0 | } | 123 | | | 124 | 18.1k | png_handler.info_ptr = png_create_info_struct(png_handler.png_ptr); | 125 | 18.1k | if (!png_handler.info_ptr) { | 126 | 0 | PNG_CLEANUP | 127 | 0 | return 0; | 128 | 0 | } | 129 | | | 130 | 18.1k | png_handler.end_info_ptr = png_create_info_struct(png_handler.png_ptr); | 131 | 18.1k | if (!png_handler.end_info_ptr) { | 132 | 0 | PNG_CLEANUP | 133 | 0 | return 0; | 134 | 0 | } | 135 | | | 136 | | // Use a custom allocator that fails for large allocations to avoid OOM. | 137 | 18.1k | png_set_mem_fn(png_handler.png_ptr, nullptr, limited_malloc, default_free); | 138 | | | 139 | 18.1k | png_set_crc_action(png_handler.png_ptr, PNG_CRC_QUIET_USE, PNG_CRC_QUIET_USE); | 140 | 18.1k | #ifdef PNG_IGNORE_ADLER32 | 141 | 18.1k | png_set_option(png_handler.png_ptr, PNG_IGNORE_ADLER32, PNG_OPTION_ON); | 142 | 18.1k | #endif | 143 | | | 144 | | // Setting up reading from buffer. | 145 | 18.1k | png_handler.buf_state = new BufState(); | 146 | 18.1k | png_handler.buf_state->data = data + kPngHeaderSize; | 147 | 18.1k | png_handler.buf_state->bytes_left = size - kPngHeaderSize; | 148 | 18.1k | png_set_read_fn(png_handler.png_ptr, png_handler.buf_state, user_read_data); | 149 | 18.1k | png_set_sig_bytes(png_handler.png_ptr, kPngHeaderSize); | 150 | | | 151 | 18.1k | if (setjmp(png_jmpbuf(png_handler.png_ptr))) { | 152 | 13.8k | PNG_CLEANUP | 153 | 13.8k | return 0; | 154 | 13.8k | } | 155 | | | 156 | | // Reading. | 157 | 4.37k | png_read_info(png_handler.png_ptr, png_handler.info_ptr); | 158 | | | 159 | | // reset error handler to put png_deleter into scope. | 160 | 4.37k | if (setjmp(png_jmpbuf(png_handler.png_ptr))) { | 161 | 2.86k | PNG_CLEANUP | 162 | 2.86k | return 0; | 163 | 2.86k | } | 164 | | | 165 | 1.51k | png_uint_32 width, height; | 166 | 1.51k | int bit_depth, color_type, interlace_type, compression_type; | 167 | 1.51k | int filter_type; | 168 | | | 169 | 1.51k | if (!png_get_IHDR(png_handler.png_ptr, png_handler.info_ptr, &width, | 170 | 1.51k | &height, &bit_depth, &color_type, &interlace_type, | 171 | 1.51k | &compression_type, &filter_type)) { | 172 | 0 | PNG_CLEANUP | 173 | 0 | return 0; | 174 | 0 | } | 175 | | | 176 | | // This is going to be too slow. | 177 | 4.37k | if (width && height > 100000000 / width) { | 178 | 0 | PNG_CLEANUP | 179 | 0 | return 0; | 180 | 0 | } | 181 | | | 182 | | // Set several transforms that browsers typically use: | 183 | 1.51k | png_set_gray_to_rgb(png_handler.png_ptr); | 184 | 1.51k | png_set_expand(png_handler.png_ptr); | 185 | 1.51k | png_set_packing(png_handler.png_ptr); | 186 | 1.51k | png_set_scale_16(png_handler.png_ptr); | 187 | 1.51k | png_set_tRNS_to_alpha(png_handler.png_ptr); | 188 | | | 189 | 1.51k | int passes = png_set_interlace_handling(png_handler.png_ptr); | 190 | | | 191 | 1.51k | png_read_update_info(png_handler.png_ptr, png_handler.info_ptr); | 192 | | | 193 | 1.51k | png_handler.row_ptr = png_malloc( | 194 | 1.51k | png_handler.png_ptr, png_get_rowbytes(png_handler.png_ptr, | 195 | 1.51k | png_handler.info_ptr)); | 196 | | | 197 | 13.8k | for (int pass = 0; pass < passes; ++pass) { | 198 | 148k | for (png_uint_32 y = 0; y < height; ++y) { | 199 | 135k | png_read_row(png_handler.png_ptr, | 200 | 135k | static_cast<png_bytep>(png_handler.row_ptr), nullptr); | 201 | 135k | } | 202 | 12.3k | } | 203 | | | 204 | 1.51k | png_read_end(png_handler.png_ptr, png_handler.end_info_ptr); | 205 | | | 206 | 1.51k | PNG_CLEANUP | 207 | 1.51k | return 0; | 208 | 1.51k | } |
Line | Count | Source | 101 | 7.76k | extern "C" int LLVMFuzzerTestOneInput(const uint8_t* data, size_t size) { | 102 | 7.76k | if (size < kPngHeaderSize) { | 103 | 4 | return 0; | 104 | 4 | } | 105 | | | 106 | 7.76k | std::vector<unsigned char> v(data, data + size); | 107 | 7.76k | if (png_sig_cmp(v.data(), 0, kPngHeaderSize)) { | 108 | | // not a PNG. | 109 | 70 | return 0; | 110 | 70 | } | 111 | | | 112 | 7.69k | PngObjectHandler png_handler; | 113 | 7.69k | png_handler.png_ptr = nullptr; | 114 | 7.69k | png_handler.row_ptr = nullptr; | 115 | 7.69k | png_handler.info_ptr = nullptr; | 116 | 7.69k | png_handler.end_info_ptr = nullptr; | 117 | | | 118 | 7.69k | png_handler.png_ptr = png_create_read_struct | 119 | 7.69k | (PNG_LIBPNG_VER_STRING, nullptr, nullptr, nullptr); | 120 | 7.69k | if (!png_handler.png_ptr) { | 121 | 0 | return 0; | 122 | 0 | } | 123 | | | 124 | 7.69k | png_handler.info_ptr = png_create_info_struct(png_handler.png_ptr); | 125 | 7.69k | if (!png_handler.info_ptr) { | 126 | 0 | PNG_CLEANUP | 127 | 0 | return 0; | 128 | 0 | } | 129 | | | 130 | 7.69k | png_handler.end_info_ptr = png_create_info_struct(png_handler.png_ptr); | 131 | 7.69k | if (!png_handler.end_info_ptr) { | 132 | 0 | PNG_CLEANUP | 133 | 0 | return 0; | 134 | 0 | } | 135 | | | 136 | | // Use a custom allocator that fails for large allocations to avoid OOM. | 137 | 7.69k | png_set_mem_fn(png_handler.png_ptr, nullptr, limited_malloc, default_free); | 138 | | | 139 | 7.69k | png_set_crc_action(png_handler.png_ptr, PNG_CRC_QUIET_USE, PNG_CRC_QUIET_USE); | 140 | 7.69k | #ifdef PNG_IGNORE_ADLER32 | 141 | 7.69k | png_set_option(png_handler.png_ptr, PNG_IGNORE_ADLER32, PNG_OPTION_ON); | 142 | 7.69k | #endif | 143 | | | 144 | | // Setting up reading from buffer. | 145 | 7.69k | png_handler.buf_state = new BufState(); | 146 | 7.69k | png_handler.buf_state->data = data + kPngHeaderSize; | 147 | 7.69k | png_handler.buf_state->bytes_left = size - kPngHeaderSize; | 148 | 7.69k | png_set_read_fn(png_handler.png_ptr, png_handler.buf_state, user_read_data); | 149 | 7.69k | png_set_sig_bytes(png_handler.png_ptr, kPngHeaderSize); | 150 | | | 151 | 7.69k | if (setjmp(png_jmpbuf(png_handler.png_ptr))) { | 152 | 6.03k | PNG_CLEANUP | 153 | 6.03k | return 0; | 154 | 6.03k | } | 155 | | | 156 | | // Reading. | 157 | 1.65k | png_read_info(png_handler.png_ptr, png_handler.info_ptr); | 158 | | | 159 | | // reset error handler to put png_deleter into scope. | 160 | 1.65k | if (setjmp(png_jmpbuf(png_handler.png_ptr))) { | 161 | 1.55k | PNG_CLEANUP | 162 | 1.55k | return 0; | 163 | 1.55k | } | 164 | | | 165 | 98 | png_uint_32 width, height; | 166 | 98 | int bit_depth, color_type, interlace_type, compression_type; | 167 | 98 | int filter_type; | 168 | | | 169 | 98 | if (!png_get_IHDR(png_handler.png_ptr, png_handler.info_ptr, &width, | 170 | 98 | &height, &bit_depth, &color_type, &interlace_type, | 171 | 98 | &compression_type, &filter_type)) { | 172 | 0 | PNG_CLEANUP | 173 | 0 | return 0; | 174 | 0 | } | 175 | | | 176 | | // This is going to be too slow. | 177 | 1.65k | if (width && height > 100000000 / width) { | 178 | 65 | PNG_CLEANUP | 179 | 65 | return 0; | 180 | 65 | } | 181 | | | 182 | | // Set several transforms that browsers typically use: | 183 | 33 | png_set_gray_to_rgb(png_handler.png_ptr); | 184 | 33 | png_set_expand(png_handler.png_ptr); | 185 | 33 | png_set_packing(png_handler.png_ptr); | 186 | 33 | png_set_scale_16(png_handler.png_ptr); | 187 | 33 | png_set_tRNS_to_alpha(png_handler.png_ptr); | 188 | | | 189 | 33 | int passes = png_set_interlace_handling(png_handler.png_ptr); | 190 | | | 191 | 33 | png_read_update_info(png_handler.png_ptr, png_handler.info_ptr); | 192 | | | 193 | 33 | png_handler.row_ptr = png_malloc( | 194 | 33 | png_handler.png_ptr, png_get_rowbytes(png_handler.png_ptr, | 195 | 33 | png_handler.info_ptr)); | 196 | | | 197 | 3.41k | for (int pass = 0; pass < passes; ++pass) { | 198 | 100k | for (png_uint_32 y = 0; y < height; ++y) { | 199 | 97.1k | png_read_row(png_handler.png_ptr, | 200 | 97.1k | static_cast<png_bytep>(png_handler.row_ptr), nullptr); | 201 | 97.1k | } | 202 | 3.38k | } | 203 | | | 204 | 33 | png_read_end(png_handler.png_ptr, png_handler.end_info_ptr); | 205 | | | 206 | 33 | PNG_CLEANUP | 207 | 33 | return 0; | 208 | 98 | } |
|