/src/libreoffice/vcl/workben/fods2xlsfuzzer.cxx
Line | Count | Source |
1 | | /* -*- Mode: C++; tab-width: 4; indent-tabs-mode: nil; c-basic-offset: 4 -*- */ |
2 | | /* |
3 | | * This file is part of the LibreOffice project. |
4 | | * |
5 | | * This Source Code Form is subject to the terms of the Mozilla Public |
6 | | * License, v. 2.0. If a copy of the MPL was not distributed with this |
7 | | * file, You can obtain one at http://mozilla.org/MPL/2.0/. |
8 | | */ |
9 | | |
10 | | #include <tools/stream.hxx> |
11 | | #include <vcl/FilterConfigItem.hxx> |
12 | | #include <com/sun/star/awt/XToolkit.hpp> |
13 | | #include <com/sun/star/ucb/XContentProvider.hpp> |
14 | | #include <com/sun/star/ucb/XUniversalContentBroker.hpp> |
15 | | #include <libxml/parser.h> |
16 | | #include "commonfuzzer.hxx" |
17 | | |
18 | 0 | extern "C" void* ScCreateDialogFactory() { return nullptr; } |
19 | | |
20 | | extern "C" bool TestFODSExportXLS(SvStream& rStream); |
21 | | |
22 | 0 | static void silent_error_func(void*, const char* /*format*/, ...) {} |
23 | | |
24 | | extern "C" int LLVMFuzzerInitialize(int* argc, char*** argv) |
25 | 12 | { |
26 | 12 | if (__lsan_disable) |
27 | 0 | __lsan_disable(); |
28 | | |
29 | 12 | CommonInitialize(argc, argv); |
30 | | |
31 | | // initialise unconfigured UCB: |
32 | 12 | css::uno::Reference<css::ucb::XUniversalContentBroker> xUcb( |
33 | 12 | comphelper::getProcessServiceFactory()->createInstance( |
34 | 12 | "com.sun.star.ucb.UniversalContentBroker"), |
35 | 12 | css::uno::UNO_QUERY_THROW); |
36 | 12 | css::uno::Sequence<css::uno::Any> aArgs{ css::uno::Any(OUString("NoConfig")) }; |
37 | 12 | css::uno::Reference<css::ucb::XContentProvider> xFileProvider( |
38 | 12 | comphelper::getProcessServiceFactory()->createInstanceWithArguments( |
39 | 12 | "com.sun.star.ucb.FileContentProvider", aArgs), |
40 | 12 | css::uno::UNO_QUERY_THROW); |
41 | 12 | xUcb->registerContentProvider(xFileProvider, "file", true); |
42 | | |
43 | | // create and hold a reference to XToolkit here to avoid the lsan warning about its leak |
44 | | // due to getting created in the unusual case of no vcl main loop |
45 | 12 | static css::uno::Reference<css::awt::XToolkit> xTk( |
46 | 12 | comphelper::getProcessServiceFactory()->createInstance("com.sun.star.awt.Toolkit"), |
47 | 12 | css::uno::UNO_QUERY_THROW); |
48 | | |
49 | 12 | if (__lsan_enable) |
50 | 0 | __lsan_enable(); |
51 | | |
52 | 12 | xmlInitParser(); |
53 | 12 | xmlSetGenericErrorFunc(nullptr, silent_error_func); |
54 | | |
55 | 12 | return 0; |
56 | 12 | } |
57 | | |
58 | | extern "C" size_t LLVMFuzzerMutate(uint8_t* Data, size_t Size, size_t MaxSize); |
59 | | |
60 | | extern "C" { |
61 | 5.25k | __attribute__((weak)) void __msan_unpoison(const volatile void*, size_t) {} |
62 | | } |
63 | | |
64 | | extern "C" size_t LLVMFuzzerCustomMutator(uint8_t* Data, size_t Size, size_t MaxSize, |
65 | | unsigned int /*Seed*/) |
66 | 0 | { |
67 | 0 | size_t Ret = LLVMFuzzerMutate(Data, Size, MaxSize); |
68 | |
|
69 | 0 | __msan_unpoison(Data, Ret); |
70 | | |
71 | | // an effort to only generate valid xml, in this fuzzer we only really care |
72 | | // about the deeper levels of turning valid input into calc layout and |
73 | | // xls export |
74 | |
|
75 | 0 | xmlParserCtxtPtr ctxt = xmlNewParserCtxt(); |
76 | 0 | xmlDocPtr Doc = xmlCtxtReadMemory(ctxt, reinterpret_cast<const char*>(Data), Ret, nullptr, |
77 | 0 | nullptr, XML_PARSE_NONET); |
78 | 0 | if (Doc == nullptr) |
79 | 0 | Ret = 0; |
80 | 0 | else |
81 | 0 | xmlFreeDoc(Doc); |
82 | 0 | xmlFreeParserCtxt(ctxt); |
83 | 0 | xmlResetLastError(); |
84 | 0 | return Ret; |
85 | 0 | } |
86 | | |
87 | | extern "C" int LLVMFuzzerTestOneInput(const uint8_t* data, size_t size) |
88 | 13.2k | { |
89 | 13.2k | SvMemoryStream aStream(const_cast<uint8_t*>(data), size, StreamMode::READ); |
90 | 13.2k | bool bFODTLoaded = TestFODSExportXLS(aStream); |
91 | | // if the fodt didn't load then reject so that input will not be added to the corpus |
92 | | // we're not interested in input that doesn't go on to exercise the xls export |
93 | 13.2k | return bFODTLoaded ? 0 : -1; |
94 | 13.2k | } |
95 | | |
96 | | /* vim:set shiftwidth=4 softtabstop=4 expandtab: */ |