/src/pupnp/fuzzer/FuzzServiceTable.c
Line | Count | Source |
1 | | #include "service_table.h" |
2 | | |
3 | | /* "ixml.h" is not included here on purpose: service_table.h already includes |
4 | | * it, together with the other headers this target needs (config.h, upnp.h, |
5 | | * LinkedList.h). */ |
6 | | |
7 | | #include <stddef.h> |
8 | | #include <stdint.h> |
9 | | #include <stdlib.h> |
10 | | #include <string.h> |
11 | | |
12 | | extern int LLVMFuzzerTestOneInput(const uint8_t *Data, size_t Size) |
13 | 3.19k | { |
14 | | /* service_table, getServiceTable() and freeServiceTable() are only declared |
15 | | * when the device APIs and GENA are compiled in. Without this guard the |
16 | | * target fails to build on a client-only configuration, for instance |
17 | | * cmake -DFUZZER=ON -DUPNP_ENABLE_DEVICE_API=OFF. */ |
18 | 3.19k | #if defined(INCLUDE_DEVICE_APIS) && EXCLUDE_GENA == 0 |
19 | 3.19k | IXML_Document *doc = NULL; |
20 | 3.19k | service_table table; |
21 | 3.19k | char *xml; |
22 | | |
23 | | /* The upper bound is a harness-side safety net only. The input size is |
24 | | * meant to be driven by the runner, through libFuzzer's -max_len flag: |
25 | | * on the command line, as in |
26 | | * ./FuzzServiceTable corpus/ -max_len=65536 |
27 | | * or, under OSS-Fuzz, through a FuzzServiceTable.options file holding |
28 | | * [libfuzzer] |
29 | | * max_len = 65536 |
30 | | * Neither is set today, so libFuzzer's own default of 4096 bytes |
31 | | * applies and the test below never actually fires. */ |
32 | 3.19k | if (Size < 1 || Size > 65536) { |
33 | 0 | return 0; |
34 | 0 | } |
35 | | |
36 | 3.19k | xml = malloc(Size + 1); |
37 | 3.19k | if (!xml) { |
38 | 0 | return 0; |
39 | 0 | } |
40 | 3.19k | memcpy(xml, Data, Size); |
41 | 3.19k | xml[Size] = '\0'; |
42 | | |
43 | | /* A control point parses the device description document fetched from a |
44 | | * device, then builds the service table from it. */ |
45 | 3.19k | if (ixmlParseBufferEx(xml, &doc) == IXML_SUCCESS && doc) { |
46 | 80 | memset(&table, 0, sizeof(table)); |
47 | 80 | getServiceTable((IXML_Node *)doc, &table, "http://127.0.0.1/"); |
48 | 80 | freeServiceTable(&table); |
49 | 80 | ixmlDocument_free(doc); |
50 | 80 | } |
51 | | |
52 | 3.19k | free(xml); |
53 | | #else |
54 | | (void)Data; |
55 | | (void)Size; |
56 | | #endif |
57 | | |
58 | 3.19k | return 0; |
59 | 3.19k | } |