/src/samba/lib/fuzzing/fuzz_lzxpress_huffman_compress.c
Line | Count | Source |
1 | | /* |
2 | | Fuzzing for lzxpress_huffman_compress_talloc |
3 | | Copyright (C) Michael Hanselmann 2019 |
4 | | Copyright (C) Douglas Bagnall 2022 <dbagnall@samba.org> |
5 | | |
6 | | This program is free software; you can redistribute it and/or modify |
7 | | it under the terms of the GNU General Public License as published by |
8 | | the Free Software Foundation; either version 3 of the License, or |
9 | | (at your option) any later version. |
10 | | |
11 | | This program is distributed in the hope that it will be useful, |
12 | | but WITHOUT ANY WARRANTY; without even the implied warranty of |
13 | | MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the |
14 | | GNU General Public License for more details. |
15 | | |
16 | | You should have received a copy of the GNU General Public License |
17 | | along with this program. If not, see <http://www.gnu.org/licenses/>. |
18 | | */ |
19 | | |
20 | | #include "includes.h" |
21 | | #include "fuzzing/fuzzing.h" |
22 | | #include "compression/lzxpress_huffman.h" |
23 | | |
24 | | int LLVMFuzzerInitialize(int *argc, char ***argv) |
25 | 377 | { |
26 | 377 | return 0; |
27 | 377 | } |
28 | | |
29 | | |
30 | | #define MAX_SIZE (1024 * 1024) |
31 | | |
32 | | int LLVMFuzzerTestOneInput(const uint8_t *buf, size_t len) |
33 | 1.99k | { |
34 | 1.99k | static uint8_t *output; |
35 | 1.99k | size_t output_len; |
36 | 1.99k | TALLOC_CTX *mem_ctx = NULL; |
37 | 1.99k | struct lzxhuff_compressor_mem cmp_mem; |
38 | | |
39 | | /* |
40 | | * The round-trip fuzzer checks the compressor with an unconstrained |
41 | | * output buffer; here we see what happens if the buffer is possibly too |
42 | | * small. |
43 | | */ |
44 | 1.99k | if (len < 3) { |
45 | 4 | return 0; |
46 | 4 | } |
47 | 1.99k | output_len = MIN(MAX_SIZE, buf[0] | (buf[1] << 8) | (buf[2] << 16)); |
48 | 1.99k | buf += 3; |
49 | 1.99k | len -= 3; |
50 | 1.99k | mem_ctx = talloc_new(NULL); |
51 | | |
52 | 1.99k | output = talloc_array(mem_ctx, uint8_t, output_len); |
53 | | |
54 | 1.99k | lzxpress_huffman_compress(&cmp_mem, buf, len, output, output_len); |
55 | | |
56 | | talloc_free(mem_ctx); |
57 | 1.99k | return 0; |
58 | 1.99k | } |