mirror of
https://chromium.googlesource.com/crosvm/crosvm
synced 2024-11-25 13:23:08 +00:00
981f304f84
This simplifies `cargo fuzz` usage. Fuzzers can be built with `cargo fuzz build` without any other arguments. BUG=b:279217867 TEST=`cargo fuzz build` Change-Id: I11b8a8ba4c2b3e2d1a42973699e4d9c3920635b6 Reviewed-on: https://chromium-review.googlesource.com/c/crosvm/crosvm/+/4540001 Commit-Queue: Dennis Kempin <denniskempin@google.com> Reviewed-by: Daniel Verkamp <dverkamp@chromium.org>
60 lines
1.7 KiB
Rust
60 lines
1.7 KiB
Rust
// Copyright 2019 The ChromiumOS Authors
|
|
// Use of this source code is governed by a BSD-style license that can be
|
|
// found in the LICENSE file.
|
|
|
|
#![cfg(not(test))]
|
|
#![no_main]
|
|
|
|
#[cfg(unix)]
|
|
mod fuzzer {
|
|
use std::convert::TryInto;
|
|
|
|
use crosvm_fuzz::fuzz_target;
|
|
use devices::virtio::create_descriptor_chain;
|
|
use devices::virtio::DescriptorType;
|
|
use fuse::fuzzing::fuzz_server;
|
|
use vm_memory::GuestAddress;
|
|
use vm_memory::GuestMemory;
|
|
|
|
const MEM_SIZE: u64 = 256 * 1024 * 1024;
|
|
const BUFFER_ADDR: GuestAddress = GuestAddress(0x100);
|
|
|
|
thread_local! {
|
|
static GUEST_MEM: GuestMemory = GuestMemory::new(&[(GuestAddress(0), MEM_SIZE)]).unwrap();
|
|
}
|
|
|
|
fuzz_target!(|data| {
|
|
use DescriptorType::*;
|
|
|
|
GUEST_MEM.with(|mem| {
|
|
mem.write_all_at_addr(data, BUFFER_ADDR).unwrap();
|
|
|
|
// We need a valid descriptor chain, but it's not part of what is being fuzzed here.
|
|
// So skip fuzzing if the chain is invalid.
|
|
if let Ok(mut chain) = create_descriptor_chain(
|
|
mem,
|
|
GuestAddress(0),
|
|
BUFFER_ADDR,
|
|
vec![
|
|
(Readable, data.len().try_into().unwrap()),
|
|
(
|
|
Writable,
|
|
(MEM_SIZE as u32)
|
|
.saturating_sub(data.len().try_into().unwrap())
|
|
.saturating_sub(0x100),
|
|
),
|
|
],
|
|
0,
|
|
) {
|
|
fuzz_server(&mut chain.reader, &mut chain.writer);
|
|
}
|
|
});
|
|
});
|
|
}
|
|
|
|
#[cfg(not(unix))]
|
|
mod fuzzer {
|
|
use crosvm_fuzz::fuzz_target;
|
|
|
|
fuzz_target!(|_data| {});
|
|
}
|