Source code and Makefile to fuzz libelf in Google's oss-fuzz infrastructure.
Introduce FUZZ_NO_LIBXC in libelf-private.h. That macro will be set when compiling libelf fuzzer target because libxc is not required in libelf fuzzing. Signed-off-by: Wei Liu <wei.l...@citrix.com> --- Cc: Andrew Cooper <andrew.coop...@citrix.com> Cc: George Dunlap <george.dun...@eu.citrix.com> Cc: Ian Jackson <ian.jack...@eu.citrix.com> Cc: Jan Beulich <jbeul...@suse.com> Cc: Konrad Rzeszutek Wilk <konrad.w...@oracle.com> Cc: Stefano Stabellini <sstabell...@kernel.org> Cc: Tim Deegan <t...@xen.org> Cc: Wei Liu <wei.l...@citrix.com> --- tools/fuzz/libelf/Makefile | 31 +++++++++++++++++++++++++++++++ tools/fuzz/libelf/libelf-fuzzer.c | 32 ++++++++++++++++++++++++++++++++ xen/common/libelf/libelf-private.h | 2 ++ 3 files changed, 65 insertions(+) create mode 100644 tools/fuzz/libelf/Makefile create mode 100644 tools/fuzz/libelf/libelf-fuzzer.c diff --git a/tools/fuzz/libelf/Makefile b/tools/fuzz/libelf/Makefile new file mode 100644 index 0000000..0e9d40a --- /dev/null +++ b/tools/fuzz/libelf/Makefile @@ -0,0 +1,31 @@ +XEN_ROOT = $(CURDIR)/../../.. +include $(XEN_ROOT)/tools/Rules.mk + +# libelf fuzz target +vpath %.c ../../../xen/common/libelf +CFLAGS += -I../../../xen/common/libelf +ELF_SRCS-y += libelf-tools.c libelf-loader.c libelf-dominfo.c +ELF_LIB_OBJS := $(patsubst %.c,%.o,$(ELF_SRCS-y)) + +$(patsubst %.c,%.o,$(ELF_SRCS-y)): CFLAGS += -Wno-pointer-sign + +$(ELF_LIB_OBJS): CFLAGS += -DFUZZ_NO_LIBXC $(CFLAGS_xeninclude) + +libelf-fuzzer.o: CFLAGS += $(CFLAGS_xeninclude) + +libelf.a: $(ELF_LIB_OBJS) + $(AR) rc $@ $^ + +.PHONY: libelf-fuzzer-all +libelf-fuzzer-all: libelf.a libelf-fuzzer.o + +# Common targets +.PHONY: all +all: libelf-fuzzer-all + +.PHONY: distclean +distclean: clean + +.PHONY: clean +clean: + rm -f *.o *.a diff --git a/tools/fuzz/libelf/libelf-fuzzer.c b/tools/fuzz/libelf/libelf-fuzzer.c new file mode 100644 index 0000000..71561d3 --- /dev/null +++ b/tools/fuzz/libelf/libelf-fuzzer.c @@ -0,0 +1,32 @@ +#include <inttypes.h> +#include <stddef.h> +#include <stdlib.h> +#include <string.h> + +#include <xen/libelf/libelf.h> + +int LLVMFuzzerTestOneInput(const uint8_t *data, size_t size) +{ + struct elf_binary elf_buf, *elf; + struct elf_dom_parms parms; + + elf = &elf_buf; + + memset(elf, 0, sizeof(*elf)); + elf_init(elf, (const char *)data, size); + elf_parse_binary(elf); + elf_xen_parse(elf, &parms); + + return 0; +} + + +/* + * Local variables: + * mode: C + * c-file-style: "BSD" + * c-basic-offset: 4 + * tab-width: 4 + * indent-tabs-mode: nil + * End: + */ diff --git a/xen/common/libelf/libelf-private.h b/xen/common/libelf/libelf-private.h index 388c3da..47db679 100644 --- a/xen/common/libelf/libelf-private.h +++ b/xen/common/libelf/libelf-private.h @@ -72,8 +72,10 @@ #include <xen/elfnote.h> #include <xen/libelf/libelf.h> +#ifndef FUZZ_NO_LIBXC #include "xenctrl.h" #include "xc_private.h" +#endif #define elf_msg(elf, fmt, args ... ) \ elf_call_log_callback(elf, 0, fmt , ## args ); -- 2.1.4 _______________________________________________ Xen-devel mailing list Xen-devel@lists.xen.org https://lists.xen.org/xen-devel