Add a fuzzer for the linker's ElfReader class.
Bug: https://issuetracker.google.com/380356872
Change-Id: I23d26ae464344fb4075e308bc2438f804a57039a
diff --git a/linker/Android.bp b/linker/Android.bp
index 4863b92..66a0633 100644
--- a/linker/Android.bp
+++ b/linker/Android.bp
@@ -542,3 +542,31 @@
},
},
}
+
+cc_fuzz {
+ name: "ElfReader_fuzzer",
+ srcs: [
+ "ElfReader_fuzzer.cpp",
+ "linker.cpp",
+ "linker_block_allocator.cpp",
+ "linker_debug.cpp",
+ "linker_dlwarning.cpp",
+ "linker_globals.cpp",
+ "linker_mapped_file_fragment.cpp",
+ "linker_phdr.cpp",
+ "linker_sdk_versions.cpp",
+ "linker_utils.cpp",
+ ":elf_note_sources",
+ ],
+ static_libs: [
+ "libasync_safe",
+ "libbase",
+ "libziparchive",
+ ],
+ include_dirs: ["bionic/libc"],
+ // TODO: use all the architectures' files.
+ // We'll either need to give them unique names across architectures,
+ // or change soong to preserve subdirectories in `corpus:`,
+ // and maybe also the [deprecated] LLVM fuzzer infrastructure?
+ corpus: [":bionic_prebuilt_test_elf_files_arm64"],
+}
diff --git a/linker/ElfReader_fuzzer.cpp b/linker/ElfReader_fuzzer.cpp
new file mode 100644
index 0000000..a23132b
--- /dev/null
+++ b/linker/ElfReader_fuzzer.cpp
@@ -0,0 +1,46 @@
+/*
+ * Copyright (C) 2024 The Android Open Source Project
+ * All rights reserved.
+ *
+ * Redistribution and use in source and binary forms, with or without
+ * modification, are permitted provided that the following conditions
+ * are met:
+ * * Redistributions of source code must retain the above copyright
+ * notice, this list of conditions and the following disclaimer.
+ * * Redistributions in binary form must reproduce the above copyright
+ * notice, this list of conditions and the following disclaimer in
+ * the documentation and/or other materials provided with the
+ * distribution.
+ *
+ * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
+ * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
+ * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS
+ * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE
+ * COPYRIGHT OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT,
+ * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING,
+ * BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS
+ * OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED
+ * AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY,
+ * OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT
+ * OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
+ * SUCH DAMAGE.
+ */
+
+#include "linker_phdr.h"
+
+#include <stddef.h>
+#include <stdint.h>
+
+#include <android-base/file.h>
+
+// See current fuzz coverage here:
+// https://android-coverage.googleplex.com/fuzz_targets/ElfReader_fuzzer/index.html
+
+extern "C" int LLVMFuzzerTestOneInput(const uint8_t* data, size_t size) {
+ TemporaryFile tf;
+ android::base::WriteFully(tf.fd, data, size);
+
+ ElfReader er;
+ er.Read(tf.path, tf.fd, 0, size);
+ return 0;
+}