diff --git a/tests/fuzz/Makefile.am b/tests/fuzz/Makefile.am index 3809408e5..dbd2b2e75 100644 --- a/tests/fuzz/Makefile.am +++ b/tests/fuzz/Makefile.am @@ -31,6 +31,7 @@ include $(abs_top_nlbuild_autotools_dir)/automake/pre.am bin_PROGRAMS = \ ip6-send-fuzzer \ radio-receive-done-fuzzer \ + ncp-uart-received-fuzzer \ $(NULL) AM_CPPFLAGS = \ @@ -39,6 +40,7 @@ AM_CPPFLAGS = \ $(NULL) COMMON_LDADD = \ + $(top_builddir)/src/ncp/libopenthread-ncp-ftd.a \ $(top_builddir)/src/core/libopenthread-ftd.a \ $(top_builddir)/third_party/mbedtls/libmbedcrypto.a \ $(LIB_FUZZING_ENGINE) \ @@ -50,4 +52,7 @@ ip6_send_fuzzer_SOURCES = ip6_send.cpp fuzzer_ radio_receive_done_fuzzer_LDADD = $(COMMON_LDADD) radio_receive_done_fuzzer_SOURCES = radio_receive_done.cpp fuzzer_platform.c +ncp_uart_received_fuzzer_LDADD = $(COMMON_LDADD) +ncp_uart_received_fuzzer_SOURCES = ncp_uart_received.cpp fuzzer_platform.c + include $(abs_top_nlbuild_autotools_dir)/automake/post.am diff --git a/tests/fuzz/fuzzer_platform.c b/tests/fuzz/fuzzer_platform.c index bd3e72a15..eca3ad6ae 100644 --- a/tests/fuzz/fuzzer_platform.c +++ b/tests/fuzz/fuzzer_platform.c @@ -29,11 +29,13 @@ #include #include +#include #include #include #include #include #include +#include static uint32_t sRandomState = 1; @@ -76,6 +78,13 @@ void otPlatAlarmMicroStop(otInstance *aInstance) (void)aInstance; } +void otDiagProcessCmdLine(const char *aString, char *aOutput, size_t aOutputMaxLen) +{ + (void)aString; + (void)aOutput; + (void)aOutputMaxLen; +} + void otPlatReset(otInstance *aInstance) { (void)aInstance; @@ -94,6 +103,10 @@ void otPlatLog(otLogLevel aLogLevel, otLogRegion aLogRegion, const char *aFormat (void)aFormat; } +void otPlatWakeHost(void) +{ +} + void otPlatRadioGetIeeeEui64(otInstance *aInstance, uint8_t *aIeeeEui64) { (void)aInstance; @@ -162,6 +175,13 @@ otError otPlatRadioTransmit(otInstance *aInstance, otRadioFrame *aFrame) return OT_ERROR_NONE; } +otError otPlatRadioGetTransmitPower(otInstance *aInstance, int8_t *aPower) +{ + (void)aInstance; + (void)aPower; + return OT_ERROR_NONE; +} + otRadioFrame *otPlatRadioGetTransmitBuffer(otInstance *aInstance) { (void)aInstance; @@ -346,3 +366,20 @@ void otPlatSettingsWipe(otInstance *aInstance) { (void)aInstance; } + +otError otPlatUartEnable(void) +{ + return OT_ERROR_NONE; +} + +otError otPlatUartDisable(void) +{ + return OT_ERROR_NONE; +} + +otError otPlatUartSend(const uint8_t *aBuf, uint16_t aBufLength) +{ + (void)aBuf; + (void)aBufLength; + return OT_ERROR_NONE; +} diff --git a/tests/fuzz/ncp_uart_received.cpp b/tests/fuzz/ncp_uart_received.cpp new file mode 100644 index 000000000..7e42fb163 --- /dev/null +++ b/tests/fuzz/ncp_uart_received.cpp @@ -0,0 +1,81 @@ +/* + * Copyright (c) 2018, The OpenThread Authors. + * All rights reserved. + * + * Redistribution and use in source and binary forms, with or without + * modification, are permitted provided that the following conditions are met: + * 1. Redistributions of source code must retain the above copyright + * notice, this list of conditions and the following disclaimer. + * 2. Redistributions in binary form must reproduce the above copyright + * notice, this list of conditions and the following disclaimer in the + * documentation and/or other materials provided with the distribution. + * 3. Neither the name of the copyright holder nor the + * names of its contributors may be used to endorse or promote products + * derived from this software without specific prior written permission. + * + * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" + * AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE + * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE + * ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE + * LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR + * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF + * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS + * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN + * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) + * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE + * POSSIBILITY OF SUCH DAMAGE. + */ + +#include +#include + +#include +#include +#include +#include +#include +#include +#include + +#include "common/code_utils.hpp" + +extern "C" void FuzzerPlatformInit(void); + +extern "C" int LLVMFuzzerTestOneInput(const uint8_t *data, size_t size) +{ + const otPanId panId = 0xdead; + + otInstance *instance = NULL; + uint8_t * buf = NULL; + + VerifyOrExit(size <= 65536); + + FuzzerPlatformInit(); + + instance = otInstanceInitSingle(); + otNcpInit(instance); + otLinkSetPanId(instance, panId); + otIp6SetEnabled(instance, true); + otThreadSetEnabled(instance, true); + otThreadBecomeLeader(instance); + + buf = static_cast(malloc(size)); + + memcpy(buf, data, size); + + otPlatUartReceived(buf, (uint16_t)size); + +exit: + + if (buf != NULL) + { + free(buf); + } + + if (instance != NULL) + { + otInstanceFinalize(instance); + } + + return 0; +}