diff --git a/tests/fuzz/Makefile.am b/tests/fuzz/Makefile.am index dbd2b2e75..0ad1697e0 100644 --- a/tests/fuzz/Makefile.am +++ b/tests/fuzz/Makefile.am @@ -29,6 +29,7 @@ include $(abs_top_nlbuild_autotools_dir)/automake/pre.am bin_PROGRAMS = \ + cli-uart-received-fuzzer \ ip6-send-fuzzer \ radio-receive-done-fuzzer \ ncp-uart-received-fuzzer \ @@ -40,19 +41,29 @@ AM_CPPFLAGS = \ $(NULL) COMMON_LDADD = \ - $(top_builddir)/src/ncp/libopenthread-ncp-ftd.a \ $(top_builddir)/src/core/libopenthread-ftd.a \ $(top_builddir)/third_party/mbedtls/libmbedcrypto.a \ $(LIB_FUZZING_ENGINE) \ $(NULL) +cli_uart_received_fuzzer_LDADD = \ + $(top_builddir)/src/cli/libopenthread-cli-ftd.a \ + $(COMMON_LDADD) \ + $(NULL) + +cli_uart_received_fuzzer_SOURCES = cli_uart_received.cpp fuzzer_platform.c + ip6_send_fuzzer_LDADD = $(COMMON_LDADD) ip6_send_fuzzer_SOURCES = ip6_send.cpp fuzzer_platform.c radio_receive_done_fuzzer_LDADD = $(COMMON_LDADD) radio_receive_done_fuzzer_SOURCES = radio_receive_done.cpp fuzzer_platform.c -ncp_uart_received_fuzzer_LDADD = $(COMMON_LDADD) +ncp_uart_received_fuzzer_LDADD = \ + $(top_builddir)/src/ncp/libopenthread-ncp-ftd.a \ + $(COMMON_LDADD) \ + $(NULL) + ncp_uart_received_fuzzer_SOURCES = ncp_uart_received.cpp fuzzer_platform.c include $(abs_top_nlbuild_autotools_dir)/automake/post.am diff --git a/tests/fuzz/cli_uart_received.cpp b/tests/fuzz/cli_uart_received.cpp new file mode 100644 index 000000000..7b35a869d --- /dev/null +++ b/tests/fuzz/cli_uart_received.cpp @@ -0,0 +1,81 @@ +/* + * Copyright (c) 2019, The OpenThread Authors. + * All rights reserved. + * + * Redistribution and use in source and binary forms, with or without + * modification, are permitted provided that the following conditions are met: + * 1. Redistributions of source code must retain the above copyright + * notice, this list of conditions and the following disclaimer. + * 2. Redistributions in binary form must reproduce the above copyright + * notice, this list of conditions and the following disclaimer in the + * documentation and/or other materials provided with the distribution. + * 3. Neither the name of the copyright holder nor the + * names of its contributors may be used to endorse or promote products + * derived from this software without specific prior written permission. + * + * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" + * AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE + * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE + * ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE + * LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR + * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF + * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS + * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN + * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) + * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE + * POSSIBILITY OF SUCH DAMAGE. + */ + +#include +#include + +#include +#include +#include +#include +#include +#include +#include + +#include "common/code_utils.hpp" + +extern "C" void FuzzerPlatformInit(void); + +extern "C" int LLVMFuzzerTestOneInput(const uint8_t *data, size_t size) +{ + const otPanId panId = 0xdead; + + otInstance *instance = NULL; + uint8_t * buf = NULL; + + VerifyOrExit(size <= 65536); + + FuzzerPlatformInit(); + + instance = otInstanceInitSingle(); + otCliUartInit(instance); + otLinkSetPanId(instance, panId); + otIp6SetEnabled(instance, true); + otThreadSetEnabled(instance, true); + otThreadBecomeLeader(instance); + + buf = static_cast(malloc(size)); + + memcpy(buf, data, size); + + otPlatUartReceived(buf, (uint16_t)size); + +exit: + + if (buf != NULL) + { + free(buf); + } + + if (instance != NULL) + { + otInstanceFinalize(instance); + } + + return 0; +} diff --git a/tests/fuzz/fuzzer_platform.c b/tests/fuzz/fuzzer_platform.c index eca3ad6ae..d9f4edf25 100644 --- a/tests/fuzz/fuzzer_platform.c +++ b/tests/fuzz/fuzzer_platform.c @@ -78,6 +78,19 @@ void otPlatAlarmMicroStop(otInstance *aInstance) (void)aInstance; } +bool otDiagIsEnabled(void) +{ + return false; +} + +void otDiagProcessCmd(int aArgCount, char *aArgVector[], char *aOutput, size_t aOutputMaxLen) +{ + (void)aArgCount; + (void)aArgVector; + (void)aOutput; + (void)aOutputMaxLen; +} + void otDiagProcessCmdLine(const char *aString, char *aOutput, size_t aOutputMaxLen) { (void)aString;