fuzzing_common.c 1.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384
  1. #include "orconfig.h"
  2. #include "or.h"
  3. #include "backtrace.h"
  4. #include "config.h"
  5. #include "fuzzing.h"
  6. extern const char tor_git_revision[];
  7. const char tor_git_revision[] = "";
  8. #define MAX_FUZZ_SIZE (128*1024)
  9. #ifdef LLVM_FUZZ
  10. int
  11. LLVMFuzzerTestOneInput(const uint8_t *Data, size_t Size) {
  12. static int initialized = 0;
  13. if (!initialized) {
  14. if (fuzz_init() < 0)
  15. abort();
  16. }
  17. return fuzz_main(Data, Size);
  18. }
  19. #else /* Not LLVM_FUZZ, so AFL. */
  20. int
  21. main(int argc, char **argv)
  22. {
  23. size_t size;
  24. tor_threads_init();
  25. init_logging(1);
  26. /* Disable logging by default to speed up fuzzing. */
  27. int loglevel = LOG_ERR;
  28. /* Initialise logging first */
  29. init_logging(1);
  30. configure_backtrace_handler(get_version());
  31. for (int i = 1; i < argc; ++i) {
  32. if (!strcmp(argv[i], "--warn")) {
  33. loglevel = LOG_WARN;
  34. } else if (!strcmp(argv[i], "--notice")) {
  35. loglevel = LOG_NOTICE;
  36. } else if (!strcmp(argv[i], "--info")) {
  37. loglevel = LOG_INFO;
  38. } else if (!strcmp(argv[i], "--debug")) {
  39. loglevel = LOG_DEBUG;
  40. }
  41. }
  42. {
  43. log_severity_list_t s;
  44. memset(&s, 0, sizeof(s));
  45. set_log_severity_config(loglevel, LOG_ERR, &s);
  46. /* ALWAYS log bug warnings. */
  47. s.masks[LOG_WARN-LOG_ERR] |= LD_BUG;
  48. add_stream_log(&s, "", fileno(stdout));
  49. }
  50. /* Make BUG() and nonfatal asserts crash */
  51. tor_set_failed_assertion_callback(abort);
  52. if (fuzz_init() < 0)
  53. abort();
  54. #ifdef __AFL_HAVE_MANUAL_CONTROL
  55. /* Tell AFL to pause and fork here - ignored if not using AFL */
  56. __AFL_INIT();
  57. #endif
  58. char *input = read_file_to_str_until_eof(0, MAX_FUZZ_SIZE, &size);
  59. tor_assert(input);
  60. fuzz_main((const uint8_t*)input, size);
  61. tor_free(input);
  62. if (fuzz_cleanup() < 0)
  63. abort();
  64. return 0;
  65. }
  66. #endif