1
0
mirror of https://github.com/janet-lang/janet synced 2025-01-28 08:04:45 +00:00

Merge pull request #350 from DavidKorczynski/master

Updated the libfuzzer to target marshalling.
This commit is contained in:
Calvin Rose 2020-04-19 18:56:51 -04:00 committed by GitHub
commit 63812c9f80
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -3,20 +3,44 @@
#include <janet.h> #include <janet.h>
int LLVMFuzzerTestOneInput(const uint8_t *data, size_t size) { int LLVMFuzzerTestOneInput(const uint8_t *data, size_t size) {
char *new_str = (char *)malloc(size + 1);
if (new_str == NULL) {
return 0;
}
memcpy(new_str, data, size);
new_str[size] = '\0';
/* janet logic */ /* init Janet */
janet_init(); janet_init();
JanetTable *env = janet_core_env(NULL);
janet_dostring(env, new_str, "main", NULL); /* fuzz the parser */
JanetParser parser;
janet_parser_init(&parser);
for (int i=0, done = 0; i < size; i++)
{
switch (janet_parser_status(&parser)) {
case JANET_PARSE_DEAD:
case JANET_PARSE_ERROR:
done = 1;
break;
case JANET_PARSE_PENDING:
if (i == size) {
janet_parser_eof(&parser);
} else {
janet_parser_consume(&parser, data[i]);
}
break;
case JANET_PARSE_ROOT:
if (i >= size) {
janet_parser_eof(&parser);
} else {
janet_parser_consume(&parser, data[i]);
}
break;
}
if (done == 1)
break;
}
janet_parser_deinit(&parser);
/* cleanup Janet */
janet_deinit(); janet_deinit();
free(new_str);
return 0; return 0;
} }