xref: /aosp_15_r20/external/open-dice/src/android_fuzzer.cc (revision 60b67249c2e226f42f35cc6cfe66c6048e0bae6b)
1*60b67249SAndroid Build Coastguard Worker // Copyright 2021 Google LLC
2*60b67249SAndroid Build Coastguard Worker //
3*60b67249SAndroid Build Coastguard Worker // Licensed under the Apache License, Version 2.0 (the "License"); you may not
4*60b67249SAndroid Build Coastguard Worker // use this file except in compliance with the License. You may obtain a copy of
5*60b67249SAndroid Build Coastguard Worker // the License at
6*60b67249SAndroid Build Coastguard Worker //
7*60b67249SAndroid Build Coastguard Worker //     https://www.apache.org/licenses/LICENSE-2.0
8*60b67249SAndroid Build Coastguard Worker //
9*60b67249SAndroid Build Coastguard Worker // Unless required by applicable law or agreed to in writing, software
10*60b67249SAndroid Build Coastguard Worker // distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
11*60b67249SAndroid Build Coastguard Worker // WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the
12*60b67249SAndroid Build Coastguard Worker // License for the specific language governing permissions and limitations under
13*60b67249SAndroid Build Coastguard Worker // the License.
14*60b67249SAndroid Build Coastguard Worker 
15*60b67249SAndroid Build Coastguard Worker #include "dice/android.h"
16*60b67249SAndroid Build Coastguard Worker #include "dice/fuzz_utils.h"
17*60b67249SAndroid Build Coastguard Worker #include "dice/utils.h"
18*60b67249SAndroid Build Coastguard Worker #include "fuzzer/FuzzedDataProvider.h"
19*60b67249SAndroid Build Coastguard Worker 
20*60b67249SAndroid Build Coastguard Worker using dice::fuzz::ConsumeRandomLengthStringAsBytesFrom;
21*60b67249SAndroid Build Coastguard Worker using dice::fuzz::FuzzedInputValues;
22*60b67249SAndroid Build Coastguard Worker 
LLVMFuzzerTestOneInput(const uint8_t * data,size_t size)23*60b67249SAndroid Build Coastguard Worker extern "C" int LLVMFuzzerTestOneInput(const uint8_t* data, size_t size) {
24*60b67249SAndroid Build Coastguard Worker   // Exit early if there might not be enough data to fill buffers.
25*60b67249SAndroid Build Coastguard Worker   if (size < 512) {
26*60b67249SAndroid Build Coastguard Worker     return 0;
27*60b67249SAndroid Build Coastguard Worker   }
28*60b67249SAndroid Build Coastguard Worker 
29*60b67249SAndroid Build Coastguard Worker   FuzzedDataProvider fdp(data, size);
30*60b67249SAndroid Build Coastguard Worker 
31*60b67249SAndroid Build Coastguard Worker   // Prepare the fuzzed inputs.
32*60b67249SAndroid Build Coastguard Worker   auto input_values = FuzzedInputValues::ConsumeFrom(fdp);
33*60b67249SAndroid Build Coastguard Worker   auto handover = ConsumeRandomLengthStringAsBytesFrom(fdp);
34*60b67249SAndroid Build Coastguard Worker 
35*60b67249SAndroid Build Coastguard Worker   // Initialize output parameters with fuzz data in case they are wrongly being
36*60b67249SAndroid Build Coastguard Worker   // read from.
37*60b67249SAndroid Build Coastguard Worker   constexpr size_t kNextHandoverBufferSize = 1024;
38*60b67249SAndroid Build Coastguard Worker   auto next_handover_actual_size = fdp.ConsumeIntegral<size_t>();
39*60b67249SAndroid Build Coastguard Worker   uint8_t next_handover[kNextHandoverBufferSize] = {};
40*60b67249SAndroid Build Coastguard Worker 
41*60b67249SAndroid Build Coastguard Worker   fdp.ConsumeData(&next_handover, kNextHandoverBufferSize);
42*60b67249SAndroid Build Coastguard Worker 
43*60b67249SAndroid Build Coastguard Worker   // Fuzz the main flow.
44*60b67249SAndroid Build Coastguard Worker   DiceAndroidHandoverMainFlow(
45*60b67249SAndroid Build Coastguard Worker       /*context=*/NULL, handover.data(), handover.size(), input_values,
46*60b67249SAndroid Build Coastguard Worker       kNextHandoverBufferSize, next_handover, &next_handover_actual_size);
47*60b67249SAndroid Build Coastguard Worker 
48*60b67249SAndroid Build Coastguard Worker   return 0;
49*60b67249SAndroid Build Coastguard Worker }
50