1*60b67249SAndroid Build Coastguard Worker // Copyright 2021 Google LLC
2*60b67249SAndroid Build Coastguard Worker //
3*60b67249SAndroid Build Coastguard Worker // Licensed under the Apache License, Version 2.0 (the "License"); you may not
4*60b67249SAndroid Build Coastguard Worker // use this file except in compliance with the License. You may obtain a copy of
5*60b67249SAndroid Build Coastguard Worker // the License at
6*60b67249SAndroid Build Coastguard Worker //
7*60b67249SAndroid Build Coastguard Worker // https://www.apache.org/licenses/LICENSE-2.0
8*60b67249SAndroid Build Coastguard Worker //
9*60b67249SAndroid Build Coastguard Worker // Unless required by applicable law or agreed to in writing, software
10*60b67249SAndroid Build Coastguard Worker // distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
11*60b67249SAndroid Build Coastguard Worker // WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the
12*60b67249SAndroid Build Coastguard Worker // License for the specific language governing permissions and limitations under
13*60b67249SAndroid Build Coastguard Worker // the License.
14*60b67249SAndroid Build Coastguard Worker
15*60b67249SAndroid Build Coastguard Worker #include "dice/android.h"
16*60b67249SAndroid Build Coastguard Worker #include "dice/fuzz_utils.h"
17*60b67249SAndroid Build Coastguard Worker #include "dice/utils.h"
18*60b67249SAndroid Build Coastguard Worker #include "fuzzer/FuzzedDataProvider.h"
19*60b67249SAndroid Build Coastguard Worker
20*60b67249SAndroid Build Coastguard Worker using dice::fuzz::ConsumeRandomLengthStringAsBytesFrom;
21*60b67249SAndroid Build Coastguard Worker using dice::fuzz::FuzzedInputValues;
22*60b67249SAndroid Build Coastguard Worker
LLVMFuzzerTestOneInput(const uint8_t * data,size_t size)23*60b67249SAndroid Build Coastguard Worker extern "C" int LLVMFuzzerTestOneInput(const uint8_t* data, size_t size) {
24*60b67249SAndroid Build Coastguard Worker // Exit early if there might not be enough data to fill buffers.
25*60b67249SAndroid Build Coastguard Worker if (size < 512) {
26*60b67249SAndroid Build Coastguard Worker return 0;
27*60b67249SAndroid Build Coastguard Worker }
28*60b67249SAndroid Build Coastguard Worker
29*60b67249SAndroid Build Coastguard Worker FuzzedDataProvider fdp(data, size);
30*60b67249SAndroid Build Coastguard Worker
31*60b67249SAndroid Build Coastguard Worker // Prepare the fuzzed inputs.
32*60b67249SAndroid Build Coastguard Worker auto input_values = FuzzedInputValues::ConsumeFrom(fdp);
33*60b67249SAndroid Build Coastguard Worker auto handover = ConsumeRandomLengthStringAsBytesFrom(fdp);
34*60b67249SAndroid Build Coastguard Worker
35*60b67249SAndroid Build Coastguard Worker // Initialize output parameters with fuzz data in case they are wrongly being
36*60b67249SAndroid Build Coastguard Worker // read from.
37*60b67249SAndroid Build Coastguard Worker constexpr size_t kNextHandoverBufferSize = 1024;
38*60b67249SAndroid Build Coastguard Worker auto next_handover_actual_size = fdp.ConsumeIntegral<size_t>();
39*60b67249SAndroid Build Coastguard Worker uint8_t next_handover[kNextHandoverBufferSize] = {};
40*60b67249SAndroid Build Coastguard Worker
41*60b67249SAndroid Build Coastguard Worker fdp.ConsumeData(&next_handover, kNextHandoverBufferSize);
42*60b67249SAndroid Build Coastguard Worker
43*60b67249SAndroid Build Coastguard Worker // Fuzz the main flow.
44*60b67249SAndroid Build Coastguard Worker DiceAndroidHandoverMainFlow(
45*60b67249SAndroid Build Coastguard Worker /*context=*/NULL, handover.data(), handover.size(), input_values,
46*60b67249SAndroid Build Coastguard Worker kNextHandoverBufferSize, next_handover, &next_handover_actual_size);
47*60b67249SAndroid Build Coastguard Worker
48*60b67249SAndroid Build Coastguard Worker return 0;
49*60b67249SAndroid Build Coastguard Worker }
50