/* * The MIT License (MIT) * * Copyright (c) 2022 Nathaniel Brough * * Permission is hereby granted, free of charge, to any person obtaining a copy * of this software and associated documentation files (the "Software"), to deal * in the Software without restriction, including without limitation the rights * to use, copy, modify, merge, publish, distribute, sublicense, and/or sell * copies of the Software, and to permit persons to whom the Software is * furnished to do so, subject to the following conditions: * * The above copyright notice and this permission notice shall be included in * all copies or substantial portions of the Software. * * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE * AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, * OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN * THE SOFTWARE. * */ #include #include #include #include #include #include "class/cdc/cdc_device.h" #include "class/net/net_device.h" #include "fuzz/fuzz.h" #include "tusb.h" #include #include #include extern "C" { #define FUZZ_ITERATIONS 500 //--------------------------------------------------------------------+ // MACRO CONSTANT TYPEDEF PROTYPES //--------------------------------------------------------------------+ void net_task(FuzzedDataProvider *provider); extern "C" int LLVMFuzzerTestOneInput(const uint8_t *Data, size_t Size) { FuzzedDataProvider provider(Data, Size); std::vector callback_data = provider.ConsumeBytes( provider.ConsumeIntegralInRange(0, Size)); fuzz_init(callback_data.data(), callback_data.size()); // init device stack on configured roothub port tud_init(BOARD_TUD_RHPORT); for (int i = 0; i < FUZZ_ITERATIONS; i++) { if (provider.remaining_bytes() == 0) { return 0; } tud_int_handler(provider.ConsumeIntegral()); tud_task(); // tinyusb device task net_task(&provider); } return 0; } //--------------------------------------------------------------------+ // USB CDC //--------------------------------------------------------------------+ enum NetApiFuncs { kNetworkRecvRenew, kNetworkCanXmit, kNetworkXmit, kMaxValue, }; void net_task(FuzzedDataProvider *provider) { assert(provider != NULL); switch (provider->ConsumeEnum()) { case kNetworkRecvRenew: tud_network_recv_renew(); break; case kNetworkCanXmit: (void)tud_network_can_xmit(provider->ConsumeIntegral()); case kNetworkXmit: // TODO: Actually pass real values here later. tud_network_xmit(NULL, 0); case kMaxValue: // Noop. break; } } }