2019-06-23 18:31:35 +00:00
|
|
|
#include <qpdf/Pl_DCT.hh>
|
|
|
|
#include <qpdf/Pl_Discard.hh>
|
2020-10-22 10:27:25 +00:00
|
|
|
#include <cstdlib>
|
2019-06-23 18:31:35 +00:00
|
|
|
#include <iostream>
|
|
|
|
#include <stdexcept>
|
|
|
|
|
|
|
|
class FuzzHelper
|
|
|
|
{
|
|
|
|
public:
|
|
|
|
FuzzHelper(unsigned char const* data, size_t size);
|
|
|
|
void run();
|
|
|
|
|
|
|
|
private:
|
|
|
|
void doChecks();
|
|
|
|
|
|
|
|
unsigned char const* data;
|
|
|
|
size_t size;
|
|
|
|
};
|
|
|
|
|
|
|
|
FuzzHelper::FuzzHelper(unsigned char const* data, size_t size) :
|
|
|
|
data(data),
|
|
|
|
size(size)
|
|
|
|
{
|
|
|
|
}
|
|
|
|
|
|
|
|
void
|
|
|
|
FuzzHelper::doChecks()
|
|
|
|
{
|
2024-07-02 13:04:53 +00:00
|
|
|
// Limit the memory used to decompress JPEG files during fuzzing. Excessive memory use during
|
|
|
|
// fuzzing is due to corrupt JPEG data which sometimes cannot be detected before
|
|
|
|
// jpeg_start_decompress is called. During normal use of qpdf very large JPEGs can occasionally
|
|
|
|
// occur legitimately and therefore must be allowed during normal operations.
|
|
|
|
Pl_DCT::setMemoryLimit(1'000'000'000);
|
|
|
|
|
|
|
|
// Do not decompress corrupt data. This may cause extended runtime within jpeglib without
|
|
|
|
// exercising additional code paths in qpdf.
|
|
|
|
Pl_DCT::setThrowOnCorruptData(true);
|
|
|
|
|
2019-06-23 18:31:35 +00:00
|
|
|
Pl_Discard discard;
|
2024-07-02 13:04:53 +00:00
|
|
|
Pl_DCT p("decode", &discard);
|
2019-06-23 18:31:35 +00:00
|
|
|
p.write(const_cast<unsigned char*>(data), size);
|
|
|
|
p.finish();
|
|
|
|
}
|
|
|
|
|
|
|
|
void
|
|
|
|
FuzzHelper::run()
|
|
|
|
{
|
|
|
|
try {
|
|
|
|
doChecks();
|
|
|
|
} catch (std::runtime_error const& e) {
|
|
|
|
std::cerr << "runtime_error: " << e.what() << std::endl;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
extern "C" int
|
|
|
|
LLVMFuzzerTestOneInput(unsigned char const* data, size_t size)
|
|
|
|
{
|
2020-10-22 10:27:25 +00:00
|
|
|
#ifndef _WIN32
|
|
|
|
// Used by jpeg library to work around false positives in memory
|
|
|
|
// sanitizer.
|
|
|
|
setenv("JSIMD_FORCENONE", "1", 1);
|
|
|
|
#endif
|
2019-06-23 18:31:35 +00:00
|
|
|
FuzzHelper f(data, size);
|
|
|
|
f.run();
|
|
|
|
return 0;
|
|
|
|
}
|