Skip to content

Commit c4de252

Browse files
authored
Merge pull request commonmark#318 from kevinbackhouse/fuzz-quadratic-brackets
Fuzz target for bracketed patterns, such as [[[[x]]]]
2 parents dcf6b38 + d5b0cfb commit c4de252

File tree

2 files changed

+109
-0
lines changed

2 files changed

+109
-0
lines changed

fuzz/CMakeLists.txt

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -19,3 +19,4 @@ macro(fuzzer name)
1919
endmacro()
2020

2121
fuzzer(fuzz_quadratic)
22+
fuzzer(fuzz_quadratic_brackets)

fuzz/fuzz_quadratic_brackets.c

Lines changed: 108 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,108 @@
1+
#include <stdint.h>
2+
#include <stdlib.h>
3+
#include <string.h>
4+
#include "cmark-gfm.h"
5+
#include "cmark-gfm-core-extensions.h"
6+
#include <sys/types.h>
7+
#include <sys/stat.h>
8+
#include <fcntl.h>
9+
#include <unistd.h>
10+
11+
const char *extension_names[] = {
12+
"autolink",
13+
"strikethrough",
14+
"table",
15+
"tagfilter",
16+
NULL,
17+
};
18+
19+
int LLVMFuzzerInitialize(int *argc, char ***argv) {
20+
cmark_gfm_core_extensions_ensure_registered();
21+
return 0;
22+
}
23+
24+
int LLVMFuzzerTestOneInput(const uint8_t* data, size_t size) {
25+
struct __attribute__((packed)) {
26+
int options;
27+
int width;
28+
uint8_t startlen;
29+
uint8_t openlen;
30+
uint8_t middlelen;
31+
uint8_t closelen;
32+
} fuzz_config;
33+
34+
if (size >= sizeof(fuzz_config)) {
35+
/* The beginning of `data` is treated as fuzzer configuration */
36+
memcpy(&fuzz_config, data, sizeof(fuzz_config));
37+
38+
/* Test options that are used by GitHub. */
39+
fuzz_config.options = CMARK_OPT_UNSAFE | CMARK_OPT_FOOTNOTES | CMARK_OPT_GITHUB_PRE_LANG | CMARK_OPT_HARDBREAKS;
40+
fuzz_config.openlen = fuzz_config.openlen & 0x7;
41+
fuzz_config.middlelen = fuzz_config.middlelen & 0x7;
42+
fuzz_config.closelen = fuzz_config.closelen & 0x7;
43+
44+
/* Remainder of input is the markdown */
45+
const char *markdown0 = (const char *)(data + sizeof(fuzz_config));
46+
const size_t markdown_size0 = size - sizeof(fuzz_config);
47+
char markdown[0x80000];
48+
if (markdown_size0 <= sizeof(markdown)) {
49+
size_t markdown_size = 0;
50+
const size_t componentslen = fuzz_config.startlen + fuzz_config.openlen + fuzz_config.middlelen + fuzz_config.closelen;
51+
if (componentslen <= markdown_size0) {
52+
size_t offset = 0;
53+
const size_t endlen = markdown_size0 - componentslen;
54+
memcpy(&markdown[markdown_size], &markdown0[offset], fuzz_config.startlen);
55+
markdown_size += fuzz_config.startlen;
56+
offset += fuzz_config.startlen;
57+
58+
if (0 < fuzz_config.openlen) {
59+
while (markdown_size + fuzz_config.openlen <= sizeof(markdown)/2) {
60+
memcpy(&markdown[markdown_size], &markdown0[offset],
61+
fuzz_config.openlen);
62+
markdown_size += fuzz_config.openlen;
63+
}
64+
offset += fuzz_config.openlen;
65+
}
66+
memcpy(&markdown[markdown_size], &markdown0[offset],
67+
fuzz_config.middlelen);
68+
markdown_size += fuzz_config.middlelen;
69+
offset += fuzz_config.middlelen;
70+
if (0 < fuzz_config.closelen) {
71+
while (markdown_size + fuzz_config.closelen + endlen <= sizeof(markdown)) {
72+
memcpy(&markdown[markdown_size], &markdown0[offset],
73+
fuzz_config.closelen);
74+
markdown_size += fuzz_config.closelen;
75+
}
76+
offset += fuzz_config.closelen;
77+
}
78+
memcpy(&markdown[markdown_size], &markdown0[offset],
79+
endlen);
80+
markdown_size += endlen;
81+
} else {
82+
markdown_size = markdown_size0;
83+
memcpy(markdown, markdown0, markdown_size);
84+
}
85+
86+
cmark_parser *parser = cmark_parser_new(fuzz_config.options);
87+
88+
for (const char **it = extension_names; *it; ++it) {
89+
const char *extension_name = *it;
90+
cmark_syntax_extension *syntax_extension = cmark_find_syntax_extension(extension_name);
91+
if (!syntax_extension) {
92+
fprintf(stderr, "%s is not a valid syntax extension\n", extension_name);
93+
abort();
94+
}
95+
cmark_parser_attach_syntax_extension(parser, syntax_extension);
96+
}
97+
98+
cmark_parser_feed(parser, markdown, markdown_size);
99+
cmark_node *doc = cmark_parser_finish(parser);
100+
101+
free(cmark_render_html(doc, fuzz_config.options, NULL));
102+
103+
cmark_node_free(doc);
104+
cmark_parser_free(parser);
105+
}
106+
}
107+
return 0;
108+
}

0 commit comments

Comments
 (0)