|
| 1 | +#include <stdint.h> |
| 2 | +#include <stdlib.h> |
| 3 | +#include <string.h> |
| 4 | +#include "cmark-gfm.h" |
| 5 | +#include "cmark-gfm-core-extensions.h" |
| 6 | +#include <sys/types.h> |
| 7 | +#include <sys/stat.h> |
| 8 | +#include <fcntl.h> |
| 9 | +#include <unistd.h> |
| 10 | + |
| 11 | +const char *extension_names[] = { |
| 12 | + "autolink", |
| 13 | + "strikethrough", |
| 14 | + "table", |
| 15 | + "tagfilter", |
| 16 | + NULL, |
| 17 | +}; |
| 18 | + |
| 19 | +int LLVMFuzzerInitialize(int *argc, char ***argv) { |
| 20 | + cmark_gfm_core_extensions_ensure_registered(); |
| 21 | + return 0; |
| 22 | +} |
| 23 | + |
| 24 | +int LLVMFuzzerTestOneInput(const uint8_t* data, size_t size) { |
| 25 | + struct __attribute__((packed)) { |
| 26 | + int options; |
| 27 | + int width; |
| 28 | + uint8_t startlen; |
| 29 | + uint8_t openlen; |
| 30 | + uint8_t middlelen; |
| 31 | + uint8_t closelen; |
| 32 | + } fuzz_config; |
| 33 | + |
| 34 | + if (size >= sizeof(fuzz_config)) { |
| 35 | + /* The beginning of `data` is treated as fuzzer configuration */ |
| 36 | + memcpy(&fuzz_config, data, sizeof(fuzz_config)); |
| 37 | + |
| 38 | + /* Test options that are used by GitHub. */ |
| 39 | + fuzz_config.options = CMARK_OPT_UNSAFE | CMARK_OPT_FOOTNOTES | CMARK_OPT_GITHUB_PRE_LANG | CMARK_OPT_HARDBREAKS; |
| 40 | + fuzz_config.openlen = fuzz_config.openlen & 0x7; |
| 41 | + fuzz_config.middlelen = fuzz_config.middlelen & 0x7; |
| 42 | + fuzz_config.closelen = fuzz_config.closelen & 0x7; |
| 43 | + |
| 44 | + /* Remainder of input is the markdown */ |
| 45 | + const char *markdown0 = (const char *)(data + sizeof(fuzz_config)); |
| 46 | + const size_t markdown_size0 = size - sizeof(fuzz_config); |
| 47 | + char markdown[0x80000]; |
| 48 | + if (markdown_size0 <= sizeof(markdown)) { |
| 49 | + size_t markdown_size = 0; |
| 50 | + const size_t componentslen = fuzz_config.startlen + fuzz_config.openlen + fuzz_config.middlelen + fuzz_config.closelen; |
| 51 | + if (componentslen <= markdown_size0) { |
| 52 | + size_t offset = 0; |
| 53 | + const size_t endlen = markdown_size0 - componentslen; |
| 54 | + memcpy(&markdown[markdown_size], &markdown0[offset], fuzz_config.startlen); |
| 55 | + markdown_size += fuzz_config.startlen; |
| 56 | + offset += fuzz_config.startlen; |
| 57 | + |
| 58 | + if (0 < fuzz_config.openlen) { |
| 59 | + while (markdown_size + fuzz_config.openlen <= sizeof(markdown)/2) { |
| 60 | + memcpy(&markdown[markdown_size], &markdown0[offset], |
| 61 | + fuzz_config.openlen); |
| 62 | + markdown_size += fuzz_config.openlen; |
| 63 | + } |
| 64 | + offset += fuzz_config.openlen; |
| 65 | + } |
| 66 | + memcpy(&markdown[markdown_size], &markdown0[offset], |
| 67 | + fuzz_config.middlelen); |
| 68 | + markdown_size += fuzz_config.middlelen; |
| 69 | + offset += fuzz_config.middlelen; |
| 70 | + if (0 < fuzz_config.closelen) { |
| 71 | + while (markdown_size + fuzz_config.closelen + endlen <= sizeof(markdown)) { |
| 72 | + memcpy(&markdown[markdown_size], &markdown0[offset], |
| 73 | + fuzz_config.closelen); |
| 74 | + markdown_size += fuzz_config.closelen; |
| 75 | + } |
| 76 | + offset += fuzz_config.closelen; |
| 77 | + } |
| 78 | + memcpy(&markdown[markdown_size], &markdown0[offset], |
| 79 | + endlen); |
| 80 | + markdown_size += endlen; |
| 81 | + } else { |
| 82 | + markdown_size = markdown_size0; |
| 83 | + memcpy(markdown, markdown0, markdown_size); |
| 84 | + } |
| 85 | + |
| 86 | + cmark_parser *parser = cmark_parser_new(fuzz_config.options); |
| 87 | + |
| 88 | + for (const char **it = extension_names; *it; ++it) { |
| 89 | + const char *extension_name = *it; |
| 90 | + cmark_syntax_extension *syntax_extension = cmark_find_syntax_extension(extension_name); |
| 91 | + if (!syntax_extension) { |
| 92 | + fprintf(stderr, "%s is not a valid syntax extension\n", extension_name); |
| 93 | + abort(); |
| 94 | + } |
| 95 | + cmark_parser_attach_syntax_extension(parser, syntax_extension); |
| 96 | + } |
| 97 | + |
| 98 | + cmark_parser_feed(parser, markdown, markdown_size); |
| 99 | + cmark_node *doc = cmark_parser_finish(parser); |
| 100 | + |
| 101 | + free(cmark_render_html(doc, fuzz_config.options, NULL)); |
| 102 | + |
| 103 | + cmark_node_free(doc); |
| 104 | + cmark_parser_free(parser); |
| 105 | + } |
| 106 | + } |
| 107 | + return 0; |
| 108 | +} |
0 commit comments