[libFuzzer] add an assert to protect against LLVMFuzzerInitialize changing argv[0]

llvm-svn: 292652
This commit is contained in:
Kostya Serebryany 2017-01-20 21:34:24 +00:00
parent f170504c41
commit 87a3811d32
4 changed files with 22 additions and 0 deletions

View File

@ -358,12 +358,15 @@ int MinimizeCrashInputInternalStep(Fuzzer *F, InputCorpus *Corpus) {
int FuzzerDriver(int *argc, char ***argv, UserCallback Callback) { int FuzzerDriver(int *argc, char ***argv, UserCallback Callback) {
using namespace fuzzer; using namespace fuzzer;
assert(argc && argv && "Argument pointers cannot be nullptr"); assert(argc && argv && "Argument pointers cannot be nullptr");
std::string Argv0((*argv)[0]);
EF = new ExternalFunctions(); EF = new ExternalFunctions();
if (EF->LLVMFuzzerInitialize) if (EF->LLVMFuzzerInitialize)
EF->LLVMFuzzerInitialize(argc, argv); EF->LLVMFuzzerInitialize(argc, argv);
const std::vector<std::string> Args(*argv, *argv + *argc); const std::vector<std::string> Args(*argv, *argv + *argc);
assert(!Args.empty()); assert(!Args.empty());
ProgName = new std::string(Args[0]); ProgName = new std::string(Args[0]);
assert(Argv0 == *ProgName &&
"argv[0] has been modified in LLVMFuzzerInitialize");
ParseFlags(Args); ParseFlags(Args);
if (Flags.help) { if (Flags.help) {
PrintHelp(); PrintHelp();

View File

@ -0,0 +1,15 @@
// This file is distributed under the University of Illinois Open Source
// License. See LICENSE.TXT for details.
// Make sure LLVMFuzzerInitialize does not change argv[0].
#include <stddef.h>
#include <stdint.h>
extern "C" int LLVMFuzzerInitialize(int *argc, char ***argv) {
***argv = 'X';
return 0;
}
extern "C" int LLVMFuzzerTestOneInput(const uint8_t *Data, size_t Size) {
return 0;
}

View File

@ -65,6 +65,7 @@ set(Tests
AbsNegAndConstantTest AbsNegAndConstantTest
AbsNegAndConstant64Test AbsNegAndConstant64Test
AccumulateAllocationsTest AccumulateAllocationsTest
BogusInitializeTest
BufferOverflowOnInput BufferOverflowOnInput
CallerCalleeTest CallerCalleeTest
CounterTest CounterTest

View File

@ -55,3 +55,6 @@ RUN: ASAN_OPTIONS=strict_string_checks=1 not LLVMFuzzer-StrncmpOOBTest -seed=1 -
STRNCMP: AddressSanitizer: heap-buffer-overflow STRNCMP: AddressSanitizer: heap-buffer-overflow
STRNCMP-NOT: __sanitizer_weak_hook_strncmp STRNCMP-NOT: __sanitizer_weak_hook_strncmp
STRNCMP: in LLVMFuzzerTestOneInput STRNCMP: in LLVMFuzzerTestOneInput
RUN: not --crash LLVMFuzzer-BogusInitializeTest 2>&1 | FileCheck %s --check-prefix=BOGUS_INITIALIZE
BOGUS_INITIALIZE: argv[0] has been modified in LLVMFuzzerInitialize