aboutsummaryrefslogtreecommitdiff
path: root/bolt/tools/llvm-bolt-fuzzer/llvm-bolt-fuzzer.cpp
blob: bdb5768a91da1d719ce935f558ca4041a96c7db5 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
//===- llvm-bolt-fuzzer.cpp - Fuzzing target for llvm-bolt ----------------===//
//
// Part of the LLVM Project, under the Apache License v2.0 with LLVM Exceptions.
// See https://llvm.org/LICENSE.txt for license information.
// SPDX-License-Identifier: Apache-2.0 WITH LLVM-exception
//
//===----------------------------------------------------------------------===//

#include "bolt/Rewrite/RewriteInstance.h"
#include "llvm/Support/CommandLine.h"
#include "llvm/Support/TargetSelect.h"

using namespace llvm;
using namespace object;
using namespace bolt;

namespace opts {
extern cl::opt<std::string> OutputFilename;
extern cl::opt<bool> Lite;
} // namespace opts

extern "C" int LLVMFuzzerTestOneInput(const char *Data, size_t Size) {
  const char *argv[] = {"llvm-bolt", nullptr};
  const char argc = 1;
  opts::OutputFilename = "/dev/null";
  opts::Lite = false;

  // Input has to be an ELF - we don't want to fuzz createBinary interface.
  if (Size < 4 || strncmp("\177ELF", Data, 4) != 0)
    return 0;
  // Construct an ELF binary from fuzzer input.
  std::unique_ptr<MemoryBuffer> Buffer =
      MemoryBuffer::getMemBuffer(StringRef(Data, Size), "", false);
  Expected<std::unique_ptr<Binary>> BinaryOrErr =
      createBinary(Buffer->getMemBufferRef());
  // Check that the input is a valid binary.
  if (Error E = BinaryOrErr.takeError()) {
    consumeError(std::move(E));
    return 0;
  }
  Binary &Binary = *BinaryOrErr.get();
  // Check that the binary is an ELF64LE object file.
  auto *E = dyn_cast<ELF64LEObjectFile>(&Binary);
  if (!E)
    return 0;

  // Fuzz RewriteInstance.
  auto RIOrErr = RewriteInstance::create(E, argc, argv, "llvm-bolt");
  if (Error E = RIOrErr.takeError()) {
    consumeError(std::move(E));
    return 0;
  }
  RewriteInstance &RI = *RIOrErr.get();
  if (Error E = RI.run())
    consumeError(std::move(E));
  return 0;
}

extern "C" LLVM_ATTRIBUTE_USED int LLVMFuzzerInitialize(int *argc,
                                                        char ***argv) {
  llvm::InitializeAllTargetInfos();
  llvm::InitializeAllTargetMCs();
  llvm::InitializeAllAsmParsers();
  llvm::InitializeAllDisassemblers();

  llvm::InitializeAllTargets();
  llvm::InitializeAllAsmPrinters();

  return 0;
}