aboutsummaryrefslogtreecommitdiffstats
path: root/tests/libfuzzer
diff options
context:
space:
mode:
authorRobert Loehning <robert.loehning@qt.io>2020-04-24 20:44:22 +0200
committerRobert Loehning <robert.loehning@qt.io>2020-05-19 10:48:34 +0000
commitb780deba1b4fc0ad0a4269d40b9a65e9488a70db (patch)
tree121f6b2438091d173c1e0c8999378b2670be8fe2 /tests/libfuzzer
parent5188167e633af743548be90db4fdcd2791dd9637 (diff)
Fuzzing: Add fuzz target for QQmlComponent::create()
Pick-to: 5.15 Task-number: QTBUG-71580 Change-Id: I160a0c73bbd3ee593228c95f2d6315c4964fdca0 Reviewed-by: Ulf Hermann <ulf.hermann@qt.io>
Diffstat (limited to 'tests/libfuzzer')
-rw-r--r--tests/libfuzzer/qml/qml/qqmlcomponent/create/create.pro11
-rw-r--r--tests/libfuzzer/qml/qml/qqmlcomponent/create/main.cpp51
2 files changed, 62 insertions, 0 deletions
diff --git a/tests/libfuzzer/qml/qml/qqmlcomponent/create/create.pro b/tests/libfuzzer/qml/qml/qqmlcomponent/create/create.pro
new file mode 100644
index 0000000000..1b042c94d3
--- /dev/null
+++ b/tests/libfuzzer/qml/qml/qqmlcomponent/create/create.pro
@@ -0,0 +1,11 @@
+QT -= gui
+QT += qml
+CONFIG += console
+CONFIG -= app_bundle
+SOURCES += main.cpp
+FUZZ_ENGINE = $$(LIB_FUZZING_ENGINE)
+isEmpty(FUZZ_ENGINE) {
+ QMAKE_LFLAGS += -fsanitize=fuzzer
+} else {
+ LIBS += $$FUZZ_ENGINE
+}
diff --git a/tests/libfuzzer/qml/qml/qqmlcomponent/create/main.cpp b/tests/libfuzzer/qml/qml/qqmlcomponent/create/main.cpp
new file mode 100644
index 0000000000..db8e5d4256
--- /dev/null
+++ b/tests/libfuzzer/qml/qml/qqmlcomponent/create/main.cpp
@@ -0,0 +1,51 @@
+/****************************************************************************
+**
+** Copyright (C) 2020 The Qt Company Ltd.
+** Contact: https://www.qt.io/licensing/
+**
+** This file is part of the test suite of the Qt Toolkit.
+**
+** $QT_BEGIN_LICENSE:GPL-EXCEPT$
+** Commercial License Usage
+** Licensees holding valid commercial Qt licenses may use this file in
+** accordance with the commercial license agreement provided with the
+** Software or, alternatively, in accordance with the terms contained in
+** a written agreement between you and The Qt Company. For licensing terms
+** and conditions see https://www.qt.io/terms-conditions. For further
+** information use the contact form at https://www.qt.io/contact-us.
+**
+** GNU General Public License Usage
+** Alternatively, this file may be used under the terms of the GNU
+** General Public License version 3 as published by the Free Software
+** Foundation with exceptions as appearing in the file LICENSE.GPL3-EXCEPT
+** included in the packaging of this file. Please review the following
+** information to ensure the GNU General Public License requirements will
+** be met: https://www.gnu.org/licenses/gpl-3.0.html.
+**
+** $QT_END_LICENSE$
+**
+****************************************************************************/
+
+#include <QCoreApplication>
+#include <QQmlComponent>
+#include <QQmlEngine>
+#include <QtGlobal>
+
+// silence warnings
+static QtMessageHandler mh = qInstallMessageHandler([](QtMsgType, const QMessageLogContext &,
+ const QString &) {});
+
+extern "C" int LLVMFuzzerTestOneInput(const char *Data, size_t Size) {
+ static int argc = 3;
+ static char arg1[] = "fuzzer";
+ static char arg2[] = "-platform";
+ static char arg3[] = "minimal";
+ static char *argv[] = {arg1, arg2, arg3, nullptr};
+ static QCoreApplication qca(argc, argv);
+ QQmlEngine qqe;
+ QQmlComponent qqc(&qqe);
+ static const QUrl u;
+ qqc.setData(QByteArray::fromRawData(Data, Size), u);
+ delete qqc.create();
+ return 0;
+}