From b780deba1b4fc0ad0a4269d40b9a65e9488a70db Mon Sep 17 00:00:00 2001 From: Robert Loehning Date: Fri, 24 Apr 2020 20:44:22 +0200 Subject: Fuzzing: Add fuzz target for QQmlComponent::create() Pick-to: 5.15 Task-number: QTBUG-71580 Change-Id: I160a0c73bbd3ee593228c95f2d6315c4964fdca0 Reviewed-by: Ulf Hermann --- .../qml/qml/qqmlcomponent/create/create.pro | 11 +++++ .../qml/qml/qqmlcomponent/create/main.cpp | 51 ++++++++++++++++++++++ 2 files changed, 62 insertions(+) create mode 100644 tests/libfuzzer/qml/qml/qqmlcomponent/create/create.pro create mode 100644 tests/libfuzzer/qml/qml/qqmlcomponent/create/main.cpp (limited to 'tests/libfuzzer') diff --git a/tests/libfuzzer/qml/qml/qqmlcomponent/create/create.pro b/tests/libfuzzer/qml/qml/qqmlcomponent/create/create.pro new file mode 100644 index 0000000000..1b042c94d3 --- /dev/null +++ b/tests/libfuzzer/qml/qml/qqmlcomponent/create/create.pro @@ -0,0 +1,11 @@ +QT -= gui +QT += qml +CONFIG += console +CONFIG -= app_bundle +SOURCES += main.cpp +FUZZ_ENGINE = $$(LIB_FUZZING_ENGINE) +isEmpty(FUZZ_ENGINE) { + QMAKE_LFLAGS += -fsanitize=fuzzer +} else { + LIBS += $$FUZZ_ENGINE +} diff --git a/tests/libfuzzer/qml/qml/qqmlcomponent/create/main.cpp b/tests/libfuzzer/qml/qml/qqmlcomponent/create/main.cpp new file mode 100644 index 0000000000..db8e5d4256 --- /dev/null +++ b/tests/libfuzzer/qml/qml/qqmlcomponent/create/main.cpp @@ -0,0 +1,51 @@ +/**************************************************************************** +** +** Copyright (C) 2020 The Qt Company Ltd. +** Contact: https://www.qt.io/licensing/ +** +** This file is part of the test suite of the Qt Toolkit. +** +** $QT_BEGIN_LICENSE:GPL-EXCEPT$ +** Commercial License Usage +** Licensees holding valid commercial Qt licenses may use this file in +** accordance with the commercial license agreement provided with the +** Software or, alternatively, in accordance with the terms contained in +** a written agreement between you and The Qt Company. For licensing terms +** and conditions see https://www.qt.io/terms-conditions. For further +** information use the contact form at https://www.qt.io/contact-us. +** +** GNU General Public License Usage +** Alternatively, this file may be used under the terms of the GNU +** General Public License version 3 as published by the Free Software +** Foundation with exceptions as appearing in the file LICENSE.GPL3-EXCEPT +** included in the packaging of this file. Please review the following +** information to ensure the GNU General Public License requirements will +** be met: https://www.gnu.org/licenses/gpl-3.0.html. +** +** $QT_END_LICENSE$ +** +****************************************************************************/ + +#include +#include +#include +#include + +// silence warnings +static QtMessageHandler mh = qInstallMessageHandler([](QtMsgType, const QMessageLogContext &, + const QString &) {}); + +extern "C" int LLVMFuzzerTestOneInput(const char *Data, size_t Size) { + static int argc = 3; + static char arg1[] = "fuzzer"; + static char arg2[] = "-platform"; + static char arg3[] = "minimal"; + static char *argv[] = {arg1, arg2, arg3, nullptr}; + static QCoreApplication qca(argc, argv); + QQmlEngine qqe; + QQmlComponent qqc(&qqe); + static const QUrl u; + qqc.setData(QByteArray::fromRawData(Data, Size), u); + delete qqc.create(); + return 0; +} -- cgit v1.2.3