Index: lldb/tools/CMakeLists.txt =================================================================== --- lldb/tools/CMakeLists.txt +++ lldb/tools/CMakeLists.txt @@ -6,6 +6,7 @@ # i.e. if a target requires it as dependency. The typical # example is `check-lldb`. So, we pass EXCLUDE_FROM_ALL here. add_subdirectory(lldb-test EXCLUDE_FROM_ALL) +add_subdirectory(lldb-fuzzer EXCLUDE_FROM_ALL) add_lldb_tool_subdirectory(lldb-instr) add_lldb_tool_subdirectory(lldb-vscode) Index: lldb/tools/lldb-fuzzer/CMakeLists.txt =================================================================== --- /dev/null +++ lldb/tools/lldb-fuzzer/CMakeLists.txt @@ -0,0 +1,17 @@ +add_subdirectory(utils) + +set(LLVM_LINK_COMPONENTS + Support + ) + +add_llvm_fuzzer(lldb-fuzzer-target + EXCLUDE_FROM_ALL + lldb-fuzzer-target.cpp + ) + +target_link_libraries(lldb-fuzzer-target + PRIVATE + liblldb + lldbFuzzerUtils + ) + Index: lldb/tools/lldb-fuzzer/lldb-fuzzer-target.cpp =================================================================== --- /dev/null +++ lldb/tools/lldb-fuzzer/lldb-fuzzer-target.cpp @@ -0,0 +1,34 @@ +//===-- lldb-fuzzer-target.cpp - Fuzz target creation ---------------------===// +// +// Part of the LLVM Project, under the Apache License v2.0 with LLVM Exceptions. +// See https://llvm.org/LICENSE.txt for license information. +// SPDX-License-Identifier: Apache-2.0 WITH LLVM-exception +// +//===----------------------------------------------------------------------===// + +#include + +#include "lldb/API/SBDebugger.h" +#include "lldb/API/SBTarget.h" + +using namespace lldb; +using namespace lldb_fuzzer; +using namespace llvm; + +extern "C" int LLVMFuzzerInitialize(int *argc, char ***argv) { + SBDebugger::Initialize(); + return 0; +} + +extern "C" int LLVMFuzzerTestOneInput(uint8_t *data, size_t size) { + auto file = TempFile::Create(data, size); + if (!file) + return 1; + + SBDebugger debugger = SBDebugger::Create(false); + SBTarget target = debugger.CreateTarget(file->GetPath().data()); + debugger.DeleteTarget(target); + SBDebugger::Destroy(debugger); + + return 0; +} Index: lldb/tools/lldb-fuzzer/utils/CMakeLists.txt =================================================================== --- /dev/null +++ lldb/tools/lldb-fuzzer/utils/CMakeLists.txt @@ -0,0 +1,6 @@ +add_lldb_library(lldbFuzzerUtils + TempFile.cpp + + LINK_COMPONENTS + Support + ) Index: lldb/tools/lldb-fuzzer/utils/TempFile.h =================================================================== --- /dev/null +++ lldb/tools/lldb-fuzzer/utils/TempFile.h @@ -0,0 +1,27 @@ +//===-- TempFile.h ----------------------------------------------*- C++ -*-===// +// +// Part of the LLVM Project, under the Apache License v2.0 with LLVM Exceptions. +// See https://llvm.org/LICENSE.txt for license information. +// SPDX-License-Identifier: Apache-2.0 WITH LLVM-exception +// +//===----------------------------------------------------------------------===// + +#include "llvm/ADT/SmallString.h" +#include "llvm/ADT/StringRef.h" +#include "llvm/Support/Error.h" + +namespace lldb_fuzzer { + +class TempFile { +public: + TempFile() = default; + ~TempFile(); + + static std::unique_ptr Create(uint8_t *data, size_t size); + llvm::StringRef GetPath() { return m_path.str(); } + +private: + llvm::SmallString<128> m_path; +}; + +} // namespace lldb_fuzzer Index: lldb/tools/lldb-fuzzer/utils/TempFile.cpp =================================================================== --- /dev/null +++ lldb/tools/lldb-fuzzer/utils/TempFile.cpp @@ -0,0 +1,33 @@ +//===-- TempFile.cpp ------------------------------------------------------===// +// +// Part of the LLVM Project, under the Apache License v2.0 with LLVM Exceptions. +// See https://llvm.org/LICENSE.txt for license information. +// SPDX-License-Identifier: Apache-2.0 WITH LLVM-exception +// +//===----------------------------------------------------------------------===// + +#include "llvm/Support/FileSystem.h" +#include + +using namespace lldb_fuzzer; +using namespace llvm; + +TempFile::~TempFile() { + if (!m_path.empty()) + sys::fs::remove(m_path.str(), true); +} + +std::unique_ptr TempFile::Create(uint8_t *data, size_t size) { + int fd; + std::unique_ptr temp_file = std::make_unique(); + std::error_code ec = sys::fs::createTemporaryFile("lldb-fuzzer", "input", fd, + temp_file->m_path); + if (ec) + return nullptr; + + raw_fd_ostream os(fd, true); + os.write(reinterpret_cast(data), size); + os.close(); + + return temp_file; +}