summaryrefslogtreecommitdiff
path: root/testing/libfuzzer/pdf_cfx_saxreader_fuzzer.cc
diff options
context:
space:
mode:
authordsinclair <dsinclair@chromium.org>2016-06-16 07:40:47 -0700
committerCommit bot <commit-bot@chromium.org>2016-06-16 07:40:47 -0700
commit5377267504015d056bc0860ffadc23289b21039d (patch)
treeaecbd448c6853bb5a56406e61fe909bd492405c2 /testing/libfuzzer/pdf_cfx_saxreader_fuzzer.cc
parent23c9c47096376be564bd6d5f3ab939e327928f6b (diff)
downloadpdfium-5377267504015d056bc0860ffadc23289b21039d.tar.xz
Add CFX_SAXReader fuzzer
This CL adds a fuzzer for the CFX_SAXReader. BUG=chromium:587126 Review-Url: https://codereview.chromium.org/2070103002
Diffstat (limited to 'testing/libfuzzer/pdf_cfx_saxreader_fuzzer.cc')
-rw-r--r--testing/libfuzzer/pdf_cfx_saxreader_fuzzer.cc37
1 files changed, 37 insertions, 0 deletions
diff --git a/testing/libfuzzer/pdf_cfx_saxreader_fuzzer.cc b/testing/libfuzzer/pdf_cfx_saxreader_fuzzer.cc
new file mode 100644
index 0000000000..54cc410a36
--- /dev/null
+++ b/testing/libfuzzer/pdf_cfx_saxreader_fuzzer.cc
@@ -0,0 +1,37 @@
+// Copyright 2016 The PDFium Authors. All rights reserved.
+// Use of this source code is governed by a BSD-style license that can be
+// found in the LICENSE file.
+
+#include <memory>
+
+#include "xfa/fde/xml/cfx_saxreader.h"
+#include "xfa/fgas/crt/fgas_stream.h"
+#include "xfa/fxfa/parser/xfa_utils.h"
+
+extern "C" int LLVMFuzzerTestOneInput(const uint8_t* data, size_t size) {
+ CFX_WideString input = CFX_WideString::FromUTF8(
+ CFX_ByteStringC(data, static_cast<FX_STRSIZE>(size)));
+ std::unique_ptr<IFX_Stream, ReleaseDeleter<IFX_Stream>> stream(
+ XFA_CreateWideTextRead(input));
+ if (!stream)
+ return 0;
+
+ std::unique_ptr<IFX_FileRead, ReleaseDeleter<IFX_FileRead>> fileRead(
+ FX_CreateFileRead(stream.get(), false));
+ if (!fileRead)
+ return 0;
+
+ CFX_SAXReader reader;
+ if (reader.StartParse(fileRead.get(), 0, -1, CFX_SaxParseMode_NotSkipSpace) <
+ 0) {
+ return 0;
+ }
+
+ while (1) {
+ int32_t ret = reader.ContinueParse(nullptr);
+ if (ret < 0 || ret > 99)
+ break;
+ }
+
+ return 0;
+}