xref: /cloud-hypervisor/fuzz/fuzz_targets/cmos.rs (revision eea9bcea38e0c5649f444c829f3a4f9c22aa486c)
1 // Copyright © 2022 Intel Corporation
2 //
3 // SPDX-License-Identifier: Apache-2.0
4 
5 #![no_main]
6 use devices::legacy::Cmos;
7 use libc::EFD_NONBLOCK;
8 use libfuzzer_sys::fuzz_target;
9 use vm_device::BusDevice;
10 use vmm_sys_util::eventfd::EventFd;
11 
12 fuzz_target!(|bytes| {
13     // Need at least 16 bytes for the test
14     if bytes.len() < 16 {
15         return;
16     }
17 
18     let mut below_4g = [0u8; 8];
19     let mut above_4g = [0u8; 8];
20 
21     below_4g.copy_from_slice(&bytes[0..8]);
22     above_4g.copy_from_slice(&bytes[8..16]);
23 
24     let mut cmos = Cmos::new(
25         u64::from_le_bytes(below_4g),
26         u64::from_le_bytes(above_4g),
27         EventFd::new(EFD_NONBLOCK).unwrap(),
28     );
29 
30     let mut i = 16;
31     while i < bytes.len() {
32         let read = bytes.get(i).unwrap_or(&0) % 2 == 0;
33         i += 1;
34 
35         if read {
36             let offset = (bytes.get(i).unwrap_or(&0) % 2) as u64;
37             i += 1;
38             let mut out_bytes = vec![0];
39             cmos.read(0, offset, &mut out_bytes);
40         } else {
41             let offset = (bytes.get(i).unwrap_or(&0) % 2) as u64;
42             i += 1;
43             let data = vec![*bytes.get(i).unwrap_or(&0)];
44             i += 1;
45             cmos.write(0, offset, &data);
46         }
47     }
48 });
49