xref: /cloud-hypervisor/fuzz/fuzz_targets/linux_loader.rs (revision 5e52729453cb62edbe4fb3a4aa24f8cca31e667e)
1 // Copyright 2018 The Chromium OS Authors. All rights reserved.
2 // Use of this source code is governed by a BSD-style license that can be
3 // found in the LICENSE file.
4 //
5 // Copyright © 2022 Intel Corporation
6 //
7 // SPDX-License-Identifier: Apache-2.0 AND BSD-3-Clause
8 
9 #![no_main]
10 
11 use libfuzzer_sys::fuzz_target;
12 use linux_loader::loader::KernelLoader;
13 use std::ffi;
14 use std::fs::File;
15 use std::io;
16 use std::io::{Seek, SeekFrom, Write};
17 use std::os::unix::io::{FromRawFd, RawFd};
18 use vm_memory::{bitmap::AtomicBitmap, GuestAddress};
19 
20 type GuestMemoryMmap = vm_memory::GuestMemoryMmap<AtomicBitmap>;
21 
22 const MEM_SIZE: usize = 256 * 1024 * 1024;
23 // From 'arch::x86_64::layout::HIGH_RAM_START'
24 const HIGH_RAM_START: GuestAddress = GuestAddress(0x100000);
25 
26 fuzz_target!(|bytes| {
27     let shm = memfd_create(&ffi::CString::new("fuzz_load_kernel").unwrap(), 0).unwrap();
28     let mut kernel_file: File = unsafe { File::from_raw_fd(shm) };
29     kernel_file.write_all(&bytes).unwrap();
30     kernel_file.seek(SeekFrom::Start(0)).unwrap();
31 
32     let guest_memory = GuestMemoryMmap::from_ranges(&[(GuestAddress(0), MEM_SIZE)]).unwrap();
33     linux_loader::loader::elf::Elf::load(
34         &guest_memory,
35         None,
36         &mut kernel_file,
37         Some(HIGH_RAM_START),
38     )
39     .ok();
40 });
41 
42 fn memfd_create(name: &ffi::CStr, flags: u32) -> Result<RawFd, io::Error> {
43     let res = unsafe { libc::syscall(libc::SYS_memfd_create, name.as_ptr(), flags) };
44 
45     if res < 0 {
46         Err(io::Error::last_os_error())
47     } else {
48         Ok(res as RawFd)
49     }
50 }
51