1 // Copyright 2018 The Chromium OS Authors. All rights reserved. 2 // Use of this source code is governed by a BSD-style license that can be 3 // found in the LICENSE file. 4 // 5 // Copyright © 2022 Intel Corporation 6 // 7 // SPDX-License-Identifier: Apache-2.0 AND BSD-3-Clause 8 9 #![no_main] 10 11 use libfuzzer_sys::fuzz_target; 12 use linux_loader::loader::KernelLoader; 13 use std::ffi; 14 use std::fs::File; 15 use std::io; 16 use std::io::{Seek, SeekFrom, Write}; 17 use std::os::unix::io::{FromRawFd, RawFd}; 18 use vm_memory::{bitmap::AtomicBitmap, GuestAddress}; 19 20 type GuestMemoryMmap = vm_memory::GuestMemoryMmap<AtomicBitmap>; 21 22 const MEM_SIZE: usize = 256 * 1024 * 1024; 23 // From 'arch::x86_64::layout::HIGH_RAM_START' 24 const HIGH_RAM_START: GuestAddress = GuestAddress(0x100000); 25 26 fuzz_target!(|bytes| { 27 let shm = memfd_create(&ffi::CString::new("fuzz_load_kernel").unwrap(), 0).unwrap(); 28 let mut kernel_file: File = unsafe { File::from_raw_fd(shm) }; 29 kernel_file.write_all(&bytes).unwrap(); 30 kernel_file.seek(SeekFrom::Start(0)).unwrap(); 31 32 let guest_memory = GuestMemoryMmap::from_ranges(&[(GuestAddress(0), MEM_SIZE)]).unwrap(); 33 linux_loader::loader::elf::Elf::load( 34 &guest_memory, 35 None, 36 &mut kernel_file, 37 Some(HIGH_RAM_START), 38 ) 39 .ok(); 40 }); 41 42 fn memfd_create(name: &ffi::CStr, flags: u32) -> Result<RawFd, io::Error> { 43 let res = unsafe { libc::syscall(libc::SYS_memfd_create, name.as_ptr(), flags) }; 44 45 if res < 0 { 46 Err(io::Error::last_os_error()) 47 } else { 48 Ok(res as RawFd) 49 } 50 } 51