Reactivate xz (#11805)

Lasse and I have discussed this and we'd like oss-fuzz working again on
the repository as fixes and various cleanups continue to be committed.

The malicious test files have been purged already in
e93e13c8b3.

Obviously will need an ACK from @Larhzu.
This commit is contained in:
Sam James 2024-04-19 01:00:50 +01:00 committed by GitHub
parent 90f2481efd
commit 963b9acb36
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194
7 changed files with 203 additions and 0 deletions

View File

@ -0,0 +1,24 @@
# Copyright 2023 Google LLC
#
# Licensed under the Apache License, Version 2.0 (the "License");
# you may not use this file except in compliance with the License.
# You may obtain a copy of the License at
#
# http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.
#
################################################################################
FROM gcr.io/oss-fuzz-base/base-builder-jvm
RUN apt-get install ant -y
RUN git clone --depth 1 https://github.com/tukaani-project/xz-java $SRC/xz-java
COPY build.sh $SRC/
COPY *Fuzzer.java $SRC/
WORKDIR $SRC/xz-java

View File

@ -0,0 +1,42 @@
// Copyright 2024 Google LLC
//
// Licensed under the Apache License, Version 2.0 (the "License");
// you may not use this file except in compliance with the License.
// You may obtain a copy of the License at
//
// http://www.apache.org/licenses/LICENSE-2.0
//
// Unless required by applicable law or agreed to in writing, software
// distributed under the License is distributed on an "AS IS" BASIS,
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
// See the License for the specific language governing permissions and
// limitations under the License.
//
import com.code_intelligence.jazzer.api.FuzzedDataProvider;
import org.tukaani.xz.LZMA2Options;
import org.tukaani.xz.UnsupportedOptionsException;
import org.tukaani.xz.XZOutputStream;
import java.io.ByteArrayInputStream;
import java.io.ByteArrayOutputStream;
import java.io.IOException;
public class XZEncoderFuzzer {
public static void fuzzerTestOneInput(FuzzedDataProvider data) {
ByteArrayInputStream in = new ByteArrayInputStream(data.consumeBytes(300));
ByteArrayOutputStream out = new ByteArrayOutputStream();
LZMA2Options options = new LZMA2Options();
try {
options.setPreset(data.consumeInt(LZMA2Options.PRESET_MIN, LZMA2Options.PRESET_MAX));
} catch (UnsupportedOptionsException e) {
throw new RuntimeException(e);
}
byte[] buf = data.consumeBytes(300);
try {
XZOutputStream xzOut = new XZOutputStream(out, options);
xzOut.write(buf, 0, buf.length);
xzOut.finish();
} catch (IOException e) {}
}
}

53
projects/xz-java/build.sh Normal file
View File

@ -0,0 +1,53 @@
#!/bin/bash -eu
# Copyright 2024 Google LLC
#
# Licensed under the Apache License, Version 2.0 (the "License");
# you may not use this file except in compliance with the License.
# You may obtain a copy of the License at
#
# http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.
#
################################################################################
ant
cp "$SRC/xz-java/build/jar/xz.jar" $OUT/
ALL_JARS=$(find $OUT/ -name *.jar ! -name jazzer*.jar -printf "%f ")
# The classpath at build-time includes the project jars in $OUT as well as the
# Jazzer API.
BUILD_CLASSPATH=$(echo $ALL_JARS | xargs printf -- "$OUT/%s:"):$JAZZER_API_PATH
# All .jar and .class files lie in the same directory as the fuzzer at runtime.
RUNTIME_CLASSPATH=$(echo $ALL_JARS | xargs printf -- "\$this_dir/%s:"):\$this_dir
for fuzzer in $(find $SRC -name '*Fuzzer.java'); do
fuzzer_basename=$(basename -s .java $fuzzer)
javac -cp $BUILD_CLASSPATH $fuzzer
cp $SRC/*.class $OUT/
# Create an execution wrapper that executes Jazzer with the correct arguments.
echo "#!/bin/bash
# LLVMFuzzerTestOneInput for fuzzer detection.
this_dir=\$(dirname \"\$0\")
if [[ \"\$@\" =~ (^| )-runs=[0-9]+($| ) ]]; then
mem_settings='-Xmx1900m:-Xss900k'
else
mem_settings='-Xmx2048m:-Xss1024k'
fi
LD_LIBRARY_PATH=\"$JVM_LD_LIBRARY_PATH\":\$this_dir \
\$this_dir/jazzer_driver --agent_path=\$this_dir/jazzer_agent_deploy.jar \
--cp=$RUNTIME_CLASSPATH \
--target_class=$fuzzer_basename \
--jvm_args=\"\$mem_settings\" \
\$@" > $OUT/$fuzzer_basename
chmod u+x $OUT/$fuzzer_basename
done

View File

@ -0,0 +1,10 @@
homepage: "https://tukaani.org/xz/java.html"
language: jvm
primary_contact: "lasse.collin@tukaani.org"
fuzzing_engines:
- libfuzzer
main_repo: "https://github.com/tukaani-project/xz-java"
sanitizers:
- address
vendor_ccs:
- "bug-disclosure@code-intelligence.com"

21
projects/xz/Dockerfile Normal file
View File

@ -0,0 +1,21 @@
# Copyright 2018 Google Inc.
#
# Licensed under the Apache License, Version 2.0 (the "License");
# you may not use this file except in compliance with the License.
# You may obtain a copy of the License at
#
# http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.
#
################################################################################
FROM gcr.io/oss-fuzz-base/base-builder
RUN apt-get update && apt-get install -y make autoconf autopoint libtool zip
RUN git clone https://github.com/tukaani-project/xz.git
COPY build.sh $SRC/
WORKDIR xz

38
projects/xz/build.sh Executable file
View File

@ -0,0 +1,38 @@
#!/bin/bash -eu
# Copyright 2024 Google LLC
#
# Licensed under the Apache License, Version 2.0 (the "License");
# you may not use this file except in compliance with the License.
# You may obtain a copy of the License at
#
# http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.
#
################################################################################
./autogen.sh --no-po4a --no-doxygen
./configure \
--enable-static \
--disable-debug \
--disable-shared \
--disable-xz \
--disable-xzdec \
--disable-lzmadec \
--disable-lzmainfo
make clean
make -j$(nproc)
make -C tests/ossfuzz
cp $SRC/xz/tests/ossfuzz/config/*.options $OUT/
cp $SRC/xz/tests/ossfuzz/config/*.dict $OUT/
find $SRC/xz/tests/files -name "*.lzma" \
-exec zip -ujq $OUT/fuzz_decode_alone_seed_corpus.zip "{}" \;
find $SRC/xz/tests/files -name "*.xz" \
-exec zip -ujq $OUT/fuzz_decode_stream_seed_corpus.zip "{}" \;

15
projects/xz/project.yaml Normal file
View File

@ -0,0 +1,15 @@
homepage: "https://tukaani.org/xz/"
language: c++
primary_contact: "lasse.collin@tukaani.org"
auto_ccs:
- "bshas3@gmail.com"
- "samjd1024@gmail.com"
fuzzing_engines:
- libfuzzer
- afl
- honggfuzz
sanitizers:
- address
- memory
- undefined
main_repo: 'https://github.com/tukaani-project/xz.git'