blob: 91f36296cebb6a16247fc4b449ee1d4b8a37dccf [file] [log] [blame]
Florian Mayer60d1e132018-01-26 15:00:52 +00001/*
2 * Copyright (C) 2018 The Android Open Source Project
3 *
4 * Licensed under the Apache License, Version 2.0 (the "License");
5 * you may not use this file except in compliance with the License.
6 * You may obtain a copy of the License at
7 *
8 * http://www.apache.org/licenses/LICENSE-2.0
9 *
10 * Unless required by applicable law or agreed to in writing, software
11 * distributed under the License is distributed on an "AS IS" BASIS,
12 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13 * See the License for the specific language governing permissions and
14 * limitations under the License.
15 */
16
17#include <stddef.h>
18#include <stdint.h>
19#include <unistd.h>
20
21#include "perfetto/base/logging.h"
22#include "perfetto/base/task_runner.h"
Primiano Tucci2c5488f2019-06-01 03:27:28 +010023#include "perfetto/ext/base/utils.h"
Primiano Tucci2c5488f2019-06-01 03:27:28 +010024#include "perfetto/ext/tracing/core/producer.h"
25#include "perfetto/ext/tracing/core/trace_writer.h"
Stephen Nuskoac0c1972019-06-25 13:57:13 +010026#include "perfetto/ext/tracing/ipc/default_socket.h"
Primiano Tucci2c5488f2019-06-01 03:27:28 +010027#include "perfetto/ext/tracing/ipc/producer_ipc_client.h"
28#include "perfetto/ext/tracing/ipc/service_ipc_host.h"
Primiano Tucci0f9e0222019-06-05 09:36:41 +010029#include "perfetto/tracing/core/data_source_config.h"
30#include "perfetto/tracing/core/data_source_descriptor.h"
Primiano Tucci355b8c82019-08-29 08:37:51 +020031#include "protos/perfetto/trace/test_event.pbzero.h"
Florian Mayer60d1e132018-01-26 15:00:52 +000032#include "src/base/test/test_task_runner.h"
Lalit Magantic4c3ceb2018-03-29 20:38:13 +010033#include "test/test_helper.h"
Florian Mayer60d1e132018-01-26 15:00:52 +000034
Primiano Tucci355b8c82019-08-29 08:37:51 +020035#include "protos/perfetto/trace/trace_packet.pbzero.h"
Primiano Tucci07e104d2018-04-03 20:45:35 +020036
Lalit Magantic4c3ceb2018-03-29 20:38:13 +010037// If we're building on Android and starting the daemons ourselves,
38// create the sockets in a world-writable location.
39#if PERFETTO_BUILDFLAG(PERFETTO_OS_ANDROID) && \
40 PERFETTO_BUILDFLAG(PERFETTO_START_DAEMONS)
41#define TEST_PRODUCER_SOCK_NAME "/data/local/tmp/traced_producer"
42#else
Florian Mayerc29e0d32018-04-04 15:55:46 +010043#define TEST_PRODUCER_SOCK_NAME ::perfetto::GetProducerSocket()
Lalit Magantic4c3ceb2018-03-29 20:38:13 +010044#endif
Florian Mayer43374ba2018-02-16 13:35:16 +000045
Primiano Tucci02c11762019-08-30 00:57:59 +020046namespace perfetto {
47namespace shm_fuzz {
48namespace {
49
Florian Mayer60d1e132018-01-26 15:00:52 +000050// Fake producer writing a protozero message of data into shared memory
51// buffer, followed by a sentinel message to signal completion to the
52// consumer.
53class FakeProducer : public Producer {
54 public:
Florian Mayer20c2c722018-02-15 14:10:16 +000055 FakeProducer(std::string name,
56 const uint8_t* data,
57 size_t size,
Lalit Magantidd95ef92018-03-23 09:42:48 +000058 std::function<void()> on_produced_and_committed)
59 : name_(std::move(name)),
60 data_(data),
61 size_(size),
62 on_produced_and_committed_(on_produced_and_committed) {}
Florian Mayer60d1e132018-01-26 15:00:52 +000063
64 void Connect(const char* socket_name, base::TaskRunner* task_runner) {
Lalit Maganti8f47a5b2018-03-28 20:50:28 +010065 endpoint_ = ProducerIPCClient::Connect(
66 socket_name, this, "android.perfetto.FakeProducer", task_runner);
Florian Mayer60d1e132018-01-26 15:00:52 +000067 }
68
69 void OnConnect() override {
70 DataSourceDescriptor descriptor;
71 descriptor.set_name(name_);
Lalit Maganti79a69912018-03-29 17:32:29 +010072 endpoint_->RegisterDataSource(descriptor);
Florian Mayer60d1e132018-01-26 15:00:52 +000073 }
74
75 void OnDisconnect() override {}
76
Florian Mayerd0201d02018-10-02 15:14:36 +010077 void SetupDataSource(DataSourceInstanceID, const DataSourceConfig&) override {
78 }
Primiano Tucci674076d2018-10-01 10:41:09 +010079
Primiano Tucciafb72b52018-09-25 09:37:24 +010080 void StartDataSource(DataSourceInstanceID,
81 const DataSourceConfig& source_config) override {
Lalit Magantidd95ef92018-03-23 09:42:48 +000082 auto trace_writer = endpoint_->CreateTraceWriter(
83 static_cast<BufferID>(source_config.target_buffer()));
Primiano Tucciecf9e4a2018-03-14 14:51:58 +000084 {
Primiano Tucciecf9e4a2018-03-14 14:51:58 +000085 auto packet = trace_writer->NewTracePacket();
Primiano Tucci8a689af2021-01-21 18:43:39 +010086 packet->AppendRawProtoBytes(data_, size_);
Primiano Tucciecf9e4a2018-03-14 14:51:58 +000087 }
Lalit Magantidd95ef92018-03-23 09:42:48 +000088 trace_writer->Flush();
89
Primiano Tucciecf9e4a2018-03-14 14:51:58 +000090 {
Primiano Tucciecf9e4a2018-03-14 14:51:58 +000091 auto end_packet = trace_writer->NewTracePacket();
92 end_packet->set_for_testing()->set_str("end");
Primiano Tucciecf9e4a2018-03-14 14:51:58 +000093 }
Lalit Magantidd95ef92018-03-23 09:42:48 +000094 trace_writer->Flush(on_produced_and_committed_);
Florian Mayer60d1e132018-01-26 15:00:52 +000095 }
96
Primiano Tucciafb72b52018-09-25 09:37:24 +010097 void StopDataSource(DataSourceInstanceID) override {}
Primiano Tuccidca727d2018-04-04 11:31:55 +020098 void OnTracingSetup() override {}
Primiano Tuccid52e6272018-04-06 19:06:53 +020099 void Flush(FlushRequestID, const DataSourceInstanceID*, size_t) override {}
Primiano Tucci008cdb92019-07-19 19:52:41 +0100100 void ClearIncrementalState(const DataSourceInstanceID*, size_t) override {}
Florian Mayer60d1e132018-01-26 15:00:52 +0000101
102 private:
103 const std::string name_;
104 const uint8_t* data_;
105 const size_t size_;
Florian Mayer6a1a4d52018-06-08 16:47:07 +0100106 std::unique_ptr<TracingService::ProducerEndpoint> endpoint_;
Lalit Magantidd95ef92018-03-23 09:42:48 +0000107 std::function<void()> on_produced_and_committed_;
Florian Mayer60d1e132018-01-26 15:00:52 +0000108};
109
Lalit Maganti9782f492020-01-10 18:13:13 +0000110class FuzzerFakeProducerThread {
Florian Mayer60d1e132018-01-26 15:00:52 +0000111 public:
Lalit Maganti9782f492020-01-10 18:13:13 +0000112 FuzzerFakeProducerThread(const uint8_t* data,
113 size_t size,
114 std::function<void()> on_produced_and_committed)
Lalit Magantidd95ef92018-03-23 09:42:48 +0000115 : data_(data),
116 size_(size),
117 on_produced_and_committed_(on_produced_and_committed) {}
Florian Mayer60d1e132018-01-26 15:00:52 +0000118
Lalit Maganti9782f492020-01-10 18:13:13 +0000119 ~FuzzerFakeProducerThread() {
120 if (!runner_)
121 return;
122 runner_->PostTaskAndWaitForTesting([this]() { producer_.reset(); });
123 }
124
125 void Connect() {
126 runner_ = base::ThreadTaskRunner::CreateAndStart("perfetto.prd.fake");
127 runner_->PostTaskAndWaitForTesting([this]() {
128 producer_.reset(new FakeProducer("android.perfetto.FakeProducer", data_,
129 size_, on_produced_and_committed_));
130 producer_->Connect(TEST_PRODUCER_SOCK_NAME, runner_->get());
131 });
Florian Mayer60d1e132018-01-26 15:00:52 +0000132 }
133
134 private:
Lalit Maganti9782f492020-01-10 18:13:13 +0000135 base::Optional<base::ThreadTaskRunner> runner_; // Keep first.
136
Florian Mayer60d1e132018-01-26 15:00:52 +0000137 std::unique_ptr<FakeProducer> producer_;
138 const uint8_t* data_;
139 const size_t size_;
Lalit Magantidd95ef92018-03-23 09:42:48 +0000140 std::function<void()> on_produced_and_committed_;
Florian Mayer60d1e132018-01-26 15:00:52 +0000141};
142
Florian Mayer709de7f2021-01-28 21:41:14 +0000143class FuzzTestHelper : public TestHelper {
144 public:
145 explicit FuzzTestHelper(base::TestTaskRunner* task_runner)
146 : TestHelper(task_runner) {}
147 // Do not verify the data, as it will most likely be corrupted.
148 void ReadTraceData(std::vector<TracePacket>) override {}
149};
150
Florian Mayer60d1e132018-01-26 15:00:52 +0000151int FuzzSharedMemory(const uint8_t* data, size_t size);
152
153int FuzzSharedMemory(const uint8_t* data, size_t size) {
Lalit Magantidd95ef92018-03-23 09:42:48 +0000154 base::TestTaskRunner task_runner;
155
Florian Mayer709de7f2021-01-28 21:41:14 +0000156 FuzzTestHelper helper(&task_runner);
Lalit Magantic4c3ceb2018-03-29 20:38:13 +0100157 helper.StartServiceIfRequired();
Florian Mayer60d1e132018-01-26 15:00:52 +0000158
Lalit Maganti9782f492020-01-10 18:13:13 +0000159 auto cp =
160 helper.WrapTask(task_runner.CreateCheckpoint("produced.and.committed"));
161 FuzzerFakeProducerThread producer_thread(data, size, cp);
162 producer_thread.Connect();
Lalit Magantidd95ef92018-03-23 09:42:48 +0000163
Lalit Magantic4c3ceb2018-03-29 20:38:13 +0100164 helper.ConnectConsumer();
Lalit Maganti36557d82018-04-11 14:36:17 +0100165 helper.WaitForConsumerConnect();
Lalit Magantic4c3ceb2018-03-29 20:38:13 +0100166
Florian Mayer60d1e132018-01-26 15:00:52 +0000167 TraceConfig trace_config;
Florian Mayer4c3580f2018-02-12 15:59:55 +0000168 trace_config.add_buffers()->set_size_kb(8);
Florian Mayer60d1e132018-01-26 15:00:52 +0000169
Florian Mayer60d1e132018-01-26 15:00:52 +0000170 auto* ds_config = trace_config.add_data_sources()->mutable_config();
171 ds_config->set_name("android.perfetto.FakeProducer");
172 ds_config->set_target_buffer(0);
173
Lalit Magantic4c3ceb2018-03-29 20:38:13 +0100174 helper.StartTracing(trace_config);
Lalit Magantidd95ef92018-03-23 09:42:48 +0000175 task_runner.RunUntilCheckpoint("produced.and.committed");
Lalit Magantibfc3d3e2018-03-22 20:28:38 +0000176
Lalit Maganti36557d82018-04-11 14:36:17 +0100177 helper.ReadData();
178 helper.WaitForReadData();
Lalit Magantidd95ef92018-03-23 09:42:48 +0000179
Florian Mayer60d1e132018-01-26 15:00:52 +0000180 return 0;
181}
182
Primiano Tucci02c11762019-08-30 00:57:59 +0200183} // namespace
Florian Mayer60d1e132018-01-26 15:00:52 +0000184} // namespace shm_fuzz
185} // namespace perfetto
186
187extern "C" int LLVMFuzzerTestOneInput(const uint8_t* data, size_t size);
188
189extern "C" int LLVMFuzzerTestOneInput(const uint8_t* data, size_t size) {
190 return perfetto::shm_fuzz::FuzzSharedMemory(data, size);
191}