!995 fix: add spi fuzzer test

Merge pull request !995 from 张亚雷/master
This commit is contained in:
openharmony_ci
2022-05-18 09:44:35 +00:00
committed by Gitee
6 changed files with 180 additions and 0 deletions
+1
View File
@@ -12,6 +12,7 @@ group("hdf_platform_fuzztest") {
"i2c_fuzzer:fuzztest",
"pwm_fuzzer:fuzztest",
"rtc_fuzzer:fuzztest",
"spi_fuzzer:fuzztest",
"uart_fuzzer:fuzztest",
"watchdog_fuzzer:fuzztest",
]
@@ -0,0 +1,27 @@
# Copyright (c) 2022 Huawei Device Co., Ltd.
#
# HDF is dual licensed: you can use it either under the terms of
# the GPL, or the BSD license, at your option.
# See the LICENSE file in the root of this repository for complete details.
import("//drivers/framework/support/platform/test/fuzztest/fuzz.gni")
ohos_fuzztest("SpiFuzzTest") {
module_out_path = module_output_path
fuzz_config_file =
"//drivers/framework/support/platform/test/fuzztest/spi_fuzzer"
include_dirs +=
[ "//drivers/framework/support/platform/test/fuzztest/spi_fuzzer" ]
sources = [ "spi_fuzzer.cpp" ]
external_deps = platform_fuzzexternal_deps
}
group("fuzztest") {
testonly = true
deps = []
deps += [ ":SpiFuzzTest" ]
}
@@ -0,0 +1,7 @@
# Copyright (c) 2022 Huawei Device Co., Ltd.
#
# HDF is dual licensed: you can use it either under the terms of
# the GPL, or the BSD license, at your option.
# See the LICENSE file in the root of this repository for complete details.
FUZZ
@@ -0,0 +1,18 @@
<?xml version="1.0" encoding="utf-8"?>
<!--
Copyright (c) 2022 Huawei Device Co., Ltd.
HDF is dual licensed: you can use it either under the terms of
the GPL, or the BSD license, at your option.
See the LICENSE file in the root of this repository for complete details.
-->
<fuzz_config>
<fuzztest>
<!-- maximum length of a test input -->
<max_len>36</max_len>
<!-- maximum total time in seconds to run the fuzzer -->
<max_total_time>120</max_total_time>
<!-- memory usage limit in Mb -->
<rss_limit_mb>2048</rss_limit_mb>
</fuzztest>
</fuzz_config>
@@ -0,0 +1,107 @@
/*
* Copyright (c) 2022 Huawei Device Co., Ltd.
*
* HDF is dual licensed: you can use it either under the terms of
* the GPL, or the BSD license, at your option.
* See the LICENSE file in the root of this repository for complete details.
*/
#include <iostream>
#include "random.h"
#include "securec.h"
#include "hdf_base.h"
#include "spi_if.h"
#include "spi_fuzzer.h"
using namespace std;
namespace {
constexpr int32_t MIN = 0;
constexpr int32_t MAX = 2;
const int32_t busTestNum = 0;
const int32_t csTestNum = 0;
const uint32_t SPI_BUF_SIZE = 8;
}
struct AllParameters {
uint32_t descSpeed;
uint16_t descDelay;
uint8_t descKeep;
uint32_t desMaxSpeedHz;
uint16_t desMode;
uint8_t desTransferMode;
uint8_t desBitsPerWord;
uint8_t buf[SPI_BUF_SIZE];
};
namespace OHOS {
bool SpiFuzzTest(const uint8_t *data, size_t size)
{
int32_t number;
DevHandle handle = nullptr;
struct SpiMsg msg;
struct SpiCfg cfg;
struct SpiDevInfo info;
struct AllParameters params;
if (data == nullptr) {
return false;
}
if (memcpy_s ((void *)&params, sizeof(params), data, sizeof(params)) != EOK) {
return false;
}
info.busNum = busTestNum;
info.csNum = csTestNum;
msg.speed = params.descSpeed;
msg.delayUs = params.descDelay;
msg.keepCs = params.descKeep;
msg.len = SPI_BUF_SIZE;
msg.rbuf = (uint8_t *)malloc(SPI_BUF_SIZE);
if (msg.rbuf == nullptr) {
return false;
}
msg.wbuf = (uint8_t *)malloc(SPI_BUF_SIZE);
if (msg.wbuf == nullptr) {
free(msg.rbuf);
return false;
}
if (memcpy_s((void *)msg.wbuf, SPI_BUF_SIZE, params.buf, SPI_BUF_SIZE) != EOK) {
free(msg.rbuf);
free(msg.wbuf);
return false;
}
cfg.maxSpeedHz = params.desMaxSpeedHz;
cfg.mode = params.desMode;
cfg.transferMode = params.desTransferMode;
cfg.bitsPerWord = params.desBitsPerWord;
handle = SpiOpen(&info);
number = randNum(MIN, MAX);
switch (static_cast<ApiNumber>(number)) {
case ApiNumber::SPI_FUZZ_TRANSFER:
SpiTransfer(handle, &msg, SPI_BUF_SIZE);
break;
case ApiNumber::SPI_FUZZ_WRITE:
SpiWrite(handle, msg.wbuf, SPI_BUF_SIZE);
break;
case ApiNumber::SPI_FUZZ_SETCFG:
SpiSetCfg(handle, &cfg);
break;
default:
break;
}
free(msg.rbuf);
free(msg.wbuf);
SpiClose(handle);
return true;
}
}
/* Fuzzer entry point */
extern "C" int LLVMFuzzerTestOneInput(const uint8_t *data, size_t size)
{
/* Run your code on data */
OHOS::SpiFuzzTest(data, size);
return 0;
}
@@ -0,0 +1,20 @@
/*
* Copyright (c) 2022 Huawei Device Co., Ltd.
*
* HDF is dual licensed: you can use it either under the terms of
* the GPL, or the BSD license, at your option.
* See the LICENSE file in the root of this repository for complete details.
*/
#ifndef SPI_FUZZER
#define SPI_FUZZER
#define FUZZ_PROJECT_NAME "spi_fuzzer"
enum class ApiNumber {
SPI_FUZZ_TRANSFER = 0,
SPI_FUZZ_WRITE,
SPI_FUZZ_SETCFG,
};
#endif