aboutsummaryrefslogtreecommitdiffhomepage
path: root/projects/libjpeg-turbo
diff options
context:
space:
mode:
Diffstat (limited to 'projects/libjpeg-turbo')
-rw-r--r--projects/libjpeg-turbo/Dockerfile28
-rwxr-xr-xprojects/libjpeg-turbo/build.sh26
-rw-r--r--projects/libjpeg-turbo/libjpeg_turbo_fuzzer.cc48
-rw-r--r--projects/libjpeg-turbo/target.yaml1
4 files changed, 103 insertions, 0 deletions
diff --git a/projects/libjpeg-turbo/Dockerfile b/projects/libjpeg-turbo/Dockerfile
new file mode 100644
index 00000000..94a4c349
--- /dev/null
+++ b/projects/libjpeg-turbo/Dockerfile
@@ -0,0 +1,28 @@
+# Copyright 2016 Google Inc.
+#
+# Licensed under the Apache License, Version 2.0 (the "License");
+# you may not use this file except in compliance with the License.
+# You may obtain a copy of the License at
+#
+# http://www.apache.org/licenses/LICENSE-2.0
+#
+# Unless required by applicable law or agreed to in writing, software
+# distributed under the License is distributed on an "AS IS" BASIS,
+# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+# See the License for the specific language governing permissions and
+# limitations under the License.
+#
+################################################################################
+
+FROM ossfuzz/base-libfuzzer
+MAINTAINER alex.gaynor@gmail.com
+RUN apt-get install -y make autoconf automake libtool nasm curl
+RUN git clone https://github.com/libjpeg-turbo/libjpeg-turbo
+
+RUN mkdir afl-testcases
+RUN curl -o afl-testcases/afl_testcases.tgz http://lcamtuf.coredump.cx/afl/demo/afl_testcases.tgz
+RUN cd afl-testcases/ && tar -xf afl_testcases.tgz
+RUN zip libjpeg_turbo_fuzzer_seed_corpus.zip afl-testcases/jpeg/full/images/*
+
+WORKDIR libjpeg-turbo
+COPY build.sh libjpeg_turbo_fuzzer.cc $SRC/
diff --git a/projects/libjpeg-turbo/build.sh b/projects/libjpeg-turbo/build.sh
new file mode 100755
index 00000000..99213429
--- /dev/null
+++ b/projects/libjpeg-turbo/build.sh
@@ -0,0 +1,26 @@
+#!/bin/bash -eu
+# Copyright 2016 Google Inc.
+#
+# Licensed under the Apache License, Version 2.0 (the "License");
+# you may not use this file except in compliance with the License.
+# You may obtain a copy of the License at
+#
+# http://www.apache.org/licenses/LICENSE-2.0
+#
+# Unless required by applicable law or agreed to in writing, software
+# distributed under the License is distributed on an "AS IS" BASIS,
+# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+# See the License for the specific language governing permissions and
+# limitations under the License.
+#
+################################################################################
+
+autoreconf -fiv
+./configure
+make "-j$(nproc)"
+
+$CXX $CXXFLAGS -std=c++11 -I. \
+ $SRC/libjpeg_turbo_fuzzer.cc -o $OUT/libjpeg_turbo_fuzzer \
+ -lfuzzer ./.libs/libturbojpeg.a
+
+cp $SRC/libjpeg_turbo_fuzzer_seed_corpus.zip $OUT/
diff --git a/projects/libjpeg-turbo/libjpeg_turbo_fuzzer.cc b/projects/libjpeg-turbo/libjpeg_turbo_fuzzer.cc
new file mode 100644
index 00000000..1cee173d
--- /dev/null
+++ b/projects/libjpeg-turbo/libjpeg_turbo_fuzzer.cc
@@ -0,0 +1,48 @@
+/*
+# Copyright 2016 Google Inc.
+#
+# Licensed under the Apache License, Version 2.0 (the "License");
+# you may not use this file except in compliance with the License.
+# You may obtain a copy of the License at
+#
+# http://www.apache.org/licenses/LICENSE-2.0
+#
+# Unless required by applicable law or agreed to in writing, software
+# distributed under the License is distributed on an "AS IS" BASIS,
+# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+# See the License for the specific language governing permissions and
+# limitations under the License.
+#
+################################################################################
+*/
+
+#include <stdint.h>
+#include <stdlib.h>
+
+#include <memory>
+
+#include <turbojpeg.h>
+
+
+extern "C" int LLVMFuzzerTestOneInput(const uint8_t *data, size_t size) {
+ tjhandle jpegDecompressor = tjInitDecompress();
+
+ int width, height, subsamp, colorspace;
+ int res = tjDecompressHeader3(
+ jpegDecompressor, data, size, &width, &height, &subsamp, &colorspace);
+
+ // Bail out if decompressing the headers failed, the width or height is 0,
+ // or the image is too large (avoids slowing down too much)
+ if (res != 0 || width == 0 || height == 0 || (width * height > (1024 * 1024))) {
+ tjDestroy(jpegDecompressor);
+ return 0;
+ }
+
+ std::unique_ptr<unsigned char[]> buf(new unsigned char[width * height * 3]);
+ tjDecompress2(
+ jpegDecompressor, data, size, buf.get(), width, 0, height, TJPF_RGB, 0);
+
+ tjDestroy(jpegDecompressor);
+
+ return 0;
+}
diff --git a/projects/libjpeg-turbo/target.yaml b/projects/libjpeg-turbo/target.yaml
new file mode 100644
index 00000000..d75b6589
--- /dev/null
+++ b/projects/libjpeg-turbo/target.yaml
@@ -0,0 +1 @@
+homepage: "https://github.com/libjpeg-turbo/libjpeg-turbo"