2 * Copyright 2016 Google Inc.
3 * author: Edward Hervey <bilboed@bilboed.com>
5 * Licensed under the Apache License, Version 2.0 (the "License");
6 * you may not use this file except in compliance with the License.
7 * You may obtain a copy of the License at
9 * http://www.apache.org/licenses/LICENSE-2.0
11 * Unless required by applicable law or agreed to in writing, software
12 * distributed under the License is distributed on an "AS IS" BASIS,
13 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
14 * See the License for the specific language governing permissions and
15 * limitations under the License.
28 #include <gst/pbutils/pbutils.h>
30 /* push-based discoverer fuzzing target
32 * This application can be compiled with libFuzzer to simulate
33 * a push-based discoverer execution.
35 * To reproduce the failing behaviour, use:
36 * $ gst-discoverer-1.0 pushfile:///...
38 * The goal is to cover basic usage of demuxers, parsers and
39 * base decoder elements.
41 * When compiling, only link the required demuxer/parser/decoder
42 * plugins and keep it to a limited range (ex: ogg/theora/vorbis)
46 const guint8 *fuzztesting_data;
47 size_t fuzztesting_size;
50 appsrc_configuration (GstDiscoverer * dc, GstElement * source, gpointer data)
55 /* Create buffer from fuzztesting_data which shouldn't be freed */
57 gst_buffer_new_wrapped_full (0, (gpointer) fuzztesting_data,
58 fuzztesting_size, 0, fuzztesting_size, NULL, NULL);
59 g_object_set (G_OBJECT (source), "size", fuzztesting_size, NULL);
60 g_signal_emit_by_name (G_OBJECT (source), "push-buffer", buf, &ret);
61 gst_buffer_unref (buf);
65 custom_logger (const gchar * log_domain,
66 GLogLevelFlags log_level, const gchar * message, gpointer unused_data)
68 if (log_level & G_LOG_LEVEL_CRITICAL) {
69 g_printerr ("CRITICAL ERROR : %s\n", message);
71 } else if (log_level & G_LOG_LEVEL_WARNING) {
72 g_printerr ("WARNING : %s\n", message);
77 LLVMFuzzerTestOneInput (const guint8 * data, size_t size)
82 GstDiscovererInfo *info;
83 static gboolean initialized = FALSE;
86 /* We want critical warnings to assert so we can fix them */
87 g_log_set_always_fatal (G_LOG_LEVEL_CRITICAL);
88 g_log_set_default_handler (custom_logger, NULL);
90 /* Only initialize and register plugins once */
91 gst_init (NULL, NULL);
95 dc = gst_discoverer_new (timeout * GST_SECOND, &err);
96 if (G_UNLIKELY (dc == NULL)) {
97 g_print ("Error initializing: %s\n", err->message);
102 fuzztesting_data = data;
103 fuzztesting_size = size;
105 /* Connect to source-setup signal to give the data */
106 g_signal_connect (dc, "source-setup", (GCallback) appsrc_configuration, NULL);
108 info = gst_discoverer_discover_uri (dc, "appsrc://", &err);
109 g_clear_error (&err);
111 gst_discoverer_info_unref (info);