diff options
author | Jack Lloyd <[email protected]> | 2018-12-29 13:00:09 -0500 |
---|---|---|
committer | Jack Lloyd <[email protected]> | 2019-01-04 21:23:25 -0500 |
commit | b40d4c0e9c134a3daf9d77ce6f8a7b1271feb5ca (patch) | |
tree | 15c248cc358d48ad6f33128f0181113c5e0f1fde /src | |
parent | e2ee85c5de7df54953559d80e9889dd550550699 (diff) |
Update fuzzer for new Memory_Pool behavior and constructor
Diffstat (limited to 'src')
-rw-r--r-- | src/fuzzer/mem_pool.cpp | 33 |
1 files changed, 26 insertions, 7 deletions
diff --git a/src/fuzzer/mem_pool.cpp b/src/fuzzer/mem_pool.cpp index ebfe59db7..14b0fb574 100644 --- a/src/fuzzer/mem_pool.cpp +++ b/src/fuzzer/mem_pool.cpp @@ -6,19 +6,35 @@ #include "fuzzers.h" #include <botan/internal/mem_pool.h> +#include <botan/internal/bit_ops.h> #include <vector> #include <map> #include <utility> +namespace { + +size_t compute_expected_alignment(size_t plen) + { + if(Botan::is_power_of_2(plen)) + { + return plen; + } + else + { + return 8; + } + } + +} + void fuzz(const uint8_t in[], size_t in_len) { const size_t page_size = 4096; const size_t pages = 4; - const size_t expected_alignment = (1 << 4); static std::vector<uint8_t> raw_mem(page_size * pages); - Botan::Memory_Pool pool(raw_mem.data(), raw_mem.size(), page_size, 1, 128, 4); + Botan::Memory_Pool pool(raw_mem.data(), pages, page_size); std::map<uint8_t*, size_t> ptrs; while(in_len > 0) @@ -35,18 +51,21 @@ void fuzz(const uint8_t in[], size_t in_len) in_len -= 1; } + //printf("%d %d\n", op, idx); + if(op == 0) { const size_t plen = idx + 1; // ensure non-zero uint8_t* p = static_cast<uint8_t*>(pool.allocate(plen)); - if(reinterpret_cast<uintptr_t>(p) % expected_alignment != 0) - { - FUZZER_WRITE_AND_CRASH("Pointer allocated non-aligned pointer " << p); - } - if(p) { + const size_t expected_alignment = compute_expected_alignment(plen); + if(reinterpret_cast<uintptr_t>(p) % expected_alignment != 0) + { + FUZZER_WRITE_AND_CRASH("Pointer allocated non-aligned pointer " << p); + } + //printf("alloc %d -> %p\n", plen, p); for(size_t i = 0; i != plen; ++i) |