blob: bf862e7a81d35f392b4e2ad2ac2ddc1c260b177e [file] [log] [blame]
Florian Mayer60d1e132018-01-26 15:00:52 +00001/*
2 * Copyright (C) 2018 The Android Open Source Project
3 *
4 * Licensed under the Apache License, Version 2.0 (the "License");
5 * you may not use this file except in compliance with the License.
6 * You may obtain a copy of the License at
7 *
8 * http://www.apache.org/licenses/LICENSE-2.0
9 *
10 * Unless required by applicable law or agreed to in writing, software
11 * distributed under the License is distributed on an "AS IS" BASIS,
12 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13 * See the License for the specific language governing permissions and
14 * limitations under the License.
15 */
16
17#include <stddef.h>
18#include <stdint.h>
19#include <unistd.h>
20
21#include "perfetto/base/logging.h"
22#include "perfetto/base/task_runner.h"
23#include "perfetto/base/utils.h"
24#include "perfetto/ipc/host.h"
Hector Dearmanfaa22f82018-02-14 12:02:51 +000025#include "perfetto/trace/test_event.pbzero.h"
Florian Mayer60d1e132018-01-26 15:00:52 +000026#include "perfetto/trace/trace_packet.pb.h"
27#include "perfetto/trace/trace_packet.pbzero.h"
28#include "perfetto/tracing/core/data_source_config.h"
29#include "perfetto/tracing/core/data_source_descriptor.h"
30#include "perfetto/tracing/core/producer.h"
31#include "perfetto/tracing/core/trace_writer.h"
32#include "perfetto/tracing/ipc/producer_ipc_client.h"
33#include "perfetto/tracing/ipc/service_ipc_host.h"
34#include "src/base/test/test_task_runner.h"
35#include "test/fake_consumer.h"
36#include "test/task_runner_thread.h"
Lalit Magantibfc3d3e2018-03-22 20:28:38 +000037#include "test/task_runner_thread_delegates.h"
Florian Mayer60d1e132018-01-26 15:00:52 +000038
Florian Mayer60d1e132018-01-26 15:00:52 +000039namespace perfetto {
40namespace shm_fuzz {
41
Florian Mayer43374ba2018-02-16 13:35:16 +000042static const char* kProducerSocket = tempnam("/tmp", "perfetto-producer");
43static const char* kConsumerSocket = tempnam("/tmp", "perfetto-consumer");
44
Florian Mayer60d1e132018-01-26 15:00:52 +000045// Fake producer writing a protozero message of data into shared memory
46// buffer, followed by a sentinel message to signal completion to the
47// consumer.
48class FakeProducer : public Producer {
49 public:
Florian Mayer20c2c722018-02-15 14:10:16 +000050 FakeProducer(std::string name,
51 const uint8_t* data,
52 size_t size,
Lalit Magantidd95ef92018-03-23 09:42:48 +000053 std::function<void()> on_produced_and_committed)
54 : name_(std::move(name)),
55 data_(data),
56 size_(size),
57 on_produced_and_committed_(on_produced_and_committed) {}
Florian Mayer60d1e132018-01-26 15:00:52 +000058
59 void Connect(const char* socket_name, base::TaskRunner* task_runner) {
Lalit Maganti8f47a5b2018-03-28 20:50:28 +010060 endpoint_ = ProducerIPCClient::Connect(
61 socket_name, this, "android.perfetto.FakeProducer", task_runner);
Florian Mayer60d1e132018-01-26 15:00:52 +000062 }
63
64 void OnConnect() override {
65 DataSourceDescriptor descriptor;
66 descriptor.set_name(name_);
Lalit Maganti79a69912018-03-29 17:32:29 +010067 endpoint_->RegisterDataSource(descriptor);
Florian Mayer60d1e132018-01-26 15:00:52 +000068 }
69
70 void OnDisconnect() override {}
71
72 void CreateDataSourceInstance(
73 DataSourceInstanceID,
74 const DataSourceConfig& source_config) override {
Lalit Magantidd95ef92018-03-23 09:42:48 +000075 auto trace_writer = endpoint_->CreateTraceWriter(
76 static_cast<BufferID>(source_config.target_buffer()));
Primiano Tucciecf9e4a2018-03-14 14:51:58 +000077 {
Primiano Tucciecf9e4a2018-03-14 14:51:58 +000078 auto packet = trace_writer->NewTracePacket();
79 packet->stream_writer_->WriteBytes(data_, size_);
Primiano Tucciecf9e4a2018-03-14 14:51:58 +000080 }
Lalit Magantidd95ef92018-03-23 09:42:48 +000081 trace_writer->Flush();
82
Primiano Tucciecf9e4a2018-03-14 14:51:58 +000083 {
Primiano Tucciecf9e4a2018-03-14 14:51:58 +000084 auto end_packet = trace_writer->NewTracePacket();
85 end_packet->set_for_testing()->set_str("end");
Primiano Tucciecf9e4a2018-03-14 14:51:58 +000086 }
Lalit Magantidd95ef92018-03-23 09:42:48 +000087 trace_writer->Flush(on_produced_and_committed_);
Florian Mayer60d1e132018-01-26 15:00:52 +000088 }
89
90 void TearDownDataSourceInstance(DataSourceInstanceID) override {}
Isabelle Taylor69faa902018-03-21 15:42:03 +000091 void OnTracingStart() override {}
92 void OnTracingStop() override {}
Florian Mayer60d1e132018-01-26 15:00:52 +000093
94 private:
95 const std::string name_;
96 const uint8_t* data_;
97 const size_t size_;
Florian Mayer60d1e132018-01-26 15:00:52 +000098 std::unique_ptr<Service::ProducerEndpoint> endpoint_;
Lalit Magantidd95ef92018-03-23 09:42:48 +000099 std::function<void()> on_produced_and_committed_;
Florian Mayer60d1e132018-01-26 15:00:52 +0000100};
101
102class FakeProducerDelegate : public ThreadDelegate {
103 public:
Lalit Magantidd95ef92018-03-23 09:42:48 +0000104 FakeProducerDelegate(const uint8_t* data,
105 size_t size,
106 std::function<void()> on_produced_and_committed)
107 : data_(data),
108 size_(size),
109 on_produced_and_committed_(on_produced_and_committed) {}
Florian Mayer60d1e132018-01-26 15:00:52 +0000110 ~FakeProducerDelegate() override = default;
111
112 void Initialize(base::TaskRunner* task_runner) override {
Florian Mayer20c2c722018-02-15 14:10:16 +0000113 producer_.reset(new FakeProducer("android.perfetto.FakeProducer", data_,
Lalit Magantidd95ef92018-03-23 09:42:48 +0000114 size_, on_produced_and_committed_));
Florian Mayer43374ba2018-02-16 13:35:16 +0000115 producer_->Connect(kProducerSocket, task_runner);
Florian Mayer60d1e132018-01-26 15:00:52 +0000116 }
117
118 private:
119 std::unique_ptr<FakeProducer> producer_;
120 const uint8_t* data_;
121 const size_t size_;
Lalit Magantidd95ef92018-03-23 09:42:48 +0000122 std::function<void()> on_produced_and_committed_;
Florian Mayer60d1e132018-01-26 15:00:52 +0000123};
124
Florian Mayer60d1e132018-01-26 15:00:52 +0000125int FuzzSharedMemory(const uint8_t* data, size_t size);
126
127int FuzzSharedMemory(const uint8_t* data, size_t size) {
Lalit Magantidd95ef92018-03-23 09:42:48 +0000128 base::TestTaskRunner task_runner;
129
Lalit Magantibfc3d3e2018-03-22 20:28:38 +0000130 TaskRunnerThread service_thread("perfetto.svc");
131 service_thread.Start(std::unique_ptr<ServiceDelegate>(
132 new ServiceDelegate(kProducerSocket, kConsumerSocket)));
Florian Mayer60d1e132018-01-26 15:00:52 +0000133
Lalit Magantidd95ef92018-03-23 09:42:48 +0000134 auto on_produced_and_committed =
135 task_runner.CreateCheckpoint("produced.and.committed");
136 auto posted_on_produced_and_committed = [&task_runner,
137 &on_produced_and_committed] {
138 task_runner.PostTask(on_produced_and_committed);
139 };
140 TaskRunnerThread producer_thread("perfetto.prd");
141 producer_thread.Start(std::unique_ptr<FakeProducerDelegate>(
142 new FakeProducerDelegate(data, size, posted_on_produced_and_committed)));
143
Florian Mayer60d1e132018-01-26 15:00:52 +0000144 // Setup the TraceConfig for the consumer.
145 TraceConfig trace_config;
Florian Mayer4c3580f2018-02-12 15:59:55 +0000146 trace_config.add_buffers()->set_size_kb(8);
Florian Mayer60d1e132018-01-26 15:00:52 +0000147
Lalit Magantidd95ef92018-03-23 09:42:48 +0000148 // Create the buffer for the fake producer.
Florian Mayer60d1e132018-01-26 15:00:52 +0000149 auto* ds_config = trace_config.add_data_sources()->mutable_config();
150 ds_config->set_name("android.perfetto.FakeProducer");
151 ds_config->set_target_buffer(0);
152
Lalit Magantidd95ef92018-03-23 09:42:48 +0000153 auto on_readback_complete = task_runner.CreateCheckpoint("readback.complete");
154 auto on_consumer_data = [&on_readback_complete](
155 std::vector<TracePacket> packets, bool has_more) {
Florian Mayer60d1e132018-01-26 15:00:52 +0000156 for (auto& p : packets) {
157 p.Decode();
Hector Dearmanfaa22f82018-02-14 12:02:51 +0000158 if (p->for_testing().str() == "end")
Lalit Magantidd95ef92018-03-23 09:42:48 +0000159 on_readback_complete();
Florian Mayer60d1e132018-01-26 15:00:52 +0000160 }
161 };
Lalit Magantidd95ef92018-03-23 09:42:48 +0000162
Lalit Magantibfc3d3e2018-03-22 20:28:38 +0000163 auto on_connect = task_runner.CreateCheckpoint("consumer.connected");
164 FakeConsumer consumer(trace_config, std::move(on_connect),
Lalit Magantidd95ef92018-03-23 09:42:48 +0000165 std::move(on_consumer_data), &task_runner);
166
Florian Mayer43374ba2018-02-16 13:35:16 +0000167 consumer.Connect(kConsumerSocket);
Lalit Magantibfc3d3e2018-03-22 20:28:38 +0000168 task_runner.RunUntilCheckpoint("consumer.connected");
Florian Mayer20c2c722018-02-15 14:10:16 +0000169
Lalit Magantibfc3d3e2018-03-22 20:28:38 +0000170 consumer.EnableTracing();
Lalit Magantidd95ef92018-03-23 09:42:48 +0000171 task_runner.RunUntilCheckpoint("produced.and.committed");
Lalit Magantibfc3d3e2018-03-22 20:28:38 +0000172
Lalit Magantidd95ef92018-03-23 09:42:48 +0000173 consumer.ReadTraceData();
174 task_runner.RunUntilCheckpoint("readback.complete");
175
176 consumer.Disconnect();
177
Florian Mayer60d1e132018-01-26 15:00:52 +0000178 return 0;
179}
180
181} // namespace shm_fuzz
182} // namespace perfetto
183
184extern "C" int LLVMFuzzerTestOneInput(const uint8_t* data, size_t size);
185
186extern "C" int LLVMFuzzerTestOneInput(const uint8_t* data, size_t size) {
187 return perfetto::shm_fuzz::FuzzSharedMemory(data, size);
188}