Name |
Last commit
|
Last update |
---|---|---|
.. | ||
corpora | ||
CMakeLists.txt | ||
config_file_fuzzer.c | ||
download_refs_fuzzer.c | ||
packfile_fuzzer.c | ||
standalone_driver.c |
The standalone driver for libgit2's fuzzing targets makes use of functions from libgit2 itself. While this is totally fine to do, we need to make sure to always have libgit2 initialized via `git_libgit2_init` before we call out to any of these. While this happens in most cases as we call `LLVMFuzzerInitialize`, which is provided by our fuzzers and which right now always calls `git_libgit2_init`, one exception to this rule is our error path when not enough arguments have been given. In this case, we will call `git_vector_free_deep` without libgit2 having been initialized. As we did not set up our allocation functions in that case, this will lead to a segmentation fault. Fix the issue by always initializing and shutting down libgit2 in the standalone driver. Note that we cannot let this replace the initialization in `LLVMFuzzerInitialize`, as it is required when using the "real" fuzzers by LLVM without our standalone driver. It's no problem to call the initialization and deinitialization functions multiple times, though.
Name |
Last commit
|
Last update |
---|---|---|
.. | ||
corpora | Loading commit data... | |
CMakeLists.txt | Loading commit data... | |
config_file_fuzzer.c | Loading commit data... | |
download_refs_fuzzer.c | Loading commit data... | |
packfile_fuzzer.c | Loading commit data... | |
standalone_driver.c | Loading commit data... |