OLD | NEW |
1 // Copyright 2015 The Chromium Authors. All rights reserved. | 1 // Copyright 2015 The Chromium Authors. All rights reserved. |
2 // Use of this source code is governed by a BSD-style license that can be | 2 // Use of this source code is governed by a BSD-style license that can be |
3 // found in the LICENSE file. | 3 // found in the LICENSE file. |
4 | 4 |
5 #include <stddef.h> | 5 #include <stddef.h> |
6 #include <stdint.h> | 6 #include <stdint.h> |
7 | 7 |
8 #include <vector> | 8 #include <vector> |
9 | 9 |
| 10 #include "base/test/fuzzed_data_provider.h" |
10 #include "net/websockets/websocket_frame_parser.h" | 11 #include "net/websockets/websocket_frame_parser.h" |
11 | 12 |
12 // Entry point for LibFuzzer. | 13 // Entry point for LibFuzzer. |
13 extern "C" int LLVMFuzzerTestOneInput(const uint8_t* data, size_t size) { | 14 extern "C" int LLVMFuzzerTestOneInput(const uint8_t* data, size_t size) { |
| 15 base::FuzzedDataProvider fuzzed_data_provider(data, size); |
14 net::WebSocketFrameParser parser; | 16 net::WebSocketFrameParser parser; |
15 std::vector<std::unique_ptr<net::WebSocketFrameChunk>> frame_chunks; | 17 std::vector<std::unique_ptr<net::WebSocketFrameChunk>> frame_chunks; |
16 parser.Decode(reinterpret_cast<const char*>(data), size, &frame_chunks); | 18 while (fuzzed_data_provider.remaining_bytes() > 0) { |
17 | 19 size_t chunk_size = fuzzed_data_provider.ConsumeUint32InRange(1, 32); |
| 20 base::StringPiece chunk = fuzzed_data_provider.ConsumeBytes(chunk_size); |
| 21 parser.Decode(chunk.data(), chunk.size(), &frame_chunks); |
| 22 } |
18 return 0; | 23 return 0; |
19 } | 24 } |
OLD | NEW |