summaryrefslogtreecommitdiff
path: root/test/fuzz/device/net_ncm/Makefile
blob: df5a61324552459fed403d0d14af88b6e588dc96 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
# Focused fuzz harness for the NCM receive path (recv_validate_datagram).
#
# It is self-contained: it #includes src/class/net/ncm_device.c and stubs the
# few usbd/glue symbols, so it does not link the whole device stack.
#
#   make            # build the libFuzzer target: _build/net_ncm
#   make regression # build + replay the crafted seed under ASan (no engine)
#   make clean

TOP := ../../../..
BUILD := _build

CC ?= clang

INC += \
  $(TOP)/src \
  .

CFLAGS += $(addprefix -I,$(INC)) -g -O1 -fsanitize=address

FUZZ_FLAGS := -fsanitize=fuzzer

.PHONY: all regression clean get-deps

all: $(BUILD)/net_ncm

# No external dependencies (the harness only needs the in-tree NCM driver).
get-deps:

# libFuzzer supplies its own main(), so drop the standalone driver here.
$(BUILD)/net_ncm: fuzz.c
	mkdir -p $(@D)
	$(CC) $(CFLAGS) $(FUZZ_FLAGS) -DNO_MAIN -o $@ $<

# Standalone build with a plain main(): replays the crafted seed and any extra
# corpus files given as arguments. Used as a deterministic regression.
regression: fuzz.c
	mkdir -p $(BUILD)
	$(CC) $(CFLAGS) -o $(BUILD)/net_ncm_regression $<
	./$(BUILD)/net_ncm_regression

clean:
	$(RM) -rf $(BUILD) *.dSYM