[PATCH v2] libsepol: add module package fuzzer

Petr Matyas <[email protected]>
Newsgroups org.kernel.vger.selinux
Message-ID <[email protected]>
Add a libFuzzer target for the binary module package format
(.mod/.pp) read by sepol_module_package_read(). On a valid package,
also exercises sepol_module_package_to_cil() to cover the CIL
conversion path for module policies.

The seed corpus contains a minimal module package produced by
checkmodule + semodule_package to give the fuzzer a structurally
correct starting point.

Wire the new fuzzer into scripts/oss-fuzz.sh alongside the existing
libsepol and checkpolicy fuzzers.

Signed-off-by: Petr Matyas <[email protected]>
---
 libsepol/fuzz/min_mod.pp              | Bin 0 -> 859 bytes
 libsepol/fuzz/module-package-fuzzer.c |  47 ++++++++++++++++++++++++++
 scripts/oss-fuzz.sh                   |  11 ++++++
 3 files changed, 58 insertions(+)
 create mode 100644 libsepol/fuzz/min_mod.pp
 create mode 100644 libsepol/fuzz/module-package-fuzzer.c

diff --git a/libsepol/fuzz/min_mod.pp b/libsepol/fuzz/min_mod.pp
new file mode 100644
index 0000000000000000000000000000000000000000..264bd4406bf94b1c0044d46d0ca82fcdc4716f88
GIT binary patch
literal 859
zcmb`FOA5k35Jbxl=uVd|J%Q*A+_=+~2MCyq;4dTjfQwu~Jg+OIFa^zEK*a~mbWhh*
zC(yS?b#DP+3;|pp)qMb9y%;ZdX?Yp1d{Q1=8^EZR_3@$y;IvDllTSJTW|Qf>?pS0_
zHBrrzoHHN0Jnz=6t<MgUaFAqvvv+Y3Wp+eUE^I&aR86ez;Ih;mqe31{=)Jy=*gJYM
z)YoZe5nJ0l^b4_C<_yiy`HMz`Zw0+SohO>SzP<k!{0FXMy?QKdaP72i-21Sn6|wj4
Fcmk%9EE)g+

literal 0
HcmV?d00001

diff --git a/libsepol/fuzz/module-package-fuzzer.c b/libsepol/fuzz/module-package-fuzzer.c
new file mode 100644
index 00000000..2516970b
--- /dev/null
+++ b/libsepol/fuzz/module-package-fuzzer.c
@@ -0,0 +1,47 @@
+#include <sepol/debug.h>
+#include <sepol/module.h>
+#include <sepol/module_to_cil.h>
+
+extern int LLVMFuzzerTestOneInput(const uint8_t *data, size_t size);
+
+// set to 1 to enable more verbose libsepol logging
+#define VERBOSE 0
+
+int LLVMFuzzerTestOneInput(const uint8_t *data, size_t size)
+{
+	sepol_module_package_t *mod = NULL;
+	struct sepol_policy_file *spf = NULL;
+	FILE *devnull = NULL;
+
+	sepol_debug(VERBOSE);
+
+	if (sepol_policy_file_create(&spf))
+		goto exit;
+
+	sepol_policy_file_set_mem(spf, (char *)data, size);
+
+	if (sepol_module_package_create(&mod))
+		goto exit;
+
+	if (sepol_module_package_read(mod, spf, VERBOSE))
+		goto exit;
+
+	devnull = fopen("/dev/null", "we");
+	if (!devnull)
+		goto exit;
+
+	/* sepol_module_package_read() stores contexts sections as raw blobs
+	 * without validating their text syntax; sepol_module_package_to_cil()
+	 * is the first place that parses them, so a graceful error return here
+	 * is expected behaviour for malformed input, not a bug. */
+	(void)sepol_module_package_to_cil(devnull, mod);
+
+exit:
+	if (devnull)
+		fclose(devnull);
+	sepol_module_package_free(mod);
+	sepol_policy_file_free(spf);
+
+	/* Non-zero return values are reserved for future use. */
+	return 0;
+}
diff --git a/scripts/oss-fuzz.sh b/scripts/oss-fuzz.sh
index 9376b6e4..08e06975 100755
--- a/scripts/oss-fuzz.sh
+++ b/scripts/oss-fuzz.sh
@@ -74,6 +74,17 @@ $CXX $CXXFLAGS $LIB_FUZZING_ENGINE binpolicy-fuzzer.o "$DESTDIR/usr/lib/libsepol
 
 zip -j "$OUT/binpolicy-fuzzer_seed_corpus.zip" libsepol/fuzz/policy.bin
 
+## module package fuzzer ##
+
+# CFLAGS, CXXFLAGS and LIB_FUZZING_ENGINE have to be split to be accepted by
+# the compiler/linker so they shouldn't be quoted
+# shellcheck disable=SC2086
+$CC $CFLAGS -c -o module-package-fuzzer.o libsepol/fuzz/module-package-fuzzer.c
+# shellcheck disable=SC2086
+$CXX $CXXFLAGS $LIB_FUZZING_ENGINE module-package-fuzzer.o "$DESTDIR/usr/lib/libsepol.a" -o "$OUT/module-package-fuzzer"
+
+zip -j "$OUT/module-package-fuzzer_seed_corpus.zip" libsepol/fuzz/min_mod.pp
+
 ## checkpolicy fuzzer ##
 
 make -C checkpolicy clean
-- 
2.55.0
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.