HarfBuzz text shaping engine http://harfbuzz.github.io/
You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
 
 
 
 
 
 
Ebrahim Byagowi d57fc627e9 [meson] raise timeout value of subset fuzzer 5 years ago
..
fonts Add potentially crashing font as a fuzzer seed. 5 years ago
sets [fuzz] minor, move two fuzzer cases to their correct place 5 years ago
Makefile.am Remove cmake testing and add meson build bot 5 years ago
README Move all references of old url to the new address (#622) 7 years ago
hb-draw-fuzzer.cc Move outline draw API behind HB_EXPERIMENTAL_API directive 5 years ago
hb-fuzzer.hh [fuzzer] Separate main() into a new file 8 years ago
hb-set-fuzzer.cc [fuzz] minor style fixes 5 years ago
hb-shape-fuzzer.cc [fuzz] Avoid empty memcpy and ubsan complain by length checking before memcpy 5 years ago
hb-subset-fuzzer.cc [fuzz] Don't fail when blob is empty 5 years ago
main.cc [fuzz] minor don't abort main.cc when the file was empty or not found 5 years ago
meson.build [meson] raise timeout value of subset fuzzer 5 years ago
run-draw-fuzzer-tests.py [tests] Remove py2 workaround for lack of timeout in subprocess 5 years ago
run-shape-fuzzer-tests.py [tests] Remove py2 workaround for lack of timeout in subprocess 5 years ago
run-subset-fuzzer-tests.py [tests] Remove py2 workaround for lack of timeout in subprocess 5 years ago

README

In order to build the fuzzer one needs to build HarfBuzz and
harfbuzz/test/fuzzing/hb-fuzzer.cc with:
- Using the most recent Clang
- With -fsanitize=address (or =undefined, or a combination)
- With -fsanitize-coverage=edge[,8bit-counters,trace-cmp]
- With various defines that limit worst case exponential behavior.
See FUZZING_CPPFLAGS in harfbuzz/src/Makefile.am for the list.
- link against libFuzzer

To run the fuzzer one needs to first obtain a test corpus as a directory
containing interesting fonts. A good starting point is inside
harfbuzz/test/shaping/fonts/fonts/.
Then, run the fuzzer like this:
./hb-fuzzer -max_len=2048 CORPUS_DIR
Where max_len specifies the maximal length of font files to handle.
The smaller the faster.

For more details consult the following locations:
- http://llvm.org/docs/LibFuzzer.html or
- https://github.com/google/libfuzzer-bot/tree/master/harfbuzz
- https://github.com/harfbuzz/harfbuzz/issues/139