Merge branch 'master' into master

This commit is contained in:
rsheeter
2017-02-23 13:09:01 -08:00
committed by GitHub
8 changed files with 67 additions and 25 deletions
+1
View File
@@ -1,3 +1,4 @@
*.o *.o
*.a
/woff2_compress /woff2_compress
/woff2_decompress /woff2_decompress
+11 -3
View File
@@ -2,10 +2,13 @@ OS := $(shell uname)
CPPFLAGS = -I./brotli/include/ -I./src CPPFLAGS = -I./brotli/include/ -I./src
AR ?= ar
CC ?= gcc CC ?= gcc
CXX ?= g++ CXX ?= g++
COMMON_FLAGS = -fno-omit-frame-pointer -no-canonical-prefixes -DFONT_COMPRESSION_BIN -D __STDC_FORMAT_MACROS # It's helpful to be able to turn this off for fuzzing
CANONICAL_PREFIXES ?= -no-canonical-prefixes
COMMON_FLAGS = -fno-omit-frame-pointer $(CANONICAL_PREFIXES) -DFONT_COMPRESSION_BIN -D __STDC_FORMAT_MACROS
ifeq ($(OS), Darwin) ifeq ($(OS), Darwin)
CPPFLAGS += -DOS_MACOSX CPPFLAGS += -DOS_MACOSX
@@ -13,6 +16,7 @@ else
COMMON_FLAGS += -fno-tree-vrp COMMON_FLAGS += -fno-tree-vrp
endif endif
ARFLAGS = crf
CFLAGS += $(COMMON_FLAGS) CFLAGS += $(COMMON_FLAGS)
CXXFLAGS += $(COMMON_FLAGS) -std=c++11 CXXFLAGS += $(COMMON_FLAGS) -std=c++11
@@ -30,14 +34,18 @@ COMMONOBJ = $(BROTLIOBJ)/common/*.o
OBJS = $(patsubst %, $(SRCDIR)/%, $(OUROBJ)) OBJS = $(patsubst %, $(SRCDIR)/%, $(OUROBJ))
EXECUTABLES=woff2_compress woff2_decompress EXECUTABLES=woff2_compress woff2_decompress
EXE_OBJS=$(patsubst %, $(SRCDIR)/%.o, $(EXECUTABLES)) EXE_OBJS=$(patsubst %, $(SRCDIR)/%.o, $(EXECUTABLES))
ARCHIVES=convert_woff2ttf_fuzzer convert_woff2ttf_fuzzer_new_entry
ARCHIVE_OBJS=$(patsubst %, $(SRCDIR)/%.o, $(ARCHIVES))
ifeq (,$(wildcard $(BROTLI)/*)) ifeq (,$(wildcard $(BROTLI)/*))
$(error Brotli dependency not found : you must initialize the Git submodule) $(error Brotli dependency not found : you must initialize the Git submodule)
endif endif
all : $(OBJS) $(EXECUTABLES) all : $(OBJS) $(EXECUTABLES) $(ARCHIVES)
$(ARCHIVES) : $(ARCHIVE_OBJS) $(OBJS) deps
$(AR) $(ARFLAGS) $(SRCDIR)/$@.a $(OBJS) $(ENCOBJ) $(DECOBJ) $(SRCDIR)/$@.o
$(EXECUTABLES) : $(EXE_OBJS) deps $(EXECUTABLES) : $(EXE_OBJS) deps
$(CXX) $(LFLAGS) $(OBJS) $(COMMONOBJ) $(ENCOBJ) $(DECOBJ) $(SRCDIR)/$@.o -o $@ $(CXX) $(LFLAGS) $(OBJS) $(COMMONOBJ) $(ENCOBJ) $(DECOBJ) $(SRCDIR)/$@.o -o $@
+5 -5
View File
@@ -65,8 +65,8 @@ inline bool Failure(const char *f, int l, const char *fn) {
// ----------------------------------------------------------------------------- // -----------------------------------------------------------------------------
class Buffer { class Buffer {
public: public:
Buffer(const uint8_t *buffer, size_t len) Buffer(const uint8_t *data, size_t len)
: buffer_(buffer), : buffer_(data),
length_(len), length_(len),
offset_(0) { } offset_(0) { }
@@ -74,7 +74,7 @@ class Buffer {
return Read(NULL, n_bytes); return Read(NULL, n_bytes);
} }
bool Read(uint8_t *buffer, size_t n_bytes) { bool Read(uint8_t *data, size_t n_bytes) {
if (n_bytes > 1024 * 1024 * 1024) { if (n_bytes > 1024 * 1024 * 1024) {
return FONT_COMPRESSION_FAILURE(); return FONT_COMPRESSION_FAILURE();
} }
@@ -82,8 +82,8 @@ class Buffer {
(offset_ > length_ - n_bytes)) { (offset_ > length_ - n_bytes)) {
return FONT_COMPRESSION_FAILURE(); return FONT_COMPRESSION_FAILURE();
} }
if (buffer) { if (data) {
std::memcpy(buffer, buffer_ + offset_, n_bytes); std::memcpy(data, buffer_ + offset_, n_bytes);
} }
offset_ += n_bytes; offset_ += n_bytes;
return true; return true;
+13
View File
@@ -0,0 +1,13 @@
#include <stddef.h>
#include <stdint.h>
#include "woff2_dec.h"
// Entry point for LibFuzzer.
extern "C" int LLVMFuzzerTestOneInput(const uint8_t* data, size_t size) {
std::string buf;
woff2::WOFF2StringOut out(&buf);
out.SetMaxSize(30 * 1024 * 1024);
woff2::ConvertWOFF2ToTTF(data, size, &out);
return 0;
}
+12
View File
@@ -0,0 +1,12 @@
#include <string>
#include "woff2_dec.h"
extern "C" int LLVMFuzzerTestOneInput(const uint8_t *data, size_t data_size) {
// Decode using newer entry pattern.
// Same pattern as woff2_decompress.
std::string output(std::min(woff2::ComputeWOFF2FinalSize(data, data_size),
woff2::kDefaultMaxSize), 0);
woff2::WOFF2StringOut out(&output);
woff2::ConvertWOFF2ToTTF(data, data_size, &out);
return 0;
}
+6
View File
@@ -105,6 +105,12 @@ bool ReadTrueTypeFont(Buffer* file, const uint8_t* data, size_t len,
last_offset = i.first + i.second; last_offset = i.first + i.second;
} }
// Sanity check key tables
const Font::Table* head_table = font->FindTable(kHeadTableTag);
if (head_table != NULL && head_table->length < 52) {
return FONT_COMPRESSION_FAILURE();
}
return true; return true;
} }
+17 -15
View File
@@ -118,25 +118,27 @@ bool ReadGlyph(const uint8_t* data, size_t len, Glyph* glyph) {
// Read the run-length coded flags. // Read the run-length coded flags.
std::vector<std::vector<uint8_t> > flags(num_contours); std::vector<std::vector<uint8_t> > flags(num_contours);
uint8_t flag = 0; {
uint8_t flag_repeat = 0; uint8_t flag = 0;
for (int i = 0; i < num_contours; ++i) { uint8_t flag_repeat = 0;
flags[i].resize(glyph->contours[i].size()); for (int i = 0; i < num_contours; ++i) {
for (size_t j = 0; j < glyph->contours[i].size(); ++j) { flags[i].resize(glyph->contours[i].size());
if (flag_repeat == 0) { for (size_t j = 0; j < glyph->contours[i].size(); ++j) {
if (!buffer.ReadU8(&flag)) { if (flag_repeat == 0) {
return FONT_COMPRESSION_FAILURE(); if (!buffer.ReadU8(&flag)) {
}
if (flag & kFLAG_REPEAT) {
if (!buffer.ReadU8(&flag_repeat)) {
return FONT_COMPRESSION_FAILURE(); return FONT_COMPRESSION_FAILURE();
} }
if (flag & kFLAG_REPEAT) {
if (!buffer.ReadU8(&flag_repeat)) {
return FONT_COMPRESSION_FAILURE();
}
}
} else {
flag_repeat--;
} }
} else { flags[i][j] = flag;
flag_repeat--; glyph->contours[i][j].on_curve = flag & kFLAG_ONCURVE;
} }
flags[i][j] = flag;
glyph->contours[i][j].on_curve = flag & kFLAG_ONCURVE;
} }
} }
+2 -2
View File
@@ -49,8 +49,8 @@ void Write255UShort(std::vector<uint8_t>* out, int value) {
void Store255UShort(int val, size_t* offset, uint8_t* dst) { void Store255UShort(int val, size_t* offset, uint8_t* dst) {
std::vector<uint8_t> packed; std::vector<uint8_t> packed;
Write255UShort(&packed, val); Write255UShort(&packed, val);
for (uint8_t val : packed) { for (uint8_t packed_byte : packed) {
dst[(*offset)++] = val; dst[(*offset)++] = packed_byte;
} }
} }