aboutsummaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorvan Hauser <vh@thc.org>2020-08-05 11:17:15 +0200
committervan Hauser <vh@thc.org>2020-08-05 11:17:15 +0200
commitf30ca1476c2d4d08d46fe9657ad4aa1d828eb578 (patch)
treec625c30a3e5db9918b8242ddcb7dff2c817832d2
parent0712d44cbcf1153972cd5457508dec5387e5b72e (diff)
downloadafl++-f30ca1476c2d4d08d46fe9657ad4aa1d828eb578.tar.gz
fix short write
-rw-r--r--include/afl-fuzz.h4
-rw-r--r--llvm_mode/afl-clang-fast.c10
-rw-r--r--src/afl-fuzz-queue.c2
-rw-r--r--src/afl-fuzz-run.c17
4 files changed, 24 insertions, 9 deletions
diff --git a/include/afl-fuzz.h b/include/afl-fuzz.h
index 2324efa5..bb1bb314 100644
--- a/include/afl-fuzz.h
+++ b/include/afl-fuzz.h
@@ -986,7 +986,7 @@ uint64_t rand_next(afl_state_t *afl);
static inline u32 rand_below(afl_state_t *afl, u32 limit) {
- if (limit <= 1) return 0;
+ if (limit <= 1) return 0;
/* The boundary not being necessarily a power of 2,
we need to ensure the result uniformity. */
@@ -1008,7 +1008,7 @@ static inline u32 rand_below(afl_state_t *afl, u32 limit) {
expand havoc mode */
static inline u32 rand_below_datalen(afl_state_t *afl, u32 limit) {
- if (limit <= 1) return 0;
+ if (limit <= 1) return 0;
switch (rand_below(afl, 3)) {
diff --git a/llvm_mode/afl-clang-fast.c b/llvm_mode/afl-clang-fast.c
index 16f2c9c0..3038df30 100644
--- a/llvm_mode/afl-clang-fast.c
+++ b/llvm_mode/afl-clang-fast.c
@@ -161,8 +161,8 @@ static void find_obj(u8 *argv0) {
static void edit_params(u32 argc, char **argv, char **envp) {
- u8 fortify_set = 0, asan_set = 0, x_set = 0, bit_mode = 0,
- preprocessor_only = 0;
+ u8 fortify_set = 0, asan_set = 0, x_set = 0, bit_mode = 0,
+ preprocessor_only = 0;
u8 have_pic = 0;
u8 *name;
@@ -400,7 +400,7 @@ static void edit_params(u32 argc, char **argv, char **envp) {
if (lto_mode && !strncmp(cur, "-fuse-ld=", 9)) continue;
if (lto_mode && !strncmp(cur, "--ld-path=", 10)) continue;
-
+
if (!strcmp(cur, "-E")) preprocessor_only = 1;
cc_params[cc_par_cnt++] = cur;
@@ -566,8 +566,9 @@ static void edit_params(u32 argc, char **argv, char **envp) {
cc_params[cc_par_cnt++] = "none";
}
-
+
if (preprocessor_only) {
+
/* In the preprocessor_only case (-E), we are not actually compiling at
all but requesting the compiler to output preprocessed sources only.
We must not add the runtime in this case because the compiler will
@@ -575,6 +576,7 @@ static void edit_params(u32 argc, char **argv, char **envp) {
systems that rely on a separate source preprocessing step. */
cc_params[cc_par_cnt] = NULL;
return;
+
}
#ifndef __ANDROID__
diff --git a/src/afl-fuzz-queue.c b/src/afl-fuzz-queue.c
index 71874283..f35df914 100644
--- a/src/afl-fuzz-queue.c
+++ b/src/afl-fuzz-queue.c
@@ -112,8 +112,10 @@ static u8 check_if_text(struct queue_entry *q) {
u8 buf[MAX_FILE];
s32 fd, len = q->len, offset = 0, ascii = 0, utf8 = 0, comp;
+ if (len >= MAX_FILE) len = MAX_FILE - 1;
if ((fd = open(q->fname, O_RDONLY)) < 0) return 0;
if ((comp = read(fd, buf, len)) != len) return 0;
+ buf[len] = 0;
close(fd);
while (offset < len) {
diff --git a/src/afl-fuzz-run.c b/src/afl-fuzz-run.c
index 44d3c522..ed4a1081 100644
--- a/src/afl-fuzz-run.c
+++ b/src/afl-fuzz-run.c
@@ -819,16 +819,27 @@ u8 trim_case(afl_state_t *afl, struct queue_entry *q, u8 *in_buf) {
fd = open(q->fname, O_WRONLY | O_CREAT | O_TRUNC, 0600);
+ if (fd < 0) { PFATAL("Unable to create '%s'", q->fname); }
+
+ u32 written = 0;
+ while (written < q->len) {
+
+ ssize_t result = write(fd, in_buf, q->len - written);
+ if (result > 0) written += result;
+
+ }
+
} else {
unlink(q->fname); /* ignore errors */
fd = open(q->fname, O_WRONLY | O_CREAT | O_EXCL, 0600);
- }
+ if (fd < 0) { PFATAL("Unable to create '%s'", q->fname); }
- if (fd < 0) { PFATAL("Unable to create '%s'", q->fname); }
+ ck_write(fd, in_buf, q->len, q->fname);
+
+ }
- ck_write(fd, in_buf, q->len, q->fname);
close(fd);
memcpy(afl->fsrv.trace_bits, afl->clean_trace, afl->fsrv.map_size);