webrtc/test/fuzzers/corpora
Danil Chapovalov 5314b13a8d Fix undefined-shift in RtpDepacketizerAv1::AssembleFrame
Bug: chromium:1028348
Change-Id: I824e84138acbf4e73fc21ee8248e29e5cc7a0ba0
Reviewed-on: https://webrtc-review.googlesource.com/c/src/+/160643
Reviewed-by: Sam Zackrisson <saza@webrtc.org>
Commit-Queue: Danil Chapovalov <danilchap@webrtc.org>
Cr-Commit-Position: refs/heads/master@{#29945}
2019-11-28 11:27:33 +00:00
..
aec3-config-json-corpus Add AEC3 config json parsing fuzzer 2019-10-17 16:33:44 +00:00
agc-corpus Add AGC1 fuzzer 2018-06-21 13:09:03 +00:00
audio_processing-corpus Template argument and corpora for Audio Processing Fuzzer. 2018-03-02 14:00:39 +00:00
dependency_descriptor-corpus Add fuzzer testing for Dependency Descriptor rtp header extension 2019-09-20 12:40:24 +00:00
field_trial-corpus Field trial fuzzer. 2019-03-12 20:47:15 +00:00
mdns-corpus Add the multicast DNS message format. 2018-08-31 00:02:44 +00:00
pseudotcp-corpus Moving src/webrtc into src/. 2017-09-15 04:25:06 +00:00
rtcp-corpus Moving src/webrtc into src/. 2017-09-15 04:25:06 +00:00
rtp-corpus Discard frame self-dependency when parsing genric frame descriptor 2018-07-03 10:28:05 +00:00
rtp-depacketizer-av1-assemble-frame-corpus Fix undefined-shift in RtpDepacketizerAv1::AssembleFrame 2019-11-28 11:27:33 +00:00
rtpdump-corpus Fuzzing support for RTPDump VP8 and VP9 Streams. 2019-03-15 18:48:43 +00:00
sdp-corpus Adding simulcast examples to the fuzzing corpus. 2019-03-14 01:10:08 +00:00
string_to_number-corpus Fuzz rtc::StringToNumber. 2019-03-12 22:05:46 +00:00
stun-corpus Moving src/webrtc into src/. 2017-09-15 04:25:06 +00:00
README Moving src/webrtc into src/. 2017-09-15 04:25:06 +00:00
sdp.tokens Moving src/webrtc into src/. 2017-09-15 04:25:06 +00:00
stun.tokens Moving src/webrtc into src/. 2017-09-15 04:25:06 +00:00

This is a collection of corpora for various WebRTC fuzzers. To use
them, the gn targets define seed_corpus=$corpus_dir, which causes the
ClusterFuzz upload bot to bundle $corpus_dir and upload it.

The format is simple: one file per test case. Specific notes are
included below.

### SDP ###
This corpus was initially assembled manually from the following
sources:

  - curl --silent https://www.ietf.org/rfc/rfc4317.txt | grep '^[ a-z]*=[^=]*$' | sed 's/^[[:space:]]*//' | awk -v RS='(^|\n)v=' '/./ {print "v="$0 > NR".sdp"}'
  - all the SDPs used in the parser unit tests
  - some manually gathered SDPs from Firefox and Opera

The SDP tokens come from:

 -  grep "^static const " webrtc/api/webrtcsdp.cc | cut -d'=' -f2 | cut -d ';' -f1 | tr -d '"' | tr -d "'" | tr -d ' ' | sort -u | grep -v '^(\n|\r|\r\n)$|^$' | sed -e 's/^/"/' -e 's/$/"/' | tail -n +2

### STUN ###
This corpus was initially assembled from the STUN unit tests, together
with a crash that it found relatively quickly.

### RT(C)P ###
This corpus was initially assembled from the unittests. RTCP was
minimised first.

There is also rt(c?)p-corpus-with-extra-byte, in which each sample is
prefixed by the byte 0xff. Some of the rtp fuzzers need to decide
which header extensions to enable, and the first byte of the fuzz data
is used for this.

### PseudoTCP ###
Very small corpus minimised from the unit tests.