Keep the colleague's microbu-esp32c5 tree in this repository

obu-firmware builds against vanetza-idf from microbu-esp32c5/external, but
that tree was gitignored, so a clone of this repository could not build the
firmware it ships. It is now committed here as ordinary files in its own
folder, microbu-esp32c5/: the colleague's commit cf4b99f plus the V2X2MAP
bridge's signature verification (--trust) used on the bench. Nothing is
fetched from or pushed to the colleague's repository; this repository and
its remotes carry everything. The folder's own .gitignore keeps build output,
downloaded components and private key material out, as it did there; the
committed file set is identical to that repository's tracked files.

The ESP32-C5 is still flashed from obu-firmware/, which only takes
vanetza-idf from microbu-esp32c5/, so the two stay separate folders.
FLASHING.md says how to take a newer version of the colleague's tree (copy
it over the folder, rebuild, test, commit).
This commit is contained in:
Ashin Walpola
2026-09-23 17:46:40 +02:00
parent 2f60623e18
commit 0e9525162d
9881 changed files with 1582523 additions and 17 deletions
@@ -0,0 +1 @@
output/
@@ -0,0 +1,5 @@
add_executable(fuzzing-persistent router_fuzzing_context.cpp persistent.cpp)
target_link_libraries(fuzzing-persistent PUBLIC vanetza)
add_executable(fuzzing-run router_fuzzing_context.cpp run.cpp)
target_link_libraries(fuzzing-run PUBLIC vanetza)
@@ -0,0 +1,15 @@
ARG VERSION=latest
FROM aflplusplus/aflplusplus:${VERSION}
# install build dependencies for Vanetza
RUN apt-get update && apt-get install --no-install-recommends -y \
libboost-all-dev libcrypto++-dev libgeographic-dev libssl-dev
# install casr-afl tool
RUN cargo install --root /usr/local casr
# set up "fuzz" user and mapping of host user
RUN useradd -m -s /bin/bash fuzz
RUN cp /root/.bashrc /home/fuzz/.bashrc && chown fuzz:fuzz /home/fuzz/.bashrc
COPY docker-entrypoint.sh /docker-entrypoint.sh
ENTRYPOINT ["/docker-entrypoint.sh"]
@@ -0,0 +1,25 @@
#!/bin/bash
set -eu
if [[ ! -d "/AFLplusplus" ]] ; then
echo "This script shall be run inside the AFL++ container"
exit 1
fi
cd /home/fuzz
export CC=${CC:=afl-clang-lto}
export CXX=${CXX:=afl-clang-lto++}
export AFL_LLVM_CMPLOG=1
mkdir -p build/cmplog
cmake -S source -B build/cmplog -G Ninja -DBUILD_FUZZ=ON
cmake --build build/cmplog
unset AFL_LLVM_CMPLOG
# see https://aflplus.plus/docs/env_variables/ for supported environment variables
export AFL_USE_ASAN=1
export AFL_USE_UBSAN=1
mkdir -p build/asan
cmake -S source -B build/asan -G Ninja -DBUILD_FUZZ=ON
cmake --build build/asan
@@ -0,0 +1,11 @@
#!/bin/bash -eu
afl-system-config
usermod -u ${HOST_USER_ID} -g ${HOST_GROUP_ID} fuzz
ln -sf /source /home/fuzz/source
ln -sf /input /home/fuzz/input
ln -sf /output /home/fuzz/output
ln -sf /source/tools/fuzz-harness/compile.sh /home/fuzz/compile.sh
ln -sf /source/tools/fuzz-harness/fuzz.sh /home/fuzz/fuzz.sh
cd /home/fuzz
su fuzz
@@ -0,0 +1,16 @@
#!/bin/bash
set -eu
HARNESS_DIR=$(realpath $(dirname $0))
SOURCE_DIR=$HARNESS_DIR/../..
docker build $HARNESS_DIR
IMAGE=$(docker build -q $HARNESS_DIR)
mkdir -p $HARNESS_DIR/output
docker run --rm -it \
--security-opt seccomp=unconfined \
-v$SOURCE_DIR:/source:ro \
-v$HARNESS_DIR/input:/input:ro \
-v$HARNESS_DIR/output:/output \
-e HOST_USER_ID=$(id -u) -e HOST_GROUP_ID=$(id -g) \
$IMAGE
@@ -0,0 +1,6 @@
#!/bin/bash
set -eu
: ${FUZZ_INPUT:="$HOME/input"}
: ${FUZZ_OUTPUT:="$HOME/output"}
: ${FUZZ_BUILD:="$HOME/build"}
afl-fuzz -i $FUZZ_INPUT -o $FUZZ_OUTPUT -c $FUZZ_BUILD/cmplog/bin/fuzzing-persistent -m none -- $FUZZ_BUILD/asan/bin/fuzzing-persistent
@@ -0,0 +1,34 @@
#include "router_fuzzing_context.hpp"
#include <stdio.h>
#include <unistd.h>
#ifndef __AFL_FUZZ_TESTCASE_LEN
ssize_t fuzz_len;
#define __AFL_FUZZ_TESTCASE_LEN fuzz_len
unsigned char fuzz_buf[1024000];
#define __AFL_FUZZ_TESTCASE_BUF fuzz_buf
#define __AFL_FUZZ_INIT() void sync(void);
#define __AFL_LOOP(x) ((fuzz_len = read(0, fuzz_buf, sizeof(fuzz_buf))) > 0 ? 1 : 0)
#define __AFL_INIT() sync()
#endif
__AFL_FUZZ_INIT();
int main()
{
#ifdef __AFL_HAVE_MANUAL_CONTROL
__AFL_INIT();
#endif
vanetza::RouterFuzzingContext context;
unsigned char *buf = __AFL_FUZZ_TESTCASE_BUF;
while (__AFL_LOOP(10000)) {
int len = __AFL_FUZZ_TESTCASE_LEN;
vanetza::ByteBuffer buffer { buf, buf + len };
context.initialize();
context.indicate(std::move(buffer));
}
return 0;
}
@@ -0,0 +1,45 @@
#include "router_fuzzing_context.hpp"
namespace vanetza
{
class FuzzingRequestInterface : public dcc::RequestInterface
{
void request(const dcc::DataRequest&, std::unique_ptr<ChunkPacket>) override {}
};
class FuzzingTransportInterface : public geonet::TransportInterface
{
void indicate(const geonet::DataIndication&, std::unique_ptr<geonet::UpPacket>) override {}
};
RouterFuzzingContext::RouterFuzzingContext() :
runtime(vanetza::Clock::at("2010-12-23 18:29")),
security(runtime),
req_ifc(std::make_unique<FuzzingRequestInterface>()),
ind_ifc(std::make_unique<FuzzingTransportInterface>())
{
initialize();
}
void RouterFuzzingContext::initialize()
{
router = std::make_unique<geonet::Router>(runtime, mib);
router->set_security_entity(&security.entity());
router->set_access_interface(req_ifc.get());
router->set_transport_handler(geonet::UpperProtocol::BTP_B, ind_ifc.get());
geonet::Address gn_addr;
gn_addr.mid(MacAddress{0, 0, 0, 0, 0, 1});
router->set_address(gn_addr);
}
void RouterFuzzingContext::indicate(ByteBuffer&& buffer)
{
MacAddress source { 0, 0, 0, 0, 0, 2 };
MacAddress destination { 0xff, 0xff, 0xff, 0xff, 0xff, 0xff };
auto packet = std::make_unique<geonet::UpPacket>(CohesivePacket { std::move(buffer), OsiLayer::Network });
router->indicate(std::move(packet), source, destination);
}
} // namespace vanetza
@@ -0,0 +1,30 @@
#ifndef VANETZA_ROUTER_FUZZING_CONTEXT_HPP
#define VANETZA_ROUTER_FUZZING_CONTEXT_HPP
#include <vanetza/common/manual_runtime.hpp>
#include <vanetza/dcc/interface.hpp>
#include <vanetza/geonet/router.hpp>
#include <vanetza/geonet/transport_interface.hpp>
#include <vanetza/geonet/tests/security_context.hpp>
namespace vanetza
{
class RouterFuzzingContext {
public:
RouterFuzzingContext();
void initialize();
void indicate(ByteBuffer&& buffer);
private:
ManualRuntime runtime;
SecurityContext security;
geonet::ManagementInformationBase mib;
std::unique_ptr<geonet::Router> router;
std::unique_ptr<dcc::RequestInterface> req_ifc;
std::unique_ptr<geonet::TransportInterface> ind_ifc;
};
} // namespace vanetza
#endif //VANETZA_ROUTER_FUZZING_CONTEXT_HPP
@@ -0,0 +1,42 @@
#include "router_fuzzing_context.hpp"
#include <iostream>
#include <fstream>
vanetza::ByteBuffer readFileIntoBuffer(const std::string &filename)
{
std::ifstream file(filename, std::ios::binary | std::ios::ate);
if (!file.is_open()) {
std::cerr << "Error opening file: " << filename << std::endl;
return {};
}
const std::streamsize size = file.tellg();
file.seekg(0, std::ios::beg);
vanetza::ByteBuffer buffer(size);
if (!file.read(reinterpret_cast<char *>(buffer.data()), size)) {
std::cerr << "Error reading file: " << filename << std::endl;
return {};
}
return buffer;
}
int main(int argc, char* argv[])
{
if (argc != 2) {
std::cerr << "Usage: " << argv[0] << " <filepath>" << std::endl;
return 1;
}
const std::string filename = argv[1];
vanetza::ByteBuffer buffer = readFileIntoBuffer(filename);
if (buffer.empty()) {
return 1;
}
vanetza::RouterFuzzingContext context;
context.indicate(std::move(buffer));
return 0;
}