Keep vanetza-idf in obu-firmware, so a plain clone builds the firmware

obu-firmware builds against the vanetza-idf C-ITS library, which until now
came from the colleague's microbu-esp32c5 tree beside the repository and was
not tracked here, so a clone of this repository could not build the firmware
it ships. The library alone is now part of obu-firmware, as
obu-firmware/external/vanetza-idf: their external/vanetza-idf at commit
cf4b99f, unchanged (9775 files; see its PROVENANCE.md). CMake takes it from
there by default; -DVANETZA_IDF_DIR still points the build elsewhere.

The rest of the colleague's tree (their own VAM firmware, PKI tooling,
station-link Python tools, the V2X2MAP bridge) stays out of this repository
and gitignored; nothing is pushed to their repository. NOTES.md, docs/06,
TODO.md and the pcap verifier's usage line point at the new location.
This commit is contained in:
Ashin Walpola
2026-09-24 10:56:05 +02:00
parent 2f60623e18
commit d107534eb2
9781 changed files with 1560475 additions and 17 deletions
@@ -0,0 +1 @@
output/
@@ -0,0 +1,5 @@
add_executable(fuzzing-persistent router_fuzzing_context.cpp persistent.cpp)
target_link_libraries(fuzzing-persistent PUBLIC vanetza)
add_executable(fuzzing-run router_fuzzing_context.cpp run.cpp)
target_link_libraries(fuzzing-run PUBLIC vanetza)
@@ -0,0 +1,15 @@
ARG VERSION=latest
FROM aflplusplus/aflplusplus:${VERSION}
# install build dependencies for Vanetza
RUN apt-get update && apt-get install --no-install-recommends -y \
libboost-all-dev libcrypto++-dev libgeographic-dev libssl-dev
# install casr-afl tool
RUN cargo install --root /usr/local casr
# set up "fuzz" user and mapping of host user
RUN useradd -m -s /bin/bash fuzz
RUN cp /root/.bashrc /home/fuzz/.bashrc && chown fuzz:fuzz /home/fuzz/.bashrc
COPY docker-entrypoint.sh /docker-entrypoint.sh
ENTRYPOINT ["/docker-entrypoint.sh"]
@@ -0,0 +1,25 @@
#!/bin/bash
set -eu
if [[ ! -d "/AFLplusplus" ]] ; then
echo "This script shall be run inside the AFL++ container"
exit 1
fi
cd /home/fuzz
export CC=${CC:=afl-clang-lto}
export CXX=${CXX:=afl-clang-lto++}
export AFL_LLVM_CMPLOG=1
mkdir -p build/cmplog
cmake -S source -B build/cmplog -G Ninja -DBUILD_FUZZ=ON
cmake --build build/cmplog
unset AFL_LLVM_CMPLOG
# see https://aflplus.plus/docs/env_variables/ for supported environment variables
export AFL_USE_ASAN=1
export AFL_USE_UBSAN=1
mkdir -p build/asan
cmake -S source -B build/asan -G Ninja -DBUILD_FUZZ=ON
cmake --build build/asan
@@ -0,0 +1,11 @@
#!/bin/bash -eu
afl-system-config
usermod -u ${HOST_USER_ID} -g ${HOST_GROUP_ID} fuzz
ln -sf /source /home/fuzz/source
ln -sf /input /home/fuzz/input
ln -sf /output /home/fuzz/output
ln -sf /source/tools/fuzz-harness/compile.sh /home/fuzz/compile.sh
ln -sf /source/tools/fuzz-harness/fuzz.sh /home/fuzz/fuzz.sh
cd /home/fuzz
su fuzz
@@ -0,0 +1,16 @@
#!/bin/bash
set -eu
HARNESS_DIR=$(realpath $(dirname $0))
SOURCE_DIR=$HARNESS_DIR/../..
docker build $HARNESS_DIR
IMAGE=$(docker build -q $HARNESS_DIR)
mkdir -p $HARNESS_DIR/output
docker run --rm -it \
--security-opt seccomp=unconfined \
-v$SOURCE_DIR:/source:ro \
-v$HARNESS_DIR/input:/input:ro \
-v$HARNESS_DIR/output:/output \
-e HOST_USER_ID=$(id -u) -e HOST_GROUP_ID=$(id -g) \
$IMAGE
@@ -0,0 +1,6 @@
#!/bin/bash
set -eu
: ${FUZZ_INPUT:="$HOME/input"}
: ${FUZZ_OUTPUT:="$HOME/output"}
: ${FUZZ_BUILD:="$HOME/build"}
afl-fuzz -i $FUZZ_INPUT -o $FUZZ_OUTPUT -c $FUZZ_BUILD/cmplog/bin/fuzzing-persistent -m none -- $FUZZ_BUILD/asan/bin/fuzzing-persistent
@@ -0,0 +1,34 @@
#include "router_fuzzing_context.hpp"
#include <stdio.h>
#include <unistd.h>
#ifndef __AFL_FUZZ_TESTCASE_LEN
ssize_t fuzz_len;
#define __AFL_FUZZ_TESTCASE_LEN fuzz_len
unsigned char fuzz_buf[1024000];
#define __AFL_FUZZ_TESTCASE_BUF fuzz_buf
#define __AFL_FUZZ_INIT() void sync(void);
#define __AFL_LOOP(x) ((fuzz_len = read(0, fuzz_buf, sizeof(fuzz_buf))) > 0 ? 1 : 0)
#define __AFL_INIT() sync()
#endif
__AFL_FUZZ_INIT();
int main()
{
#ifdef __AFL_HAVE_MANUAL_CONTROL
__AFL_INIT();
#endif
vanetza::RouterFuzzingContext context;
unsigned char *buf = __AFL_FUZZ_TESTCASE_BUF;
while (__AFL_LOOP(10000)) {
int len = __AFL_FUZZ_TESTCASE_LEN;
vanetza::ByteBuffer buffer { buf, buf + len };
context.initialize();
context.indicate(std::move(buffer));
}
return 0;
}
@@ -0,0 +1,45 @@
#include "router_fuzzing_context.hpp"
namespace vanetza
{
class FuzzingRequestInterface : public dcc::RequestInterface
{
void request(const dcc::DataRequest&, std::unique_ptr<ChunkPacket>) override {}
};
class FuzzingTransportInterface : public geonet::TransportInterface
{
void indicate(const geonet::DataIndication&, std::unique_ptr<geonet::UpPacket>) override {}
};
RouterFuzzingContext::RouterFuzzingContext() :
runtime(vanetza::Clock::at("2010-12-23 18:29")),
security(runtime),
req_ifc(std::make_unique<FuzzingRequestInterface>()),
ind_ifc(std::make_unique<FuzzingTransportInterface>())
{
initialize();
}
void RouterFuzzingContext::initialize()
{
router = std::make_unique<geonet::Router>(runtime, mib);
router->set_security_entity(&security.entity());
router->set_access_interface(req_ifc.get());
router->set_transport_handler(geonet::UpperProtocol::BTP_B, ind_ifc.get());
geonet::Address gn_addr;
gn_addr.mid(MacAddress{0, 0, 0, 0, 0, 1});
router->set_address(gn_addr);
}
void RouterFuzzingContext::indicate(ByteBuffer&& buffer)
{
MacAddress source { 0, 0, 0, 0, 0, 2 };
MacAddress destination { 0xff, 0xff, 0xff, 0xff, 0xff, 0xff };
auto packet = std::make_unique<geonet::UpPacket>(CohesivePacket { std::move(buffer), OsiLayer::Network });
router->indicate(std::move(packet), source, destination);
}
} // namespace vanetza
@@ -0,0 +1,30 @@
#ifndef VANETZA_ROUTER_FUZZING_CONTEXT_HPP
#define VANETZA_ROUTER_FUZZING_CONTEXT_HPP
#include <vanetza/common/manual_runtime.hpp>
#include <vanetza/dcc/interface.hpp>
#include <vanetza/geonet/router.hpp>
#include <vanetza/geonet/transport_interface.hpp>
#include <vanetza/geonet/tests/security_context.hpp>
namespace vanetza
{
class RouterFuzzingContext {
public:
RouterFuzzingContext();
void initialize();
void indicate(ByteBuffer&& buffer);
private:
ManualRuntime runtime;
SecurityContext security;
geonet::ManagementInformationBase mib;
std::unique_ptr<geonet::Router> router;
std::unique_ptr<dcc::RequestInterface> req_ifc;
std::unique_ptr<geonet::TransportInterface> ind_ifc;
};
} // namespace vanetza
#endif //VANETZA_ROUTER_FUZZING_CONTEXT_HPP
@@ -0,0 +1,42 @@
#include "router_fuzzing_context.hpp"
#include <iostream>
#include <fstream>
vanetza::ByteBuffer readFileIntoBuffer(const std::string &filename)
{
std::ifstream file(filename, std::ios::binary | std::ios::ate);
if (!file.is_open()) {
std::cerr << "Error opening file: " << filename << std::endl;
return {};
}
const std::streamsize size = file.tellg();
file.seekg(0, std::ios::beg);
vanetza::ByteBuffer buffer(size);
if (!file.read(reinterpret_cast<char *>(buffer.data()), size)) {
std::cerr << "Error reading file: " << filename << std::endl;
return {};
}
return buffer;
}
int main(int argc, char* argv[])
{
if (argc != 2) {
std::cerr << "Usage: " << argv[0] << " <filepath>" << std::endl;
return 1;
}
const std::string filename = argv[1];
vanetza::ByteBuffer buffer = readFileIntoBuffer(filename);
if (buffer.empty()) {
return 1;
}
vanetza::RouterFuzzingContext context;
context.indicate(std::move(buffer));
return 0;
}