1# Copyright 2021 Code Intelligence GmbH 2# 3# Licensed under the Apache License, Version 2.0 (the "License"); 4# you may not use this file except in compliance with the License. 5# You may obtain a copy of the License at 6# 7# http://www.apache.org/licenses/LICENSE-2.0 8# 9# Unless required by applicable law or agreed to in writing, software 10# distributed under the License is distributed on an "AS IS" BASIS, 11# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 12# See the License for the specific language governing permissions and 13# limitations under the License. 14 15FROM ubuntu:20.04 AS builder 16 17ENV DEBIAN_FRONTEND=noninteractive 18RUN apt-get update && apt-get install -y curl git python3 python-is-python3 openjdk-11-jdk-headless 19 20WORKDIR /root 21RUN curl -L https://github.com/bazelbuild/bazelisk/releases/download/v1.11.0/bazelisk-linux-amd64 -o /usr/bin/bazelisk && \ 22 chmod +x /usr/bin/bazelisk && \ 23 git clone --depth=1 https://github.com/CodeIntelligenceTesting/jazzer.git && \ 24 cd jazzer && \ 25 # The LLVM toolchain requires ld and ld.gold to exist, but does not use them. 26 touch /usr/bin/ld && \ 27 touch /usr/bin/ld.gold && \ 28 BAZEL_DO_NOT_DETECT_CPP_TOOLCHAIN=1 \ 29 bazelisk build --config=toolchain --extra_toolchains=@llvm_toolchain//:cc-toolchain-x86_64-linux \ 30 //agent:jazzer_agent_deploy //driver:jazzer_driver 31 32# :debug includes a busybox shell, which is needed for libFuzzer's use of system() for e.g. the 33# -fork and -minimize_crash commands. 34FROM gcr.io/distroless/java:debug 35 36COPY --from=builder /root/jazzer/bazel-bin/agent/jazzer_agent_deploy.jar /root/jazzer/bazel-bin/driver/jazzer_driver /app/ 37# system() expects the shell at /bin/sh, but the image has it at /busybox/sh. We create a symlink, 38# but have to use the long form as a simple RUN <command> also requires /bin/sh. 39RUN ["/busybox/sh", "-c", "ln -s /busybox/sh /bin/sh"] 40WORKDIR /fuzzing 41ENTRYPOINT [ "/app/jazzer_driver" ] 42