1# Copyright 2021 Code Intelligence GmbH 2# 3# Licensed under the Apache License, Version 2.0 (the "License"); 4# you may not use this file except in compliance with the License. 5# You may obtain a copy of the License at 6# 7# http://www.apache.org/licenses/LICENSE-2.0 8# 9# Unless required by applicable law or agreed to in writing, software 10# distributed under the License is distributed on an "AS IS" BASIS, 11# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 12# See the License for the specific language governing permissions and 13# limitations under the License. 14 15FROM ubuntu:20.04 AS builder 16 17ENV DEBIAN_FRONTEND=noninteractive 18RUN apt-get update && apt-get install -y curl git python3 openjdk-17-jdk-headless 19 20WORKDIR /root 21RUN curl -L https://github.com/bazelbuild/bazelisk/releases/download/v1.15.0/bazelisk-linux-amd64 -o /usr/bin/bazelisk && \ 22 chmod +x /usr/bin/bazelisk && \ 23 git clone --depth=1 https://github.com/CodeIntelligenceTesting/jazzer.git && \ 24 cd jazzer && \ 25 # The LLVM toolchain requires ld and ld.gold to exist, but does not use them. 26 touch /usr/bin/ld && \ 27 touch /usr/bin/ld.gold && \ 28 bazelisk build --config=docker //launcher:jazzer && \ 29 mkdir -p /app && \ 30 cp $(bazelisk cquery --config=docker --output=files //src/main/java/com/code_intelligence/jazzer:jazzer_standalone_deploy.jar) /app/jazzer_standalone.jar && \ 31 cp $(bazelisk cquery --config=docker --output=files //launcher:jazzer) /app/ 32 33# :debug includes a busybox shell, which is needed for libFuzzer's use of system() for e.g. the 34# -fork and -minimize_crash commands. 35FROM gcr.io/distroless/java17:debug 36 37COPY --from=builder /app/* /app/ 38# system() expects the shell at /bin/sh, but the image has it at /busybox/sh. We create a symlink, 39# but have to use the long form as a simple RUN <command> also requires /bin/sh. 40RUN ["/busybox/sh", "-c", "ln -s /busybox/sh /bin/sh"] 41WORKDIR /fuzzing 42ENTRYPOINT [ "/app/jazzer" ] 43