mirror of
https://github.com/bitcoin/bitcoin.git
synced 2025-02-24 12:41:41 -05:00
data:image/s3,"s3://crabby-images/20a7b/20a7bb858966ce0238eeb308a1b4dc1e593105ce" alt="Martin Leitner-Ankerl"
There exist many usages of `fuzzed_data_provider` where it is evaluated directly in the function call. Unfortunately, the order of evaluation of function arguments is unspecified. This means it can differ between compilers/version/optimization levels etc. But when the evaluation order changes, the same fuzzing input will produce different output, which is bad for coverage/reproducibility. This PR fixes all these cases where by moving multiple calls to `fuzzed_data_provider` out of the function arguments.
48 lines
1.9 KiB
C++
48 lines
1.9 KiB
C++
// Copyright (c) 2020-2022 The Bitcoin Core developers
|
|
// Distributed under the MIT software license, see the accompanying
|
|
// file COPYING or http://www.opensource.org/licenses/mit-license.php.
|
|
|
|
#include <netaddress.h>
|
|
#include <netbase.h>
|
|
#include <test/fuzz/FuzzedDataProvider.h>
|
|
#include <test/fuzz/fuzz.h>
|
|
#include <test/fuzz/util.h>
|
|
#include <test/fuzz/util/net.h>
|
|
#include <test/util/setup_common.h>
|
|
|
|
#include <cstdint>
|
|
#include <string>
|
|
#include <vector>
|
|
|
|
extern std::chrono::milliseconds g_socks5_recv_timeout;
|
|
|
|
namespace {
|
|
decltype(g_socks5_recv_timeout) default_socks5_recv_timeout;
|
|
};
|
|
|
|
void initialize_socks5()
|
|
{
|
|
static const auto testing_setup = MakeNoLogFileContext<const BasicTestingSetup>();
|
|
default_socks5_recv_timeout = g_socks5_recv_timeout;
|
|
}
|
|
|
|
FUZZ_TARGET(socks5, .init = initialize_socks5)
|
|
{
|
|
FuzzedDataProvider fuzzed_data_provider{buffer.data(), buffer.size()};
|
|
ProxyCredentials proxy_credentials;
|
|
proxy_credentials.username = fuzzed_data_provider.ConsumeRandomLengthString(512);
|
|
proxy_credentials.password = fuzzed_data_provider.ConsumeRandomLengthString(512);
|
|
if (fuzzed_data_provider.ConsumeBool()) {
|
|
g_socks5_interrupt();
|
|
}
|
|
// Set FUZZED_SOCKET_FAKE_LATENCY=1 to exercise recv timeout code paths. This
|
|
// will slow down fuzzing.
|
|
g_socks5_recv_timeout = (fuzzed_data_provider.ConsumeBool() && std::getenv("FUZZED_SOCKET_FAKE_LATENCY") != nullptr) ? 1ms : default_socks5_recv_timeout;
|
|
FuzzedSock fuzzed_sock = ConsumeSock(fuzzed_data_provider);
|
|
// This Socks5(...) fuzzing harness would have caught CVE-2017-18350 within
|
|
// a few seconds of fuzzing.
|
|
auto str_dest = fuzzed_data_provider.ConsumeRandomLengthString(512);
|
|
auto port = fuzzed_data_provider.ConsumeIntegral<uint16_t>();
|
|
auto* auth = fuzzed_data_provider.ConsumeBool() ? &proxy_credentials : nullptr;
|
|
(void)Socks5(str_dest, port, auth, fuzzed_sock);
|
|
}
|