Skip to content

Commit 1f66386

Browse files
author
MarcoFalke
committed
Merge #17113: tests: Add fuzzing harness for descriptor Span-parsing helpers
58d67f1 tests: Add fuzzing harness for descriptor Span-parsing helpers (practicalswift) Pull request description: Add fuzzing harness for descriptor Span-parsing helpers (`spanparsing`). As suggested by a fuzz testing enthusiast in bitcoin/bitcoin#16887 (comment). **Testing this PR** Run: ``` $ CC=clang CXX=clang++ ./configure --enable-fuzz \ --with-sanitizers=address,fuzzer,undefined $ make $ src/test/fuzz/spanparsing ``` ACKs for top commit: MarcoFalke: re-ACK 58d67f1 Tree-SHA512: 5eaca9fcda2856e0dcfeb4a98a2dc97051ae6251f7642b92fdae3ff96bb95ccb0377ee4e6c6b531e59061983b8d9485a5282467f2ab1d614861f60202a893b1c
2 parents 4cfb673 + 58d67f1 commit 1f66386

File tree

2 files changed

+37
-0
lines changed

2 files changed

+37
-0
lines changed

src/Makefile.test.include

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -23,6 +23,7 @@ FUZZ_TARGETS = \
2323
test/fuzz/netaddr_deserialize \
2424
test/fuzz/script_flags \
2525
test/fuzz/service_deserialize \
26+
test/fuzz/spanparsing \
2627
test/fuzz/transaction \
2728
test/fuzz/txoutcompressor_deserialize \
2829
test/fuzz/txundo_deserialize
@@ -270,6 +271,12 @@ test_fuzz_service_deserialize_CXXFLAGS = $(AM_CXXFLAGS) $(PIE_FLAGS)
270271
test_fuzz_service_deserialize_LDFLAGS = $(RELDFLAGS) $(AM_LDFLAGS) $(LIBTOOL_APP_LDFLAGS)
271272
test_fuzz_service_deserialize_LDADD = $(FUZZ_SUITE_LD_COMMON)
272273

274+
test_fuzz_spanparsing_SOURCES = $(FUZZ_SUITE) test/fuzz/spanparsing.cpp
275+
test_fuzz_spanparsing_CPPFLAGS = $(AM_CPPFLAGS) $(BITCOIN_INCLUDES)
276+
test_fuzz_spanparsing_CXXFLAGS = $(AM_CXXFLAGS) $(PIE_FLAGS)
277+
test_fuzz_spanparsing_LDFLAGS = $(RELDFLAGS) $(AM_LDFLAGS) $(LIBTOOL_APP_LDFLAGS)
278+
test_fuzz_spanparsing_LDADD = $(FUZZ_SUITE_LD_COMMON)
279+
273280
test_fuzz_messageheader_deserialize_SOURCES = $(FUZZ_SUITE) test/fuzz/deserialize.cpp
274281
test_fuzz_messageheader_deserialize_CPPFLAGS = $(AM_CPPFLAGS) $(BITCOIN_INCLUDES) -DMESSAGEHEADER_DESERIALIZE=1
275282
test_fuzz_messageheader_deserialize_CXXFLAGS = $(AM_CXXFLAGS) $(PIE_FLAGS)

src/test/fuzz/spanparsing.cpp

Lines changed: 30 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,30 @@
1+
// Copyright (c) 2019 The Bitcoin Core developers
2+
// Distributed under the MIT software license, see the accompanying
3+
// file COPYING or http://www.opensource.org/licenses/mit-license.php.
4+
5+
#include <test/fuzz/FuzzedDataProvider.h>
6+
#include <test/fuzz/fuzz.h>
7+
#include <util/spanparsing.h>
8+
9+
void test_one_input(const std::vector<uint8_t>& buffer)
10+
{
11+
FuzzedDataProvider fuzzed_data_provider(buffer.data(), buffer.size());
12+
const size_t query_size = fuzzed_data_provider.ConsumeIntegral<size_t>();
13+
const std::string query = fuzzed_data_provider.ConsumeBytesAsString(std::min<size_t>(query_size, 1024 * 1024));
14+
const std::string span_str = fuzzed_data_provider.ConsumeRemainingBytesAsString();
15+
const Span<const char> const_span = MakeSpan(span_str);
16+
17+
Span<const char> mut_span = const_span;
18+
(void)spanparsing::Const(query, mut_span);
19+
20+
mut_span = const_span;
21+
(void)spanparsing::Func(query, mut_span);
22+
23+
mut_span = const_span;
24+
(void)spanparsing::Expr(mut_span);
25+
26+
if (!query.empty()) {
27+
mut_span = const_span;
28+
(void)spanparsing::Split(mut_span, query.front());
29+
}
30+
}

0 commit comments

Comments
 (0)