Skip to content

Commit 3f5107d

Browse files
author
MarcoFalke
committed
Merge #18423: tests: Add fuzzing harness for classes/functions in blockfilter.h. Add integer {de,}serialization fuzzing.
102f326 tests: Add fuzzing harness for classes/functions in blockfilter.h (practicalswift) 87d24e6 tests: Add integer serialization/deserialization fuzzing harness (practicalswift) Pull request description: Add fuzzing harness for classes/functions in `blockfilter.h`. Add integer serialization/deserialization fuzzing harness. Top commit has no ACKs. Tree-SHA512: 729e6bc1adf5873a64ca334a0ddc279c6cddf208923ca37cec712e9c73d0216a641045e10084925b055230f9d31fbd85ba61e59e4da3f865a544c5f8afc05e05
2 parents 5b4a9f4 + 102f326 commit 3f5107d

File tree

4 files changed

+101
-0
lines changed

4 files changed

+101
-0
lines changed

src/Makefile.test.include

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -17,6 +17,7 @@ FUZZ_TARGETS = \
1717
test/fuzz/block_filter_deserialize \
1818
test/fuzz/block_header \
1919
test/fuzz/block_header_and_short_txids_deserialize \
20+
test/fuzz/blockfilter \
2021
test/fuzz/blockheader_deserialize \
2122
test/fuzz/blocklocator_deserialize \
2223
test/fuzz/blockmerkleroot \
@@ -369,6 +370,12 @@ test_fuzz_block_header_and_short_txids_deserialize_LDADD = $(FUZZ_SUITE_LD_COMMO
369370
test_fuzz_block_header_and_short_txids_deserialize_LDFLAGS = $(RELDFLAGS) $(AM_LDFLAGS) $(LIBTOOL_APP_LDFLAGS)
370371
test_fuzz_block_header_and_short_txids_deserialize_SOURCES = $(FUZZ_SUITE) test/fuzz/deserialize.cpp
371372

373+
test_fuzz_blockfilter_CPPFLAGS = $(AM_CPPFLAGS) $(BITCOIN_INCLUDES)
374+
test_fuzz_blockfilter_CXXFLAGS = $(AM_CXXFLAGS) $(PIE_FLAGS)
375+
test_fuzz_blockfilter_LDADD = $(FUZZ_SUITE_LD_COMMON)
376+
test_fuzz_blockfilter_LDFLAGS = $(RELDFLAGS) $(AM_LDFLAGS) $(LIBTOOL_APP_LDFLAGS)
377+
test_fuzz_blockfilter_SOURCES = $(FUZZ_SUITE) test/fuzz/blockfilter.cpp
378+
372379
test_fuzz_blockheader_deserialize_CPPFLAGS = $(AM_CPPFLAGS) $(BITCOIN_INCLUDES) -DBLOCKHEADER_DESERIALIZE=1
373380
test_fuzz_blockheader_deserialize_CXXFLAGS = $(AM_CXXFLAGS) $(PIE_FLAGS)
374381
test_fuzz_blockheader_deserialize_LDADD = $(FUZZ_SUITE_LD_COMMON)

src/test/fuzz/blockfilter.cpp

Lines changed: 44 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,44 @@
1+
// Copyright (c) 2020 The Bitcoin Core developers
2+
// Distributed under the MIT software license, see the accompanying
3+
// file COPYING or http://www.opensource.org/licenses/mit-license.php.
4+
5+
#include <blockfilter.h>
6+
#include <optional.h>
7+
#include <test/fuzz/FuzzedDataProvider.h>
8+
#include <test/fuzz/fuzz.h>
9+
#include <test/fuzz/util.h>
10+
11+
#include <cstdint>
12+
#include <string>
13+
#include <vector>
14+
15+
void test_one_input(const std::vector<uint8_t>& buffer)
16+
{
17+
FuzzedDataProvider fuzzed_data_provider(buffer.data(), buffer.size());
18+
const Optional<BlockFilter> block_filter = ConsumeDeserializable<BlockFilter>(fuzzed_data_provider);
19+
if (!block_filter) {
20+
return;
21+
}
22+
{
23+
(void)block_filter->ComputeHeader(ConsumeUInt256(fuzzed_data_provider));
24+
(void)block_filter->GetBlockHash();
25+
(void)block_filter->GetEncodedFilter();
26+
(void)block_filter->GetHash();
27+
}
28+
{
29+
const BlockFilterType block_filter_type = block_filter->GetFilterType();
30+
(void)BlockFilterTypeName(block_filter_type);
31+
}
32+
{
33+
const GCSFilter gcs_filter = block_filter->GetFilter();
34+
(void)gcs_filter.GetN();
35+
(void)gcs_filter.GetParams();
36+
(void)gcs_filter.GetEncoded();
37+
(void)gcs_filter.Match(ConsumeRandomLengthByteVector(fuzzed_data_provider));
38+
GCSFilter::ElementSet element_set;
39+
while (fuzzed_data_provider.ConsumeBool()) {
40+
element_set.insert(ConsumeRandomLengthByteVector(fuzzed_data_provider));
41+
gcs_filter.MatchAny(element_set);
42+
}
43+
}
44+
}

src/test/fuzz/integer.cpp

Lines changed: 40 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -227,4 +227,44 @@ void test_one_input(const std::vector<uint8_t>& buffer)
227227
(void)HasAllDesirableServiceFlags(service_flags);
228228
(void)MayHaveUsefulAddressDB(service_flags);
229229
}
230+
231+
{
232+
CDataStream stream(SER_NETWORK, INIT_PROTO_VERSION);
233+
234+
ser_writedata64(stream, u64);
235+
const uint64_t deserialized_u64 = ser_readdata64(stream);
236+
assert(u64 == deserialized_u64 && stream.empty());
237+
238+
ser_writedata32(stream, u32);
239+
const uint32_t deserialized_u32 = ser_readdata32(stream);
240+
assert(u32 == deserialized_u32 && stream.empty());
241+
242+
ser_writedata32be(stream, u32);
243+
const uint32_t deserialized_u32be = ser_readdata32be(stream);
244+
assert(u32 == deserialized_u32be && stream.empty());
245+
246+
ser_writedata16(stream, u16);
247+
const uint16_t deserialized_u16 = ser_readdata16(stream);
248+
assert(u16 == deserialized_u16 && stream.empty());
249+
250+
ser_writedata16be(stream, u16);
251+
const uint16_t deserialized_u16be = ser_readdata16be(stream);
252+
assert(u16 == deserialized_u16be && stream.empty());
253+
254+
ser_writedata8(stream, u8);
255+
const uint8_t deserialized_u8 = ser_readdata8(stream);
256+
assert(u8 == deserialized_u8 && stream.empty());
257+
}
258+
259+
{
260+
CDataStream stream(SER_NETWORK, INIT_PROTO_VERSION);
261+
262+
WriteCompactSize(stream, u64);
263+
try {
264+
const uint64_t deserialized_u64 = ReadCompactSize(stream);
265+
assert(u64 == deserialized_u64 && stream.empty());
266+
}
267+
catch (const std::ios_base::failure&) {
268+
}
269+
}
230270
}

src/test/fuzz/util.h

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -13,6 +13,7 @@
1313
#include <streams.h>
1414
#include <test/fuzz/FuzzedDataProvider.h>
1515
#include <test/fuzz/fuzz.h>
16+
#include <uint256.h>
1617
#include <version.h>
1718

1819
#include <cstdint>
@@ -70,6 +71,15 @@ NODISCARD inline CScriptNum ConsumeScriptNum(FuzzedDataProvider& fuzzed_data_pro
7071
return CScriptNum{fuzzed_data_provider.ConsumeIntegral<int64_t>()};
7172
}
7273

74+
NODISCARD inline uint256 ConsumeUInt256(FuzzedDataProvider& fuzzed_data_provider) noexcept
75+
{
76+
const std::vector<unsigned char> v256 = fuzzed_data_provider.ConsumeBytes<unsigned char>(sizeof(uint256));
77+
if (v256.size() != sizeof(uint256)) {
78+
return {};
79+
}
80+
return uint256{v256};
81+
}
82+
7383
template <typename T>
7484
bool MultiplicationOverflow(T i, T j)
7585
{

0 commit comments

Comments
 (0)