Skip to content

Commit eabbbe4

Browse files
tests: Add fuzzing harness for rolling bloom filter class CRollingBloomFilter
1 parent 2a6a6ea commit eabbbe4

File tree

3 files changed

+58
-0
lines changed

3 files changed

+58
-0
lines changed

src/Makefile.test.include

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -51,6 +51,7 @@ FUZZ_TARGETS = \
5151
test/fuzz/psbt_input_deserialize \
5252
test/fuzz/psbt_output_deserialize \
5353
test/fuzz/pub_key_deserialize \
54+
test/fuzz/rolling_bloom_filter \
5455
test/fuzz/script \
5556
test/fuzz/script_deserialize \
5657
test/fuzz/script_flags \
@@ -523,6 +524,12 @@ test_fuzz_pub_key_deserialize_LDADD = $(FUZZ_SUITE_LD_COMMON)
523524
test_fuzz_pub_key_deserialize_LDFLAGS = $(RELDFLAGS) $(AM_LDFLAGS) $(LIBTOOL_APP_LDFLAGS)
524525
test_fuzz_pub_key_deserialize_SOURCES = $(FUZZ_SUITE) test/fuzz/deserialize.cpp
525526

527+
test_fuzz_rolling_bloom_filter_CPPFLAGS = $(AM_CPPFLAGS) $(BITCOIN_INCLUDES)
528+
test_fuzz_rolling_bloom_filter_CXXFLAGS = $(AM_CXXFLAGS) $(PIE_FLAGS)
529+
test_fuzz_rolling_bloom_filter_LDADD = $(FUZZ_SUITE_LD_COMMON)
530+
test_fuzz_rolling_bloom_filter_LDFLAGS = $(RELDFLAGS) $(AM_LDFLAGS) $(LIBTOOL_APP_LDFLAGS)
531+
test_fuzz_rolling_bloom_filter_SOURCES = $(FUZZ_SUITE) test/fuzz/rolling_bloom_filter.cpp
532+
526533
test_fuzz_script_CPPFLAGS = $(AM_CPPFLAGS) $(BITCOIN_INCLUDES)
527534
test_fuzz_script_CXXFLAGS = $(AM_CXXFLAGS) $(PIE_FLAGS)
528535
test_fuzz_script_LDADD = $(FUZZ_SUITE_LD_COMMON)
Lines changed: 50 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,50 @@
1+
// Copyright (c) 2020 The Bitcoin Core developers
2+
// Distributed under the MIT software license, see the accompanying
3+
// file COPYING or http://www.opensource.org/licenses/mit-license.php.
4+
5+
#include <bloom.h>
6+
#include <optional.h>
7+
#include <test/fuzz/FuzzedDataProvider.h>
8+
#include <test/fuzz/fuzz.h>
9+
#include <test/fuzz/util.h>
10+
#include <uint256.h>
11+
12+
#include <cassert>
13+
#include <cstdint>
14+
#include <string>
15+
#include <vector>
16+
17+
void test_one_input(const std::vector<uint8_t>& buffer)
18+
{
19+
FuzzedDataProvider fuzzed_data_provider(buffer.data(), buffer.size());
20+
21+
CRollingBloomFilter rolling_bloom_filter{
22+
fuzzed_data_provider.ConsumeIntegralInRange<unsigned int>(1, 1000),
23+
0.999 / fuzzed_data_provider.ConsumeIntegralInRange<unsigned int>(1, std::numeric_limits<unsigned int>::max())};
24+
while (fuzzed_data_provider.remaining_bytes() > 0) {
25+
switch (fuzzed_data_provider.ConsumeIntegralInRange(0, 2)) {
26+
case 0: {
27+
const std::vector<unsigned char>& b = ConsumeRandomLengthByteVector(fuzzed_data_provider);
28+
(void)rolling_bloom_filter.contains(b);
29+
rolling_bloom_filter.insert(b);
30+
const bool present = rolling_bloom_filter.contains(b);
31+
assert(present);
32+
break;
33+
}
34+
case 1: {
35+
const Optional<uint256> u256 = ConsumeDeserializable<uint256>(fuzzed_data_provider);
36+
if (!u256) {
37+
break;
38+
}
39+
(void)rolling_bloom_filter.contains(*u256);
40+
rolling_bloom_filter.insert(*u256);
41+
const bool present = rolling_bloom_filter.contains(*u256);
42+
assert(present);
43+
break;
44+
}
45+
case 2:
46+
rolling_bloom_filter.reset();
47+
break;
48+
}
49+
}
50+
}

test/fuzz/test_runner.py

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -40,6 +40,7 @@
4040
"psbt_input_deserialize",
4141
"psbt_output_deserialize",
4242
"pub_key_deserialize",
43+
"rolling_bloom_filter",
4344
"script_deserialize",
4445
"strprintf",
4546
"sub_net_deserialize",

0 commit comments

Comments
 (0)