Skip to content

Commit fad3d76

Browse files
author
MarcoFalke
committed
fuzz: Avoid initializing version to less than MIN_PEER_PROTO_VERSION
1 parent fa99e33 commit fad3d76

File tree

4 files changed

+16
-10
lines changed

4 files changed

+16
-10
lines changed

src/test/fuzz/process_message.cpp

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -60,10 +60,12 @@ void fuzz_target(const std::vector<uint8_t>& buffer, const std::string& LIMIT_TO
6060
return;
6161
}
6262
CNode& p2p_node = *ConsumeNodeAsUniquePtr(fuzzed_data_provider).release();
63-
FillNode(fuzzed_data_provider, p2p_node);
64-
p2p_node.fSuccessfullyConnected = true;
63+
64+
const bool successfully_connected{true};
65+
p2p_node.fSuccessfullyConnected = successfully_connected;
6566
connman.AddTestNode(p2p_node);
6667
g_setup->m_node.peerman->InitializeNode(&p2p_node);
68+
FillNode(fuzzed_data_provider, p2p_node, /* init_version */ successfully_connected);
6769

6870
const auto mock_time = ConsumeTime(fuzzed_data_provider);
6971
SetMockTime(mock_time);

src/test/fuzz/process_messages.cpp

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -45,11 +45,12 @@ FUZZ_TARGET_INIT(process_messages, initialize_process_messages)
4545
for (int i = 0; i < num_peers_to_add; ++i) {
4646
peers.push_back(ConsumeNodeAsUniquePtr(fuzzed_data_provider, i).release());
4747
CNode& p2p_node = *peers.back();
48-
FillNode(fuzzed_data_provider, p2p_node);
4948

50-
p2p_node.fSuccessfullyConnected = true;
49+
const bool successfully_connected{true};
50+
p2p_node.fSuccessfullyConnected = successfully_connected;
5151
p2p_node.fPauseSend = false;
5252
g_setup->m_node.peerman->InitializeNode(&p2p_node);
53+
FillNode(fuzzed_data_provider, p2p_node, /* init_version */ successfully_connected);
5354

5455
connman.AddTestNode(p2p_node);
5556
}

src/test/fuzz/util.cpp

Lines changed: 7 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -3,18 +3,21 @@
33
// file COPYING or http://www.opensource.org/licenses/mit-license.php.
44

55
#include <test/fuzz/util.h>
6+
#include <version.h>
67

7-
void FillNode(FuzzedDataProvider& fuzzed_data_provider, CNode& node, const std::optional<int32_t>& version_in) noexcept
8+
void FillNode(FuzzedDataProvider& fuzzed_data_provider, CNode& node, bool init_version) noexcept
89
{
910
const ServiceFlags remote_services = ConsumeWeakEnum(fuzzed_data_provider, ALL_SERVICE_FLAGS);
1011
const NetPermissionFlags permission_flags = ConsumeWeakEnum(fuzzed_data_provider, ALL_NET_PERMISSION_FLAGS);
11-
const int32_t version = version_in.value_or(fuzzed_data_provider.ConsumeIntegral<int32_t>());
12+
const int32_t version = fuzzed_data_provider.ConsumeIntegralInRange<int32_t>(MIN_PEER_PROTO_VERSION, std::numeric_limits<int32_t>::max());
1213
const bool filter_txs = fuzzed_data_provider.ConsumeBool();
1314

1415
node.nServices = remote_services;
1516
node.m_permissionFlags = permission_flags;
16-
node.nVersion = version;
17-
node.SetCommonVersion(version);
17+
if (init_version) {
18+
node.nVersion = version;
19+
node.SetCommonVersion(std::min(version, PROTOCOL_VERSION));
20+
}
1821
if (node.m_tx_relay != nullptr) {
1922
LOCK(node.m_tx_relay->cs_filter);
2023
node.m_tx_relay->fRelayTxes = filter_txs;

src/test/fuzz/util.h

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -320,9 +320,9 @@ auto ConsumeNode(FuzzedDataProvider& fuzzed_data_provider, const std::optional<N
320320
return CNode{node_id, local_services, socket, address, keyed_net_group, local_host_nonce, addr_bind, addr_name, conn_type, inbound_onion};
321321
}
322322
}
323-
inline std::unique_ptr<CNode> ConsumeNodeAsUniquePtr(FuzzedDataProvider& fdp, const std::optional<NodeId>& node_id_in = nullopt) { return ConsumeNode<true>(fdp, node_id_in); }
323+
inline std::unique_ptr<CNode> ConsumeNodeAsUniquePtr(FuzzedDataProvider& fdp, const std::optional<NodeId>& node_id_in = std::nullopt) { return ConsumeNode<true>(fdp, node_id_in); }
324324

325-
void FillNode(FuzzedDataProvider& fuzzed_data_provider, CNode& node, const std::optional<int32_t>& version_in = std::nullopt) noexcept;
325+
void FillNode(FuzzedDataProvider& fuzzed_data_provider, CNode& node, bool init_version) noexcept;
326326

327327
template <class T = const BasicTestingSetup>
328328
std::unique_ptr<T> MakeFuzzingContext(const std::string& chain_name = CBaseChainParams::REGTEST, const std::vector<const char*>& extra_args = {})

0 commit comments

Comments
 (0)