Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(492)

Issue 1890193002: Add a fuzzer for HttpProxyClientSocket. (Closed)

Created:
4 years, 8 months ago by mmenke
Modified:
4 years, 7 months ago
Reviewers:
eroman
CC:
chromium-reviews, cbentzel+watch_chromium.org
Base URL:
https://chromium.googlesource.com/chromium/src.git@master
Target Ref:
refs/pending/heads/master
Project:
chromium
Visibility:
Public.

Description

Add a fuzzer for HttpProxyClientSocket. BUG=599582 Committed: https://crrev.com/8e9314bcf382b9df7caa3ab331e1b0090c27b62f Cr-Commit-Position: refs/heads/master@{#387707}

Patch Set 1 #

Patch Set 2 : Remove test code, dictionary #

Total comments: 15

Patch Set 3 : Response to comments #

Patch Set 4 : NET_EXPORT_PRIVATE #

Unified diffs Side-by-side diffs Delta from patch set Stats (+104 lines, -2 lines) Patch
M net/BUILD.gn View 1 2 1 chunk +12 lines, -0 lines 0 comments Download
M net/http/http_proxy_client_socket.h View 1 2 3 2 chunks +2 lines, -1 line 0 comments Download
A net/http/http_proxy_client_socket_fuzzer.cc View 1 2 1 chunk +89 lines, -0 lines 0 comments Download
M net/socket/fuzzed_socket.cc View 1 chunk +1 line, -1 line 0 comments Download

Messages

Total messages: 25 (11 generated)
mmenke
I've verified that with the right input, connect can succeed, both with and without an ...
4 years, 8 months ago (2016-04-15 18:41:55 UTC) #4
eroman
lgtm https://codereview.chromium.org/1890193002/diff/20001/net/BUILD.gn File net/BUILD.gn (right): https://codereview.chromium.org/1890193002/diff/20001/net/BUILD.gn#newcode1985 net/BUILD.gn:1985: dict = "http/http_chunked_decoder_fuzzer.dict" do you think the problem ...
4 years, 8 months ago (2016-04-15 19:07:21 UTC) #5
mmenke
https://codereview.chromium.org/1890193002/diff/20001/net/BUILD.gn File net/BUILD.gn (right): https://codereview.chromium.org/1890193002/diff/20001/net/BUILD.gn#newcode1985 net/BUILD.gn:1985: dict = "http/http_chunked_decoder_fuzzer.dict" On 2016/04/15 19:07:21, eroman wrote: > ...
4 years, 8 months ago (2016-04-15 19:23:52 UTC) #6
commit-bot: I haz the power
CQ is trying da patch. Follow status at https://chromium-cq-status.appspot.com/patch-status/1890193002/40001 View timeline at https://chromium-cq-status.appspot.com/patch-timeline/1890193002/40001
4 years, 8 months ago (2016-04-15 19:25:13 UTC) #9
eroman
lgtm https://codereview.chromium.org/1890193002/diff/20001/net/http/http_proxy_client_socket_fuzzer.cc File net/http/http_proxy_client_socket_fuzzer.cc (right): https://codereview.chromium.org/1890193002/diff/20001/net/http/http_proxy_client_socket_fuzzer.cc#newcode46 net/http/http_proxy_client_socket_fuzzer.cc:46: is_https_proxy = !(data[size - 1] & 1); On ...
4 years, 8 months ago (2016-04-15 19:31:56 UTC) #10
commit-bot: I haz the power
Try jobs failed on following builders: linux_chromium_compile_dbg_ng on tryserver.chromium.linux (JOB_FAILED, http://build.chromium.org/p/tryserver.chromium.linux/builders/linux_chromium_compile_dbg_ng/builds/79688)
4 years, 8 months ago (2016-04-15 19:59:39 UTC) #12
commit-bot: I haz the power
CQ is trying da patch. Follow status at https://chromium-cq-status.appspot.com/patch-status/1890193002/40001 View timeline at https://chromium-cq-status.appspot.com/patch-timeline/1890193002/40001
4 years, 8 months ago (2016-04-15 20:06:35 UTC) #14
mmenke
Eric: Am I missing something obvious here? That one builder really does not want to ...
4 years, 8 months ago (2016-04-15 20:35:51 UTC) #15
mmenke
On 2016/04/15 20:35:51, mmenke wrote: > Eric: Am I missing something obvious here? That one ...
4 years, 8 months ago (2016-04-15 20:41:23 UTC) #16
commit-bot: I haz the power
CQ is trying da patch. Follow status at https://chromium-cq-status.appspot.com/patch-status/1890193002/60001 View timeline at https://chromium-cq-status.appspot.com/patch-timeline/1890193002/60001
4 years, 8 months ago (2016-04-15 20:44:35 UTC) #19
commit-bot: I haz the power
Committed patchset #4 (id:60001)
4 years, 8 months ago (2016-04-15 21:45:11 UTC) #21
commit-bot: I haz the power
Patchset 4 (id:??) landed as https://crrev.com/8e9314bcf382b9df7caa3ab331e1b0090c27b62f Cr-Commit-Position: refs/heads/master@{#387707}
4 years, 8 months ago (2016-04-15 21:46:47 UTC) #23
mmoroz
I checked logs for these fuzzers. Looks like they are stuck, they find only one ...
4 years, 7 months ago (2016-05-04 15:17:43 UTC) #24
mmenke
4 years, 7 months ago (2016-05-04 17:00:16 UTC) #25
Message was sent while issue was closed.
On 2016/05/04 15:17:43, mmoroz wrote:
> I checked logs for these fuzzers. Looks like they are stuck, they find only
one
> testcase per hour (sometimes 2-3, but very barely).
> 
> Do we have any testcases to use as seed corpus? We can store them inside the
> repo or just upload to:
>
https://pantheon.corp.google.com/storage/browser/clusterfuzz-corpus/libfuzzer...
> and
>
https://pantheon.corp.google.com/storage/browser/clusterfuzz-corpus/libfuzzer...

Those links are for the socks proxy fuzzers (Which are, admittedly, for fairly
simple code), which this CL is for the HTTP proxy fuzzer, which is a wee bit
more complicated.  Which fuzzer are you referring to?

If you're talking about the socks/socks5 fuzzers, those are both simple enough
cases that I don't think more is needed, and would expect fairly modest sized
corpuses for both - in fact, if there's a way to tell the fuzzer infrastructure
"Run this fuzzer a lot less often, as it doesn't cover as much", I think it
would make a lot of sense for those two.

If you're talking about the HTTP proxy client socket fuzzer, that fuzzer has a
much larger space to explore, so issues with that one would be more concerning.

Powered by Google App Engine
This is Rietveld 408576698