Chromium Code Reviews| OLD | NEW |
|---|---|
| (Empty) | |
| 1 // Copyright 2015 The Chromium Authors. All rights reserved. | |
| 2 // Use of this source code is governed by a BSD-style license that can be | |
| 3 // found in the LICENSE file. | |
| 4 | |
| 5 #include <stddef.h> | |
| 6 #include <stdint.h> | |
| 7 | |
| 8 #include <memory> | |
| 9 #include <string> | |
| 10 #include <vector> | |
| 11 | |
| 12 #include "base/logging.h" | |
| 13 #include "base/memory/ptr_util.h" | |
|
yhirano
2016/08/31 06:10:00
+base/strings/string_piece.h
Adam Rice
2016/08/31 06:57:20
Done.
| |
| 14 #include "base/test/fuzzed_data_provider.h" | |
| 15 #include "net/base/completion_callback.h" | |
| 16 #include "net/base/io_buffer.h" | |
| 17 #include "net/base/net_errors.h" | |
| 18 #include "net/websockets/websocket_deflate_parameters.h" | |
| 19 #include "net/websockets/websocket_deflate_predictor.h" | |
| 20 #include "net/websockets/websocket_deflate_predictor_impl.h" | |
| 21 #include "net/websockets/websocket_deflate_stream.h" | |
| 22 #include "net/websockets/websocket_extension.h" | |
| 23 #include "net/websockets/websocket_frame.h" | |
| 24 #include "net/websockets/websocket_stream.h" | |
| 25 | |
| 26 namespace net { | |
| 27 | |
| 28 namespace { | |
| 29 | |
| 30 class WebSocketFuzzedStream final : public WebSocketStream { | |
| 31 public: | |
| 32 WebSocketFuzzedStream(const uint8_t* data, size_t size) | |
| 33 : fuzzed_data_provider_(data, size) {} | |
| 34 | |
| 35 int ReadFrames(std::vector<std::unique_ptr<WebSocketFrame>>* frames, | |
| 36 const CompletionCallback& callback) override { | |
| 37 if (fuzzed_data_provider_.remaining_bytes() == 0) | |
| 38 return ERR_CONNECTION_CLOSED; | |
| 39 while (fuzzed_data_provider_.remaining_bytes() > 0) | |
| 40 frames->push_back(CreateFrame()); | |
| 41 return OK; | |
| 42 } | |
| 43 | |
| 44 int WriteFrames(std::vector<std::unique_ptr<WebSocketFrame>>* frames, | |
| 45 const CompletionCallback& callback) override { | |
| 46 return ERR_FILE_NOT_FOUND; | |
| 47 } | |
| 48 | |
| 49 void Close() override {} | |
| 50 std::string GetSubProtocol() const override { return std::string(); } | |
| 51 std::string GetExtensions() const override { return std::string(); } | |
| 52 | |
| 53 private: | |
| 54 std::unique_ptr<WebSocketFrame> CreateFrame() { | |
| 55 WebSocketFrameHeader::OpCode opcode = | |
| 56 fuzzed_data_provider_.ConsumeInt32InRange( | |
| 57 WebSocketFrameHeader::kOpCodeContinuation, | |
| 58 WebSocketFrameHeader::kOpCodeControlUnused); | |
| 59 auto frame = base::MakeUnique<WebSocketFrame>(opcode); | |
| 60 // Bad news: ConsumeBool actually consumes a whole byte per call, so do | |
| 61 // something hacky to conserve precious bits. | |
| 62 uint8_t flags = fuzzed_data_provider_.ConsumeUint8(); | |
| 63 frame->header.final = flags & 0x1; | |
| 64 frame->header.reserved1 = (flags >> 1) & 0x1; | |
| 65 frame->header.reserved2 = (flags >> 2) & 0x1; | |
| 66 frame->header.reserved3 = (flags >> 3) & 0x1; | |
| 67 frame->header.masked = (flags >> 4) & 0x1; | |
| 68 uint64_t payload_length = fuzzed_data_provider_.ConsumeInt32InRange(0, 64); | |
| 69 base::StringPiece payload = | |
| 70 fuzzed_data_provider_.ConsumeBytes(payload_length); | |
| 71 frame->data = new WrappedIOBuffer(payload.data()); | |
| 72 frame->header.payload_length = payload.size(); | |
| 73 return frame; | |
| 74 } | |
| 75 | |
| 76 base::FuzzedDataProvider fuzzed_data_provider_; | |
| 77 }; | |
| 78 | |
| 79 void WebSocketDeflateStreamFuzz(const uint8_t* data, size_t size) { | |
| 80 // WebSocketDeflateStream needs to be constructed on each call because it | |
| 81 // has state. | |
| 82 std::string failure_message; | |
| 83 WebSocketDeflateParameters parameters; | |
| 84 parameters.Initialize(WebSocketExtension("permessage-deflate"), | |
| 85 &failure_message); | |
| 86 WebSocketDeflateStream deflate_stream( | |
| 87 base::MakeUnique<WebSocketFuzzedStream>(data, size), parameters, | |
| 88 base::MakeUnique<WebSocketDeflatePredictorImpl>()); | |
| 89 std::vector<std::unique_ptr<net::WebSocketFrame>> frames; | |
| 90 deflate_stream.ReadFrames(&frames, CompletionCallback()); | |
| 91 } | |
| 92 | |
| 93 } // namespace | |
| 94 | |
| 95 } // namespace net | |
| 96 | |
| 97 // Entry point for LibFuzzer. | |
| 98 extern "C" int LLVMFuzzerTestOneInput(const uint8_t* data, size_t size) { | |
| 99 net::WebSocketDeflateStreamFuzz(data, size); | |
| 100 | |
| 101 return 0; | |
| 102 } | |
| OLD | NEW |