Thus increase fuzzing coverage.
Signed-off-by: Petr Štetiar <ynezz@true.cz>
IF(CMAKE_C_COMPILER_ID STREQUAL "Clang")
+ ADD_SUBDIRECTORY(fuzz)
ADD_SUBDIRECTORY(fuzz-multipart-parser)
ENDIF()
--- /dev/null
+FILE(GLOB test_cases "test-*.c")
+
+MACRO(ADD_FUZZER_TEST name)
+ ADD_EXECUTABLE(${name} ${name}.c)
+ TARGET_COMPILE_OPTIONS(${name} PRIVATE -g -O1 -fno-omit-frame-pointer -fsanitize=fuzzer,address,leak,undefined)
+ TARGET_INCLUDE_DIRECTORIES(${name} PRIVATE ${PROJECT_SOURCE_DIR})
+ TARGET_LINK_OPTIONS(${name} PRIVATE -stdlib=libc++ -fsanitize=fuzzer,address,leak,undefined)
+ TARGET_LINK_LIBRARIES(${name} cgi-lib)
+ ADD_TEST(
+ NAME ${name}
+ COMMAND ${name} -max_len=256 -timeout=10 -max_total_time=300 ${CMAKE_CURRENT_SOURCE_DIR}/corpus
+ )
+ENDMACRO(ADD_FUZZER_TEST)
+
+FOREACH(test_case ${test_cases})
+ GET_FILENAME_COMPONENT(test_case ${test_case} NAME_WE)
+ ADD_FUZZER_TEST(${test_case})
+ENDFOREACH(test_case)
--- /dev/null
+J
\ No newline at end of file
--- /dev/null
+#define _GNU_SOURCE
+#include <stdio.h>
+#include <stdint.h>
+#include <stdlib.h>
+#include <stddef.h>
+#include <string.h>
+#include <fcntl.h>
+#include <errno.h>
+#include <unistd.h>
+
+#include <sys/types.h>
+#include <sys/stat.h>
+
+#include "util.h"
+
+static void fuzz_parse_command(const char *buf)
+{
+ char **p = parse_command(buf);
+ if (p)
+ free(p);
+}
+
+int LLVMFuzzerTestOneInput(const uint8_t *input, size_t size)
+{
+ char *p = NULL;
+ char *fields[] = { "sessionid", NULL, "path", NULL, "filename", NULL, "mimetype", NULL };
+ char *buf = calloc(1, size+1);
+ memcpy(buf, input, size);
+
+ urldecode(buf);
+ fuzz_parse_command(buf);
+ p = canonicalize_path(buf, size+1);
+ if (p)
+ free(p);
+
+ p = postdecode_fields(buf, size+1, fields, 4);
+ if (!p)
+ return 0;
+
+ free(buf);
+
+ return 0;
+}
#include <string.h>
#include <unistd.h>
+#include <stdio.h>
+
#include "util.h"
char **
return argv;
}
+char *
+postdecode_fields(char *postbuf, ssize_t len, char **fields, int n_fields)
+{
+ char *p;
+ int i, field, found = 0;
+
+ for (p = postbuf, i = 0; i <= len; i++)
+ {
+ if (postbuf[i] == '=')
+ {
+ postbuf[i] = 0;
+
+ for (field = 0; field < (n_fields * 2); field += 2)
+ {
+ if (!strcmp(p, fields[field]))
+ {
+ fields[field + 1] = postbuf + i + 1;
+ found++;
+ }
+ }
+ }
+ else if (postbuf[i] == '&' || postbuf[i] == '\0')
+ {
+ postbuf[i] = 0;
+
+ if (found >= n_fields)
+ break;
+
+ p = postbuf + i + 1;
+ }
+ }
+
+ for (field = 0; field < (n_fields * 2); field += 2)
+ {
+ if (!urldecode(fields[field + 1]))
+ {
+ free(postbuf);
+ return NULL;
+ }
+ }
+
+ return postbuf;
+}
+
char *
postdecode(char **fields, int n_fields)
{
const char *var;
char *p, *postbuf;
- int i, field, found = 0;
ssize_t len = 0, rlen = 0, content_length = 0;
var = getenv("CONTENT_TYPE");
return NULL;
}
- for (p = postbuf, i = 0; i <= len; i++)
- {
- if (postbuf[i] == '=')
- {
- postbuf[i] = 0;
-
- for (field = 0; field < (n_fields * 2); field += 2)
- {
- if (!strcmp(p, fields[field]))
- {
- fields[field + 1] = postbuf + i + 1;
- found++;
- }
- }
- }
- else if (postbuf[i] == '&' || postbuf[i] == '\0')
- {
- postbuf[i] = 0;
-
- if (found >= n_fields)
- break;
-
- p = postbuf + i + 1;
- }
- }
-
- for (field = 0; field < (n_fields * 2); field += 2)
- {
- if (!urldecode(fields[field + 1]))
- {
- free(postbuf);
- return NULL;
- }
- }
-
- return postbuf;
+ return postdecode_fields(postbuf, len, fields, n_fields);
}
char *
char** parse_command(const char *cmdline);
char* postdecode(char **fields, int n_fields);
+char* postdecode_fields(char *postbuf, ssize_t len, char **fields, int n_fields);
char* canonicalize_path(const char *path, size_t len);
bool urldecode(char *buf);
char* datadup(const void *in, size_t len);