Coverage Report

Created: 2026-09-28 07:05

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/brpc/test/fuzzing/fuzz_amf.cpp
Line
Count
Source
1
// Licensed to the Apache Software Foundation (ASF) under one
2
// or more contributor license agreements.  See the NOTICE file
3
// distributed with this work for additional information
4
// regarding copyright ownership.  The ASF licenses this file
5
// to you under the Apache License, Version 2.0 (the
6
// "License"); you may not use this file except in compliance
7
// with the License.  You may obtain a copy of the License at
8
//
9
//   http://www.apache.org/licenses/LICENSE-2.0
10
//
11
// Unless required by applicable law or agreed to in writing,
12
// software distributed under the License is distributed on an
13
// "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
14
// KIND, either express or implied.  See the License for the
15
// specific language governing permissions and limitations
16
// under the License.
17
18
#include "brpc/amf.h"
19
#include "butil/iobuf.h"
20
21
4.31k
#define kMinInputLength 5
22
2.15k
#define kMaxInputLength 4096
23
24
extern "C" int
25
LLVMFuzzerTestOneInput(const uint8_t *data, size_t size)
26
2.15k
{
27
2.15k
    if (size < kMinInputLength || size > kMaxInputLength){
28
19
        return 1;
29
19
    }
30
31
2.13k
    uint8_t mode = data[0] % 3;
32
2.13k
    const uint8_t *payload = data + 1;
33
2.13k
    size_t payload_size = size - 1;
34
35
2.13k
    butil::IOBuf buf;
36
2.13k
    buf.append(payload, payload_size);
37
38
2.13k
    switch (mode) {
39
1.87k
        case 0: {
40
            // Read AMF object
41
1.87k
            butil::IOBufAsZeroCopyInputStream zc_stream(buf);
42
1.87k
            brpc::AMFInputStream stream(&zc_stream);
43
1.87k
            brpc::AMFObject obj;
44
1.87k
            brpc::ReadAMFObject(&obj, &stream);
45
1.87k
            break;
46
0
        }
47
133
        case 1: {
48
            // Read AMF string
49
133
            butil::IOBufAsZeroCopyInputStream zc_stream(buf);
50
133
            brpc::AMFInputStream stream(&zc_stream);
51
133
            std::string val;
52
133
            brpc::ReadAMFString(&val, &stream);
53
133
            break;
54
0
        }
55
127
        case 2: {
56
            // Read raw AMF fields by consuming the stream directly
57
127
            butil::IOBufAsZeroCopyInputStream zc_stream(buf);
58
127
            brpc::AMFInputStream stream(&zc_stream);
59
127
            uint8_t marker;
60
12.7k
            while (stream.good() && stream.cut_u8(&marker) == 1) {
61
                // Try to identify marker type and read value
62
12.6k
                if (marker == brpc::AMF_MARKER_NUMBER) {
63
1.50k
                    uint64_t num;
64
1.50k
                    stream.cut_u64(&num);
65
11.1k
                } else if (marker == brpc::AMF_MARKER_BOOLEAN) {
66
1.67k
                    uint8_t b;
67
1.67k
                    stream.cut_u8(&b);
68
9.46k
                } else if (marker == brpc::AMF_MARKER_STRING) {
69
1.41k
                    uint16_t len;
70
1.41k
                    if (stream.cut_u16(&len) == 2 && len < 1024) {
71
402
                        char tmp[1024];
72
402
                        stream.cutn(tmp, len);
73
402
                    }
74
1.41k
                }
75
12.6k
            }
76
127
            break;
77
0
        }
78
2.13k
    }
79
80
2.13k
    return 0;
81
2.13k
}