/src/brpc/test/fuzzing/fuzz_amf.cpp
Line | Count | Source |
1 | | // Licensed to the Apache Software Foundation (ASF) under one |
2 | | // or more contributor license agreements. See the NOTICE file |
3 | | // distributed with this work for additional information |
4 | | // regarding copyright ownership. The ASF licenses this file |
5 | | // to you under the Apache License, Version 2.0 (the |
6 | | // "License"); you may not use this file except in compliance |
7 | | // with the License. You may obtain a copy of the License at |
8 | | // |
9 | | // http://www.apache.org/licenses/LICENSE-2.0 |
10 | | // |
11 | | // Unless required by applicable law or agreed to in writing, |
12 | | // software distributed under the License is distributed on an |
13 | | // "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY |
14 | | // KIND, either express or implied. See the License for the |
15 | | // specific language governing permissions and limitations |
16 | | // under the License. |
17 | | |
18 | | #include "brpc/amf.h" |
19 | | #include "butil/iobuf.h" |
20 | | |
21 | 4.31k | #define kMinInputLength 5 |
22 | 2.15k | #define kMaxInputLength 4096 |
23 | | |
24 | | extern "C" int |
25 | | LLVMFuzzerTestOneInput(const uint8_t *data, size_t size) |
26 | 2.15k | { |
27 | 2.15k | if (size < kMinInputLength || size > kMaxInputLength){ |
28 | 19 | return 1; |
29 | 19 | } |
30 | | |
31 | 2.13k | uint8_t mode = data[0] % 3; |
32 | 2.13k | const uint8_t *payload = data + 1; |
33 | 2.13k | size_t payload_size = size - 1; |
34 | | |
35 | 2.13k | butil::IOBuf buf; |
36 | 2.13k | buf.append(payload, payload_size); |
37 | | |
38 | 2.13k | switch (mode) { |
39 | 1.87k | case 0: { |
40 | | // Read AMF object |
41 | 1.87k | butil::IOBufAsZeroCopyInputStream zc_stream(buf); |
42 | 1.87k | brpc::AMFInputStream stream(&zc_stream); |
43 | 1.87k | brpc::AMFObject obj; |
44 | 1.87k | brpc::ReadAMFObject(&obj, &stream); |
45 | 1.87k | break; |
46 | 0 | } |
47 | 133 | case 1: { |
48 | | // Read AMF string |
49 | 133 | butil::IOBufAsZeroCopyInputStream zc_stream(buf); |
50 | 133 | brpc::AMFInputStream stream(&zc_stream); |
51 | 133 | std::string val; |
52 | 133 | brpc::ReadAMFString(&val, &stream); |
53 | 133 | break; |
54 | 0 | } |
55 | 127 | case 2: { |
56 | | // Read raw AMF fields by consuming the stream directly |
57 | 127 | butil::IOBufAsZeroCopyInputStream zc_stream(buf); |
58 | 127 | brpc::AMFInputStream stream(&zc_stream); |
59 | 127 | uint8_t marker; |
60 | 12.7k | while (stream.good() && stream.cut_u8(&marker) == 1) { |
61 | | // Try to identify marker type and read value |
62 | 12.6k | if (marker == brpc::AMF_MARKER_NUMBER) { |
63 | 1.50k | uint64_t num; |
64 | 1.50k | stream.cut_u64(&num); |
65 | 11.1k | } else if (marker == brpc::AMF_MARKER_BOOLEAN) { |
66 | 1.67k | uint8_t b; |
67 | 1.67k | stream.cut_u8(&b); |
68 | 9.46k | } else if (marker == brpc::AMF_MARKER_STRING) { |
69 | 1.41k | uint16_t len; |
70 | 1.41k | if (stream.cut_u16(&len) == 2 && len < 1024) { |
71 | 402 | char tmp[1024]; |
72 | 402 | stream.cutn(tmp, len); |
73 | 402 | } |
74 | 1.41k | } |
75 | 12.6k | } |
76 | 127 | break; |
77 | 0 | } |
78 | 2.13k | } |
79 | | |
80 | 2.13k | return 0; |
81 | 2.13k | } |