/src/curl_fuzzer/legacy_fuzzer.cc
Line | Count | Source |
1 | | /*************************************************************************** |
2 | | * _ _ ____ _ |
3 | | * Project ___| | | | _ \| | |
4 | | * / __| | | | |_) | | |
5 | | * | (__| |_| | _ <| |___ |
6 | | * \___|\___/|_| \_\_____| |
7 | | * |
8 | | * Copyright (C) Max Dymond, <cmeister2@gmail.com>, et al. |
9 | | * |
10 | | * This software is licensed as described in the file COPYING, which |
11 | | * you should have received as part of this distribution. The terms |
12 | | * are also available at https://curl.se/docs/copyright.html. |
13 | | * |
14 | | * You may opt to use, copy, modify, merge, publish, distribute and/or sell |
15 | | * copies of the Software, and permit persons to whom the Software is |
16 | | * furnished to do so, under the terms of the COPYING file. |
17 | | * |
18 | | * This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY |
19 | | * KIND, either express or implied. |
20 | | * |
21 | | ***************************************************************************/ |
22 | | |
23 | | #include <stdlib.h> |
24 | | #include <signal.h> |
25 | | #include <string.h> |
26 | | #include <unistd.h> |
27 | | #include <curl/curl.h> |
28 | | #include "curl_fuzzer.h" |
29 | | #include "legacy_fuzzer.h" |
30 | | #include "legacy_protocol_allowlist.h" |
31 | | #include "legacy_tlv_mutator.h" |
32 | | |
33 | | /** |
34 | | * Run one legacy TLV input independently of the exported libFuzzer symbol. |
35 | | * Keeping the implementation behind a normal C++ function lets every |
36 | | * protocol binary expose its own same-named source entrypoint, which is how |
37 | | * Fuzz Introspector attributes a binary's runtime coverage to its call tree. |
38 | | */ |
39 | | int LegacyFuzzerTestOneInput(const uint8_t *data, size_t size) |
40 | 19.1k | { |
41 | 19.1k | int rc = 0; |
42 | 19.1k | int tlv_rc; |
43 | 19.1k | FUZZ_DATA fuzz; |
44 | 19.1k | TLV tlv; |
45 | | |
46 | | /* Ignore SIGPIPE errors. We'll handle the errors ourselves. */ |
47 | 19.1k | signal(SIGPIPE, SIG_IGN); |
48 | | |
49 | | /* Have to set all fields to zero before getting to the terminate function */ |
50 | 19.1k | memset(&fuzz, 0, sizeof(FUZZ_DATA)); |
51 | | |
52 | 19.1k | if(size < sizeof(TLV_RAW)) { |
53 | | /* Not enough data for a single TLV - don't continue */ |
54 | 4 | goto EXIT_LABEL; |
55 | 4 | } |
56 | | |
57 | | /* Try to initialize the fuzz data */ |
58 | 19.1k | FTRY(fuzz_initialize_fuzz_data(&fuzz, data, size)); |
59 | | |
60 | 19.1k | for(tlv_rc = fuzz_get_first_tlv(&fuzz, &tlv); |
61 | 114k | tlv_rc == 0; |
62 | 97.5k | tlv_rc = fuzz_get_next_tlv(&fuzz, &tlv)) { |
63 | | |
64 | | /* Have the TLV in hand. Parse the TLV. */ |
65 | 97.5k | rc = fuzz_parse_tlv(&fuzz, &tlv); |
66 | | |
67 | 97.5k | if(rc != 0) { |
68 | | /* Failed to parse the TLV. Can't continue. */ |
69 | 1.84k | goto EXIT_LABEL; |
70 | 1.84k | } |
71 | 97.5k | } |
72 | | |
73 | 17.3k | if(tlv_rc != TLV_RC_NO_MORE_TLVS) { |
74 | | /* A TLV call failed. Can't continue. */ |
75 | 162 | goto EXIT_LABEL; |
76 | 162 | } |
77 | | |
78 | | /* Set up the standard easy options. */ |
79 | 17.1k | FTRY(fuzz_set_easy_options(&fuzz)); |
80 | | |
81 | | /** |
82 | | * Add in more curl options that have been accumulated over possibly |
83 | | * multiple TLVs. |
84 | | */ |
85 | 17.1k | if(fuzz.header_list != NULL) { |
86 | 1.42k | curl_easy_setopt(fuzz.easy, CURLOPT_HTTPHEADER, fuzz.header_list); |
87 | 1.42k | } |
88 | | |
89 | 17.1k | if(fuzz.mail_recipients_list != NULL) { |
90 | 133 | curl_easy_setopt(fuzz.easy, CURLOPT_MAIL_RCPT, fuzz.mail_recipients_list); |
91 | 133 | } |
92 | | |
93 | 17.1k | if(fuzz.mime != NULL) { |
94 | 482 | curl_easy_setopt(fuzz.easy, CURLOPT_MIMEPOST, fuzz.mime); |
95 | 482 | } |
96 | | |
97 | 17.1k | if (fuzz.httppost != NULL) { |
98 | 180 | curl_easy_setopt(fuzz.easy, CURLOPT_HTTPPOST, fuzz.httppost); |
99 | 180 | } |
100 | | |
101 | | /* Run the transfer. */ |
102 | 17.1k | fuzz_handle_transfer(&fuzz); |
103 | | |
104 | 19.1k | EXIT_LABEL: |
105 | | |
106 | 19.1k | fuzz_terminate_fuzz_data(&fuzz); |
107 | | |
108 | | /* This function must always return 0. Non-zero codes are reserved. */ |
109 | 19.1k | return 0; |
110 | 17.1k | } |
111 | | |
112 | | /** |
113 | | * Utility function to convert 4 bytes to a u32 predictably. |
114 | | */ |
115 | | uint32_t to_u32(const uint8_t b[4]) |
116 | 119k | { |
117 | 119k | uint32_t u; |
118 | | /* Promote into the unsigned result type before shifting. uint8_t otherwise |
119 | | promotes to signed int, and values with the high bit set make the |
120 | | left-shift undefined before curl ever observes the fuzzed boundary. */ |
121 | 119k | u = (static_cast<uint32_t>(b[0]) << 24) | |
122 | 119k | (static_cast<uint32_t>(b[1]) << 16) | |
123 | 119k | (static_cast<uint32_t>(b[2]) << 8) | |
124 | 119k | static_cast<uint32_t>(b[3]); |
125 | 119k | return u; |
126 | 119k | } |
127 | | |
128 | | /** |
129 | | * Utility function to convert 2 bytes to a u16 predictably. |
130 | | */ |
131 | | uint16_t to_u16(const uint8_t b[2]) |
132 | 99.8k | { |
133 | 99.8k | uint16_t u; |
134 | 99.8k | u = (b[0] << 8) + b[1]; |
135 | 99.8k | return u; |
136 | 99.8k | } |
137 | | |
138 | | /** |
139 | | * Initialize the local fuzz data structure. |
140 | | */ |
141 | | int fuzz_initialize_fuzz_data(FUZZ_DATA *fuzz, |
142 | | const uint8_t *data, |
143 | | size_t data_len) |
144 | 19.1k | { |
145 | 19.1k | int rc = 0; |
146 | 19.1k | int ii; |
147 | | |
148 | | /* Initialize the fuzz data. */ |
149 | 19.1k | memset(fuzz, 0, sizeof(FUZZ_DATA)); |
150 | | |
151 | | /* Create an easy handle. This will have all of the settings configured on |
152 | | it. */ |
153 | 19.1k | fuzz->easy = curl_easy_init(); |
154 | 19.1k | FCHECK(fuzz->easy != NULL); |
155 | | |
156 | | /* Set up the state parser */ |
157 | 19.1k | fuzz->state.data = data; |
158 | 19.1k | fuzz->state.data_len = data_len; |
159 | | |
160 | | /* Set up the state of the server sockets. */ |
161 | 57.5k | for(ii = 0; ii < FUZZ_NUM_CONNECTIONS; ii++) { |
162 | 38.3k | fuzz->sockman[ii].index = ii; |
163 | 38.3k | fuzz->sockman[ii].fd_state = FUZZ_SOCK_CLOSED; |
164 | 38.3k | } |
165 | | |
166 | | /* Check for verbose mode. */ |
167 | 19.1k | fuzz->verbose = (getenv("FUZZ_VERBOSE") != NULL); |
168 | | |
169 | 19.1k | FCHECK(setenv("CURL_HSTS_HTTP", "1", 0) == 0); |
170 | 19.1k | FCHECK(setenv("CURL_ALTSVC_HTTP", "1", 0) == 0); |
171 | | |
172 | 19.1k | EXIT_LABEL: |
173 | | |
174 | 19.1k | return rc; |
175 | 19.1k | } |
176 | | |
177 | | /** |
178 | | * Reapply resolver-sensitive string options with their canonical loopback |
179 | | * values before starting a transfer. |
180 | | * |
181 | | * Custom mutation and crossover already finalize generated buffers, but an |
182 | | * initial corpus entry or standalone reproducer is executed without passing |
183 | | * through either callback. The option tracker identifies only values that the |
184 | | * TLV parser successfully applied, so this does not enable routing options that |
185 | | * were absent from the input. DNS_INTERFACE is deliberately excluded: with |
186 | | * c-ares it is a device name passed to ares_set_local_dev(), not a hostname. |
187 | | */ |
188 | | static int fuzz_finalize_routing_options(FUZZ_DATA *fuzz) |
189 | 17.1k | { |
190 | 17.1k | int rc = 0; |
191 | | |
192 | 17.1k | #define FFINALIZE_ROUTING_OPTION(TLVTYPE, CURLOPTNAME) \ |
193 | 68.6k | if(fuzz->options[(CURLOPTNAME) % 1000]) { \ |
194 | 1.32k | const char *canonical = \ |
195 | 1.32k | legacy_tlv_mutator::CanonicalRoutingValue((TLVTYPE)); \ |
196 | 1.32k | FCHECK(canonical != NULL); \ |
197 | 1.32k | FTRY(curl_easy_setopt(fuzz->easy, (CURLOPTNAME), canonical)); \ |
198 | 1.32k | } |
199 | | |
200 | 17.1k | FFINALIZE_ROUTING_OPTION(TLV_TYPE_PROXY, CURLOPT_PROXY); |
201 | 17.1k | FFINALIZE_ROUTING_OPTION(TLV_TYPE_FTPPORT, CURLOPT_FTPPORT); |
202 | 17.1k | FFINALIZE_ROUTING_OPTION(TLV_TYPE_INTERFACE, CURLOPT_INTERFACE); |
203 | 17.1k | FFINALIZE_ROUTING_OPTION(TLV_TYPE_PRE_PROXY, CURLOPT_PRE_PROXY); |
204 | | |
205 | 17.1k | #undef FFINALIZE_ROUTING_OPTION |
206 | | |
207 | 17.1k | EXIT_LABEL: |
208 | 17.1k | return rc; |
209 | 17.1k | } |
210 | | |
211 | | /** |
212 | | * Set standard options on the curl easy. |
213 | | */ |
214 | | int fuzz_set_easy_options(FUZZ_DATA *fuzz) |
215 | 17.1k | { |
216 | 17.1k | int rc = 0; |
217 | | |
218 | | /* Existing seeds and direct reproducers bypass the custom mutator. Close |
219 | | that path before any transfer can resolve a corpus-provided endpoint. */ |
220 | 17.1k | FTRY(fuzz_finalize_routing_options(fuzz)); |
221 | | |
222 | | /* Set some standard options on the CURL easy handle. We need to override the |
223 | | socket function so that we create our own sockets to present to CURL. */ |
224 | 17.1k | FTRY(curl_easy_setopt(fuzz->easy, |
225 | 17.1k | CURLOPT_OPENSOCKETFUNCTION, |
226 | 17.1k | fuzz_open_socket)); |
227 | 17.1k | FTRY(curl_easy_setopt(fuzz->easy, CURLOPT_OPENSOCKETDATA, fuzz)); |
228 | | |
229 | | /* In case something tries to set a socket option, intercept this. */ |
230 | 17.1k | FTRY(curl_easy_setopt(fuzz->easy, |
231 | 17.1k | CURLOPT_SOCKOPTFUNCTION, |
232 | 17.1k | fuzz_sockopt_callback)); |
233 | | |
234 | | /* Set the standard read function callback. */ |
235 | 17.1k | FTRY(curl_easy_setopt(fuzz->easy, |
236 | 17.1k | CURLOPT_READFUNCTION, |
237 | 17.1k | fuzz_read_callback)); |
238 | 17.1k | FTRY(curl_easy_setopt(fuzz->easy, CURLOPT_READDATA, fuzz)); |
239 | | |
240 | | /* Set the standard write function callback. */ |
241 | 17.1k | FTRY(curl_easy_setopt(fuzz->easy, |
242 | 17.1k | CURLOPT_WRITEFUNCTION, |
243 | 17.1k | fuzz_write_callback)); |
244 | 17.1k | FTRY(curl_easy_setopt(fuzz->easy, CURLOPT_WRITEDATA, fuzz)); |
245 | | |
246 | | /* Set the writable cookie jar path so cookies are tested. */ |
247 | 17.1k | FTRY(curl_easy_setopt(fuzz->easy, CURLOPT_COOKIEJAR, FUZZ_COOKIE_JAR_PATH)); |
248 | | |
249 | | /* Set the RO cookie file path so cookies are tested. */ |
250 | 17.1k | FTRY(curl_easy_setopt(fuzz->easy, CURLOPT_COOKIEFILE, FUZZ_RO_COOKIE_FILE_PATH)); |
251 | | |
252 | | /* Set altsvc header cache filepath so that it can be fuzzed. */ |
253 | 17.1k | FTRY(curl_easy_setopt(fuzz->easy, CURLOPT_ALTSVC, FUZZ_ALT_SVC_HEADER_CACHE_PATH)); |
254 | | |
255 | | /* Set the hsts header cache filepath so that it can be fuzzed. */ |
256 | 17.1k | FTRY(curl_easy_setopt(fuzz->easy, CURLOPT_HSTS, FUZZ_HSTS_HEADER_CACHE_PATH)); |
257 | | |
258 | | /* Set the Certificate Revocation List file path so it can be fuzzed */ |
259 | 17.1k | FTRY(curl_easy_setopt(fuzz->easy, CURLOPT_CRLFILE, FUZZ_CRL_FILE_PATH)); |
260 | | |
261 | | /* Loading the host trust store for every WSS mutation dominates the |
262 | | WebSocket target even when the in-process mock immediately ends the TLS |
263 | | handshake. Keep this exception local to that target: the other legacy |
264 | | fuzzers should retain libcurl's verification default so their ordinary |
265 | | mutations continue to cover certificate setup. An explicit |
266 | | SSL_VERIFYPEER TLV still restores verification in the WebSocket target. */ |
267 | | #ifdef FUZZ_PROTOCOLS_WS |
268 | | if(!fuzz->options[CURLOPT_SSL_VERIFYPEER % 1000]) { |
269 | | FTRY(curl_easy_setopt(fuzz->easy, CURLOPT_SSL_VERIFYPEER, 0L)); |
270 | | } |
271 | | #endif |
272 | | |
273 | | /* Set the .netrc file path so it can be fuzzed */ |
274 | 17.1k | FTRY(curl_easy_setopt(fuzz->easy, CURLOPT_NETRC_FILE, FUZZ_NETRC_FILE_PATH)); |
275 | | |
276 | | /* Time out requests quickly. */ |
277 | 17.1k | FTRY(curl_easy_setopt(fuzz->easy, CURLOPT_TIMEOUT_MS, 200L)); |
278 | 17.1k | FTRY(curl_easy_setopt(fuzz->easy, CURLOPT_SERVER_RESPONSE_TIMEOUT, 1L)); |
279 | | |
280 | | /* Can enable verbose mode by having the environment variable FUZZ_VERBOSE. */ |
281 | 17.1k | if(fuzz->verbose) { |
282 | 0 | FTRY(curl_easy_setopt(fuzz->easy, CURLOPT_VERBOSE, 1L)); |
283 | 0 | } |
284 | | |
285 | | /* Force resolution of all addresses to a specific IP address. */ |
286 | 17.1k | fuzz->connect_to_list = curl_slist_append(NULL, "::127.0.1.127:"); |
287 | 17.1k | FTRY(curl_easy_setopt(fuzz->easy, CURLOPT_CONNECT_TO, fuzz->connect_to_list)); |
288 | | |
289 | | /* Limit the protocols in use by this fuzzer. */ |
290 | 17.1k | FTRY(fuzz_set_allowed_protocols(fuzz)); |
291 | | |
292 | 17.1k | EXIT_LABEL: |
293 | | |
294 | 17.1k | return rc; |
295 | 17.1k | } |
296 | | |
297 | | /** |
298 | | * Terminate the fuzz data structure, including freeing any allocated memory. |
299 | | */ |
300 | | void fuzz_terminate_fuzz_data(FUZZ_DATA *fuzz) |
301 | 19.1k | { |
302 | 19.1k | int ii; |
303 | | |
304 | 19.1k | fuzz_free((void **)&fuzz->postfields); |
305 | | |
306 | 57.5k | for(ii = 0; ii < FUZZ_NUM_CONNECTIONS; ii++) { |
307 | 38.3k | if(fuzz->sockman[ii].fd_state != FUZZ_SOCK_CLOSED) { |
308 | 11.4k | close(fuzz->sockman[ii].fd); |
309 | 11.4k | fuzz->sockman[ii].fd_state = FUZZ_SOCK_CLOSED; |
310 | 11.4k | } |
311 | 38.3k | } |
312 | | |
313 | 19.1k | if(fuzz->connect_to_list != NULL) { |
314 | 17.1k | curl_slist_free_all(fuzz->connect_to_list); |
315 | 17.1k | fuzz->connect_to_list = NULL; |
316 | 17.1k | } |
317 | | |
318 | 19.1k | if(fuzz->header_list != NULL) { |
319 | 1.43k | curl_slist_free_all(fuzz->header_list); |
320 | 1.43k | fuzz->header_list = NULL; |
321 | 1.43k | } |
322 | | |
323 | 19.1k | if(fuzz->mail_recipients_list != NULL) { |
324 | 138 | curl_slist_free_all(fuzz->mail_recipients_list); |
325 | 138 | fuzz->mail_recipients_list = NULL; |
326 | 138 | } |
327 | | |
328 | 19.1k | if(fuzz->mime != NULL) { |
329 | 490 | curl_mime_free(fuzz->mime); |
330 | 490 | fuzz->mime = NULL; |
331 | 490 | } |
332 | | |
333 | 19.1k | if(fuzz->easy != NULL) { |
334 | 19.1k | curl_easy_cleanup(fuzz->easy); |
335 | 19.1k | fuzz->easy = NULL; |
336 | 19.1k | } |
337 | | |
338 | | /* When you have passed the struct curl_httppost pointer to curl_easy_setopt |
339 | | * (using the CURLOPT_HTTPPOST option), you must not free the list until after |
340 | | * you have called curl_easy_cleanup for the curl handle. |
341 | | * https://curl.se/libcurl/c/curl_formadd.html */ |
342 | 19.1k | if (fuzz->httppost != NULL) { |
343 | 183 | curl_formfree(fuzz->httppost); |
344 | 183 | fuzz->httppost = NULL; |
345 | 183 | } |
346 | | |
347 | | // free after httppost and last_post_part. |
348 | 19.1k | if (fuzz->post_body != NULL) { |
349 | 183 | fuzz_free((void **)&fuzz->post_body); |
350 | 183 | } |
351 | 19.1k | } |
352 | | |
353 | | /** |
354 | | * If a pointer has been allocated, free that pointer. |
355 | | */ |
356 | | void fuzz_free(void **ptr) |
357 | 117k | { |
358 | 117k | if(*ptr != NULL) { |
359 | 60.4k | free(*ptr); |
360 | 60.4k | *ptr = NULL; |
361 | 60.4k | } |
362 | 117k | } |
363 | | |
364 | | /** |
365 | | * Function for handling the fuzz transfer, including sending responses to |
366 | | * requests. |
367 | | */ |
368 | | int fuzz_handle_transfer(FUZZ_DATA *fuzz) |
369 | 17.1k | { |
370 | 17.1k | int rc = 0; |
371 | 17.1k | CURLM *multi_handle; |
372 | 17.1k | int still_running; /* keep number of running handles */ |
373 | 17.1k | CURLMsg *msg; /* for picking up messages with the transfer status */ |
374 | 17.1k | int msgs_left; /* how many messages are left */ |
375 | 17.1k | int double_timeout = 0; |
376 | 17.1k | fd_set fdread; |
377 | 17.1k | fd_set fdwrite; |
378 | 17.1k | fd_set fdexcep; |
379 | 17.1k | struct timeval timeout; |
380 | 17.1k | int select_rc; |
381 | 17.1k | CURLMcode mc; |
382 | 17.1k | int maxfd = -1; |
383 | 17.1k | long curl_timeo = -1; |
384 | 17.1k | int ii; |
385 | 17.1k | FUZZ_SOCKET_MANAGER *sman[FUZZ_NUM_CONNECTIONS]; |
386 | | |
387 | 51.5k | for(ii = 0; ii < FUZZ_NUM_CONNECTIONS; ii++) { |
388 | 34.3k | sman[ii] = &fuzz->sockman[ii]; |
389 | | |
390 | | /* Set up the starting index for responses. */ |
391 | 34.3k | sman[ii]->response_index = 1; |
392 | 34.3k | } |
393 | | |
394 | | /* init a multi stack */ |
395 | 17.1k | multi_handle = curl_multi_init(); |
396 | | |
397 | | /* add the individual transfers */ |
398 | 17.1k | curl_multi_add_handle(multi_handle, fuzz->easy); |
399 | | |
400 | | /* Do an initial process. This might end the transfer immediately. */ |
401 | 17.1k | curl_multi_perform(multi_handle, &still_running); |
402 | 17.1k | FV_PRINTF(fuzz, |
403 | 17.1k | "FUZZ: Initial perform; still running? %d \n", |
404 | 17.1k | still_running); |
405 | | |
406 | 23.2k | while(still_running) { |
407 | | /* Reset the sets of file descriptors. */ |
408 | 6.38k | FD_ZERO(&fdread); |
409 | 6.38k | FD_ZERO(&fdwrite); |
410 | 6.38k | FD_ZERO(&fdexcep); |
411 | | |
412 | | /* Set a timeout of 10ms. This is lower than recommended by the multi guide |
413 | | but we're not going to any remote servers, so everything should complete |
414 | | very quickly. */ |
415 | 6.38k | timeout.tv_sec = 0; |
416 | 6.38k | timeout.tv_usec = 10000; |
417 | | |
418 | | /* get file descriptors from the transfers */ |
419 | 6.38k | mc = curl_multi_fdset(multi_handle, &fdread, &fdwrite, &fdexcep, &maxfd); |
420 | 6.38k | if(mc != CURLM_OK) { |
421 | 0 | fprintf(stderr, "curl_multi_fdset() failed, code %d.\n", mc); |
422 | 0 | rc = -1; |
423 | 0 | break; |
424 | 0 | } |
425 | | |
426 | 19.1k | for(ii = 0; ii < FUZZ_NUM_CONNECTIONS; ii++) { |
427 | | /* Add the socket FD into the readable set if connected. */ |
428 | 12.7k | if(sman[ii]->fd_state == FUZZ_SOCK_OPEN) { |
429 | 5.47k | FD_SET(sman[ii]->fd, &fdread); |
430 | | |
431 | | /* Work out the maximum FD between the cURL file descriptors and the |
432 | | server FD. */ |
433 | 5.47k | maxfd = FUZZ_MAX(sman[ii]->fd, maxfd); |
434 | 5.47k | } |
435 | 12.7k | } |
436 | | |
437 | | /* Work out what file descriptors need work. */ |
438 | 6.38k | rc = fuzz_select(maxfd + 1, &fdread, &fdwrite, &fdexcep, &timeout); |
439 | | |
440 | 6.38k | if(rc == -1) { |
441 | | /* Had an issue while selecting a file descriptor. Let's just exit. */ |
442 | 0 | FV_PRINTF(fuzz, "FUZZ: select failed, exiting \n"); |
443 | 0 | break; |
444 | 0 | } |
445 | | |
446 | | /* Check to see if a server file descriptor is readable. If it is, |
447 | | then send the next response from the fuzzing data. */ |
448 | 6.38k | int server_data_sent = 0; |
449 | 19.0k | for(ii = 0; ii < FUZZ_NUM_CONNECTIONS; ii++) { |
450 | 12.7k | if(sman[ii]->fd_state == FUZZ_SOCK_OPEN && |
451 | 12.7k | FD_ISSET(sman[ii]->fd, &fdread)) { |
452 | 5.11k | rc = fuzz_send_next_response(fuzz, sman[ii]); |
453 | 5.11k | if(rc != 0) { |
454 | | /* Failed to send a response. Break out here. */ |
455 | 61 | break; |
456 | 61 | } |
457 | 5.04k | server_data_sent = 1; |
458 | 5.04k | } |
459 | 12.7k | } |
460 | | |
461 | | /* Stall detection: exit after two consecutive iterations where no new |
462 | | data was provided to curl. This handles both select() timeouts and |
463 | | cases where curl registers a writable fd but cannot make progress |
464 | | (e.g. HTTP/2 egress stuck with no real peer to drain to). */ |
465 | 6.38k | if(!server_data_sent) { |
466 | 1.33k | FV_PRINTF(fuzz, "FUZZ: No data sent; stall count %d \n", double_timeout); |
467 | 1.33k | if(double_timeout == 1) { |
468 | 351 | break; |
469 | 351 | } |
470 | 985 | double_timeout = 1; |
471 | 985 | } |
472 | 5.04k | else { |
473 | 5.04k | double_timeout = 0; |
474 | 5.04k | } |
475 | | |
476 | 6.03k | curl_multi_perform(multi_handle, &still_running); |
477 | 6.03k | } |
478 | | |
479 | | /* Remove the easy handle from the multi stack. */ |
480 | 17.1k | curl_multi_remove_handle(multi_handle, fuzz->easy); |
481 | | |
482 | | /* Clean up the multi handle - the top level function will handle the easy |
483 | | handle. */ |
484 | 17.1k | curl_multi_cleanup(multi_handle); |
485 | | |
486 | 17.1k | return rc; |
487 | 17.1k | } |
488 | | |
489 | | /** |
490 | | * Sends the next fuzzing response to the server file descriptor. |
491 | | */ |
492 | | int fuzz_send_next_response(FUZZ_DATA *fuzz, FUZZ_SOCKET_MANAGER *sman) |
493 | 5.11k | { |
494 | 5.11k | int rc = 0; |
495 | 5.11k | ssize_t ret_in; |
496 | 5.11k | ssize_t ret_out; |
497 | 5.11k | char buffer[8192]; |
498 | 5.11k | const uint8_t *data; |
499 | 5.11k | size_t data_len; |
500 | | |
501 | | /* Need to read all data sent by the client so the file descriptor becomes |
502 | | unreadable. Because the file descriptor is non-blocking we won't just |
503 | | hang here. */ |
504 | 11.2k | do { |
505 | 11.2k | ret_in = read(sman->fd, buffer, sizeof(buffer)); |
506 | 11.2k | if(fuzz->verbose && ret_in > 0) { |
507 | 0 | printf("FUZZ[%d]: Received %zu bytes \n==>\n", sman->index, ret_in); |
508 | 0 | fwrite(buffer, ret_in, 1, stdout); |
509 | 0 | printf("\n<==\n"); |
510 | 0 | } |
511 | 11.2k | } while (ret_in > 0); |
512 | | |
513 | | /* Now send a response to the request that the client just made. */ |
514 | 5.11k | FV_PRINTF(fuzz, |
515 | 5.11k | "FUZZ[%d]: Sending next response: %d \n", |
516 | 5.11k | sman->index, |
517 | 5.11k | sman->response_index); |
518 | 5.11k | data = sman->responses[sman->response_index].data; |
519 | 5.11k | data_len = sman->responses[sman->response_index].data_len; |
520 | | |
521 | 5.11k | if(data != NULL) { |
522 | 5.11k | if(write(sman->fd, data, data_len) != (ssize_t)data_len) { |
523 | | /* Failed to write the data back to the client. Prevent any further |
524 | | testing. */ |
525 | 61 | rc = -1; |
526 | 61 | } |
527 | 5.11k | } |
528 | | |
529 | | /* Work out if there are any more responses. If not, then shut down the |
530 | | server. */ |
531 | 5.11k | sman->response_index++; |
532 | | |
533 | 5.11k | if(sman->response_index >= TLV_MAX_NUM_RESPONSES || |
534 | 5.11k | sman->responses[sman->response_index].data == NULL) { |
535 | 4.59k | FV_PRINTF(fuzz, |
536 | 4.59k | "FUZZ[%d]: Shutting down server socket: %d \n", |
537 | 4.59k | sman->index, |
538 | 4.59k | sman->fd); |
539 | 4.59k | shutdown(sman->fd, SHUT_WR); |
540 | 4.59k | sman->fd_state = FUZZ_SOCK_SHUTDOWN; |
541 | 4.59k | } |
542 | | |
543 | 5.11k | return rc; |
544 | 5.11k | } |
545 | | |
546 | | /** |
547 | | * Wrapper for select() so profiling can track it. |
548 | | */ |
549 | | int fuzz_select(int nfds, |
550 | | fd_set *readfds, |
551 | | fd_set *writefds, |
552 | | fd_set *exceptfds, |
553 | 6.38k | struct timeval *timeout) { |
554 | 6.38k | return select(nfds, readfds, writefds, exceptfds, timeout); |
555 | 6.38k | } |
556 | | |
557 | | /** |
558 | | * Set allowed protocols based on the compile options. |
559 | | * |
560 | | * Note that it can only use ONE of the FUZZ_PROTOCOLS_* defines. |
561 | | */ |
562 | | int fuzz_set_allowed_protocols(FUZZ_DATA *fuzz) |
563 | 17.1k | { |
564 | 17.1k | int rc = 0; |
565 | 17.1k | const char *allowed_protocols = ""; |
566 | | |
567 | | #ifdef FUZZ_PROTOCOLS_ALL |
568 | | /* CURLOPT_PROTOCOLS_STR rejects the complete value if even one requested |
569 | | protocol was compiled out. Derive the generic target's stable safety |
570 | | policy from this libcurl build so optional RTMP and SSH backends cannot |
571 | | prevent every transfer from starting. */ |
572 | | allowed_protocols = legacy_protocol_allowlist::ForCurrentCurl().c_str(); |
573 | | #endif |
574 | | #ifdef FUZZ_PROTOCOLS_DICT |
575 | | allowed_protocols = "dict"; |
576 | | #endif |
577 | | #ifdef FUZZ_PROTOCOLS_FILE |
578 | | allowed_protocols = "file"; |
579 | | #endif |
580 | | #ifdef FUZZ_PROTOCOLS_FTP |
581 | | allowed_protocols = "ftp,ftps"; |
582 | | #endif |
583 | | #ifdef FUZZ_PROTOCOLS_GOPHER |
584 | | allowed_protocols = "gopher,gophers"; |
585 | | #endif |
586 | | #ifdef FUZZ_PROTOCOLS_HTTP |
587 | | allowed_protocols = "http"; |
588 | | #endif |
589 | | #ifdef FUZZ_PROTOCOLS_HTTPS |
590 | | allowed_protocols = "https"; |
591 | | #endif |
592 | | #ifdef FUZZ_PROTOCOLS_IMAP |
593 | | allowed_protocols = "imap,imaps"; |
594 | | #endif |
595 | | #ifdef FUZZ_PROTOCOLS_LDAP |
596 | | allowed_protocols = "ldap,ldaps"; |
597 | | #endif |
598 | | #ifdef FUZZ_PROTOCOLS_MQTT |
599 | | allowed_protocols = "mqtt"; |
600 | | #endif |
601 | | #ifdef FUZZ_PROTOCOLS_POP3 |
602 | | allowed_protocols = "pop3,pop3s"; |
603 | | #endif |
604 | | #ifdef FUZZ_PROTOCOLS_RTMP |
605 | | allowed_protocols = "rtmp,rtmpe,rtmps,rtmpt,rtmpte,rtmpts"; |
606 | | #endif |
607 | 17.1k | #ifdef FUZZ_PROTOCOLS_RTSP |
608 | 17.1k | allowed_protocols = "rtsp"; |
609 | 17.1k | #endif |
610 | | #ifdef FUZZ_PROTOCOLS_SCP |
611 | | allowed_protocols = "scp"; |
612 | | #endif |
613 | | #ifdef FUZZ_PROTOCOLS_SFTP |
614 | | allowed_protocols = "sftp"; |
615 | | #endif |
616 | | #ifdef FUZZ_PROTOCOLS_SMB |
617 | | allowed_protocols = "smb,smbs"; |
618 | | #endif |
619 | | #ifdef FUZZ_PROTOCOLS_SMTP |
620 | | allowed_protocols = "smtp,smtps"; |
621 | | #endif |
622 | | #ifdef FUZZ_PROTOCOLS_TFTP |
623 | | allowed_protocols = "tftp"; |
624 | | #endif |
625 | | #ifdef FUZZ_PROTOCOLS_WS |
626 | | // http is required by websockets |
627 | | allowed_protocols = "http,ws,wss"; |
628 | | FTRY(curl_easy_setopt(fuzz->easy, CURLOPT_CONNECT_ONLY, 2L)); |
629 | | #endif |
630 | | |
631 | 17.1k | FTRY(curl_easy_setopt(fuzz->easy, CURLOPT_PROTOCOLS_STR, allowed_protocols)); |
632 | | |
633 | 17.1k | EXIT_LABEL: |
634 | | |
635 | 17.1k | return rc; |
636 | 17.1k | } |