Coverage Report

Created: 2026-08-13 06:49

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/librabbitmq/fuzz/fuzz_codec.c
Line
Count
Source
1
// Copyright 2007 - 2026, Arthur Chan and the rabbitmq-c contributors.
2
// SPDX-License-Identifier: mit
3
4
#include <stdint.h>
5
#include <stdlib.h>
6
#include <string.h>
7
8
#include <rabbitmq-c/amqp.h>
9
#include <rabbitmq-c/framing.h>
10
11
// Round-trips the AMQP codecs. The existing fuzzers only decode; the generated
12
// serializers (amqp_encode_method/properties/table) and amqp_table_clone are
13
// unreachable from hand-written input. Each mode decodes attacker bytes into the
14
// in-memory struct, then re-encodes/clones it -- the decoder supplies the
15
// adversarial-but-valid structs the encoders would otherwise never see.
16
17
7.05k
#define ENC_BUF_SIZE (1u << 20)
18
19
4.20k
static void roundtrip_method(const uint8_t *p, size_t n) {
20
4.20k
  amqp_pool_t pool;
21
4.20k
  void *decoded = NULL;
22
4.20k
  amqp_method_number_t method_id;
23
4.20k
  amqp_bytes_t encoded;
24
25
4.20k
  if (n < 4) {
26
4
    return;
27
4
  }
28
4.20k
  method_id = ((amqp_method_number_t)p[0] << 24) |
29
4.20k
              ((amqp_method_number_t)p[1] << 16) |
30
4.20k
              ((amqp_method_number_t)p[2] << 8) | (amqp_method_number_t)p[3];
31
4.20k
  encoded.len = n - 4;
32
4.20k
  encoded.bytes = (void *)(p + 4);
33
34
4.20k
  init_amqp_pool(&pool, 4096);
35
4.20k
  if (amqp_decode_method(method_id, &pool, encoded, &decoded) ==
36
4.20k
          AMQP_STATUS_OK &&
37
2.23k
      decoded != NULL) {
38
2.23k
    void *buf = malloc(ENC_BUF_SIZE);
39
2.23k
    if (buf != NULL) {
40
2.23k
      amqp_bytes_t out;
41
2.23k
      out.len = ENC_BUF_SIZE;
42
2.23k
      out.bytes = buf;
43
2.23k
      amqp_encode_method(method_id, decoded, out);
44
2.23k
      free(buf);
45
2.23k
    }
46
2.23k
  }
47
4.20k
  empty_amqp_pool(&pool);
48
4.20k
}
49
50
870
static void roundtrip_properties(const uint8_t *p, size_t n) {
51
870
  amqp_pool_t pool;
52
870
  void *decoded = NULL;
53
870
  uint16_t class_id;
54
870
  amqp_bytes_t encoded;
55
56
870
  if (n < 2) {
57
2
    return;
58
2
  }
59
868
  class_id = ((uint16_t)p[0] << 8) | (uint16_t)p[1];
60
868
  encoded.len = n - 2;
61
868
  encoded.bytes = (void *)(p + 2);
62
63
868
  init_amqp_pool(&pool, 4096);
64
868
  if (amqp_decode_properties(class_id, &pool, encoded, &decoded) ==
65
868
          AMQP_STATUS_OK &&
66
562
      decoded != NULL) {
67
562
    void *buf = malloc(ENC_BUF_SIZE);
68
562
    if (buf != NULL) {
69
562
      amqp_bytes_t out;
70
562
      out.len = ENC_BUF_SIZE;
71
562
      out.bytes = buf;
72
562
      amqp_encode_properties(class_id, decoded, out);
73
562
      free(buf);
74
562
    }
75
562
  }
76
868
  empty_amqp_pool(&pool);
77
868
}
78
79
1.10k
static void roundtrip_table(const uint8_t *p, size_t n) {
80
1.10k
  amqp_pool_t pool;
81
1.10k
  amqp_table_t decoded;
82
1.10k
  amqp_bytes_t encoded;
83
1.10k
  size_t offset = 0;
84
85
1.10k
  encoded.len = n;
86
1.10k
  encoded.bytes = (void *)p;
87
88
1.10k
  init_amqp_pool(&pool, 4096);
89
1.10k
  memset(&decoded, 0, sizeof(decoded));
90
1.10k
  if (amqp_decode_table(encoded, &pool, &decoded, &offset) == AMQP_STATUS_OK) {
91
736
    void *buf = malloc(ENC_BUF_SIZE);
92
736
    if (buf != NULL) {
93
736
      amqp_bytes_t out;
94
736
      size_t out_off = 0;
95
736
      out.len = ENC_BUF_SIZE;
96
736
      out.bytes = buf;
97
736
      amqp_encode_table(out, &decoded, &out_off);
98
736
      free(buf);
99
736
    }
100
736
    {
101
736
      amqp_pool_t clone_pool;
102
736
      amqp_table_t clone;
103
736
      init_amqp_pool(&clone_pool, 4096);
104
736
      memset(&clone, 0, sizeof(clone));
105
736
      amqp_table_clone(&decoded, &clone, &clone_pool);
106
736
      empty_amqp_pool(&clone_pool);
107
736
    }
108
736
  }
109
1.10k
  empty_amqp_pool(&pool);
110
1.10k
}
111
112
// First byte selects the codec; the remainder is the payload, framed like the
113
// matching decode fuzzer (method-id / class-id prefix where applicable).
114
6.18k
extern int LLVMFuzzerTestOneInput(const char *data, size_t size) {
115
6.18k
  const uint8_t *bytes = (const uint8_t *)data;
116
117
6.18k
  if (size < 1) {
118
0
    return 0;
119
0
  }
120
6.18k
  switch (bytes[0] % 3) {
121
4.20k
    case 0:
122
4.20k
      roundtrip_method(bytes + 1, size - 1);
123
4.20k
      break;
124
870
    case 1:
125
870
      roundtrip_properties(bytes + 1, size - 1);
126
870
      break;
127
1.10k
    default:
128
1.10k
      roundtrip_table(bytes + 1, size - 1);
129
1.10k
      break;
130
6.18k
  }
131
6.18k
  return 0;
132
6.18k
}