Coverage Report

Created: 2026-08-31 06:13

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/librabbitmq/fuzz/fuzz_codec.c
Line
Count
Source
1
// Copyright 2007 - 2026, Arthur Chan and the rabbitmq-c contributors.
2
// SPDX-License-Identifier: mit
3
4
#include <stdint.h>
5
#include <stdlib.h>
6
#include <string.h>
7
8
#include <rabbitmq-c/amqp.h>
9
#include <rabbitmq-c/framing.h>
10
11
// Round-trips the AMQP codecs. The existing fuzzers only decode; the generated
12
// serializers (amqp_encode_method/properties/table) and amqp_table_clone are
13
// unreachable from hand-written input. Each mode decodes attacker bytes into the
14
// in-memory struct, then re-encodes/clones it -- the decoder supplies the
15
// adversarial-but-valid structs the encoders would otherwise never see.
16
17
7.10k
#define ENC_BUF_SIZE (1u << 20)
18
19
4.24k
static void roundtrip_method(const uint8_t *p, size_t n) {
20
4.24k
  amqp_pool_t pool;
21
4.24k
  void *decoded = NULL;
22
4.24k
  amqp_method_number_t method_id;
23
4.24k
  amqp_bytes_t encoded;
24
25
4.24k
  if (n < 4) {
26
4
    return;
27
4
  }
28
4.24k
  method_id = ((amqp_method_number_t)p[0] << 24) |
29
4.24k
              ((amqp_method_number_t)p[1] << 16) |
30
4.24k
              ((amqp_method_number_t)p[2] << 8) | (amqp_method_number_t)p[3];
31
4.24k
  encoded.len = n - 4;
32
4.24k
  encoded.bytes = (void *)(p + 4);
33
34
4.24k
  init_amqp_pool(&pool, 4096);
35
4.24k
  if (amqp_decode_method(method_id, &pool, encoded, &decoded) ==
36
4.24k
          AMQP_STATUS_OK &&
37
2.24k
      decoded != NULL) {
38
2.24k
    void *buf = malloc(ENC_BUF_SIZE);
39
2.24k
    if (buf != NULL) {
40
2.24k
      amqp_bytes_t out;
41
2.24k
      out.len = ENC_BUF_SIZE;
42
2.24k
      out.bytes = buf;
43
2.24k
      amqp_encode_method(method_id, decoded, out);
44
2.24k
      free(buf);
45
2.24k
    }
46
2.24k
  }
47
4.24k
  empty_amqp_pool(&pool);
48
4.24k
}
49
50
884
static void roundtrip_properties(const uint8_t *p, size_t n) {
51
884
  amqp_pool_t pool;
52
884
  void *decoded = NULL;
53
884
  uint16_t class_id;
54
884
  amqp_bytes_t encoded;
55
56
884
  if (n < 2) {
57
2
    return;
58
2
  }
59
882
  class_id = ((uint16_t)p[0] << 8) | (uint16_t)p[1];
60
882
  encoded.len = n - 2;
61
882
  encoded.bytes = (void *)(p + 2);
62
63
882
  init_amqp_pool(&pool, 4096);
64
882
  if (amqp_decode_properties(class_id, &pool, encoded, &decoded) ==
65
882
          AMQP_STATUS_OK &&
66
567
      decoded != NULL) {
67
567
    void *buf = malloc(ENC_BUF_SIZE);
68
567
    if (buf != NULL) {
69
567
      amqp_bytes_t out;
70
567
      out.len = ENC_BUF_SIZE;
71
567
      out.bytes = buf;
72
567
      amqp_encode_properties(class_id, decoded, out);
73
567
      free(buf);
74
567
    }
75
567
  }
76
882
  empty_amqp_pool(&pool);
77
882
}
78
79
1.10k
static void roundtrip_table(const uint8_t *p, size_t n) {
80
1.10k
  amqp_pool_t pool;
81
1.10k
  amqp_table_t decoded;
82
1.10k
  amqp_bytes_t encoded;
83
1.10k
  size_t offset = 0;
84
85
1.10k
  encoded.len = n;
86
1.10k
  encoded.bytes = (void *)p;
87
88
1.10k
  init_amqp_pool(&pool, 4096);
89
1.10k
  memset(&decoded, 0, sizeof(decoded));
90
1.10k
  if (amqp_decode_table(encoded, &pool, &decoded, &offset) == AMQP_STATUS_OK) {
91
737
    void *buf = malloc(ENC_BUF_SIZE);
92
737
    if (buf != NULL) {
93
737
      amqp_bytes_t out;
94
737
      size_t out_off = 0;
95
737
      out.len = ENC_BUF_SIZE;
96
737
      out.bytes = buf;
97
737
      amqp_encode_table(out, &decoded, &out_off);
98
737
      free(buf);
99
737
    }
100
737
    {
101
737
      amqp_pool_t clone_pool;
102
737
      amqp_table_t clone;
103
737
      init_amqp_pool(&clone_pool, 4096);
104
737
      memset(&clone, 0, sizeof(clone));
105
737
      amqp_table_clone(&decoded, &clone, &clone_pool);
106
737
      empty_amqp_pool(&clone_pool);
107
737
    }
108
737
  }
109
1.10k
  empty_amqp_pool(&pool);
110
1.10k
}
111
112
// First byte selects the codec; the remainder is the payload, framed like the
113
// matching decode fuzzer (method-id / class-id prefix where applicable).
114
6.23k
extern int LLVMFuzzerTestOneInput(const char *data, size_t size) {
115
6.23k
  const uint8_t *bytes = (const uint8_t *)data;
116
117
6.23k
  if (size < 1) {
118
0
    return 0;
119
0
  }
120
6.23k
  switch (bytes[0] % 3) {
121
4.24k
    case 0:
122
4.24k
      roundtrip_method(bytes + 1, size - 1);
123
4.24k
      break;
124
884
    case 1:
125
884
      roundtrip_properties(bytes + 1, size - 1);
126
884
      break;
127
1.10k
    default:
128
1.10k
      roundtrip_table(bytes + 1, size - 1);
129
1.10k
      break;
130
6.23k
  }
131
6.23k
  return 0;
132
6.23k
}