Coverage Report

Created: 2026-09-06 07:05

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/librabbitmq/fuzz/fuzz_codec.c
Line
Count
Source
1
// Copyright 2007 - 2026, Arthur Chan and the rabbitmq-c contributors.
2
// SPDX-License-Identifier: mit
3
4
#include <stdint.h>
5
#include <stdlib.h>
6
#include <string.h>
7
8
#include <rabbitmq-c/amqp.h>
9
#include <rabbitmq-c/framing.h>
10
11
// Round-trips the AMQP codecs. The existing fuzzers only decode; the generated
12
// serializers (amqp_encode_method/properties/table) and amqp_table_clone are
13
// unreachable from hand-written input. Each mode decodes attacker bytes into the
14
// in-memory struct, then re-encodes/clones it -- the decoder supplies the
15
// adversarial-but-valid structs the encoders would otherwise never see.
16
17
7.28k
#define ENC_BUF_SIZE (1u << 20)
18
19
4.32k
static void roundtrip_method(const uint8_t *p, size_t n) {
20
4.32k
  amqp_pool_t pool;
21
4.32k
  void *decoded = NULL;
22
4.32k
  amqp_method_number_t method_id;
23
4.32k
  amqp_bytes_t encoded;
24
25
4.32k
  if (n < 4) {
26
4
    return;
27
4
  }
28
4.32k
  method_id = ((amqp_method_number_t)p[0] << 24) |
29
4.32k
              ((amqp_method_number_t)p[1] << 16) |
30
4.32k
              ((amqp_method_number_t)p[2] << 8) | (amqp_method_number_t)p[3];
31
4.32k
  encoded.len = n - 4;
32
4.32k
  encoded.bytes = (void *)(p + 4);
33
34
4.32k
  init_amqp_pool(&pool, 4096);
35
4.32k
  if (amqp_decode_method(method_id, &pool, encoded, &decoded) ==
36
4.32k
          AMQP_STATUS_OK &&
37
2.28k
      decoded != NULL) {
38
2.28k
    void *buf = malloc(ENC_BUF_SIZE);
39
2.28k
    if (buf != NULL) {
40
2.28k
      amqp_bytes_t out;
41
2.28k
      out.len = ENC_BUF_SIZE;
42
2.28k
      out.bytes = buf;
43
2.28k
      amqp_encode_method(method_id, decoded, out);
44
2.28k
      free(buf);
45
2.28k
    }
46
2.28k
  }
47
4.32k
  empty_amqp_pool(&pool);
48
4.32k
}
49
50
912
static void roundtrip_properties(const uint8_t *p, size_t n) {
51
912
  amqp_pool_t pool;
52
912
  void *decoded = NULL;
53
912
  uint16_t class_id;
54
912
  amqp_bytes_t encoded;
55
56
912
  if (n < 2) {
57
2
    return;
58
2
  }
59
910
  class_id = ((uint16_t)p[0] << 8) | (uint16_t)p[1];
60
910
  encoded.len = n - 2;
61
910
  encoded.bytes = (void *)(p + 2);
62
63
910
  init_amqp_pool(&pool, 4096);
64
910
  if (amqp_decode_properties(class_id, &pool, encoded, &decoded) ==
65
910
          AMQP_STATUS_OK &&
66
594
      decoded != NULL) {
67
594
    void *buf = malloc(ENC_BUF_SIZE);
68
594
    if (buf != NULL) {
69
594
      amqp_bytes_t out;
70
594
      out.len = ENC_BUF_SIZE;
71
594
      out.bytes = buf;
72
594
      amqp_encode_properties(class_id, decoded, out);
73
594
      free(buf);
74
594
    }
75
594
  }
76
910
  empty_amqp_pool(&pool);
77
910
}
78
79
1.12k
static void roundtrip_table(const uint8_t *p, size_t n) {
80
1.12k
  amqp_pool_t pool;
81
1.12k
  amqp_table_t decoded;
82
1.12k
  amqp_bytes_t encoded;
83
1.12k
  size_t offset = 0;
84
85
1.12k
  encoded.len = n;
86
1.12k
  encoded.bytes = (void *)p;
87
88
1.12k
  init_amqp_pool(&pool, 4096);
89
1.12k
  memset(&decoded, 0, sizeof(decoded));
90
1.12k
  if (amqp_decode_table(encoded, &pool, &decoded, &offset) == AMQP_STATUS_OK) {
91
759
    void *buf = malloc(ENC_BUF_SIZE);
92
759
    if (buf != NULL) {
93
759
      amqp_bytes_t out;
94
759
      size_t out_off = 0;
95
759
      out.len = ENC_BUF_SIZE;
96
759
      out.bytes = buf;
97
759
      amqp_encode_table(out, &decoded, &out_off);
98
759
      free(buf);
99
759
    }
100
759
    {
101
759
      amqp_pool_t clone_pool;
102
759
      amqp_table_t clone;
103
759
      init_amqp_pool(&clone_pool, 4096);
104
759
      memset(&clone, 0, sizeof(clone));
105
759
      amqp_table_clone(&decoded, &clone, &clone_pool);
106
759
      empty_amqp_pool(&clone_pool);
107
759
    }
108
759
  }
109
1.12k
  empty_amqp_pool(&pool);
110
1.12k
}
111
112
// First byte selects the codec; the remainder is the payload, framed like the
113
// matching decode fuzzer (method-id / class-id prefix where applicable).
114
6.36k
extern int LLVMFuzzerTestOneInput(const char *data, size_t size) {
115
6.36k
  const uint8_t *bytes = (const uint8_t *)data;
116
117
6.36k
  if (size < 1) {
118
0
    return 0;
119
0
  }
120
6.36k
  switch (bytes[0] % 3) {
121
4.32k
    case 0:
122
4.32k
      roundtrip_method(bytes + 1, size - 1);
123
4.32k
      break;
124
912
    case 1:
125
912
      roundtrip_properties(bytes + 1, size - 1);
126
912
      break;
127
1.12k
    default:
128
1.12k
      roundtrip_table(bytes + 1, size - 1);
129
1.12k
      break;
130
6.36k
  }
131
6.36k
  return 0;
132
6.36k
}