Coverage Report

Created: 2026-09-14 06:02

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/librabbitmq/fuzz/fuzz_codec.c
Line
Count
Source
1
// Copyright 2007 - 2026, Arthur Chan and the rabbitmq-c contributors.
2
// SPDX-License-Identifier: mit
3
4
#include <stdint.h>
5
#include <stdlib.h>
6
#include <string.h>
7
8
#include <rabbitmq-c/amqp.h>
9
#include <rabbitmq-c/framing.h>
10
11
// Round-trips the AMQP codecs. The existing fuzzers only decode; the generated
12
// serializers (amqp_encode_method/properties/table) and amqp_table_clone are
13
// unreachable from hand-written input. Each mode decodes attacker bytes into the
14
// in-memory struct, then re-encodes/clones it -- the decoder supplies the
15
// adversarial-but-valid structs the encoders would otherwise never see.
16
17
7.27k
#define ENC_BUF_SIZE (1u << 20)
18
19
4.31k
static void roundtrip_method(const uint8_t *p, size_t n) {
20
4.31k
  amqp_pool_t pool;
21
4.31k
  void *decoded = NULL;
22
4.31k
  amqp_method_number_t method_id;
23
4.31k
  amqp_bytes_t encoded;
24
25
4.31k
  if (n < 4) {
26
4
    return;
27
4
  }
28
4.31k
  method_id = ((amqp_method_number_t)p[0] << 24) |
29
4.31k
              ((amqp_method_number_t)p[1] << 16) |
30
4.31k
              ((amqp_method_number_t)p[2] << 8) | (amqp_method_number_t)p[3];
31
4.31k
  encoded.len = n - 4;
32
4.31k
  encoded.bytes = (void *)(p + 4);
33
34
4.31k
  init_amqp_pool(&pool, 4096);
35
4.31k
  if (amqp_decode_method(method_id, &pool, encoded, &decoded) ==
36
4.31k
          AMQP_STATUS_OK &&
37
2.29k
      decoded != NULL) {
38
2.29k
    void *buf = malloc(ENC_BUF_SIZE);
39
2.29k
    if (buf != NULL) {
40
2.29k
      amqp_bytes_t out;
41
2.29k
      out.len = ENC_BUF_SIZE;
42
2.29k
      out.bytes = buf;
43
2.29k
      amqp_encode_method(method_id, decoded, out);
44
2.29k
      free(buf);
45
2.29k
    }
46
2.29k
  }
47
4.31k
  empty_amqp_pool(&pool);
48
4.31k
}
49
50
901
static void roundtrip_properties(const uint8_t *p, size_t n) {
51
901
  amqp_pool_t pool;
52
901
  void *decoded = NULL;
53
901
  uint16_t class_id;
54
901
  amqp_bytes_t encoded;
55
56
901
  if (n < 2) {
57
2
    return;
58
2
  }
59
899
  class_id = ((uint16_t)p[0] << 8) | (uint16_t)p[1];
60
899
  encoded.len = n - 2;
61
899
  encoded.bytes = (void *)(p + 2);
62
63
899
  init_amqp_pool(&pool, 4096);
64
899
  if (amqp_decode_properties(class_id, &pool, encoded, &decoded) ==
65
899
          AMQP_STATUS_OK &&
66
588
      decoded != NULL) {
67
588
    void *buf = malloc(ENC_BUF_SIZE);
68
588
    if (buf != NULL) {
69
588
      amqp_bytes_t out;
70
588
      out.len = ENC_BUF_SIZE;
71
588
      out.bytes = buf;
72
588
      amqp_encode_properties(class_id, decoded, out);
73
588
      free(buf);
74
588
    }
75
588
  }
76
899
  empty_amqp_pool(&pool);
77
899
}
78
79
1.12k
static void roundtrip_table(const uint8_t *p, size_t n) {
80
1.12k
  amqp_pool_t pool;
81
1.12k
  amqp_table_t decoded;
82
1.12k
  amqp_bytes_t encoded;
83
1.12k
  size_t offset = 0;
84
85
1.12k
  encoded.len = n;
86
1.12k
  encoded.bytes = (void *)p;
87
88
1.12k
  init_amqp_pool(&pool, 4096);
89
1.12k
  memset(&decoded, 0, sizeof(decoded));
90
1.12k
  if (amqp_decode_table(encoded, &pool, &decoded, &offset) == AMQP_STATUS_OK) {
91
757
    void *buf = malloc(ENC_BUF_SIZE);
92
757
    if (buf != NULL) {
93
757
      amqp_bytes_t out;
94
757
      size_t out_off = 0;
95
757
      out.len = ENC_BUF_SIZE;
96
757
      out.bytes = buf;
97
757
      amqp_encode_table(out, &decoded, &out_off);
98
757
      free(buf);
99
757
    }
100
757
    {
101
757
      amqp_pool_t clone_pool;
102
757
      amqp_table_t clone;
103
757
      init_amqp_pool(&clone_pool, 4096);
104
757
      memset(&clone, 0, sizeof(clone));
105
757
      amqp_table_clone(&decoded, &clone, &clone_pool);
106
757
      empty_amqp_pool(&clone_pool);
107
757
    }
108
757
  }
109
1.12k
  empty_amqp_pool(&pool);
110
1.12k
}
111
112
// First byte selects the codec; the remainder is the payload, framed like the
113
// matching decode fuzzer (method-id / class-id prefix where applicable).
114
6.34k
extern int LLVMFuzzerTestOneInput(const char *data, size_t size) {
115
6.34k
  const uint8_t *bytes = (const uint8_t *)data;
116
117
6.34k
  if (size < 1) {
118
0
    return 0;
119
0
  }
120
6.34k
  switch (bytes[0] % 3) {
121
4.31k
    case 0:
122
4.31k
      roundtrip_method(bytes + 1, size - 1);
123
4.31k
      break;
124
901
    case 1:
125
901
      roundtrip_properties(bytes + 1, size - 1);
126
901
      break;
127
1.12k
    default:
128
1.12k
      roundtrip_table(bytes + 1, size - 1);
129
1.12k
      break;
130
6.34k
  }
131
6.34k
  return 0;
132
6.34k
}