/src/samba/lib/fuzzing/fuzz_ldap_decode.c
Line | Count | Source |
1 | | /* |
2 | | Fuzzing for ldap_decode. |
3 | | Copyright (C) Michael Hanselmann 2019 |
4 | | |
5 | | This program is free software; you can redistribute it and/or modify |
6 | | it under the terms of the GNU General Public License as published by |
7 | | the Free Software Foundation; either version 3 of the License, or |
8 | | (at your option) any later version. |
9 | | |
10 | | This program is distributed in the hope that it will be useful, |
11 | | but WITHOUT ANY WARRANTY; without even the implied warranty of |
12 | | MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the |
13 | | GNU General Public License for more details. |
14 | | |
15 | | You should have received a copy of the GNU General Public License |
16 | | along with this program. If not, see <http://www.gnu.org/licenses/>. |
17 | | */ |
18 | | |
19 | | #include "includes.h" |
20 | | #include "fuzzing/fuzzing.h" |
21 | | #include "lib/util/asn1.h" |
22 | | #include "libcli/ldap/ldap_message.h" |
23 | | #include "libcli/ldap/ldap_proto.h" |
24 | | |
25 | | int LLVMFuzzerInitialize(int *argc, char ***argv) |
26 | 376 | { |
27 | 376 | return 0; |
28 | 376 | } |
29 | | |
30 | | int LLVMFuzzerTestOneInput(const uint8_t *buf, size_t len) |
31 | 2.47k | { |
32 | 2.47k | TALLOC_CTX *mem_ctx = talloc_init(__FUNCTION__); |
33 | 2.47k | struct asn1_data *asn1; |
34 | 2.47k | struct ldap_message *ldap_msg; |
35 | 2.47k | struct ldap_request_limits limits = { |
36 | | /* |
37 | | * The default size is currently 256000 bytes |
38 | | */ |
39 | 2.47k | .max_search_size = 256000 |
40 | 2.47k | }; |
41 | 2.47k | NTSTATUS status; |
42 | | |
43 | | /* |
44 | | * Need to limit the max parse tree depth to 250 to prevent |
45 | | * ASAN detecting stack overflows. |
46 | | */ |
47 | 2.47k | asn1 = asn1_init(mem_ctx, 250); |
48 | 2.47k | if (!asn1) { |
49 | 0 | goto out; |
50 | 0 | } |
51 | | |
52 | 2.47k | asn1_load_nocopy(asn1, buf, len); |
53 | | |
54 | 2.47k | ldap_msg = talloc(mem_ctx, struct ldap_message); |
55 | 2.47k | if (!ldap_msg) { |
56 | 0 | goto out; |
57 | 0 | } |
58 | | |
59 | 2.47k | status = ldap_decode( |
60 | 2.47k | asn1, &limits, samba_ldap_control_handlers(), ldap_msg); |
61 | | |
62 | 2.47k | out: |
63 | 2.47k | talloc_free(mem_ctx); |
64 | | |
65 | 2.47k | return 0; |
66 | 2.47k | } |