Coverage Report

Created: 2026-09-28 06:52

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/wireshark/fuzz/fuzzshark.c
Line
Count
Source
1
/* fuzzshark.c
2
 *
3
 * Fuzzer variant of Wireshark for oss-fuzz
4
 *
5
 * Wireshark - Network traffic analyzer
6
 * By Gerald Combs <gerald@wireshark.org>
7
 * Copyright 1998 Gerald Combs
8
 *
9
 * SPDX-License-Identifier: GPL-2.0-or-later
10
 */
11
12
#include <config.h>
13
0
#define WS_LOG_DOMAIN  LOG_DOMAIN_MAIN
14
15
#include <stdlib.h>
16
#include <stdio.h>
17
#include <string.h>
18
#include <limits.h>
19
20
#include <glib.h>
21
22
#include <epan/epan.h>
23
24
#include <wsutil/cmdarg_err.h>
25
#include <ui/failure_message.h>
26
#include <wsutil/filesystem.h>
27
#include <app/application_flavor.h>
28
#include <wsutil/privileges.h>
29
#include <wsutil/clopts_common.h>
30
#include <wsutil/ws_getopt.h>
31
#include <wsutil/wslog.h>
32
#include <wsutil/version_info.h>
33
34
#include <wiretap/wtap.h>
35
36
#include <epan/color_filters.h>
37
#include <epan/timestamp.h>
38
#include <epan/prefs.h>
39
#include <epan/column.h>
40
#include <epan/column-info.h>
41
#include <epan/print.h>
42
#include <epan/epan_dissect.h>
43
#include <epan/disabled_protos.h>
44
45
#ifdef HAVE_PLUGINS
46
#include <wsutil/plugins.h>
47
#endif
48
49
#include "FuzzerInterface.h"
50
51
0
#define EPAN_INIT_FAIL 2
52
53
static column_info fuzz_cinfo;
54
static epan_t *fuzz_epan;
55
static epan_dissect_t *fuzz_edt;
56
57
static int
58
fuzzshark_pref_set(const char *name, const char *value)
59
64
{
60
64
  char pref[4096];
61
64
  char *errmsg = NULL;
62
63
64
  prefs_set_pref_e ret;
64
65
64
  snprintf(pref, sizeof(pref), "%s:%s", name, value);
66
67
64
  ret = prefs_set_pref(pref, &errmsg);
68
64
  g_free(errmsg);
69
70
64
  return (ret == PREFS_SET_OK);
71
64
}
72
73
static const nstime_t *
74
fuzzshark_get_frame_ts(struct packet_provider_data *prov _U_, uint32_t frame_num _U_)
75
439k
{
76
439k
  static nstime_t empty;
77
78
439k
  return &empty;
79
439k
}
80
81
static epan_t *
82
fuzzshark_epan_new(void)
83
16
{
84
16
  static const struct packet_provider_funcs funcs = {
85
16
    fuzzshark_get_frame_ts,
86
16
    NULL,
87
16
    NULL,
88
16
    NULL,
89
16
    NULL,
90
16
    NULL,
91
16
    NULL,
92
16
    NULL,
93
16
    NULL,
94
16
    NULL,
95
16
    NULL,
96
16
    NULL,
97
16
    NULL,
98
16
    NULL,
99
16
    NULL,
100
16
    NULL,
101
16
  };
102
103
16
  return epan_new(NULL, &funcs);
104
16
}
105
106
static dissector_handle_t
107
get_dissector_handle(const char *table, const char *target)
108
16
{
109
16
  dissector_handle_t fuzz_handle = NULL;
110
111
16
  if (table != NULL && target != NULL)
112
12
  {
113
    /* search for handle, cannot use dissector_table_get_dissector_handle() cause it's using short-name, and I already used filter name in samples ;/ */
114
12
    GSList *handle_list = dissector_table_get_dissector_handles(find_dissector_table(table));
115
2.75k
    while (handle_list)
116
2.73k
    {
117
2.73k
      dissector_handle_t handle = (dissector_handle_t) handle_list->data;
118
2.73k
      const char *handle_filter_name = proto_get_protocol_filter_name(dissector_handle_get_protocol_index(handle));
119
120
2.73k
      if (!strcmp(handle_filter_name, target))
121
12
        fuzz_handle = handle;
122
2.73k
      handle_list = handle_list->next;
123
2.73k
    }
124
12
  }
125
4
  else if (target != NULL)
126
4
  {
127
4
    fuzz_handle = find_dissector(target);
128
4
  }
129
130
16
  return fuzz_handle;
131
16
}
132
133
static void
134
fuzz_prefs_apply(void)
135
16
{
136
  /* Turn off fragmentation for some protocols */
137
16
  fuzzshark_pref_set("ip.defragment", "FALSE");
138
16
  fuzzshark_pref_set("ipv6.defragment", "FALSE");
139
16
  fuzzshark_pref_set("wlan.defragment", "FALSE");
140
16
  fuzzshark_pref_set("tcp.desegment_tcp_streams", "FALSE");
141
142
  /* Notify all registered modules that have had any of their preferences changed. */
143
16
  prefs_apply_all();
144
16
}
145
146
static int
147
fuzz_init(int argc, char **argv)
148
16
{
149
16
  char                *configuration_init_error;
150
151
152
16
  char                *err_msg = NULL;
153
16
  e_prefs             *prefs_p;
154
16
  int                  ret = EXIT_SUCCESS;
155
16
  size_t               i;
156
16
  static const struct ws_option long_options[] = {
157
16
    LONGOPT_WSLOG
158
16
    {0, 0, 0, 0 }
159
16
  };
160
16
  const struct file_extension_info* file_extensions;
161
16
  unsigned num_extensions;
162
16
  epan_app_data_t app_data;
163
164
  /* Future proof by zeroing out all data */
165
16
  memset(&app_data, 0, sizeof(app_data));
166
167
16
  const char *fuzz_target =
168
16
#if defined(FUZZ_DISSECTOR_TARGET)
169
16
    FUZZ_DISSECTOR_TARGET;
170
#else
171
    getenv("FUZZSHARK_TARGET");
172
#endif
173
174
16
  const char *disabled_dissector_list[] =
175
16
  {
176
16
#ifdef FUZZ_DISSECTOR_LIST
177
16
    FUZZ_DISSECTOR_LIST ,
178
16
#endif
179
16
    "snort"
180
16
  };
181
182
#if !defined(FUZZ_DISSECTOR_TABLE) && !defined(FUZZ_DISSECTOR_TARGET)
183
  const char *fuzz_table = getenv("FUZZSHARK_TABLE");
184
185
  /*
186
   * Set the program name.
187
   *
188
   * XXX - yes, this isn't main(), but it still needs to be
189
   * set, as many Wireshark library routines depend on it
190
   * being set.
191
   */
192
  g_set_prgname("oss-fuzzshark");
193
194
  if (!fuzz_table && !fuzz_target) {
195
    fprintf(stderr,
196
"Missing environment variables!\n"
197
"\n"
198
"Modes of operation:\n"
199
"\n"
200
" 1. Call a dissector directly by its name:\n"
201
"      FUZZSHARK_TARGET=dns %s input-file\n"
202
"    Calls dissect_x from register_dissector(NAME, dissect_x, proto_x)\n"
203
"\n"
204
" 2. Call a dissector by its filter name in a dissector table:\n"
205
"      FUZZSHARK_TABLE=ip.proto FUZZSHARK_TARGET=ospf %s input-file\n"
206
"    The filter name is from proto_register_protocol(., ., FILTER_NAME)\n"
207
"    Selects dissectors from dissector_add_uint* or dissector_add_for_decode_as.\n"
208
"\n"
209
"Either mode runs the selected dissector once and can hopefully reproduce a\n"
210
"crash. Mode (2) can be used if a dissector (such as 'ospf') is not available\n"
211
"through (1).\n"
212
"\n"
213
"For best results, build dedicated fuzzshark_* targets with:\n"
214
"    cmake -GNinja -DCMAKE_C_COMPILER=clang -DCMAKE_CXX_COMPILER=clang++\\\n"
215
"      -DENABLE_FUZZER=1 -DENABLE_ASAN=1 -DENABLE_UBSAN=1\n"
216
"    ninja all-fuzzers\n"
217
"These options enable LibFuzzer which makes fuzzing possible as opposed to\n"
218
"running dissectors only once with a sample (as is the case with this fuzzshark"
219
"binary). These fuzzshark_* targets are also used by oss-fuzz.\n",
220
      argv[0], argv[0]);
221
    return 1;
222
  }
223
#endif
224
225
16
  dissector_handle_t fuzz_handle = NULL;
226
227
  /* In oss-fuzz running environment g_get_home_dir() fails:
228
   * (process:1): GLib-WARNING **: getpwuid_r(): failed due to unknown user id (0)
229
   * (process:1): GLib-CRITICAL **: g_once_init_leave: assertion 'result != 0' failed
230
   *
231
   * Avoid GLib-CRITICAL by setting some XDG environment variables.
232
   */
233
16
  g_setenv("XDG_CACHE_HOME", "/not/existing/directory", 0);  /* g_get_user_cache_dir() */
234
16
  g_setenv("XDG_CONFIG_HOME", "/not/existing/directory", 0); /* g_get_user_config_dir() */
235
16
  g_setenv("XDG_DATA_HOME", "/not/existing/directory", 0);   /* g_get_user_data_dir() */
236
237
16
  g_setenv("WIRESHARK_DEBUG_WMEM_OVERRIDE", "simple", 0);
238
16
  g_setenv("G_SLICE", "always-malloc", 0);
239
240
16
  cmdarg_err_init(stderr_cmdarg_err, stderr_cmdarg_err_cont);
241
242
  /* Initialize log handler early so we can have proper logging during startup. */
243
16
  ws_log_init(vcmdarg_err, "Fuzzshark Debug Console");
244
245
  /* Early logging command-line initialization. */
246
16
  ws_log_parse_args(&argc, argv, "v", long_options, vcmdarg_err, LOG_ARGS_NOEXIT);
247
248
16
  ws_noisy("Finished log init and parsing command line log arguments");
249
250
  /*
251
   * Get credential information for later use, and drop privileges
252
   * before doing anything else.
253
   * Let the user know if anything happened.
254
   */
255
16
  init_process_policies();
256
#if 0 /* disable setresgid(), it fails with -EINVAL https://github.com/google/oss-fuzz/pull/532#issuecomment-294515463 */
257
  relinquish_special_privs_perm();
258
#endif
259
260
  /*
261
   * Attempt to get the pathname of the executable file.
262
   */
263
16
  configuration_init_error = configuration_init(argv[0], "wireshark");
264
16
  if (configuration_init_error != NULL) {
265
0
    fprintf(stderr, "fuzzshark: Can't get pathname of oss-fuzzshark program: %s.\n", configuration_init_error);
266
0
    g_free(configuration_init_error);
267
0
  }
268
269
  /* Initialize the version information. */
270
16
  ws_init_version_info("OSS Fuzzshark", NULL, application_get_vcs_version_info,
271
16
      epan_gather_compile_info, epan_gather_runtime_info);
272
273
16
  init_report_failure_message("fuzzshark");
274
275
16
  timestamp_set_type(TS_RELATIVE);
276
16
  timestamp_set_precision(TS_PREC_AUTO);
277
16
  timestamp_set_seconds_type(TS_SECONDS_DEFAULT);
278
279
  /*
280
   * Libwiretap must be initialized before libwireshark is, so that
281
   * dissection-time handlers for file-type-dependent blocks can
282
   * register using the file type/subtype value for the file type.
283
   */
284
16
  application_file_extensions(&file_extensions, &num_extensions);
285
16
  wtap_init(true, application_configuration_environment_prefix(), file_extensions, num_extensions);
286
287
  /* Register all dissectors; we must do this before checking for the
288
     "-G" flag, as the "-G" flag dumps information registered by the
289
     dissectors, and we must do it before we read the preferences, in
290
     case any dissectors register preferences. */
291
16
  app_data.env_var_prefix = application_configuration_environment_prefix();
292
16
  app_data.col_fmt = application_columns();
293
16
  app_data.num_cols = application_num_columns();
294
16
  app_data.register_func = register_all_protocols;
295
16
  app_data.handoff_func = register_all_protocol_handoffs;
296
16
  if (!epan_init(NULL, NULL, false, &app_data))
297
0
  {
298
0
    ret = EPAN_INIT_FAIL;
299
0
    goto clean_exit;
300
0
  }
301
302
  /* Load libwireshark settings from the current profile. */
303
16
  prefs_p = epan_load_settings();
304
305
16
  if (!color_filters_init(&err_msg, NULL, application_configuration_environment_prefix()))
306
0
  {
307
0
    fprintf(stderr, "%s\n", err_msg);
308
0
    g_free(err_msg);
309
0
  }
310
311
144
  for (i = 0; i < G_N_ELEMENTS(disabled_dissector_list); i++)
312
128
  {
313
128
    const char *item = disabled_dissector_list[i];
314
315
    /* XXX, need to think how to disallow chains like: IP -> .... -> IP,
316
     * best would be to disable dissector always, but allow it during initial call. */
317
128
    if (fuzz_target == NULL || strcmp(fuzz_target, item))
318
116
    {
319
116
      fprintf(stderr, "oss-fuzzshark: disabling: %s\n", item);
320
116
      proto_disable_proto_by_name(item);
321
116
    }
322
128
  }
323
324
16
  fuzz_prefs_apply();
325
326
  /* Build the column format array */
327
16
  build_column_format_array(&fuzz_cinfo, prefs_p->num_cols, true);
328
329
16
#if defined(FUZZ_DISSECTOR_TABLE) && defined(FUZZ_DISSECTOR_TARGET)
330
16
# define FUZZ_EPAN 1
331
16
  fprintf(stderr, "oss-fuzzshark: configured for dissector: %s in table: %s\n", fuzz_target, FUZZ_DISSECTOR_TABLE);
332
16
  fuzz_handle = get_dissector_handle(FUZZ_DISSECTOR_TABLE, fuzz_target);
333
334
#elif defined(FUZZ_DISSECTOR_TARGET)
335
# define FUZZ_EPAN 2
336
  fprintf(stderr, "oss-fuzzshark: configured for dissector: %s\n", fuzz_target);
337
  fuzz_handle = get_dissector_handle(NULL, fuzz_target);
338
339
#else
340
# define FUZZ_EPAN 3
341
  if (fuzz_table) {
342
    fprintf(stderr, "oss-fuzzshark: requested dissector: %s in table %s\n", fuzz_target, fuzz_table);
343
  } else {
344
    fprintf(stderr, "oss-fuzzshark: requested dissector: %s\n", fuzz_target);
345
  }
346
  fuzz_handle = get_dissector_handle(fuzz_table, fuzz_target);
347
#endif
348
349
16
#ifdef FUZZ_EPAN
350
16
  g_assert(fuzz_handle != NULL && "Requested dissector is not found.");
351
16
  register_postdissector(fuzz_handle);
352
16
#endif
353
354
16
  fuzz_epan = fuzzshark_epan_new();
355
16
  fuzz_edt = epan_dissect_new(fuzz_epan, true, false);
356
357
16
  return 0;
358
0
clean_exit:
359
0
  wtap_cleanup();
360
0
  free_progdirs();
361
0
  return ret;
362
16
}
363
364
#ifdef FUZZ_EPAN
365
int
366
LLVMFuzzerTestOneInput(const uint8_t *buf, size_t real_len)
367
191k
{
368
191k
  static uint32_t framenum = 0;
369
191k
  epan_dissect_t *edt = fuzz_edt;
370
371
191k
  uint32_t len = (uint32_t) real_len;
372
373
191k
  wtap_rec rec;
374
191k
  frame_data fdlocal;
375
376
191k
  wtap_rec_init(&rec, len);
377
378
  /* wtap_setup_packet_rec(&rec, WTAP_ENCAP_ETHERNET); */
379
191k
  wtap_setup_packet_rec(&rec, INT16_MAX);
380
191k
  rec.rec_header.packet_header.caplen = len;
381
191k
  rec.rec_header.packet_header.len = len;
382
383
191k
  rec.presence_flags = WTAP_HAS_TS | WTAP_HAS_CAP_LEN; /* most common flags... */
384
385
191k
  ws_buffer_append(&rec.data, buf, real_len);
386
387
191k
  frame_data_init(&fdlocal, ++framenum, &rec, /* offset */ 0, /* cum_bytes */ 0);
388
  /* frame_data_set_before_dissect() not needed */
389
191k
  epan_dissect_run(edt, WTAP_FILE_TYPE_SUBTYPE_UNKNOWN, &rec, &fdlocal, NULL /* &fuzz_cinfo */);
390
191k
  frame_data_destroy(&fdlocal);
391
392
191k
  epan_dissect_reset(edt);
393
394
191k
  wtap_rec_cleanup(&rec);
395
191k
  return 0;
396
191k
}
397
398
#else
399
# error "Missing fuzz target."
400
#endif
401
402
int
403
LLVMFuzzerInitialize(int *argc, char ***argv)
404
16
{
405
16
  return fuzz_init(*argc, *argv);
406
16
}
407
408
/*
409
 * Editor modelines  -  https://www.wireshark.org/tools/modelines.html
410
 *
411
 * Local variables:
412
 * c-basic-offset: 8
413
 * tab-width: 8
414
 * indent-tabs-mode: t
415
 * End:
416
 *
417
 * vi: set shiftwidth=8 tabstop=8 noexpandtab:
418
 * :indentSize=8:tabSize=8:noTabs=false:
419
 */