/src/wireshark/fuzz/fuzzshark.c
Line | Count | Source |
1 | | /* fuzzshark.c |
2 | | * |
3 | | * Fuzzer variant of Wireshark for oss-fuzz |
4 | | * |
5 | | * Wireshark - Network traffic analyzer |
6 | | * By Gerald Combs <gerald@wireshark.org> |
7 | | * Copyright 1998 Gerald Combs |
8 | | * |
9 | | * SPDX-License-Identifier: GPL-2.0-or-later |
10 | | */ |
11 | | |
12 | | #include <config.h> |
13 | 0 | #define WS_LOG_DOMAIN LOG_DOMAIN_MAIN |
14 | | |
15 | | #include <stdlib.h> |
16 | | #include <stdio.h> |
17 | | #include <string.h> |
18 | | #include <limits.h> |
19 | | |
20 | | #include <glib.h> |
21 | | |
22 | | #include <epan/epan.h> |
23 | | |
24 | | #include <wsutil/cmdarg_err.h> |
25 | | #include <ui/failure_message.h> |
26 | | #include <wsutil/filesystem.h> |
27 | | #include <app/application_flavor.h> |
28 | | #include <wsutil/privileges.h> |
29 | | #include <wsutil/clopts_common.h> |
30 | | #include <wsutil/ws_getopt.h> |
31 | | #include <wsutil/wslog.h> |
32 | | #include <wsutil/version_info.h> |
33 | | |
34 | | #include <wiretap/wtap.h> |
35 | | |
36 | | #include <epan/color_filters.h> |
37 | | #include <epan/timestamp.h> |
38 | | #include <epan/prefs.h> |
39 | | #include <epan/column.h> |
40 | | #include <epan/column-info.h> |
41 | | #include <epan/print.h> |
42 | | #include <epan/epan_dissect.h> |
43 | | #include <epan/disabled_protos.h> |
44 | | |
45 | | #ifdef HAVE_PLUGINS |
46 | | #include <wsutil/plugins.h> |
47 | | #endif |
48 | | |
49 | | #include "FuzzerInterface.h" |
50 | | |
51 | 0 | #define EPAN_INIT_FAIL 2 |
52 | | |
53 | | static column_info fuzz_cinfo; |
54 | | static epan_t *fuzz_epan; |
55 | | static epan_dissect_t *fuzz_edt; |
56 | | |
57 | | static int |
58 | | fuzzshark_pref_set(const char *name, const char *value) |
59 | 64 | { |
60 | 64 | char pref[4096]; |
61 | 64 | char *errmsg = NULL; |
62 | | |
63 | 64 | prefs_set_pref_e ret; |
64 | | |
65 | 64 | snprintf(pref, sizeof(pref), "%s:%s", name, value); |
66 | | |
67 | 64 | ret = prefs_set_pref(pref, &errmsg); |
68 | 64 | g_free(errmsg); |
69 | | |
70 | 64 | return (ret == PREFS_SET_OK); |
71 | 64 | } |
72 | | |
73 | | static const nstime_t * |
74 | | fuzzshark_get_frame_ts(struct packet_provider_data *prov _U_, uint32_t frame_num _U_) |
75 | 439k | { |
76 | 439k | static nstime_t empty; |
77 | | |
78 | 439k | return ∅ |
79 | 439k | } |
80 | | |
81 | | static epan_t * |
82 | | fuzzshark_epan_new(void) |
83 | 16 | { |
84 | 16 | static const struct packet_provider_funcs funcs = { |
85 | 16 | fuzzshark_get_frame_ts, |
86 | 16 | NULL, |
87 | 16 | NULL, |
88 | 16 | NULL, |
89 | 16 | NULL, |
90 | 16 | NULL, |
91 | 16 | NULL, |
92 | 16 | NULL, |
93 | 16 | NULL, |
94 | 16 | NULL, |
95 | 16 | NULL, |
96 | 16 | NULL, |
97 | 16 | NULL, |
98 | 16 | NULL, |
99 | 16 | NULL, |
100 | 16 | NULL, |
101 | 16 | }; |
102 | | |
103 | 16 | return epan_new(NULL, &funcs); |
104 | 16 | } |
105 | | |
106 | | static dissector_handle_t |
107 | | get_dissector_handle(const char *table, const char *target) |
108 | 16 | { |
109 | 16 | dissector_handle_t fuzz_handle = NULL; |
110 | | |
111 | 16 | if (table != NULL && target != NULL) |
112 | 12 | { |
113 | | /* search for handle, cannot use dissector_table_get_dissector_handle() cause it's using short-name, and I already used filter name in samples ;/ */ |
114 | 12 | GSList *handle_list = dissector_table_get_dissector_handles(find_dissector_table(table)); |
115 | 2.75k | while (handle_list) |
116 | 2.73k | { |
117 | 2.73k | dissector_handle_t handle = (dissector_handle_t) handle_list->data; |
118 | 2.73k | const char *handle_filter_name = proto_get_protocol_filter_name(dissector_handle_get_protocol_index(handle)); |
119 | | |
120 | 2.73k | if (!strcmp(handle_filter_name, target)) |
121 | 12 | fuzz_handle = handle; |
122 | 2.73k | handle_list = handle_list->next; |
123 | 2.73k | } |
124 | 12 | } |
125 | 4 | else if (target != NULL) |
126 | 4 | { |
127 | 4 | fuzz_handle = find_dissector(target); |
128 | 4 | } |
129 | | |
130 | 16 | return fuzz_handle; |
131 | 16 | } |
132 | | |
133 | | static void |
134 | | fuzz_prefs_apply(void) |
135 | 16 | { |
136 | | /* Turn off fragmentation for some protocols */ |
137 | 16 | fuzzshark_pref_set("ip.defragment", "FALSE"); |
138 | 16 | fuzzshark_pref_set("ipv6.defragment", "FALSE"); |
139 | 16 | fuzzshark_pref_set("wlan.defragment", "FALSE"); |
140 | 16 | fuzzshark_pref_set("tcp.desegment_tcp_streams", "FALSE"); |
141 | | |
142 | | /* Notify all registered modules that have had any of their preferences changed. */ |
143 | 16 | prefs_apply_all(); |
144 | 16 | } |
145 | | |
146 | | static int |
147 | | fuzz_init(int argc, char **argv) |
148 | 16 | { |
149 | 16 | char *configuration_init_error; |
150 | | |
151 | | |
152 | 16 | char *err_msg = NULL; |
153 | 16 | e_prefs *prefs_p; |
154 | 16 | int ret = EXIT_SUCCESS; |
155 | 16 | size_t i; |
156 | 16 | static const struct ws_option long_options[] = { |
157 | 16 | LONGOPT_WSLOG |
158 | 16 | {0, 0, 0, 0 } |
159 | 16 | }; |
160 | 16 | const struct file_extension_info* file_extensions; |
161 | 16 | unsigned num_extensions; |
162 | 16 | epan_app_data_t app_data; |
163 | | |
164 | | /* Future proof by zeroing out all data */ |
165 | 16 | memset(&app_data, 0, sizeof(app_data)); |
166 | | |
167 | 16 | const char *fuzz_target = |
168 | 16 | #if defined(FUZZ_DISSECTOR_TARGET) |
169 | 16 | FUZZ_DISSECTOR_TARGET; |
170 | | #else |
171 | | getenv("FUZZSHARK_TARGET"); |
172 | | #endif |
173 | | |
174 | 16 | const char *disabled_dissector_list[] = |
175 | 16 | { |
176 | 16 | #ifdef FUZZ_DISSECTOR_LIST |
177 | 16 | FUZZ_DISSECTOR_LIST , |
178 | 16 | #endif |
179 | 16 | "snort" |
180 | 16 | }; |
181 | | |
182 | | #if !defined(FUZZ_DISSECTOR_TABLE) && !defined(FUZZ_DISSECTOR_TARGET) |
183 | | const char *fuzz_table = getenv("FUZZSHARK_TABLE"); |
184 | | |
185 | | /* |
186 | | * Set the program name. |
187 | | * |
188 | | * XXX - yes, this isn't main(), but it still needs to be |
189 | | * set, as many Wireshark library routines depend on it |
190 | | * being set. |
191 | | */ |
192 | | g_set_prgname("oss-fuzzshark"); |
193 | | |
194 | | if (!fuzz_table && !fuzz_target) { |
195 | | fprintf(stderr, |
196 | | "Missing environment variables!\n" |
197 | | "\n" |
198 | | "Modes of operation:\n" |
199 | | "\n" |
200 | | " 1. Call a dissector directly by its name:\n" |
201 | | " FUZZSHARK_TARGET=dns %s input-file\n" |
202 | | " Calls dissect_x from register_dissector(NAME, dissect_x, proto_x)\n" |
203 | | "\n" |
204 | | " 2. Call a dissector by its filter name in a dissector table:\n" |
205 | | " FUZZSHARK_TABLE=ip.proto FUZZSHARK_TARGET=ospf %s input-file\n" |
206 | | " The filter name is from proto_register_protocol(., ., FILTER_NAME)\n" |
207 | | " Selects dissectors from dissector_add_uint* or dissector_add_for_decode_as.\n" |
208 | | "\n" |
209 | | "Either mode runs the selected dissector once and can hopefully reproduce a\n" |
210 | | "crash. Mode (2) can be used if a dissector (such as 'ospf') is not available\n" |
211 | | "through (1).\n" |
212 | | "\n" |
213 | | "For best results, build dedicated fuzzshark_* targets with:\n" |
214 | | " cmake -GNinja -DCMAKE_C_COMPILER=clang -DCMAKE_CXX_COMPILER=clang++\\\n" |
215 | | " -DENABLE_FUZZER=1 -DENABLE_ASAN=1 -DENABLE_UBSAN=1\n" |
216 | | " ninja all-fuzzers\n" |
217 | | "These options enable LibFuzzer which makes fuzzing possible as opposed to\n" |
218 | | "running dissectors only once with a sample (as is the case with this fuzzshark" |
219 | | "binary). These fuzzshark_* targets are also used by oss-fuzz.\n", |
220 | | argv[0], argv[0]); |
221 | | return 1; |
222 | | } |
223 | | #endif |
224 | | |
225 | 16 | dissector_handle_t fuzz_handle = NULL; |
226 | | |
227 | | /* In oss-fuzz running environment g_get_home_dir() fails: |
228 | | * (process:1): GLib-WARNING **: getpwuid_r(): failed due to unknown user id (0) |
229 | | * (process:1): GLib-CRITICAL **: g_once_init_leave: assertion 'result != 0' failed |
230 | | * |
231 | | * Avoid GLib-CRITICAL by setting some XDG environment variables. |
232 | | */ |
233 | 16 | g_setenv("XDG_CACHE_HOME", "/not/existing/directory", 0); /* g_get_user_cache_dir() */ |
234 | 16 | g_setenv("XDG_CONFIG_HOME", "/not/existing/directory", 0); /* g_get_user_config_dir() */ |
235 | 16 | g_setenv("XDG_DATA_HOME", "/not/existing/directory", 0); /* g_get_user_data_dir() */ |
236 | | |
237 | 16 | g_setenv("WIRESHARK_DEBUG_WMEM_OVERRIDE", "simple", 0); |
238 | 16 | g_setenv("G_SLICE", "always-malloc", 0); |
239 | | |
240 | 16 | cmdarg_err_init(stderr_cmdarg_err, stderr_cmdarg_err_cont); |
241 | | |
242 | | /* Initialize log handler early so we can have proper logging during startup. */ |
243 | 16 | ws_log_init(vcmdarg_err, "Fuzzshark Debug Console"); |
244 | | |
245 | | /* Early logging command-line initialization. */ |
246 | 16 | ws_log_parse_args(&argc, argv, "v", long_options, vcmdarg_err, LOG_ARGS_NOEXIT); |
247 | | |
248 | 16 | ws_noisy("Finished log init and parsing command line log arguments"); |
249 | | |
250 | | /* |
251 | | * Get credential information for later use, and drop privileges |
252 | | * before doing anything else. |
253 | | * Let the user know if anything happened. |
254 | | */ |
255 | 16 | init_process_policies(); |
256 | | #if 0 /* disable setresgid(), it fails with -EINVAL https://github.com/google/oss-fuzz/pull/532#issuecomment-294515463 */ |
257 | | relinquish_special_privs_perm(); |
258 | | #endif |
259 | | |
260 | | /* |
261 | | * Attempt to get the pathname of the executable file. |
262 | | */ |
263 | 16 | configuration_init_error = configuration_init(argv[0], "wireshark"); |
264 | 16 | if (configuration_init_error != NULL) { |
265 | 0 | fprintf(stderr, "fuzzshark: Can't get pathname of oss-fuzzshark program: %s.\n", configuration_init_error); |
266 | 0 | g_free(configuration_init_error); |
267 | 0 | } |
268 | | |
269 | | /* Initialize the version information. */ |
270 | 16 | ws_init_version_info("OSS Fuzzshark", NULL, application_get_vcs_version_info, |
271 | 16 | epan_gather_compile_info, epan_gather_runtime_info); |
272 | | |
273 | 16 | init_report_failure_message("fuzzshark"); |
274 | | |
275 | 16 | timestamp_set_type(TS_RELATIVE); |
276 | 16 | timestamp_set_precision(TS_PREC_AUTO); |
277 | 16 | timestamp_set_seconds_type(TS_SECONDS_DEFAULT); |
278 | | |
279 | | /* |
280 | | * Libwiretap must be initialized before libwireshark is, so that |
281 | | * dissection-time handlers for file-type-dependent blocks can |
282 | | * register using the file type/subtype value for the file type. |
283 | | */ |
284 | 16 | application_file_extensions(&file_extensions, &num_extensions); |
285 | 16 | wtap_init(true, application_configuration_environment_prefix(), file_extensions, num_extensions); |
286 | | |
287 | | /* Register all dissectors; we must do this before checking for the |
288 | | "-G" flag, as the "-G" flag dumps information registered by the |
289 | | dissectors, and we must do it before we read the preferences, in |
290 | | case any dissectors register preferences. */ |
291 | 16 | app_data.env_var_prefix = application_configuration_environment_prefix(); |
292 | 16 | app_data.col_fmt = application_columns(); |
293 | 16 | app_data.num_cols = application_num_columns(); |
294 | 16 | app_data.register_func = register_all_protocols; |
295 | 16 | app_data.handoff_func = register_all_protocol_handoffs; |
296 | 16 | if (!epan_init(NULL, NULL, false, &app_data)) |
297 | 0 | { |
298 | 0 | ret = EPAN_INIT_FAIL; |
299 | 0 | goto clean_exit; |
300 | 0 | } |
301 | | |
302 | | /* Load libwireshark settings from the current profile. */ |
303 | 16 | prefs_p = epan_load_settings(); |
304 | | |
305 | 16 | if (!color_filters_init(&err_msg, NULL, application_configuration_environment_prefix())) |
306 | 0 | { |
307 | 0 | fprintf(stderr, "%s\n", err_msg); |
308 | 0 | g_free(err_msg); |
309 | 0 | } |
310 | | |
311 | 144 | for (i = 0; i < G_N_ELEMENTS(disabled_dissector_list); i++) |
312 | 128 | { |
313 | 128 | const char *item = disabled_dissector_list[i]; |
314 | | |
315 | | /* XXX, need to think how to disallow chains like: IP -> .... -> IP, |
316 | | * best would be to disable dissector always, but allow it during initial call. */ |
317 | 128 | if (fuzz_target == NULL || strcmp(fuzz_target, item)) |
318 | 116 | { |
319 | 116 | fprintf(stderr, "oss-fuzzshark: disabling: %s\n", item); |
320 | 116 | proto_disable_proto_by_name(item); |
321 | 116 | } |
322 | 128 | } |
323 | | |
324 | 16 | fuzz_prefs_apply(); |
325 | | |
326 | | /* Build the column format array */ |
327 | 16 | build_column_format_array(&fuzz_cinfo, prefs_p->num_cols, true); |
328 | | |
329 | 16 | #if defined(FUZZ_DISSECTOR_TABLE) && defined(FUZZ_DISSECTOR_TARGET) |
330 | 16 | # define FUZZ_EPAN 1 |
331 | 16 | fprintf(stderr, "oss-fuzzshark: configured for dissector: %s in table: %s\n", fuzz_target, FUZZ_DISSECTOR_TABLE); |
332 | 16 | fuzz_handle = get_dissector_handle(FUZZ_DISSECTOR_TABLE, fuzz_target); |
333 | | |
334 | | #elif defined(FUZZ_DISSECTOR_TARGET) |
335 | | # define FUZZ_EPAN 2 |
336 | | fprintf(stderr, "oss-fuzzshark: configured for dissector: %s\n", fuzz_target); |
337 | | fuzz_handle = get_dissector_handle(NULL, fuzz_target); |
338 | | |
339 | | #else |
340 | | # define FUZZ_EPAN 3 |
341 | | if (fuzz_table) { |
342 | | fprintf(stderr, "oss-fuzzshark: requested dissector: %s in table %s\n", fuzz_target, fuzz_table); |
343 | | } else { |
344 | | fprintf(stderr, "oss-fuzzshark: requested dissector: %s\n", fuzz_target); |
345 | | } |
346 | | fuzz_handle = get_dissector_handle(fuzz_table, fuzz_target); |
347 | | #endif |
348 | | |
349 | 16 | #ifdef FUZZ_EPAN |
350 | 16 | g_assert(fuzz_handle != NULL && "Requested dissector is not found."); |
351 | 16 | register_postdissector(fuzz_handle); |
352 | 16 | #endif |
353 | | |
354 | 16 | fuzz_epan = fuzzshark_epan_new(); |
355 | 16 | fuzz_edt = epan_dissect_new(fuzz_epan, true, false); |
356 | | |
357 | 16 | return 0; |
358 | 0 | clean_exit: |
359 | 0 | wtap_cleanup(); |
360 | 0 | free_progdirs(); |
361 | 0 | return ret; |
362 | 16 | } |
363 | | |
364 | | #ifdef FUZZ_EPAN |
365 | | int |
366 | | LLVMFuzzerTestOneInput(const uint8_t *buf, size_t real_len) |
367 | 191k | { |
368 | 191k | static uint32_t framenum = 0; |
369 | 191k | epan_dissect_t *edt = fuzz_edt; |
370 | | |
371 | 191k | uint32_t len = (uint32_t) real_len; |
372 | | |
373 | 191k | wtap_rec rec; |
374 | 191k | frame_data fdlocal; |
375 | | |
376 | 191k | wtap_rec_init(&rec, len); |
377 | | |
378 | | /* wtap_setup_packet_rec(&rec, WTAP_ENCAP_ETHERNET); */ |
379 | 191k | wtap_setup_packet_rec(&rec, INT16_MAX); |
380 | 191k | rec.rec_header.packet_header.caplen = len; |
381 | 191k | rec.rec_header.packet_header.len = len; |
382 | | |
383 | 191k | rec.presence_flags = WTAP_HAS_TS | WTAP_HAS_CAP_LEN; /* most common flags... */ |
384 | | |
385 | 191k | ws_buffer_append(&rec.data, buf, real_len); |
386 | | |
387 | 191k | frame_data_init(&fdlocal, ++framenum, &rec, /* offset */ 0, /* cum_bytes */ 0); |
388 | | /* frame_data_set_before_dissect() not needed */ |
389 | 191k | epan_dissect_run(edt, WTAP_FILE_TYPE_SUBTYPE_UNKNOWN, &rec, &fdlocal, NULL /* &fuzz_cinfo */); |
390 | 191k | frame_data_destroy(&fdlocal); |
391 | | |
392 | 191k | epan_dissect_reset(edt); |
393 | | |
394 | 191k | wtap_rec_cleanup(&rec); |
395 | 191k | return 0; |
396 | 191k | } |
397 | | |
398 | | #else |
399 | | # error "Missing fuzz target." |
400 | | #endif |
401 | | |
402 | | int |
403 | | LLVMFuzzerInitialize(int *argc, char ***argv) |
404 | 16 | { |
405 | 16 | return fuzz_init(*argc, *argv); |
406 | 16 | } |
407 | | |
408 | | /* |
409 | | * Editor modelines - https://www.wireshark.org/tools/modelines.html |
410 | | * |
411 | | * Local variables: |
412 | | * c-basic-offset: 8 |
413 | | * tab-width: 8 |
414 | | * indent-tabs-mode: t |
415 | | * End: |
416 | | * |
417 | | * vi: set shiftwidth=8 tabstop=8 noexpandtab: |
418 | | * :indentSize=8:tabSize=8:noTabs=false: |
419 | | */ |