Line | Count | Source |
1 | | /* |
2 | | * Copyright (C) 2026 Emweb bv, Herent, Belgium. |
3 | | * |
4 | | * See the LICENSE file for terms of use. |
5 | | */ |
6 | | |
7 | | #include <stdint.h> |
8 | | #include <stddef.h> |
9 | | #include <vector> |
10 | | |
11 | | #include "http/RequestParser.h" |
12 | | #include "http/Request.h" |
13 | | |
14 | 3.94k | #define kMinInputLength 10 |
15 | 1.96k | #define kMaxInputLength 5120 |
16 | | |
17 | | // Fuzzes the httpd request line/header parser; parse() and validate() do not |
18 | | // use the Server, so it is driven with a null one. |
19 | 1.97k | extern "C" int LLVMFuzzerTestOneInput(const uint8_t *Data, size_t Size) { |
20 | | |
21 | 1.97k | if (Size < kMinInputLength || Size > kMaxInputLength) { |
22 | 23 | return 1; |
23 | 23 | } |
24 | | |
25 | 1.94k | std::vector<char> buf(Data, Data + Size); |
26 | | |
27 | 1.94k | http::server::RequestParser parser(nullptr); |
28 | 1.94k | http::server::Request req; |
29 | | |
30 | 1.94k | char *begin = &buf[0]; |
31 | 1.94k | char *end = begin + buf.size(); |
32 | | |
33 | 1.94k | boost::tribool result; |
34 | 1.94k | char *next; |
35 | 1.94k | boost::tie(result, next) = parser.parse(req, begin, end); |
36 | | |
37 | 1.94k | if (result) { |
38 | 1.44k | parser.validate(req); |
39 | 1.44k | } |
40 | | |
41 | 1.94k | return 0; |
42 | 1.97k | } |