From 4ad07a4f939792f8ac832aeedce2b2d606167693 Mon Sep 17 00:00:00 2001 From: Alex Hultman Date: Fri, 7 Aug 2020 16:08:53 +0200 Subject: [PATCH] Fix entirely broken TopicTree fuzz target --- fuzzing/TopicTree.cpp | 30 +++++++++++++++++++++++++----- 1 file changed, 25 insertions(+), 5 deletions(-) diff --git a/fuzzing/TopicTree.cpp b/fuzzing/TopicTree.cpp index cc4af7b..8bc1897 100644 --- a/fuzzing/TopicTree.cpp +++ b/fuzzing/TopicTree.cpp @@ -10,8 +10,16 @@ extern "C" int LLVMFuzzerTestOneInput(const uint8_t *data, size_t size) { /* Create topic tree */ uWS::TopicTree topicTree([](uWS::Subscriber *s, std::pair message) { - /* We assume sane output */ - if (!s || !message.first.length()) { + + /* Subscriber must not be null, and at this point we have to have subscriptions. + * This assumption seems to hold true. */ + if (!s->subscriptions.size()) { + free((void *) -1); + } + + /* Depending on what publishing we do below (with or without empty strings), + * this assumption can hold true or not. For now it should hold true */ + if (!message.first.length()) { free((void *) -1); } @@ -35,10 +43,12 @@ extern "C" int LLVMFuzzerTestOneInput(const uint8_t *data, size_t size) { /* Then one byte action */ if (data[4] == 'S') { /* Subscribe */ - if (subscribers.find(id) != subscribers.end()) { + if (subscribers.find(id) == subscribers.end()) { uWS::Subscriber *subscriber = new uWS::Subscriber(nullptr); subscribers[id] = std::unique_ptr(subscriber); topicTree.subscribe(lastString, subscriber); + } else { + topicTree.subscribe(lastString, subscribers[id].get()); } } else if (data[4] == 'U') { /* Unsubscribe */ @@ -53,8 +63,13 @@ extern "C" int LLVMFuzzerTestOneInput(const uint8_t *data, size_t size) { topicTree.unsubscribeAll(it->second.get()); } } else if (data[4] == 'P') { - /* Publish */ - topicTree.publish(lastString, {lastString, lastString}); + /* Publish only if we actually have data */ + if (lastString.length()) { + topicTree.publish(lastString, {lastString, lastString}); + } else { + /* We could use having more strings */ + topicTree.publish("", {"anything", "something else"}); + } } else if (data[4] == 'D') { /* Drain */ topicTree.drain(); @@ -62,6 +77,11 @@ extern "C" int LLVMFuzzerTestOneInput(const uint8_t *data, size_t size) { } }); + /* Remove any subscriber from the tree */ + for (auto &p : subscribers) { + topicTree.unsubscribeAll(p.second.get()); + } + return 0; }