Simplify PerMessageDeflate fuzzing regions
This commit is contained in:
@@ -4,6 +4,7 @@
|
||||
|
||||
#include <cstdio>
|
||||
#include <string>
|
||||
#include <bitset>
|
||||
|
||||
/* We test the permessage deflate module */
|
||||
#include "../src/PerMessageDeflate.h"
|
||||
@@ -13,9 +14,7 @@
|
||||
extern "C" int LLVMFuzzerTestOneInput(const uint8_t *data, size_t size) {
|
||||
|
||||
/* First byte determines what compressor to use */
|
||||
if (size < 1) {
|
||||
return 0;
|
||||
}
|
||||
if (size >= 1) {
|
||||
|
||||
int compressors[] = {
|
||||
uWS::DEDICATED_COMPRESSOR_3KB,
|
||||
@@ -32,6 +31,9 @@ extern "C" int LLVMFuzzerTestOneInput(const uint8_t *data, size_t size) {
|
||||
data++;
|
||||
size--;
|
||||
|
||||
/* Bits 0 - 256 are okay */
|
||||
std::bitset<257> b;
|
||||
|
||||
/* If we could specify LARGE_BUFFER_SIZE small here we could force it to inflate in chunks,
|
||||
* triggering more line coverage. Currently it is set to 16kb which is always too much */
|
||||
struct StaticData {
|
||||
@@ -42,12 +44,11 @@ extern "C" int LLVMFuzzerTestOneInput(const uint8_t *data, size_t size) {
|
||||
} staticData = {compressor};
|
||||
|
||||
/* Why is this padded? */
|
||||
makeChunked(makePadded(data, size), size, [&staticData](const uint8_t *data, size_t size) {
|
||||
makeChunked(makePadded(data, size), size, [&staticData, &b](const uint8_t *data, size_t size) {
|
||||
auto [inflation, valid] = staticData.inflationStream.inflate(&staticData.zlibContext, std::string_view((char *) data, size), 256);
|
||||
if (inflation.length() > 256) {
|
||||
/* Cause ASAN to freak out */
|
||||
delete (int *) (void *) 1;
|
||||
}
|
||||
|
||||
/* Trigger ASAN flaws if length is more than 256 */
|
||||
b.set(inflation.length());
|
||||
});
|
||||
|
||||
makeChunked(makePadded(data, size), size, [&staticData](const uint8_t *data, size_t size) {
|
||||
@@ -55,6 +56,8 @@ extern "C" int LLVMFuzzerTestOneInput(const uint8_t *data, size_t size) {
|
||||
staticData.deflationStream.deflate(&staticData.zlibContext, std::string_view((char *) data, size), true);
|
||||
});
|
||||
|
||||
}
|
||||
|
||||
return 0;
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user