Fuzz Http in chunks
This commit is contained in:
+34
-35
@@ -2,15 +2,14 @@
|
|||||||
|
|
||||||
#define WIN32_EXPORT
|
#define WIN32_EXPORT
|
||||||
|
|
||||||
|
#include "helpers.h"
|
||||||
|
|
||||||
/* We test the websocket parser */
|
/* We test the websocket parser */
|
||||||
#include "../src/HttpParser.h"
|
#include "../src/HttpParser.h"
|
||||||
|
|
||||||
/* And the router */
|
/* And the router */
|
||||||
#include "../src/HttpRouter.h"
|
#include "../src/HttpRouter.h"
|
||||||
|
|
||||||
/* We use this to pad the fuzz */
|
|
||||||
char *padded = new char[1024 * 500];
|
|
||||||
|
|
||||||
struct StaticData {
|
struct StaticData {
|
||||||
|
|
||||||
struct RouterData {
|
struct RouterData {
|
||||||
@@ -48,46 +47,46 @@ struct StaticData {
|
|||||||
} staticData;
|
} staticData;
|
||||||
|
|
||||||
extern "C" int LLVMFuzzerTestOneInput(const uint8_t *data, size_t size) {
|
extern "C" int LLVMFuzzerTestOneInput(const uint8_t *data, size_t size) {
|
||||||
|
/* Create parser */
|
||||||
/* Pad the fuzz */
|
|
||||||
uWS::HttpParser httpParser;
|
uWS::HttpParser httpParser;
|
||||||
memcpy(padded, data, size);
|
|
||||||
|
|
||||||
/* User data */
|
/* User data */
|
||||||
void *user = (void *) 13;
|
void *user = (void *) 13;
|
||||||
|
|
||||||
/* Parse it */
|
/* Iterate the padded fuzz as chunks */
|
||||||
httpParser.consumePostPadded(padded, size, user, [](void *s, uWS::HttpRequest *httpRequest) -> void * {
|
makeChunked(makePadded(data, size), size, [&httpParser, user](const uint8_t *data, size_t size) {
|
||||||
|
/* Parse it */
|
||||||
|
httpParser.consumePostPadded((char *) data, size, user, [](void *s, uWS::HttpRequest *httpRequest) -> void * {
|
||||||
|
|
||||||
/* todo: Route this via router */
|
/* todo: Route this via router */
|
||||||
|
|
||||||
httpRequest->getHeader(httpRequest->getUrl());
|
readBytes(httpRequest->getHeader(httpRequest->getUrl()));
|
||||||
httpRequest->getMethod();
|
readBytes(httpRequest->getMethod());
|
||||||
httpRequest->getQuery();
|
readBytes(httpRequest->getQuery());
|
||||||
|
|
||||||
/* Route the method and URL in two passes */
|
/* Route the method and URL in two passes */
|
||||||
StaticData::RouterData routerData = {};
|
StaticData::RouterData routerData = {};
|
||||||
if (!staticData.router.route(httpRequest->getMethod(), httpRequest->getUrl(), routerData)) {
|
if (!staticData.router.route(httpRequest->getMethod(), httpRequest->getUrl(), routerData)) {
|
||||||
/* It was not handled */
|
/* It was not handled */
|
||||||
|
return nullptr;
|
||||||
|
}
|
||||||
|
|
||||||
|
for (auto p : *httpRequest) {
|
||||||
|
|
||||||
|
}
|
||||||
|
|
||||||
|
/* Return ok */
|
||||||
|
return s;
|
||||||
|
|
||||||
|
}, [](void *user, std::string_view data, bool fin) -> void * {
|
||||||
|
|
||||||
|
/* Return ok */
|
||||||
|
return user;
|
||||||
|
|
||||||
|
}, [](void *user) {
|
||||||
|
|
||||||
|
/* Return break */
|
||||||
return nullptr;
|
return nullptr;
|
||||||
}
|
});
|
||||||
|
|
||||||
for (auto p : *httpRequest) {
|
|
||||||
|
|
||||||
}
|
|
||||||
|
|
||||||
/* Return ok */
|
|
||||||
return s;
|
|
||||||
|
|
||||||
}, [](void *user, std::string_view data, bool fin) -> void * {
|
|
||||||
|
|
||||||
/* Return ok */
|
|
||||||
return user;
|
|
||||||
|
|
||||||
}, [](void *user) {
|
|
||||||
|
|
||||||
/* Return break */
|
|
||||||
return nullptr;
|
|
||||||
});
|
});
|
||||||
|
|
||||||
return 0;
|
return 0;
|
||||||
|
|||||||
+1
-1
@@ -248,7 +248,7 @@ public:
|
|||||||
|
|
||||||
int maxCopyDistance = std::min(MAX_FALLBACK_SIZE - fallback.length(), (size_t) length);
|
int maxCopyDistance = std::min(MAX_FALLBACK_SIZE - fallback.length(), (size_t) length);
|
||||||
|
|
||||||
fallback.reserve(maxCopyDistance + 32); // todo: padding should be same as libus
|
fallback.reserve(fallback.length() + maxCopyDistance + 32); // todo: padding should be same as libus
|
||||||
fallback.append(data, maxCopyDistance);
|
fallback.append(data, maxCopyDistance);
|
||||||
|
|
||||||
// break here on break
|
// break here on break
|
||||||
|
|||||||
+1
-1
Submodule uSockets updated: 7574cd2050...5a4570eac1
Reference in New Issue
Block a user