|
|
4bff0a |
From aec984020cd22ac8a199bcd067047fba50850889 Mon Sep 17 00:00:00 2001
|
|
|
4bff0a |
From: Evgeny Vereshchagin <evvers@ya.ru>
|
|
|
4bff0a |
Date: Wed, 26 Sep 2018 15:04:26 +0000
|
|
|
4bff0a |
Subject: [PATCH] tests: add a fuzzer for sd-ndisc
|
|
|
4bff0a |
|
|
|
4bff0a |
(cherry picked from commit 0f0a1dad7d69802a7e6c7fc9aba350f0e87c1952)
|
|
|
4bff0a |
|
|
|
4bff0a |
Resolves: #1696224
|
|
|
4bff0a |
---
|
|
|
4bff0a |
src/fuzz/fuzz-ndisc-rs.c | 57 ++++++++++++++++++++++++++++++++++++++++
|
|
|
4bff0a |
src/fuzz/meson.build | 10 +++++++
|
|
|
4bff0a |
2 files changed, 67 insertions(+)
|
|
|
4bff0a |
create mode 100644 src/fuzz/fuzz-ndisc-rs.c
|
|
|
4bff0a |
|
|
|
4bff0a |
diff --git a/src/fuzz/fuzz-ndisc-rs.c b/src/fuzz/fuzz-ndisc-rs.c
|
|
|
4bff0a |
new file mode 100644
|
|
|
4bff0a |
index 0000000000..7f2d8f8649
|
|
|
4bff0a |
--- /dev/null
|
|
|
4bff0a |
+++ b/src/fuzz/fuzz-ndisc-rs.c
|
|
|
4bff0a |
@@ -0,0 +1,57 @@
|
|
|
4bff0a |
+/* SPDX-License-Identifier: LGPL-2.1+ */
|
|
|
4bff0a |
+
|
|
|
4bff0a |
+#include <netinet/icmp6.h>
|
|
|
4bff0a |
+#include <arpa/inet.h>
|
|
|
4bff0a |
+
|
|
|
4bff0a |
+#include "alloc-util.h"
|
|
|
4bff0a |
+#include "icmp6-util.h"
|
|
|
4bff0a |
+#include "fuzz.h"
|
|
|
4bff0a |
+#include "sd-ndisc.h"
|
|
|
4bff0a |
+#include "socket-util.h"
|
|
|
4bff0a |
+#include "ndisc-internal.h"
|
|
|
4bff0a |
+
|
|
|
4bff0a |
+static int test_fd[2];
|
|
|
4bff0a |
+
|
|
|
4bff0a |
+int icmp6_bind_router_solicitation(int index) {
|
|
|
4bff0a |
+ assert_se(socketpair(AF_UNIX, SOCK_DGRAM, 0, test_fd) >= 0);
|
|
|
4bff0a |
+ return test_fd[0];
|
|
|
4bff0a |
+}
|
|
|
4bff0a |
+
|
|
|
4bff0a |
+int icmp6_bind_router_advertisement(int index) {
|
|
|
4bff0a |
+ return -ENOSYS;
|
|
|
4bff0a |
+}
|
|
|
4bff0a |
+
|
|
|
4bff0a |
+int icmp6_receive(int fd, void *iov_base, size_t iov_len,
|
|
|
4bff0a |
+ struct in6_addr *dst, triple_timestamp *timestamp) {
|
|
|
4bff0a |
+ assert_se(read(fd, iov_base, iov_len) == (ssize_t) iov_len);
|
|
|
4bff0a |
+
|
|
|
4bff0a |
+ if (timestamp)
|
|
|
4bff0a |
+ triple_timestamp_get(timestamp);
|
|
|
4bff0a |
+
|
|
|
4bff0a |
+ return 0;
|
|
|
4bff0a |
+}
|
|
|
4bff0a |
+
|
|
|
4bff0a |
+int icmp6_send_router_solicitation(int s, const struct ether_addr *ether_addr) {
|
|
|
4bff0a |
+ return 0;
|
|
|
4bff0a |
+}
|
|
|
4bff0a |
+
|
|
|
4bff0a |
+int LLVMFuzzerTestOneInput(const uint8_t *data, size_t size) {
|
|
|
4bff0a |
+ struct ether_addr mac_addr = {
|
|
|
4bff0a |
+ .ether_addr_octet = {'A', 'B', 'C', '1', '2', '3'}
|
|
|
4bff0a |
+ };
|
|
|
4bff0a |
+ _cleanup_(sd_event_unrefp) sd_event *e = NULL;
|
|
|
4bff0a |
+ _cleanup_(sd_ndisc_unrefp) sd_ndisc *nd = NULL;
|
|
|
4bff0a |
+
|
|
|
4bff0a |
+ assert_se(sd_event_new(&e) >= 0);
|
|
|
4bff0a |
+ assert_se(sd_ndisc_new(&nd) >= 0);
|
|
|
4bff0a |
+ assert_se(sd_ndisc_attach_event(nd, e, 0) >= 0);
|
|
|
4bff0a |
+ assert_se(sd_ndisc_set_ifindex(nd, 42) >= 0);
|
|
|
4bff0a |
+ assert_se(sd_ndisc_set_mac(nd, &mac_addr) >= 0);
|
|
|
4bff0a |
+ assert_se(sd_ndisc_start(nd) >= 0);
|
|
|
4bff0a |
+ assert_se(write(test_fd[1], data, size) == (ssize_t) size);
|
|
|
4bff0a |
+ (void) sd_event_run(e, (uint64_t) -1);
|
|
|
4bff0a |
+ assert_se(sd_ndisc_stop(nd) >= 0);
|
|
|
4bff0a |
+ close(test_fd[1]);
|
|
|
4bff0a |
+
|
|
|
4bff0a |
+ return 0;
|
|
|
4bff0a |
+}
|
|
|
4bff0a |
diff --git a/src/fuzz/meson.build b/src/fuzz/meson.build
|
|
|
4bff0a |
index 5a97ef5091..5c81ac0c5b 100644
|
|
|
4bff0a |
--- a/src/fuzz/meson.build
|
|
|
4bff0a |
+++ b/src/fuzz/meson.build
|
|
|
4bff0a |
@@ -14,6 +14,16 @@ fuzzers += [
|
|
|
4bff0a |
libshared],
|
|
|
4bff0a |
[]],
|
|
|
4bff0a |
|
|
|
4bff0a |
+ [['src/fuzz/fuzz-ndisc-rs.c',
|
|
|
4bff0a |
+ 'src/libsystemd-network/dhcp-identifier.h',
|
|
|
4bff0a |
+ 'src/libsystemd-network/dhcp-identifier.c',
|
|
|
4bff0a |
+ 'src/libsystemd-network/icmp6-util.h',
|
|
|
4bff0a |
+ 'src/systemd/sd-dhcp6-client.h',
|
|
|
4bff0a |
+ 'src/systemd/sd-ndisc.h'],
|
|
|
4bff0a |
+ [libshared,
|
|
|
4bff0a |
+ libsystemd_network],
|
|
|
4bff0a |
+ []],
|
|
|
4bff0a |
+
|
|
|
4bff0a |
[['src/fuzz/fuzz-unit-file.c'],
|
|
|
4bff0a |
[libcore,
|
|
|
4bff0a |
libshared],
|