annotate fuzzer-preauth.c @ 1408:27e65d3aed5f fuzz

fix checkmac always failing pre-kex
author Matt Johnston <matt@ucc.asn.au>
date Sun, 11 Jun 2017 21:39:40 +0800
parents f0990c284663
children a90fdd2d2ed8
Ignore whitespace changes - Everywhere: Within whitespace: At end of lines:
rev   line source
1348
5c2899e35b63 fuzz harness
Matt Johnston <matt@ucc.asn.au>
parents:
diff changeset
1 #include "fuzz.h"
5c2899e35b63 fuzz harness
Matt Johnston <matt@ucc.asn.au>
parents:
diff changeset
2 #include "session.h"
1356
3677a510f545 add wrapfd. improve fuzzer in makefile
Matt Johnston <matt@ucc.asn.au>
parents: 1348
diff changeset
3 #include "fuzz-wrapfd.h"
1358
6b89eb92f872 glaring wrapfd problems fixed
Matt Johnston <matt@ucc.asn.au>
parents: 1357
diff changeset
4 #include "debug.h"
1348
5c2899e35b63 fuzz harness
Matt Johnston <matt@ucc.asn.au>
parents:
diff changeset
5
1356
3677a510f545 add wrapfd. improve fuzzer in makefile
Matt Johnston <matt@ucc.asn.au>
parents: 1348
diff changeset
6 static void setup_fuzzer(void) {
1348
5c2899e35b63 fuzz harness
Matt Johnston <matt@ucc.asn.au>
parents:
diff changeset
7 svr_setup_fuzzer();
1358
6b89eb92f872 glaring wrapfd problems fixed
Matt Johnston <matt@ucc.asn.au>
parents: 1357
diff changeset
8 //debug_trace = 1;
1348
5c2899e35b63 fuzz harness
Matt Johnston <matt@ucc.asn.au>
parents:
diff changeset
9 }
5c2899e35b63 fuzz harness
Matt Johnston <matt@ucc.asn.au>
parents:
diff changeset
10
5c2899e35b63 fuzz harness
Matt Johnston <matt@ucc.asn.au>
parents:
diff changeset
11 int LLVMFuzzerTestOneInput(const uint8_t *Data, size_t Size) {
5c2899e35b63 fuzz harness
Matt Johnston <matt@ucc.asn.au>
parents:
diff changeset
12 static int once = 0;
5c2899e35b63 fuzz harness
Matt Johnston <matt@ucc.asn.au>
parents:
diff changeset
13 if (!once) {
5c2899e35b63 fuzz harness
Matt Johnston <matt@ucc.asn.au>
parents:
diff changeset
14 setup_fuzzer();
5c2899e35b63 fuzz harness
Matt Johnston <matt@ucc.asn.au>
parents:
diff changeset
15 once = 1;
5c2899e35b63 fuzz harness
Matt Johnston <matt@ucc.asn.au>
parents:
diff changeset
16 }
5c2899e35b63 fuzz harness
Matt Johnston <matt@ucc.asn.au>
parents:
diff changeset
17
1356
3677a510f545 add wrapfd. improve fuzzer in makefile
Matt Johnston <matt@ucc.asn.au>
parents: 1348
diff changeset
18 if (fuzzer_set_input(Data, Size) == DROPBEAR_FAILURE) {
3677a510f545 add wrapfd. improve fuzzer in makefile
Matt Johnston <matt@ucc.asn.au>
parents: 1348
diff changeset
19 return 0;
3677a510f545 add wrapfd. improve fuzzer in makefile
Matt Johnston <matt@ucc.asn.au>
parents: 1348
diff changeset
20 }
1348
5c2899e35b63 fuzz harness
Matt Johnston <matt@ucc.asn.au>
parents:
diff changeset
21
1384
ecdd4e8ae427 don't longjmp for fuzzer-preauth (temporary to debug asan)
Matt Johnston <matt@ucc.asn.au>
parents: 1383
diff changeset
22 // get prefix. input format is
ecdd4e8ae427 don't longjmp for fuzzer-preauth (temporary to debug asan)
Matt Johnston <matt@ucc.asn.au>
parents: 1383
diff changeset
23 // string prefix
ecdd4e8ae427 don't longjmp for fuzzer-preauth (temporary to debug asan)
Matt Johnston <matt@ucc.asn.au>
parents: 1383
diff changeset
24 // uint32 wrapfd seed
ecdd4e8ae427 don't longjmp for fuzzer-preauth (temporary to debug asan)
Matt Johnston <matt@ucc.asn.au>
parents: 1383
diff changeset
25 // ... to be extended later
ecdd4e8ae427 don't longjmp for fuzzer-preauth (temporary to debug asan)
Matt Johnston <matt@ucc.asn.au>
parents: 1383
diff changeset
26 // [bytes] ssh input stream
1377
d4cc85e6c569 rearrange, all fuzzers now call fuzzer_set_input()
Matt Johnston <matt@ucc.asn.au>
parents: 1364
diff changeset
27
1384
ecdd4e8ae427 don't longjmp for fuzzer-preauth (temporary to debug asan)
Matt Johnston <matt@ucc.asn.au>
parents: 1383
diff changeset
28 // be careful to avoid triggering buffer.c assertions
ecdd4e8ae427 don't longjmp for fuzzer-preauth (temporary to debug asan)
Matt Johnston <matt@ucc.asn.au>
parents: 1383
diff changeset
29 if (fuzz.input->len < 8) {
ecdd4e8ae427 don't longjmp for fuzzer-preauth (temporary to debug asan)
Matt Johnston <matt@ucc.asn.au>
parents: 1383
diff changeset
30 return 0;
ecdd4e8ae427 don't longjmp for fuzzer-preauth (temporary to debug asan)
Matt Johnston <matt@ucc.asn.au>
parents: 1383
diff changeset
31 }
ecdd4e8ae427 don't longjmp for fuzzer-preauth (temporary to debug asan)
Matt Johnston <matt@ucc.asn.au>
parents: 1383
diff changeset
32 size_t prefix_size = buf_getint(fuzz.input);
ecdd4e8ae427 don't longjmp for fuzzer-preauth (temporary to debug asan)
Matt Johnston <matt@ucc.asn.au>
parents: 1383
diff changeset
33 if (prefix_size != 4) {
ecdd4e8ae427 don't longjmp for fuzzer-preauth (temporary to debug asan)
Matt Johnston <matt@ucc.asn.au>
parents: 1383
diff changeset
34 return 0;
ecdd4e8ae427 don't longjmp for fuzzer-preauth (temporary to debug asan)
Matt Johnston <matt@ucc.asn.au>
parents: 1383
diff changeset
35 }
ecdd4e8ae427 don't longjmp for fuzzer-preauth (temporary to debug asan)
Matt Johnston <matt@ucc.asn.au>
parents: 1383
diff changeset
36 uint32_t wrapseed = buf_getint(fuzz.input);
ecdd4e8ae427 don't longjmp for fuzzer-preauth (temporary to debug asan)
Matt Johnston <matt@ucc.asn.au>
parents: 1383
diff changeset
37 wrapfd_setseed(wrapseed);
1377
d4cc85e6c569 rearrange, all fuzzers now call fuzzer_set_input()
Matt Johnston <matt@ucc.asn.au>
parents: 1364
diff changeset
38
1383
f03cfe9c76ac Disable setnonblocking(), get_socket_address(), set_sock_priority()
Matt Johnston <matt@ucc.asn.au>
parents: 1378
diff changeset
39 int fakesock = 20;
1356
3677a510f545 add wrapfd. improve fuzzer in makefile
Matt Johnston <matt@ucc.asn.au>
parents: 1348
diff changeset
40 wrapfd_add(fakesock, fuzz.input, PLAIN);
1348
5c2899e35b63 fuzz harness
Matt Johnston <matt@ucc.asn.au>
parents:
diff changeset
41
1361
f9f930e1a516 add dbmalloc epoch cleanup
Matt Johnston <matt@ucc.asn.au>
parents: 1358
diff changeset
42 m_malloc_set_epoch(1);
1348
5c2899e35b63 fuzz harness
Matt Johnston <matt@ucc.asn.au>
parents:
diff changeset
43 if (setjmp(fuzz.jmp) == 0) {
1356
3677a510f545 add wrapfd. improve fuzzer in makefile
Matt Johnston <matt@ucc.asn.au>
parents: 1348
diff changeset
44 svr_session(fakesock, fakesock);
1384
ecdd4e8ae427 don't longjmp for fuzzer-preauth (temporary to debug asan)
Matt Johnston <matt@ucc.asn.au>
parents: 1383
diff changeset
45 m_malloc_free_epoch(1, 0);
1348
5c2899e35b63 fuzz harness
Matt Johnston <matt@ucc.asn.au>
parents:
diff changeset
46 } else {
1378
7209a6e30932 linked list dbmalloc now
Matt Johnston <matt@ucc.asn.au>
parents: 1377
diff changeset
47 m_malloc_free_epoch(1, 1);
1357
08f4fa4dc6a0 closer to working
Matt Johnston <matt@ucc.asn.au>
parents: 1356
diff changeset
48 TRACE(("dropbear_exit longjmped"))
1348
5c2899e35b63 fuzz harness
Matt Johnston <matt@ucc.asn.au>
parents:
diff changeset
49 // dropbear_exit jumped here
5c2899e35b63 fuzz harness
Matt Johnston <matt@ucc.asn.au>
parents:
diff changeset
50 }
5c2899e35b63 fuzz harness
Matt Johnston <matt@ucc.asn.au>
parents:
diff changeset
51
5c2899e35b63 fuzz harness
Matt Johnston <matt@ucc.asn.au>
parents:
diff changeset
52 return 0;
5c2899e35b63 fuzz harness
Matt Johnston <matt@ucc.asn.au>
parents:
diff changeset
53 }