Skip to content

Commit 03aaa63

Browse files
committed
Fuzz the new FeatureFlags storage
No new datastructure would be complete without a dedicated fuzzer, so we add one here.
1 parent ee28ee2 commit 03aaa63

File tree

6 files changed

+226
-6
lines changed

6 files changed

+226
-6
lines changed

Diff for: fuzz/src/bin/feature_flags_target.rs

+120
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,120 @@
1+
// This file is Copyright its original authors, visible in version control
2+
// history.
3+
//
4+
// This file is licensed under the Apache License, Version 2.0 <LICENSE-APACHE
5+
// or http://www.apache.org/licenses/LICENSE-2.0> or the MIT license
6+
// <LICENSE-MIT or http://opensource.org/licenses/MIT>, at your option.
7+
// You may not use this file except in accordance with one or both of these
8+
// licenses.
9+
10+
// This file is auto-generated by gen_target.sh based on target_template.txt
11+
// To modify it, modify target_template.txt and run gen_target.sh instead.
12+
13+
#![cfg_attr(feature = "libfuzzer_fuzz", no_main)]
14+
#![cfg_attr(rustfmt, rustfmt_skip)]
15+
16+
#[cfg(not(fuzzing))]
17+
compile_error!("Fuzz targets need cfg=fuzzing");
18+
19+
#[cfg(not(hashes_fuzz))]
20+
compile_error!("Fuzz targets need cfg=hashes_fuzz");
21+
22+
#[cfg(not(secp256k1_fuzz))]
23+
compile_error!("Fuzz targets need cfg=secp256k1_fuzz");
24+
25+
extern crate lightning_fuzz;
26+
use lightning_fuzz::feature_flags::*;
27+
28+
#[cfg(feature = "afl")]
29+
#[macro_use] extern crate afl;
30+
#[cfg(feature = "afl")]
31+
fn main() {
32+
fuzz!(|data| {
33+
feature_flags_run(data.as_ptr(), data.len());
34+
});
35+
}
36+
37+
#[cfg(feature = "honggfuzz")]
38+
#[macro_use] extern crate honggfuzz;
39+
#[cfg(feature = "honggfuzz")]
40+
fn main() {
41+
loop {
42+
fuzz!(|data| {
43+
feature_flags_run(data.as_ptr(), data.len());
44+
});
45+
}
46+
}
47+
48+
#[cfg(feature = "libfuzzer_fuzz")]
49+
#[macro_use] extern crate libfuzzer_sys;
50+
#[cfg(feature = "libfuzzer_fuzz")]
51+
fuzz_target!(|data: &[u8]| {
52+
feature_flags_run(data.as_ptr(), data.len());
53+
});
54+
55+
#[cfg(feature = "stdin_fuzz")]
56+
fn main() {
57+
use std::io::Read;
58+
59+
let mut data = Vec::with_capacity(8192);
60+
std::io::stdin().read_to_end(&mut data).unwrap();
61+
feature_flags_run(data.as_ptr(), data.len());
62+
}
63+
64+
#[test]
65+
fn run_test_cases() {
66+
use std::fs;
67+
use std::io::Read;
68+
use lightning_fuzz::utils::test_logger::StringBuffer;
69+
70+
use std::sync::{atomic, Arc};
71+
{
72+
let data: Vec<u8> = vec![0];
73+
feature_flags_run(data.as_ptr(), data.len());
74+
}
75+
let mut threads = Vec::new();
76+
let threads_running = Arc::new(atomic::AtomicUsize::new(0));
77+
if let Ok(tests) = fs::read_dir("test_cases/feature_flags") {
78+
for test in tests {
79+
let mut data: Vec<u8> = Vec::new();
80+
let path = test.unwrap().path();
81+
fs::File::open(&path).unwrap().read_to_end(&mut data).unwrap();
82+
threads_running.fetch_add(1, atomic::Ordering::AcqRel);
83+
84+
let thread_count_ref = Arc::clone(&threads_running);
85+
let main_thread_ref = std::thread::current();
86+
threads.push((path.file_name().unwrap().to_str().unwrap().to_string(),
87+
std::thread::spawn(move || {
88+
let string_logger = StringBuffer::new();
89+
90+
let panic_logger = string_logger.clone();
91+
let res = if ::std::panic::catch_unwind(move || {
92+
feature_flags_test(&data, panic_logger);
93+
}).is_err() {
94+
Some(string_logger.into_string())
95+
} else { None };
96+
thread_count_ref.fetch_sub(1, atomic::Ordering::AcqRel);
97+
main_thread_ref.unpark();
98+
res
99+
})
100+
));
101+
while threads_running.load(atomic::Ordering::Acquire) > 32 {
102+
std::thread::park();
103+
}
104+
}
105+
}
106+
let mut failed_outputs = Vec::new();
107+
for (test, thread) in threads.drain(..) {
108+
if let Some(output) = thread.join().unwrap() {
109+
println!("\nOutput of {}:\n{}\n", test, output);
110+
failed_outputs.push(test);
111+
}
112+
}
113+
if !failed_outputs.is_empty() {
114+
println!("Test cases which failed: ");
115+
for case in failed_outputs {
116+
println!("{}", case);
117+
}
118+
panic!();
119+
}
120+
}

Diff for: fuzz/src/bin/gen_target.sh

+1
Original file line numberDiff line numberDiff line change
@@ -25,6 +25,7 @@ GEN_TEST indexedmap
2525
GEN_TEST onion_hop_data
2626
GEN_TEST base32
2727
GEN_TEST fromstr_to_netaddress
28+
GEN_TEST feature_flags
2829

2930
GEN_TEST msg_accept_channel msg_targets::
3031
GEN_TEST msg_announcement_signatures msg_targets::

Diff for: fuzz/src/feature_flags.rs

+89
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,89 @@
1+
// This file is Copyright its original authors, visible in version control
2+
// history.
3+
//
4+
// This file is licensed under the Apache License, Version 2.0 <LICENSE-APACHE
5+
// or http://www.apache.org/licenses/LICENSE-2.0> or the MIT license
6+
// <LICENSE-MIT or http://opensource.org/licenses/MIT>, at your option.
7+
// You may not use this file except in accordance with one or both of these
8+
// licenses.
9+
10+
use lightning::types::features::FeatureFlags;
11+
12+
use crate::utils::test_logger;
13+
14+
use std::ops::{Deref, DerefMut};
15+
16+
fn check_eq(v: &Vec<u8>, feat: &FeatureFlags, old_v: &mut Vec<u8>, old_feat: &mut FeatureFlags) {
17+
assert_eq!(v.len(), feat.len());
18+
assert_eq!(v.deref(), feat.deref());
19+
assert_eq!(old_v.deref_mut(), old_feat.deref_mut());
20+
21+
let mut feat_clone = feat.clone();
22+
assert!(feat_clone == *feat);
23+
24+
let mut feat_iter = feat.iter();
25+
let mut vec_iter = v.iter();
26+
assert_eq!(feat_iter.len(), vec_iter.len());
27+
while let Some(feat) = feat_iter.next() {
28+
let v = vec_iter.next().unwrap();
29+
assert_eq!(*feat, *v);
30+
}
31+
assert!(vec_iter.next().is_none());
32+
33+
let mut feat_iter = feat_clone.iter_mut();
34+
let mut vec_iter = v.iter();
35+
assert_eq!(feat_iter.len(), vec_iter.len());
36+
while let Some(feat) = feat_iter.next() {
37+
let v = vec_iter.next().unwrap();
38+
assert_eq!(*feat, *v);
39+
}
40+
assert!(vec_iter.next().is_none());
41+
42+
assert_eq!(v < old_v, feat < old_feat);
43+
assert_eq!(v.partial_cmp(old_v), feat.partial_cmp(old_feat));
44+
}
45+
46+
#[inline]
47+
pub fn do_test(data: &[u8]) {
48+
if data.len() % 3 != 0 {
49+
return;
50+
}
51+
let mut vec = Vec::new();
52+
let mut features = FeatureFlags::empty();
53+
54+
for step in data.windows(3) {
55+
let mut old_vec = vec.clone();
56+
let mut old_features = features.clone();
57+
match step[0] {
58+
0 => {
59+
vec.resize(step[1] as usize, step[2]);
60+
features.resize(step[1] as usize, step[2]);
61+
},
62+
1 => {
63+
if vec.len() > step[1] as usize {
64+
vec[step[1] as usize] = step[2];
65+
features[step[1] as usize] = step[2];
66+
}
67+
},
68+
2 => {
69+
if vec.len() > step[1] as usize {
70+
*vec.iter_mut().skip(step[1] as usize).next().unwrap() = step[2];
71+
*features.iter_mut().skip(step[1] as usize).next().unwrap() = step[2];
72+
}
73+
},
74+
_ => {},
75+
}
76+
check_eq(&vec, &features, &mut old_vec, &mut old_features);
77+
}
78+
79+
check_eq(&vec, &features, &mut vec.clone(), &mut features.clone());
80+
}
81+
82+
pub fn feature_flags_test<Out: test_logger::Output>(data: &[u8], _out: Out) {
83+
do_test(data);
84+
}
85+
86+
#[no_mangle]
87+
pub extern "C" fn feature_flags_run(data: *const u8, datalen: usize) {
88+
do_test(unsafe { std::slice::from_raw_parts(data, datalen) });
89+
}

Diff for: fuzz/src/lib.rs

+1
Original file line numberDiff line numberDiff line change
@@ -18,6 +18,7 @@ pub mod bech32_parse;
1818
pub mod bolt11_deser;
1919
pub mod chanmon_consistency;
2020
pub mod chanmon_deser;
21+
pub mod feature_flags;
2122
pub mod fromstr_to_netaddress;
2223
pub mod full_stack;
2324
pub mod indexedmap;

Diff for: fuzz/targets.h

+1
Original file line numberDiff line numberDiff line change
@@ -18,6 +18,7 @@ void indexedmap_run(const unsigned char* data, size_t data_len);
1818
void onion_hop_data_run(const unsigned char* data, size_t data_len);
1919
void base32_run(const unsigned char* data, size_t data_len);
2020
void fromstr_to_netaddress_run(const unsigned char* data, size_t data_len);
21+
void feature_flags_run(const unsigned char* data, size_t data_len);
2122
void msg_accept_channel_run(const unsigned char* data, size_t data_len);
2223
void msg_announcement_signatures_run(const unsigned char* data, size_t data_len);
2324
void msg_channel_reestablish_run(const unsigned char* data, size_t data_len);

Diff for: lightning-types/src/features.rs

+14-6
Original file line numberDiff line numberDiff line change
@@ -728,11 +728,13 @@ pub enum FeatureFlags {
728728
}
729729

730730
impl FeatureFlags {
731-
fn empty() -> Self {
731+
/// Constructs an empty [`FeatureFlags`]
732+
pub fn empty() -> Self {
732733
Self::Held { bytes: [0; DIRECT_ALLOC_BYTES], len: 0 }
733734
}
734735

735-
fn from(vec: Vec<u8>) -> Self {
736+
/// Constructs a [`FeatureFlags`] from the given bytes
737+
pub fn from(vec: Vec<u8>) -> Self {
736738
if vec.len() <= DIRECT_ALLOC_BYTES {
737739
let mut bytes = [0; DIRECT_ALLOC_BYTES];
738740
bytes[..vec.len()].copy_from_slice(&vec);
@@ -742,7 +744,10 @@ impl FeatureFlags {
742744
}
743745
}
744746

745-
fn resize(&mut self, new_len: usize, default: u8) {
747+
/// Resizes a [`FeatureFlags`] to the given length, padding with `default` if required.
748+
///
749+
/// See [`Vec::resize`] for more info.
750+
pub fn resize(&mut self, new_len: usize, default: u8) {
746751
match self {
747752
Self::Held { bytes, len } => {
748753
let start_len = *len as usize;
@@ -767,16 +772,19 @@ impl FeatureFlags {
767772
}
768773
}
769774

770-
fn len(&self) -> usize {
775+
/// Fetches the length of the [`FeatureFlags`], in bytes.
776+
pub fn len(&self) -> usize {
771777
self.deref().len()
772778
}
773779

774-
fn iter(&self) -> (impl ExactSizeIterator<Item = &u8> + DoubleEndedIterator<Item = &u8>) {
780+
/// Fetches an iterator over the bytes of this [`FeatureFlags`]
781+
pub fn iter(&self) -> (impl ExactSizeIterator<Item = &u8> + DoubleEndedIterator<Item = &u8>) {
775782
let slice = self.deref();
776783
slice.iter()
777784
}
778785

779-
fn iter_mut(
786+
/// Fetches a mutable iterator over the bytes of this [`FeatureFlags`]
787+
pub fn iter_mut(
780788
&mut self,
781789
) -> (impl ExactSizeIterator<Item = &mut u8> + DoubleEndedIterator<Item = &mut u8>) {
782790
let slice = self.deref_mut();

0 commit comments

Comments
 (0)