Files
tomato/toxcore/group_announce_fuzz_test.cc
Green Sky 9b36dd9d99 Squashed 'external/toxcore/c-toxcore/' changes from c9cdae001..9ed2fa80d
9ed2fa80d fix(toxav): remove extra copy of video frame on encode
de30cf3ad docs: Add new file kinds, that should be useful to all clients.
d5b5e879d fix(DHT): Correct node skipping logic timed out nodes.
30e71fe97 refactor: Generate event dispatch functions and add tox_events_dispatch.
8fdbb0b50 style: Format parameter lists in event handlers.
d00dee12b refactor: Add warning logs when losing chat invites.
b144e8db1 feat: Add a way to look up a file number by ID.
849281ea0 feat: Add a way to fetch groups by chat ID.
a2c177396 refactor: Harden event system and improve type safety.
8f5caa656 refactor: Add MessagePack string support to bin_pack.
34e8d5ad5 chore: Add GitHub CodeQL workflow and local Docker runner.
f7b068010 refactor: Add nullability annotations to event headers.
788abe651 refactor(toxav): Use system allocator for mutexes.
2e4b423eb refactor: Use specific typedefs for public API arrays.
2baf34775 docs(toxav): update idle iteration interval see 679444751876fa3882a717772918ebdc8f083354
2f87ac67b feat: Add Event Loop abstraction (Ev).
f8dfc38d8 test: Fix data race in ToxScenario virtual_clock.
38313921e test(TCP): Add regression test for TCP priority queue integrity.
f94a50d9a refactor(toxav): Replace mutable_mutex with dynamically allocated mutex.
ad054511e refactor: Internalize DHT structs and add debug helpers.
8b467cc96 fix: Prevent potential integer overflow in group chat handshake.
4962bdbb8 test: Improve TCP simulation and add tests
5f0227093 refactor: Allow nullable data in group chat handlers.
e97b18ea9 chore: Improve Windows Docker support.
b14943bbd refactor: Move Logger out of Messenger into Tox.
dd3136250 cleanup: Apply nullability qualifiers to C++ codebase.
1849f70fc refactor: Extract low-level networking code to net and os_network.
8fec75421 refactor: Delete tox_random, align on rng and os_random.
a03ae8051 refactor: Delete tox_memory, align on mem and os_memory.
4c88fed2c refactor: Use `std::` prefixes more consistently in C++ code.
72452f2ae test: Add some more tests for onion and shared key cache.
d5a51b09a cleanup: Use tox_attributes.h in tox_private.h and install it.
b6f5b9fc5 test: Add some benchmarks for various high level things.
8a8d02785 test(support): Introduce threaded Tox runner and simulation barrier
d68d1d095 perf(toxav): optimize audio and video intermediate buffers by keeping them around
REVERT: c9cdae001 fix(toxav): remove extra copy of video frame on encode

git-subtree-dir: external/toxcore/c-toxcore
git-subtree-split: 9ed2fa80d582c714d6bdde6a7648220a92cddff8
2026-02-01 14:26:52 +01:00

130 lines
4.7 KiB
C++

#include "group_announce.h"
#include <cassert>
#include <functional>
#include <memory>
#include <vector>
#include "../testing/support/public/fuzz_data.hh"
#include "../testing/support/public/simulated_environment.hh"
#include "attributes.h"
namespace {
using tox::test::FakeClock;
using tox::test::Fuzz_Data;
using tox::test::SimulatedEnvironment;
void TestUnpackAnnouncesList(Fuzz_Data &input)
{
CONSUME1_OR_RETURN(const std::uint8_t, max_count, input);
// Always allocate at least something to avoid passing nullptr to functions below.
std::vector<GC_Announce> announces(max_count + 1);
// TODO(iphydf): How do we know the packed size?
CONSUME1_OR_RETURN(const std::uint16_t, packed_size, input);
SimulatedEnvironment env;
auto c_mem = env.fake_memory().c_memory();
Logger *logger = logger_new(&c_mem);
if (gca_unpack_announces_list(logger, input.data(), input.size(), announces.data(), max_count)
!= -1) {
// Always allocate at least something to avoid passing nullptr to functions below.
std::vector<std::uint8_t> packed(packed_size + 1);
std::size_t processed;
gca_pack_announces_list(
logger, packed.data(), packed_size, announces.data(), max_count, &processed);
}
logger_kill(logger);
}
void TestUnpackPublicAnnounce(Fuzz_Data &input)
{
GC_Public_Announce public_announce;
// TODO(iphydf): How do we know the packed size?
CONSUME1_OR_RETURN(const std::uint16_t, packed_size, input);
SimulatedEnvironment env;
auto c_mem = env.fake_memory().c_memory();
Logger *logger = logger_new(&c_mem);
if (gca_unpack_public_announce(logger, input.data(), input.size(), &public_announce) != -1) {
// Always allocate at least something to avoid passing nullptr to functions below.
std::vector<std::uint8_t> packed(packed_size + 1);
gca_pack_public_announce(logger, packed.data(), packed_size, &public_announce);
}
logger_kill(logger);
}
void TestDoGca(Fuzz_Data &input)
{
SimulatedEnvironment env;
auto c_mem = env.fake_memory().c_memory();
std::unique_ptr<Logger, void (*)(Logger *)> logger(logger_new(&c_mem), logger_kill);
std::unique_ptr<Mono_Time, std::function<void(Mono_Time *)>> mono_time(
mono_time_new(
&c_mem,
[](void *_Nullable user_data) -> std::uint64_t {
return static_cast<FakeClock *>(user_data)->current_time_ms();
},
&env.fake_clock()),
[c_mem](Mono_Time *ptr) { mono_time_free(&c_mem, ptr); });
assert(mono_time != nullptr);
std::unique_ptr<GC_Announces_List, std::function<void(GC_Announces_List *)>> gca(
new_gca_list(&c_mem), [](GC_Announces_List *ptr) { kill_gca(ptr); });
assert(gca != nullptr);
while (!input.empty()) {
CONSUME1_OR_RETURN(const std::uint8_t, choice, input);
switch (choice) {
case 0: {
// Add an announce.
CONSUME1_OR_RETURN(const std::uint16_t, length, input);
CONSUME_OR_RETURN(const std::uint8_t *data, input, length);
GC_Public_Announce public_announce;
if (gca_unpack_public_announce(logger.get(), data, length, &public_announce) != -1) {
gca_add_announce(&c_mem, mono_time.get(), gca.get(), &public_announce);
}
break;
}
case 1: {
// Advance the time by a number of tox_iteration_intervals.
CONSUME1_OR_RETURN(const std::uint8_t, iterations, input);
env.fake_clock().advance(iterations * 20);
// Do an iteration.
do_gca(mono_time.get(), gca.get());
break;
}
case 2: {
// Get announces.
CONSUME1_OR_RETURN(const std::uint8_t, max_nodes, input);
// Always allocate at least something to avoid passing nullptr to functions below.
std::vector<GC_Announce> gc_announces(max_nodes + 1);
CONSUME_OR_RETURN(const std::uint8_t *chat_id, input, CHAT_ID_SIZE);
CONSUME_OR_RETURN(const std::uint8_t *except_public_key, input, ENC_PUBLIC_KEY_SIZE);
gca_get_announces(
gca.get(), gc_announces.data(), max_nodes, chat_id, except_public_key);
break;
}
case 3: {
// Remove a chat.
CONSUME_OR_RETURN(const std::uint8_t *chat_id, input, CHAT_ID_SIZE);
cleanup_gca(gca.get(), chat_id);
break;
}
}
}
}
} // namespace
extern "C" int LLVMFuzzerTestOneInput(const std::uint8_t *data, std::size_t size);
extern "C" int LLVMFuzzerTestOneInput(const std::uint8_t *data, std::size_t size)
{
tox::test::fuzz_select_target<TestUnpackAnnouncesList, TestUnpackPublicAnnounce, TestDoGca>(
data, size);
return 0;
}