Skip to content

Commit b8598eb

Browse files
practicalswiftFabcien
authored andcommitted
tests: Add fuzzing harness for serialization/deserialization of floating-points and integrals
Summary: ``` Add simple fuzzing harness for functions with floating-point parameters (such as ser_double_to_uint64(double), etc.). Add serialization/deserialization fuzzing for integral types. ``` Backport of core [[bitcoin/bitcoin#17996 | PR17996]]. The first and last commit are not relevant to us. Test Plan: ninja bitcoin-fuzzers ./test/fuzz/test_runner.py <path_to_corpus> Reviewers: #bitcoin_abc, deadalnix Reviewed By: #bitcoin_abc, deadalnix Differential Revision: https://reviews.bitcoinabc.org/D8249
1 parent 5a1a1b1 commit b8598eb

File tree

3 files changed

+110
-0
lines changed

3 files changed

+110
-0
lines changed

src/test/fuzz/CMakeLists.txt

+1
Original file line numberDiff line numberDiff line change
@@ -84,6 +84,7 @@ add_regular_fuzz_targets(
8484
cashaddr
8585
descriptor_parse
8686
eval_script
87+
float
8788
hex
8889
integer
8990
net_permissions

src/test/fuzz/float.cpp

+42
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,42 @@
1+
// Copyright (c) 2020 The Bitcoin Core developers
2+
// Distributed under the MIT software license, see the accompanying
3+
// file COPYING or http://www.opensource.org/licenses/mit-license.php.
4+
5+
#include <memusage.h>
6+
#include <serialize.h>
7+
#include <streams.h>
8+
#include <version.h>
9+
10+
#include <test/fuzz/FuzzedDataProvider.h>
11+
#include <test/fuzz/fuzz.h>
12+
13+
#include <cassert>
14+
#include <cstdint>
15+
16+
void test_one_input(const std::vector<uint8_t> &buffer) {
17+
FuzzedDataProvider fuzzed_data_provider(buffer.data(), buffer.size());
18+
19+
{
20+
const double d = fuzzed_data_provider.ConsumeFloatingPoint<double>();
21+
(void)memusage::DynamicUsage(d);
22+
assert(ser_uint64_to_double(ser_double_to_uint64(d)) == d);
23+
24+
CDataStream stream(SER_NETWORK, INIT_PROTO_VERSION);
25+
stream << d;
26+
double d_deserialized;
27+
stream >> d_deserialized;
28+
assert(d == d_deserialized);
29+
}
30+
31+
{
32+
const float f = fuzzed_data_provider.ConsumeFloatingPoint<float>();
33+
(void)memusage::DynamicUsage(f);
34+
assert(ser_uint32_to_float(ser_float_to_uint32(f)) == f);
35+
36+
CDataStream stream(SER_NETWORK, INIT_PROTO_VERSION);
37+
stream << f;
38+
float f_deserialized;
39+
stream >> f_deserialized;
40+
assert(f == f_deserialized);
41+
}
42+
}

src/test/fuzz/integer.cpp

+67
Original file line numberDiff line numberDiff line change
@@ -21,10 +21,12 @@
2121
#include <script/signingprovider.h>
2222
#include <script/standard.h>
2323
#include <serialize.h>
24+
#include <streams.h>
2425
#include <uint256.h>
2526
#include <util/strencodings.h>
2627
#include <util/system.h>
2728
#include <util/time.h>
29+
#include <version.h>
2830

2931
#include <test/fuzz/FuzzedDataProvider.h>
3032
#include <test/fuzz/fuzz.h>
@@ -57,6 +59,7 @@ void test_one_input(const std::vector<uint8_t> &buffer) {
5759
// We cannot assume a specific value of std::is_signed<char>::value:
5860
// ConsumeIntegral<char>() instead of casting from {u,}int8_t.
5961
const char ch = fuzzed_data_provider.ConsumeIntegral<char>();
62+
const bool b = fuzzed_data_provider.ConsumeBool();
6063

6164
const Consensus::Params &consensus_params = Params().GetConsensus();
6265
(void)CheckProofOfWork(BlockHash(u256), u32, consensus_params);
@@ -131,4 +134,68 @@ void test_one_input(const std::vector<uint8_t> &buffer) {
131134
(void)GetScriptForDestination(destination);
132135
(void)IsValidDestination(destination);
133136
}
137+
138+
{
139+
CDataStream stream(SER_NETWORK, INIT_PROTO_VERSION);
140+
141+
uint256 deserialized_u256;
142+
stream << u256;
143+
stream >> deserialized_u256;
144+
assert(u256 == deserialized_u256 && stream.empty());
145+
146+
uint160 deserialized_u160;
147+
stream << u160;
148+
stream >> deserialized_u160;
149+
assert(u160 == deserialized_u160 && stream.empty());
150+
151+
uint64_t deserialized_u64;
152+
stream << u64;
153+
stream >> deserialized_u64;
154+
assert(u64 == deserialized_u64 && stream.empty());
155+
156+
int64_t deserialized_i64;
157+
stream << i64;
158+
stream >> deserialized_i64;
159+
assert(i64 == deserialized_i64 && stream.empty());
160+
161+
uint32_t deserialized_u32;
162+
stream << u32;
163+
stream >> deserialized_u32;
164+
assert(u32 == deserialized_u32 && stream.empty());
165+
166+
int32_t deserialized_i32;
167+
stream << i32;
168+
stream >> deserialized_i32;
169+
assert(i32 == deserialized_i32 && stream.empty());
170+
171+
uint16_t deserialized_u16;
172+
stream << u16;
173+
stream >> deserialized_u16;
174+
assert(u16 == deserialized_u16 && stream.empty());
175+
176+
int16_t deserialized_i16;
177+
stream << i16;
178+
stream >> deserialized_i16;
179+
assert(i16 == deserialized_i16 && stream.empty());
180+
181+
uint8_t deserialized_u8;
182+
stream << u8;
183+
stream >> deserialized_u8;
184+
assert(u8 == deserialized_u8 && stream.empty());
185+
186+
int8_t deserialized_i8;
187+
stream << i8;
188+
stream >> deserialized_i8;
189+
assert(i8 == deserialized_i8 && stream.empty());
190+
191+
char deserialized_ch;
192+
stream << ch;
193+
stream >> deserialized_ch;
194+
assert(ch == deserialized_ch && stream.empty());
195+
196+
bool deserialized_b;
197+
stream << b;
198+
stream >> deserialized_b;
199+
assert(b == deserialized_b && stream.empty());
200+
}
134201
}

0 commit comments

Comments
 (0)