fuzz: add fuzzer for config parsing
Add a new fuzz target that exercises the parsing of git configs. The existing git_config_from_mem function is a perfect entry point for fuzzing as it exercises the same code paths as the rest of the config parsing functions and offers an easily fuzzable interface. Config parsing is a useful thing to fuzz because it operates on user controlled data and is a central component of many git operations. Signed-off-by: Brian C Tracy <brian.tracy33@gmail.com> Signed-off-by: Junio C Hamano <gitster@pobox.com>
Brian C Tracy committed
Mar 15, 2024 at 05:47 UTC
fe2033b84f5b486c6f715fa05b4c3ce08820d402
4 files changed
+36
-1
Makefile
+1
@@ -757,6 +757,7 @@ ETAGS_TARGET = TAGS
757
# runs in the future.
758
FUZZ_OBJS += oss-fuzz/dummy-cmd-main.o
759
FUZZ_OBJS += oss-fuzz/fuzz-commit-graph.o
760
+FUZZ_OBJS += oss-fuzz/fuzz-config.o
761
FUZZ_OBJS += oss-fuzz/fuzz-date.o
762
FUZZ_OBJS += oss-fuzz/fuzz-pack-headers.o
763
FUZZ_OBJS += oss-fuzz/fuzz-pack-idx.o
ci/run-build-and-minimal-fuzzers.sh
+1
-1
@@ -12,7 +12,7 @@ group "Build fuzzers" make \
12
LIB_FUZZING_ENGINE="-fsanitize=fuzzer,address" \
13
fuzz-all
14
15
-for fuzzer in commit-graph date pack-headers pack-idx ; do
15
+for fuzzer in commit-graph config date pack-headers pack-idx ; do
16
begin_group "fuzz-$fuzzer"
17
./oss-fuzz/fuzz-$fuzzer -verbosity=0 -runs=1 || exit 1
18
end_group "fuzz-$fuzzer"
oss-fuzz/.gitignore
+1
@@ -1,4 +1,5 @@
1
fuzz-commit-graph
2
+fuzz-config
3
fuzz-date
4
fuzz-pack-headers
5
fuzz-pack-idx
oss-fuzz/fuzz-config.c
new
+33
@@ -0,0 +1,33 @@
1
+#include "git-compat-util.h"
2
+#include "config.h"
3
+
4
+int LLVMFuzzerTestOneInput(const uint8_t *, size_t);
5
+static int config_parser_callback(const char *, const char *,
6
+ const struct config_context *, void *);
7
+
8
+static int config_parser_callback(const char *key, const char *value,
9
+ const struct config_context *ctx UNUSED,
10
+ void *data UNUSED)
11
+{
12
+ /*
13
+ * Visit every byte of memory we are given to make sure the parser
14
+ * gave it to us appropriately. We need to unconditionally return 0,
15
+ * but we also want to prevent the strlen from being optimized away.
16
+ */
17
+ size_t c = strlen(key);
18
+
19
+ if (value)
20
+ c += strlen(value);
21
+ return c == SIZE_MAX;
22
+}
23
+
24
+int LLVMFuzzerTestOneInput(const uint8_t *data, const size_t size)
25
+{
26
+ struct config_options config_opts = { 0 };
27
+
28
+ config_opts.error_action = CONFIG_ERROR_SILENT;
29
+ git_config_from_mem(config_parser_callback, CONFIG_ORIGIN_BLOB,
30
+ "fuzztest-config", (const char *)data, size, NULL,
31
+ CONFIG_SCOPE_UNKNOWN, &config_opts);
32
+ return 0;
33
+}