pcp.cpp raw
1 // Copyright (c) 2024 The Limenka developers
2 // Distributed under the MIT software license, see the accompanying
3 // file COPYING or http://www.opensource.org/licenses/mit-license.php.
4
5 #include <test/fuzz/FuzzedDataProvider.h>
6 #include <test/fuzz/fuzz.h>
7 #include <test/util/setup_common.h>
8 #include <test/fuzz/util.h>
9 #include <test/fuzz/util/net.h>
10
11 #include <common/pcp.h>
12 #include <util/check.h>
13
14 using namespace std::literals;
15
16 //! Fixed nonce to use in PCP port mapping requests.
17 constexpr PCPMappingNonce PCP_NONCE{0x11, 0x22, 0x33, 0x44, 0x55, 0x66, 0x77, 0x88, 0x99, 0xaa, 0xbb, 0xcc};
18
19 //! Number of attempts to request a NAT-PMP or PCP port mapping to the gateway.
20 constexpr int NUM_TRIES{5};
21
22 //! Timeout for each attempt to request a port mapping.
23 constexpr std::chrono::duration TIMEOUT{100ms};
24
25 void port_map_target_init()
26 {
27 LogInstance().DisableLogging();
28 }
29
30 FUZZ_TARGET(pcp_request_port_map, .init = port_map_target_init)
31 {
32 FuzzedDataProvider fuzzed_data_provider{buffer.data(), buffer.size()};
33
34 // Create a mocked socket between random (and potentially invalid) client and gateway addresses.
35 CreateSock = [&](int domain, int type, int protocol) {
36 if ((domain == AF_INET || domain == AF_INET6) && type == SOCK_DGRAM && protocol == IPPROTO_UDP) {
37 return std::make_unique<FuzzedSock>(fuzzed_data_provider);
38 }
39 return std::unique_ptr<FuzzedSock>();
40 };
41
42 // Perform the port mapping request. The mocked socket will return fuzzer-provided data.
43 const auto gateway_addr{ConsumeNetAddr(fuzzed_data_provider)};
44 const auto local_addr{ConsumeNetAddr(fuzzed_data_provider)};
45 const auto port{fuzzed_data_provider.ConsumeIntegral<uint16_t>()};
46 const auto lifetime{fuzzed_data_provider.ConsumeIntegral<uint32_t>()};
47 const auto res{PCPRequestPortMap(PCP_NONCE, gateway_addr, local_addr, port, lifetime, NUM_TRIES, TIMEOUT)};
48
49 // In case of success the mapping must be consistent with the request.
50 if (const MappingResult* mapping = std::get_if<MappingResult>(&res)) {
51 Assert(mapping);
52 Assert(mapping->internal.GetPort() == port);
53 mapping->ToString();
54 }
55 }
56
57 FUZZ_TARGET(natpmp_request_port_map, .init = port_map_target_init)
58 {
59 FuzzedDataProvider fuzzed_data_provider{buffer.data(), buffer.size()};
60
61 // Create a mocked socket between random (and potentially invalid) client and gateway addresses.
62 CreateSock = [&](int domain, int type, int protocol) {
63 if (domain == AF_INET && type == SOCK_DGRAM && protocol == IPPROTO_UDP) {
64 return std::make_unique<FuzzedSock>(fuzzed_data_provider);
65 }
66 return std::unique_ptr<FuzzedSock>();
67 };
68
69 // Perform the port mapping request. The mocked socket will return fuzzer-provided data.
70 const auto gateway_addr{ConsumeNetAddr(fuzzed_data_provider)};
71 const auto port{fuzzed_data_provider.ConsumeIntegral<uint16_t>()};
72 const auto lifetime{fuzzed_data_provider.ConsumeIntegral<uint32_t>()};
73 const auto res{NATPMPRequestPortMap(gateway_addr, port, lifetime, NUM_TRIES, TIMEOUT)};
74
75 // In case of success the mapping must be consistent with the request.
76 if (const MappingResult* mapping = std::get_if<MappingResult>(&res)) {
77 Assert(mapping);
78 Assert(mapping->internal.GetPort() == port);
79 mapping->ToString();
80 }
81 }
82