util.h raw

   1  // Copyright (c) 2009-2022 The Limenka developers
   2  // Distributed under the MIT software license, see the accompanying
   3  // file COPYING or http://www.opensource.org/licenses/mit-license.php.
   4  
   5  #ifndef LIMENKA_TEST_FUZZ_UTIL_H
   6  #define LIMENKA_TEST_FUZZ_UTIL_H
   7  
   8  #include <addresstype.h>
   9  #include <arith_uint256.h>
  10  #include <coins.h>
  11  #include <compat/compat.h>
  12  #include <consensus/amount.h>
  13  #include <consensus/consensus.h>
  14  #include <key.h>
  15  #include <merkleblock.h>
  16  #include <primitives/transaction.h>
  17  #include <script/script.h>
  18  #include <serialize.h>
  19  #include <streams.h>
  20  #include <test/fuzz/FuzzedDataProvider.h>
  21  #include <test/fuzz/fuzz.h>
  22  #include <uint256.h>
  23  
  24  #include <algorithm>
  25  #include <array>
  26  #include <cstdint>
  27  #include <cstdio>
  28  #include <optional>
  29  #include <string>
  30  #include <vector>
  31  
  32  class PeerManager;
  33  
  34  template <typename... Callables>
  35  size_t CallOneOf(FuzzedDataProvider& fuzzed_data_provider, Callables... callables)
  36  {
  37      constexpr size_t call_size{sizeof...(callables)};
  38      static_assert(call_size >= 1);
  39      const size_t call_index{fuzzed_data_provider.ConsumeIntegralInRange<size_t>(0, call_size - 1)};
  40  
  41      size_t i{0};
  42      ((i++ == call_index ? callables() : void()), ...);
  43      return call_size;
  44  }
  45  
  46  template <typename Collection>
  47  auto& PickValue(FuzzedDataProvider& fuzzed_data_provider, Collection& col)
  48  {
  49      auto sz{col.size()};
  50      assert(sz >= 1);
  51      auto it = col.begin();
  52      std::advance(it, fuzzed_data_provider.ConsumeIntegralInRange<decltype(sz)>(0, sz - 1));
  53      return *it;
  54  }
  55  
  56  template<typename B = uint8_t>
  57  [[nodiscard]] inline std::vector<B> ConsumeRandomLengthByteVector(FuzzedDataProvider& fuzzed_data_provider, const std::optional<size_t>& max_length = std::nullopt) noexcept
  58  {
  59      static_assert(sizeof(B) == 1);
  60      const std::string s = max_length ?
  61                                fuzzed_data_provider.ConsumeRandomLengthString(*max_length) :
  62                                fuzzed_data_provider.ConsumeRandomLengthString();
  63      std::vector<B> ret(s.size());
  64      std::copy(s.begin(), s.end(), reinterpret_cast<char*>(ret.data()));
  65      return ret;
  66  }
  67  
  68  [[nodiscard]] inline std::vector<bool> ConsumeRandomLengthBitVector(FuzzedDataProvider& fuzzed_data_provider, const std::optional<size_t>& max_length = std::nullopt) noexcept
  69  {
  70      return BytesToBits(ConsumeRandomLengthByteVector(fuzzed_data_provider, max_length));
  71  }
  72  
  73  [[nodiscard]] inline DataStream ConsumeDataStream(FuzzedDataProvider& fuzzed_data_provider, const std::optional<size_t>& max_length = std::nullopt) noexcept
  74  {
  75      return DataStream{ConsumeRandomLengthByteVector(fuzzed_data_provider, max_length)};
  76  }
  77  
  78  [[nodiscard]] inline std::vector<std::string> ConsumeRandomLengthStringVector(FuzzedDataProvider& fuzzed_data_provider, const size_t max_vector_size = 16, const size_t max_string_length = 16) noexcept
  79  {
  80      const size_t n_elements = fuzzed_data_provider.ConsumeIntegralInRange<size_t>(0, max_vector_size);
  81      std::vector<std::string> r;
  82      r.reserve(n_elements);
  83      for (size_t i = 0; i < n_elements; ++i) {
  84          r.push_back(fuzzed_data_provider.ConsumeRandomLengthString(max_string_length));
  85      }
  86      return r;
  87  }
  88  
  89  template <typename T>
  90  [[nodiscard]] inline std::vector<T> ConsumeRandomLengthIntegralVector(FuzzedDataProvider& fuzzed_data_provider, const size_t max_vector_size = 16) noexcept
  91  {
  92      const size_t n_elements = fuzzed_data_provider.ConsumeIntegralInRange<size_t>(0, max_vector_size);
  93      std::vector<T> r;
  94      r.reserve(n_elements);
  95      for (size_t i = 0; i < n_elements; ++i) {
  96          r.push_back(fuzzed_data_provider.ConsumeIntegral<T>());
  97      }
  98      return r;
  99  }
 100  
 101  template <typename P>
 102  [[nodiscard]] P ConsumeDeserializationParams(FuzzedDataProvider& fuzzed_data_provider) noexcept;
 103  
 104  template <typename T, typename P>
 105  [[nodiscard]] std::optional<T> ConsumeDeserializable(FuzzedDataProvider& fuzzed_data_provider, const P& params, const std::optional<size_t>& max_length = std::nullopt) noexcept
 106  {
 107      const std::vector<uint8_t> buffer{ConsumeRandomLengthByteVector(fuzzed_data_provider, max_length)};
 108      DataStream ds{buffer};
 109      T obj;
 110      try {
 111          ds >> params(obj);
 112      } catch (const std::ios_base::failure&) {
 113          return std::nullopt;
 114      }
 115      return obj;
 116  }
 117  
 118  template <typename T>
 119  [[nodiscard]] inline std::optional<T> ConsumeDeserializable(FuzzedDataProvider& fuzzed_data_provider, const std::optional<size_t>& max_length = std::nullopt) noexcept
 120  {
 121      const std::vector<uint8_t> buffer = ConsumeRandomLengthByteVector(fuzzed_data_provider, max_length);
 122      DataStream ds{buffer};
 123      T obj;
 124      try {
 125          ds >> obj;
 126      } catch (const std::ios_base::failure&) {
 127          return std::nullopt;
 128      }
 129      return obj;
 130  }
 131  
 132  template <typename WeakEnumType, size_t size>
 133  [[nodiscard]] WeakEnumType ConsumeWeakEnum(FuzzedDataProvider& fuzzed_data_provider, const WeakEnumType (&all_types)[size]) noexcept
 134  {
 135      return fuzzed_data_provider.ConsumeBool() ?
 136                 fuzzed_data_provider.PickValueInArray<WeakEnumType>(all_types) :
 137                 WeakEnumType(fuzzed_data_provider.ConsumeIntegral<typename std::underlying_type<WeakEnumType>::type>());
 138  }
 139  
 140  [[nodiscard]] inline opcodetype ConsumeOpcodeType(FuzzedDataProvider& fuzzed_data_provider) noexcept
 141  {
 142      return static_cast<opcodetype>(fuzzed_data_provider.ConsumeIntegralInRange<uint32_t>(0, MAX_OPCODE));
 143  }
 144  
 145  [[nodiscard]] CAmount ConsumeMoney(FuzzedDataProvider& fuzzed_data_provider, const std::optional<CAmount>& max = std::nullopt) noexcept;
 146  
 147  [[nodiscard]] int64_t ConsumeTime(FuzzedDataProvider& fuzzed_data_provider, const std::optional<int64_t>& min = std::nullopt, const std::optional<int64_t>& max = std::nullopt) noexcept;
 148  
 149  [[nodiscard]] CMutableTransaction ConsumeTransaction(FuzzedDataProvider& fuzzed_data_provider, const std::optional<std::vector<Txid>>& prevout_txids, const int max_num_in = 10, const int max_num_out = 10) noexcept;
 150  
 151  [[nodiscard]] CScriptWitness ConsumeScriptWitness(FuzzedDataProvider& fuzzed_data_provider, const size_t max_stack_elem_size = 32) noexcept;
 152  
 153  [[nodiscard]] CScript ConsumeScript(FuzzedDataProvider& fuzzed_data_provider, const bool maybe_p2wsh = false) noexcept;
 154  
 155  [[nodiscard]] uint32_t ConsumeSequence(FuzzedDataProvider& fuzzed_data_provider) noexcept;
 156  
 157  [[nodiscard]] inline CScriptNum ConsumeScriptNum(FuzzedDataProvider& fuzzed_data_provider) noexcept
 158  {
 159      return CScriptNum{fuzzed_data_provider.ConsumeIntegral<int64_t>()};
 160  }
 161  
 162  [[nodiscard]] inline uint160 ConsumeUInt160(FuzzedDataProvider& fuzzed_data_provider) noexcept
 163  {
 164      const std::vector<uint8_t> v160 = fuzzed_data_provider.ConsumeBytes<uint8_t>(160 / 8);
 165      if (v160.size() != 160 / 8) {
 166          return {};
 167      }
 168      return uint160{v160};
 169  }
 170  
 171  [[nodiscard]] inline uint256 ConsumeUInt256(FuzzedDataProvider& fuzzed_data_provider) noexcept
 172  {
 173      const std::vector<uint8_t> v256 = fuzzed_data_provider.ConsumeBytes<uint8_t>(256 / 8);
 174      if (v256.size() != 256 / 8) {
 175          return {};
 176      }
 177      return uint256{v256};
 178  }
 179  
 180  [[nodiscard]] inline arith_uint256 ConsumeArithUInt256(FuzzedDataProvider& fuzzed_data_provider) noexcept
 181  {
 182      return UintToArith256(ConsumeUInt256(fuzzed_data_provider));
 183  }
 184  
 185  [[nodiscard]] inline arith_uint256 ConsumeArithUInt256InRange(FuzzedDataProvider& fuzzed_data_provider, const arith_uint256& min, const arith_uint256& max) noexcept
 186  {
 187      assert(min <= max);
 188      const arith_uint256 range = max - min;
 189      const arith_uint256 value = ConsumeArithUInt256(fuzzed_data_provider);
 190      arith_uint256 result = value;
 191      // Avoid division by 0, in case range + 1 results in overflow.
 192      if (range != ~arith_uint256(0)) {
 193          const arith_uint256 quotient = value / (range + 1);
 194          result = value - (quotient * (range + 1));
 195      }
 196      result += min;
 197      assert(result >= min && result <= max);
 198      return result;
 199  }
 200  
 201  [[nodiscard]] std::map<COutPoint, Coin> ConsumeCoins(FuzzedDataProvider& fuzzed_data_provider) noexcept;
 202  
 203  [[nodiscard]] CTxDestination ConsumeTxDestination(FuzzedDataProvider& fuzzed_data_provider) noexcept;
 204  
 205  [[nodiscard]] CKey ConsumePrivateKey(FuzzedDataProvider& fuzzed_data_provider, std::optional<bool> compressed = std::nullopt) noexcept;
 206  
 207  template <typename T>
 208  [[nodiscard]] bool MultiplicationOverflow(const T i, const T j) noexcept
 209  {
 210      static_assert(std::is_integral<T>::value, "Integral required.");
 211      if (std::numeric_limits<T>::is_signed) {
 212          if (i > 0) {
 213              if (j > 0) {
 214                  return i > (std::numeric_limits<T>::max() / j);
 215              } else {
 216                  return j < (std::numeric_limits<T>::min() / i);
 217              }
 218          } else {
 219              if (j > 0) {
 220                  return i < (std::numeric_limits<T>::min() / j);
 221              } else {
 222                  return i != 0 && (j < (std::numeric_limits<T>::max() / i));
 223              }
 224          }
 225      } else {
 226          return j != 0 && i > std::numeric_limits<T>::max() / j;
 227      }
 228  }
 229  
 230  [[nodiscard]] bool ContainsSpentInput(const CTransaction& tx, const CCoinsViewCache& inputs) noexcept;
 231  
 232  /**
 233   * Sets errno to a value selected from the given std::array `errnos`.
 234   */
 235  template <typename T, size_t size>
 236  void SetFuzzedErrNo(FuzzedDataProvider& fuzzed_data_provider, const std::array<T, size>& errnos)
 237  {
 238      errno = fuzzed_data_provider.PickValueInArray(errnos);
 239  }
 240  
 241  /*
 242   * Sets a fuzzed errno in the range [0, 133 (EHWPOISON)]. Can be used from functions emulating
 243   * standard library functions that set errno, or in other contexts where the value of errno
 244   * might be relevant for the execution path that will be taken.
 245   */
 246  inline void SetFuzzedErrNo(FuzzedDataProvider& fuzzed_data_provider) noexcept
 247  {
 248      errno = fuzzed_data_provider.ConsumeIntegralInRange<int>(0, 133);
 249  }
 250  
 251  /**
 252   * Returns a byte vector of specified size regardless of the number of remaining bytes available
 253   * from the fuzzer. Pads with zero value bytes if needed to achieve the specified size.
 254   */
 255  template<typename B = uint8_t>
 256  [[nodiscard]] inline std::vector<B> ConsumeFixedLengthByteVector(FuzzedDataProvider& fuzzed_data_provider, const size_t length) noexcept
 257  {
 258      static_assert(sizeof(B) == 1);
 259      auto random_bytes = fuzzed_data_provider.ConsumeBytes<B>(length);
 260      random_bytes.resize(length);
 261      return random_bytes;
 262  }
 263  
 264  class FuzzedFileProvider
 265  {
 266      FuzzedDataProvider& m_fuzzed_data_provider;
 267      int64_t m_offset = 0;
 268  
 269  public:
 270      FuzzedFileProvider(FuzzedDataProvider& fuzzed_data_provider) : m_fuzzed_data_provider{fuzzed_data_provider}
 271      {
 272      }
 273  
 274      FILE* open();
 275  
 276      static ssize_t read(void* cookie, char* buf, size_t size);
 277  
 278      static ssize_t write(void* cookie, const char* buf, size_t size);
 279  
 280      static int seek(void* cookie, int64_t* offset, int whence);
 281  
 282      static int close(void* cookie);
 283  };
 284  
 285  #define WRITE_TO_STREAM_CASE(type, consume) \
 286      [&] {                                   \
 287          type o = consume;                   \
 288          stream << o;                        \
 289      }
 290  template <typename Stream>
 291  void WriteToStream(FuzzedDataProvider& fuzzed_data_provider, Stream& stream) noexcept
 292  {
 293      while (fuzzed_data_provider.ConsumeBool()) {
 294          try {
 295              CallOneOf(
 296                  fuzzed_data_provider,
 297                  WRITE_TO_STREAM_CASE(bool, fuzzed_data_provider.ConsumeBool()),
 298                  WRITE_TO_STREAM_CASE(int8_t, fuzzed_data_provider.ConsumeIntegral<int8_t>()),
 299                  WRITE_TO_STREAM_CASE(uint8_t, fuzzed_data_provider.ConsumeIntegral<uint8_t>()),
 300                  WRITE_TO_STREAM_CASE(int16_t, fuzzed_data_provider.ConsumeIntegral<int16_t>()),
 301                  WRITE_TO_STREAM_CASE(uint16_t, fuzzed_data_provider.ConsumeIntegral<uint16_t>()),
 302                  WRITE_TO_STREAM_CASE(int32_t, fuzzed_data_provider.ConsumeIntegral<int32_t>()),
 303                  WRITE_TO_STREAM_CASE(uint32_t, fuzzed_data_provider.ConsumeIntegral<uint32_t>()),
 304                  WRITE_TO_STREAM_CASE(int64_t, fuzzed_data_provider.ConsumeIntegral<int64_t>()),
 305                  WRITE_TO_STREAM_CASE(uint64_t, fuzzed_data_provider.ConsumeIntegral<uint64_t>()),
 306                  WRITE_TO_STREAM_CASE(std::string, fuzzed_data_provider.ConsumeRandomLengthString(32)),
 307                  WRITE_TO_STREAM_CASE(std::vector<uint8_t>, ConsumeRandomLengthIntegralVector<uint8_t>(fuzzed_data_provider)));
 308          } catch (const std::ios_base::failure&) {
 309              break;
 310          }
 311      }
 312  }
 313  
 314  #define READ_FROM_STREAM_CASE(type) \
 315      [&] {                           \
 316          type o;                     \
 317          stream >> o;                \
 318      }
 319  template <typename Stream>
 320  void ReadFromStream(FuzzedDataProvider& fuzzed_data_provider, Stream& stream) noexcept
 321  {
 322      while (fuzzed_data_provider.ConsumeBool()) {
 323          try {
 324              CallOneOf(
 325                  fuzzed_data_provider,
 326                  READ_FROM_STREAM_CASE(bool),
 327                  READ_FROM_STREAM_CASE(int8_t),
 328                  READ_FROM_STREAM_CASE(uint8_t),
 329                  READ_FROM_STREAM_CASE(int16_t),
 330                  READ_FROM_STREAM_CASE(uint16_t),
 331                  READ_FROM_STREAM_CASE(int32_t),
 332                  READ_FROM_STREAM_CASE(uint32_t),
 333                  READ_FROM_STREAM_CASE(int64_t),
 334                  READ_FROM_STREAM_CASE(uint64_t),
 335                  READ_FROM_STREAM_CASE(std::string),
 336                  READ_FROM_STREAM_CASE(std::vector<uint8_t>));
 337          } catch (const std::ios_base::failure&) {
 338              break;
 339          }
 340      }
 341  }
 342  
 343  #endif // LIMENKA_TEST_FUZZ_UTIL_H
 344