util.h raw
1 // Copyright (c) 2009-2022 The Limenka developers
2 // Distributed under the MIT software license, see the accompanying
3 // file COPYING or http://www.opensource.org/licenses/mit-license.php.
4
5 #ifndef LIMENKA_TEST_FUZZ_UTIL_H
6 #define LIMENKA_TEST_FUZZ_UTIL_H
7
8 #include <addresstype.h>
9 #include <arith_uint256.h>
10 #include <coins.h>
11 #include <compat/compat.h>
12 #include <consensus/amount.h>
13 #include <consensus/consensus.h>
14 #include <key.h>
15 #include <merkleblock.h>
16 #include <primitives/transaction.h>
17 #include <script/script.h>
18 #include <serialize.h>
19 #include <streams.h>
20 #include <test/fuzz/FuzzedDataProvider.h>
21 #include <test/fuzz/fuzz.h>
22 #include <uint256.h>
23
24 #include <algorithm>
25 #include <array>
26 #include <cstdint>
27 #include <cstdio>
28 #include <optional>
29 #include <string>
30 #include <vector>
31
32 class PeerManager;
33
34 template <typename... Callables>
35 size_t CallOneOf(FuzzedDataProvider& fuzzed_data_provider, Callables... callables)
36 {
37 constexpr size_t call_size{sizeof...(callables)};
38 static_assert(call_size >= 1);
39 const size_t call_index{fuzzed_data_provider.ConsumeIntegralInRange<size_t>(0, call_size - 1)};
40
41 size_t i{0};
42 ((i++ == call_index ? callables() : void()), ...);
43 return call_size;
44 }
45
46 template <typename Collection>
47 auto& PickValue(FuzzedDataProvider& fuzzed_data_provider, Collection& col)
48 {
49 auto sz{col.size()};
50 assert(sz >= 1);
51 auto it = col.begin();
52 std::advance(it, fuzzed_data_provider.ConsumeIntegralInRange<decltype(sz)>(0, sz - 1));
53 return *it;
54 }
55
56 template<typename B = uint8_t>
57 [[nodiscard]] inline std::vector<B> ConsumeRandomLengthByteVector(FuzzedDataProvider& fuzzed_data_provider, const std::optional<size_t>& max_length = std::nullopt) noexcept
58 {
59 static_assert(sizeof(B) == 1);
60 const std::string s = max_length ?
61 fuzzed_data_provider.ConsumeRandomLengthString(*max_length) :
62 fuzzed_data_provider.ConsumeRandomLengthString();
63 std::vector<B> ret(s.size());
64 std::copy(s.begin(), s.end(), reinterpret_cast<char*>(ret.data()));
65 return ret;
66 }
67
68 [[nodiscard]] inline std::vector<bool> ConsumeRandomLengthBitVector(FuzzedDataProvider& fuzzed_data_provider, const std::optional<size_t>& max_length = std::nullopt) noexcept
69 {
70 return BytesToBits(ConsumeRandomLengthByteVector(fuzzed_data_provider, max_length));
71 }
72
73 [[nodiscard]] inline DataStream ConsumeDataStream(FuzzedDataProvider& fuzzed_data_provider, const std::optional<size_t>& max_length = std::nullopt) noexcept
74 {
75 return DataStream{ConsumeRandomLengthByteVector(fuzzed_data_provider, max_length)};
76 }
77
78 [[nodiscard]] inline std::vector<std::string> ConsumeRandomLengthStringVector(FuzzedDataProvider& fuzzed_data_provider, const size_t max_vector_size = 16, const size_t max_string_length = 16) noexcept
79 {
80 const size_t n_elements = fuzzed_data_provider.ConsumeIntegralInRange<size_t>(0, max_vector_size);
81 std::vector<std::string> r;
82 r.reserve(n_elements);
83 for (size_t i = 0; i < n_elements; ++i) {
84 r.push_back(fuzzed_data_provider.ConsumeRandomLengthString(max_string_length));
85 }
86 return r;
87 }
88
89 template <typename T>
90 [[nodiscard]] inline std::vector<T> ConsumeRandomLengthIntegralVector(FuzzedDataProvider& fuzzed_data_provider, const size_t max_vector_size = 16) noexcept
91 {
92 const size_t n_elements = fuzzed_data_provider.ConsumeIntegralInRange<size_t>(0, max_vector_size);
93 std::vector<T> r;
94 r.reserve(n_elements);
95 for (size_t i = 0; i < n_elements; ++i) {
96 r.push_back(fuzzed_data_provider.ConsumeIntegral<T>());
97 }
98 return r;
99 }
100
101 template <typename P>
102 [[nodiscard]] P ConsumeDeserializationParams(FuzzedDataProvider& fuzzed_data_provider) noexcept;
103
104 template <typename T, typename P>
105 [[nodiscard]] std::optional<T> ConsumeDeserializable(FuzzedDataProvider& fuzzed_data_provider, const P& params, const std::optional<size_t>& max_length = std::nullopt) noexcept
106 {
107 const std::vector<uint8_t> buffer{ConsumeRandomLengthByteVector(fuzzed_data_provider, max_length)};
108 DataStream ds{buffer};
109 T obj;
110 try {
111 ds >> params(obj);
112 } catch (const std::ios_base::failure&) {
113 return std::nullopt;
114 }
115 return obj;
116 }
117
118 template <typename T>
119 [[nodiscard]] inline std::optional<T> ConsumeDeserializable(FuzzedDataProvider& fuzzed_data_provider, const std::optional<size_t>& max_length = std::nullopt) noexcept
120 {
121 const std::vector<uint8_t> buffer = ConsumeRandomLengthByteVector(fuzzed_data_provider, max_length);
122 DataStream ds{buffer};
123 T obj;
124 try {
125 ds >> obj;
126 } catch (const std::ios_base::failure&) {
127 return std::nullopt;
128 }
129 return obj;
130 }
131
132 template <typename WeakEnumType, size_t size>
133 [[nodiscard]] WeakEnumType ConsumeWeakEnum(FuzzedDataProvider& fuzzed_data_provider, const WeakEnumType (&all_types)[size]) noexcept
134 {
135 return fuzzed_data_provider.ConsumeBool() ?
136 fuzzed_data_provider.PickValueInArray<WeakEnumType>(all_types) :
137 WeakEnumType(fuzzed_data_provider.ConsumeIntegral<typename std::underlying_type<WeakEnumType>::type>());
138 }
139
140 [[nodiscard]] inline opcodetype ConsumeOpcodeType(FuzzedDataProvider& fuzzed_data_provider) noexcept
141 {
142 return static_cast<opcodetype>(fuzzed_data_provider.ConsumeIntegralInRange<uint32_t>(0, MAX_OPCODE));
143 }
144
145 [[nodiscard]] CAmount ConsumeMoney(FuzzedDataProvider& fuzzed_data_provider, const std::optional<CAmount>& max = std::nullopt) noexcept;
146
147 [[nodiscard]] int64_t ConsumeTime(FuzzedDataProvider& fuzzed_data_provider, const std::optional<int64_t>& min = std::nullopt, const std::optional<int64_t>& max = std::nullopt) noexcept;
148
149 [[nodiscard]] CMutableTransaction ConsumeTransaction(FuzzedDataProvider& fuzzed_data_provider, const std::optional<std::vector<Txid>>& prevout_txids, const int max_num_in = 10, const int max_num_out = 10) noexcept;
150
151 [[nodiscard]] CScriptWitness ConsumeScriptWitness(FuzzedDataProvider& fuzzed_data_provider, const size_t max_stack_elem_size = 32) noexcept;
152
153 [[nodiscard]] CScript ConsumeScript(FuzzedDataProvider& fuzzed_data_provider, const bool maybe_p2wsh = false) noexcept;
154
155 [[nodiscard]] uint32_t ConsumeSequence(FuzzedDataProvider& fuzzed_data_provider) noexcept;
156
157 [[nodiscard]] inline CScriptNum ConsumeScriptNum(FuzzedDataProvider& fuzzed_data_provider) noexcept
158 {
159 return CScriptNum{fuzzed_data_provider.ConsumeIntegral<int64_t>()};
160 }
161
162 [[nodiscard]] inline uint160 ConsumeUInt160(FuzzedDataProvider& fuzzed_data_provider) noexcept
163 {
164 const std::vector<uint8_t> v160 = fuzzed_data_provider.ConsumeBytes<uint8_t>(160 / 8);
165 if (v160.size() != 160 / 8) {
166 return {};
167 }
168 return uint160{v160};
169 }
170
171 [[nodiscard]] inline uint256 ConsumeUInt256(FuzzedDataProvider& fuzzed_data_provider) noexcept
172 {
173 const std::vector<uint8_t> v256 = fuzzed_data_provider.ConsumeBytes<uint8_t>(256 / 8);
174 if (v256.size() != 256 / 8) {
175 return {};
176 }
177 return uint256{v256};
178 }
179
180 [[nodiscard]] inline arith_uint256 ConsumeArithUInt256(FuzzedDataProvider& fuzzed_data_provider) noexcept
181 {
182 return UintToArith256(ConsumeUInt256(fuzzed_data_provider));
183 }
184
185 [[nodiscard]] inline arith_uint256 ConsumeArithUInt256InRange(FuzzedDataProvider& fuzzed_data_provider, const arith_uint256& min, const arith_uint256& max) noexcept
186 {
187 assert(min <= max);
188 const arith_uint256 range = max - min;
189 const arith_uint256 value = ConsumeArithUInt256(fuzzed_data_provider);
190 arith_uint256 result = value;
191 // Avoid division by 0, in case range + 1 results in overflow.
192 if (range != ~arith_uint256(0)) {
193 const arith_uint256 quotient = value / (range + 1);
194 result = value - (quotient * (range + 1));
195 }
196 result += min;
197 assert(result >= min && result <= max);
198 return result;
199 }
200
201 [[nodiscard]] std::map<COutPoint, Coin> ConsumeCoins(FuzzedDataProvider& fuzzed_data_provider) noexcept;
202
203 [[nodiscard]] CTxDestination ConsumeTxDestination(FuzzedDataProvider& fuzzed_data_provider) noexcept;
204
205 [[nodiscard]] CKey ConsumePrivateKey(FuzzedDataProvider& fuzzed_data_provider, std::optional<bool> compressed = std::nullopt) noexcept;
206
207 template <typename T>
208 [[nodiscard]] bool MultiplicationOverflow(const T i, const T j) noexcept
209 {
210 static_assert(std::is_integral<T>::value, "Integral required.");
211 if (std::numeric_limits<T>::is_signed) {
212 if (i > 0) {
213 if (j > 0) {
214 return i > (std::numeric_limits<T>::max() / j);
215 } else {
216 return j < (std::numeric_limits<T>::min() / i);
217 }
218 } else {
219 if (j > 0) {
220 return i < (std::numeric_limits<T>::min() / j);
221 } else {
222 return i != 0 && (j < (std::numeric_limits<T>::max() / i));
223 }
224 }
225 } else {
226 return j != 0 && i > std::numeric_limits<T>::max() / j;
227 }
228 }
229
230 [[nodiscard]] bool ContainsSpentInput(const CTransaction& tx, const CCoinsViewCache& inputs) noexcept;
231
232 /**
233 * Sets errno to a value selected from the given std::array `errnos`.
234 */
235 template <typename T, size_t size>
236 void SetFuzzedErrNo(FuzzedDataProvider& fuzzed_data_provider, const std::array<T, size>& errnos)
237 {
238 errno = fuzzed_data_provider.PickValueInArray(errnos);
239 }
240
241 /*
242 * Sets a fuzzed errno in the range [0, 133 (EHWPOISON)]. Can be used from functions emulating
243 * standard library functions that set errno, or in other contexts where the value of errno
244 * might be relevant for the execution path that will be taken.
245 */
246 inline void SetFuzzedErrNo(FuzzedDataProvider& fuzzed_data_provider) noexcept
247 {
248 errno = fuzzed_data_provider.ConsumeIntegralInRange<int>(0, 133);
249 }
250
251 /**
252 * Returns a byte vector of specified size regardless of the number of remaining bytes available
253 * from the fuzzer. Pads with zero value bytes if needed to achieve the specified size.
254 */
255 template<typename B = uint8_t>
256 [[nodiscard]] inline std::vector<B> ConsumeFixedLengthByteVector(FuzzedDataProvider& fuzzed_data_provider, const size_t length) noexcept
257 {
258 static_assert(sizeof(B) == 1);
259 auto random_bytes = fuzzed_data_provider.ConsumeBytes<B>(length);
260 random_bytes.resize(length);
261 return random_bytes;
262 }
263
264 class FuzzedFileProvider
265 {
266 FuzzedDataProvider& m_fuzzed_data_provider;
267 int64_t m_offset = 0;
268
269 public:
270 FuzzedFileProvider(FuzzedDataProvider& fuzzed_data_provider) : m_fuzzed_data_provider{fuzzed_data_provider}
271 {
272 }
273
274 FILE* open();
275
276 static ssize_t read(void* cookie, char* buf, size_t size);
277
278 static ssize_t write(void* cookie, const char* buf, size_t size);
279
280 static int seek(void* cookie, int64_t* offset, int whence);
281
282 static int close(void* cookie);
283 };
284
285 #define WRITE_TO_STREAM_CASE(type, consume) \
286 [&] { \
287 type o = consume; \
288 stream << o; \
289 }
290 template <typename Stream>
291 void WriteToStream(FuzzedDataProvider& fuzzed_data_provider, Stream& stream) noexcept
292 {
293 while (fuzzed_data_provider.ConsumeBool()) {
294 try {
295 CallOneOf(
296 fuzzed_data_provider,
297 WRITE_TO_STREAM_CASE(bool, fuzzed_data_provider.ConsumeBool()),
298 WRITE_TO_STREAM_CASE(int8_t, fuzzed_data_provider.ConsumeIntegral<int8_t>()),
299 WRITE_TO_STREAM_CASE(uint8_t, fuzzed_data_provider.ConsumeIntegral<uint8_t>()),
300 WRITE_TO_STREAM_CASE(int16_t, fuzzed_data_provider.ConsumeIntegral<int16_t>()),
301 WRITE_TO_STREAM_CASE(uint16_t, fuzzed_data_provider.ConsumeIntegral<uint16_t>()),
302 WRITE_TO_STREAM_CASE(int32_t, fuzzed_data_provider.ConsumeIntegral<int32_t>()),
303 WRITE_TO_STREAM_CASE(uint32_t, fuzzed_data_provider.ConsumeIntegral<uint32_t>()),
304 WRITE_TO_STREAM_CASE(int64_t, fuzzed_data_provider.ConsumeIntegral<int64_t>()),
305 WRITE_TO_STREAM_CASE(uint64_t, fuzzed_data_provider.ConsumeIntegral<uint64_t>()),
306 WRITE_TO_STREAM_CASE(std::string, fuzzed_data_provider.ConsumeRandomLengthString(32)),
307 WRITE_TO_STREAM_CASE(std::vector<uint8_t>, ConsumeRandomLengthIntegralVector<uint8_t>(fuzzed_data_provider)));
308 } catch (const std::ios_base::failure&) {
309 break;
310 }
311 }
312 }
313
314 #define READ_FROM_STREAM_CASE(type) \
315 [&] { \
316 type o; \
317 stream >> o; \
318 }
319 template <typename Stream>
320 void ReadFromStream(FuzzedDataProvider& fuzzed_data_provider, Stream& stream) noexcept
321 {
322 while (fuzzed_data_provider.ConsumeBool()) {
323 try {
324 CallOneOf(
325 fuzzed_data_provider,
326 READ_FROM_STREAM_CASE(bool),
327 READ_FROM_STREAM_CASE(int8_t),
328 READ_FROM_STREAM_CASE(uint8_t),
329 READ_FROM_STREAM_CASE(int16_t),
330 READ_FROM_STREAM_CASE(uint16_t),
331 READ_FROM_STREAM_CASE(int32_t),
332 READ_FROM_STREAM_CASE(uint32_t),
333 READ_FROM_STREAM_CASE(int64_t),
334 READ_FROM_STREAM_CASE(uint64_t),
335 READ_FROM_STREAM_CASE(std::string),
336 READ_FROM_STREAM_CASE(std::vector<uint8_t>));
337 } catch (const std::ios_base::failure&) {
338 break;
339 }
340 }
341 }
342
343 #endif // LIMENKA_TEST_FUZZ_UTIL_H
344