From da4786003fef39737734e1a5cbf752442f7793b1 Mon Sep 17 00:00:00 2001 From: Douglas Bagnall Date: Fri, 10 Jan 2020 12:35:54 +1300 Subject: [PATCH] fuzz: add ldb ldif fuzzer Signed-off-by: Douglas Bagnall Reviewed-by: Gary Lockyer --- lib/fuzzing/fuzz_ldb_ldif_read.c | 47 ++++++++++++++++++++++++++++++++ lib/fuzzing/wscript_build | 5 ++++ 2 files changed, 52 insertions(+) create mode 100644 lib/fuzzing/fuzz_ldb_ldif_read.c diff --git a/lib/fuzzing/fuzz_ldb_ldif_read.c b/lib/fuzzing/fuzz_ldb_ldif_read.c new file mode 100644 index 00000000000..f2c46bc9beb --- /dev/null +++ b/lib/fuzzing/fuzz_ldb_ldif_read.c @@ -0,0 +1,47 @@ +/* + Fuzzing ldb_parse_control_from_string + Copyright (C) Catalyst IT 2020 + + This program is free software; you can redistribute it and/or modify + it under the terms of the GNU General Public License as published by + the Free Software Foundation; either version 3 of the License, or + (at your option) any later version. + + This program is distributed in the hope that it will be useful, + but WITHOUT ANY WARRANTY; without even the implied warranty of + MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the + GNU General Public License for more details. + + You should have received a copy of the GNU General Public License + along with this program. If not, see . +*/ +#include "includes.h" +#include "fuzzing/fuzzing.h" +#include "ldb_private.h" + + +#define MAX_LENGTH (2 * 1024 * 1024 - 1) +char buf[MAX_LENGTH + 1] = {0}; + +int LLVMFuzzerTestOneInput(uint8_t *input, size_t len) +{ + struct ldb_ldif *ldif = NULL; + struct ldb_context *ldb = ldb_init(NULL, NULL); + const char *s = NULL; + + if (len > MAX_LENGTH) { + len = MAX_LENGTH; + } + memcpy(buf, input, len); + buf[len] = 0; + s = buf; + + ldif = ldb_ldif_read_string(ldb, &s); + + if(ldif != NULL) { + ldb_ldif_write_string(ldb, ldb, ldif); + ldb_ldif_write_redacted_trace_string(ldb, ldb, ldif); + } + TALLOC_FREE(ldb); + return 0; +} diff --git a/lib/fuzzing/wscript_build b/lib/fuzzing/wscript_build index 79242d45038..b5d699e4dcd 100644 --- a/lib/fuzzing/wscript_build +++ b/lib/fuzzing/wscript_build @@ -52,6 +52,11 @@ bld.SAMBA_BINARY('fuzz_ldb_dn_explode', deps='fuzzing ldb afl-fuzz-main', fuzzer=True) +bld.SAMBA_BINARY('fuzz_ldb_ldif_read', + source='fuzz_ldb_ldif_read.c', + deps='fuzzing ldb afl-fuzz-main', + fuzzer=True) + bld.SAMBA_BINARY('fuzz_ldb_parse_tree', source='fuzz_ldb_parse_tree.c', deps='fuzzing ldb afl-fuzz-main', -- 2.34.1