Skip to content

Commit

Permalink
fuzz: add fuzzer for config parsing
Browse files Browse the repository at this point in the history
Add a new fuzz target that exercises the parsing of git configs.
The existing git_config_from_mem function is a perfect entry point
for fuzzing as it exercises the same code paths as the rest of the
config parsing functions and offers an easily fuzzable interface.

Config parsing is a useful thing to fuzz because it operates on user
controlled data and is a central component of many git operations.

Signed-off-by: Brian C Tracy <[email protected]>
Signed-off-by: Junio C Hamano <[email protected]>
  • Loading branch information
briantracy authored and gitster committed Mar 15, 2024
1 parent 4f9b731 commit fe2033b
Show file tree
Hide file tree
Showing 4 changed files with 36 additions and 1 deletion.
1 change: 1 addition & 0 deletions Makefile
Original file line number Diff line number Diff line change
Expand Up @@ -757,6 +757,7 @@ ETAGS_TARGET = TAGS
# runs in the future.
FUZZ_OBJS += oss-fuzz/dummy-cmd-main.o
FUZZ_OBJS += oss-fuzz/fuzz-commit-graph.o
FUZZ_OBJS += oss-fuzz/fuzz-config.o
FUZZ_OBJS += oss-fuzz/fuzz-date.o
FUZZ_OBJS += oss-fuzz/fuzz-pack-headers.o
FUZZ_OBJS += oss-fuzz/fuzz-pack-idx.o
Expand Down
2 changes: 1 addition & 1 deletion ci/run-build-and-minimal-fuzzers.sh
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@ group "Build fuzzers" make \
LIB_FUZZING_ENGINE="-fsanitize=fuzzer,address" \
fuzz-all

for fuzzer in commit-graph date pack-headers pack-idx ; do
for fuzzer in commit-graph config date pack-headers pack-idx ; do
begin_group "fuzz-$fuzzer"
./oss-fuzz/fuzz-$fuzzer -verbosity=0 -runs=1 || exit 1
end_group "fuzz-$fuzzer"
Expand Down
1 change: 1 addition & 0 deletions oss-fuzz/.gitignore
Original file line number Diff line number Diff line change
@@ -1,4 +1,5 @@
fuzz-commit-graph
fuzz-config
fuzz-date
fuzz-pack-headers
fuzz-pack-idx
33 changes: 33 additions & 0 deletions oss-fuzz/fuzz-config.c
Original file line number Diff line number Diff line change
@@ -0,0 +1,33 @@
#include "git-compat-util.h"
#include "config.h"

int LLVMFuzzerTestOneInput(const uint8_t *, size_t);
static int config_parser_callback(const char *, const char *,
const struct config_context *, void *);

static int config_parser_callback(const char *key, const char *value,
const struct config_context *ctx UNUSED,
void *data UNUSED)
{
/*
* Visit every byte of memory we are given to make sure the parser
* gave it to us appropriately. We need to unconditionally return 0,
* but we also want to prevent the strlen from being optimized away.
*/
size_t c = strlen(key);

if (value)
c += strlen(value);
return c == SIZE_MAX;
}

int LLVMFuzzerTestOneInput(const uint8_t *data, const size_t size)
{
struct config_options config_opts = { 0 };

config_opts.error_action = CONFIG_ERROR_SILENT;
git_config_from_mem(config_parser_callback, CONFIG_ORIGIN_BLOB,
"fuzztest-config", (const char *)data, size, NULL,
CONFIG_SCOPE_UNKNOWN, &config_opts);
return 0;
}

0 comments on commit fe2033b

Please sign in to comment.