mirror of
https://github.com/samba-team/samba.git
synced 2025-08-05 12:22:11 +03:00
fuzz: add a fuzzer for parsing ldb controls
We have had issues here in the past. Signed-off-by: Douglas Bagnall <douglas.bagnall@catalyst.net.nz> Reviewed-by: Andrew Bartlett <abartlet@samba.org> Autobuild-User(master): Andrew Bartlett <abartlet@samba.org> Autobuild-Date(master): Sun Jan 12 21:21:30 UTC 2020 on sn-devel-184
This commit is contained in:
committed by
Andrew Bartlett
parent
16ca385013
commit
beb386b584
46
lib/fuzzing/fuzz_ldb_parse_control.c
Normal file
46
lib/fuzzing/fuzz_ldb_parse_control.c
Normal file
@ -0,0 +1,46 @@
|
||||
/*
|
||||
Fuzzing ldb_parse_control_from_string
|
||||
Copyright (C) Catalyst IT 2020
|
||||
|
||||
This program is free software; you can redistribute it and/or modify
|
||||
it under the terms of the GNU General Public License as published by
|
||||
the Free Software Foundation; either version 3 of the License, or
|
||||
(at your option) any later version.
|
||||
|
||||
This program is distributed in the hope that it will be useful,
|
||||
but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
||||
GNU General Public License for more details.
|
||||
|
||||
You should have received a copy of the GNU General Public License
|
||||
along with this program. If not, see <http://www.gnu.org/licenses/>.
|
||||
*/
|
||||
#include "includes.h"
|
||||
#include "fuzzing/fuzzing.h"
|
||||
#include "ldb_private.h"
|
||||
|
||||
|
||||
#define MAX_LENGTH (2 * 1024 * 1024 - 1)
|
||||
char buf[MAX_LENGTH + 1] = {0};
|
||||
|
||||
int LLVMFuzzerTestOneInput(uint8_t *input, size_t len)
|
||||
{
|
||||
struct ldb_control *control = NULL;
|
||||
struct ldb_context *ldb = ldb_init(NULL, NULL);
|
||||
/*
|
||||
* We copy the buffer in order to NUL-teminate, because running off
|
||||
* the end of the string would be an uninteresting crash.
|
||||
*/
|
||||
if (len > MAX_LENGTH) {
|
||||
len = MAX_LENGTH;
|
||||
}
|
||||
memcpy(buf, input, len);
|
||||
buf[len] = 0;
|
||||
|
||||
control = ldb_parse_control_from_string(ldb, ldb, buf);
|
||||
if (control != NULL) {
|
||||
ldb_control_to_string(ldb, control);
|
||||
}
|
||||
TALLOC_FREE(ldb);
|
||||
return 0;
|
||||
}
|
Reference in New Issue
Block a user