From 2bc7712f57af22058770d1ef131ad3da79a0c764 Mon Sep 17 00:00:00 2001 From: Jonathan Hui Date: Fri, 8 Aug 2025 22:54:35 -0700 Subject: [PATCH] [fuzz] add fuzzer for `otPlatTrelHandleReceived` (#11779) --- tests/fuzz/CMakeLists.txt | 3 + tests/fuzz/trel.cpp | 136 ++++++++++++++++++++++++++++++++++++++ 2 files changed, 139 insertions(+) create mode 100644 tests/fuzz/trel.cpp diff --git a/tests/fuzz/CMakeLists.txt b/tests/fuzz/CMakeLists.txt index c5b28972a..f8cb57939 100644 --- a/tests/fuzz/CMakeLists.txt +++ b/tests/fuzz/CMakeLists.txt @@ -47,6 +47,8 @@ set(COMMON_LIBS ot-config ) +target_compile_definitions(ot-config INTERFACE "OPENTHREAD_CONFIG_RADIO_LINK_TREL_ENABLE=1") + #---------------------------------------------------------------------------------------------------------------------- macro(ot_nexus_test name) @@ -83,3 +85,4 @@ ot_nexus_test(icmp6) ot_nexus_test(ip6) ot_nexus_test(mdns) ot_nexus_test(radio-one-node) +ot_nexus_test(trel) diff --git a/tests/fuzz/trel.cpp b/tests/fuzz/trel.cpp new file mode 100644 index 000000000..6601059dc --- /dev/null +++ b/tests/fuzz/trel.cpp @@ -0,0 +1,136 @@ +/* + * Copyright (c) 2025, The OpenThread Authors. + * All rights reserved. + * + * Redistribution and use in source and binary forms, with or without + * modification, are permitted provided that the following conditions are met: + * 1. Redistributions of source code must retain the above copyright + * notice, this list of conditions and the following disclaimer. + * 2. Redistributions in binary form must reproduce the above copyright + * notice, this list of conditions and the following disclaimer in the + * documentation and/or other materials provided with the distribution. + * 3. Neither the name of the copyright holder nor the + * names of its contributors may be used to endorse or promote products + * derived from this software without specific prior written permission. + * + * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" + * AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE + * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE + * ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE + * LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR + * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF + * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS + * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN + * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) + * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE + * POSSIBILITY OF SUCH DAMAGE. + */ + +#include +#include +#include +#include + +#include + +#include "platform/nexus_core.hpp" +#include "platform/nexus_node.hpp" + +namespace ot { +namespace Nexus { + +class FuzzDataProvider +{ +public: + FuzzDataProvider(const uint8_t *aData, size_t aSize) + : mData(aData) + , mSize(aSize) + { + } + + void ConsumeData(void *aBuf, size_t aLength) + { + assert(aLength <= mSize); + memcpy(aBuf, mData, aLength); + mData += aLength; + mSize -= aLength; + } + + uint8_t *ConsumeRemainingBytes(void) + { + uint8_t *buf = static_cast(malloc(mSize)); + memcpy(buf, mData, mSize); + mSize = 0; + return buf; + } + + size_t RemainingBytes(void) { return mSize; } + +private: + const uint8_t *mData; + size_t mSize; +}; + +extern "C" int LLVMFuzzerTestOneInput(const uint8_t *data, size_t size) +{ + const uint16_t kMaxMessageSize = 2048; + + FuzzDataProvider fdp(data, size); + + unsigned int seed; + uint8_t *buffer; + uint16_t bufferLength; + otSockAddr senderAddr; + + if (size < sizeof(seed) + sizeof(senderAddr)) + { + return 0; + } + + if (size > sizeof(seed) + sizeof(senderAddr) + kMaxMessageSize) + { + return 0; + } + + fdp.ConsumeData(&seed, sizeof(seed)); + srand(seed); + + Core nexus; + + Node &node = nexus.CreateNode(); + + node.GetInstance().SetLogLevel(kLogLevelInfo); + + node.GetInstance().Get().Init(/* aInfraIfIndex */ 1, /* aInfraIfIsRunning */ true); + node.GetInstance().Get().SetEnabled(true); + node.GetInstance().Get().SetAutoEnableMode(true); + node.GetInstance().Get().SetDhcp6PdEnabled(true); + node.GetInstance().Get().SetNat64PrefixManagerEnabled(true); + node.GetInstance().Get().SetEnabled(true); + + Log("---------------------------------------------------------------------------------------"); + Log("Form network"); + + node.Form(); + nexus.AdvanceTime(60 * 1000); + VerifyOrQuit(node.Get().IsLeader()); + VerifyOrQuit(node.Get().GetState() == Srp::Server::kStateRunning); + + Log("---------------------------------------------------------------------------------------"); + Log("Fuzz"); + + fdp.ConsumeData(&senderAddr, sizeof(senderAddr)); + bufferLength = fdp.RemainingBytes(); + buffer = fdp.ConsumeRemainingBytes(); + + otPlatTrelHandleReceived(&node.GetInstance(), buffer, bufferLength, &senderAddr); + + nexus.AdvanceTime(10 * 1000); + + free(buffer); + + return 0; +} + +} // namespace Nexus +} // namespace ot