net/content_disposition — total parser for the mojibake-prone header: RFC 6266 filename (quoted/token), RFC 5987 filename* ext-values (charset'lang'pct-encoded, incl. RFC 2231 continuations), legacy RFC 2047 encoded-words (=?UTF-8?B?..?= / ?Q?), and raw Latin-1 bytes; prefers filename* over filename; strips path components AFTER decoding (a base64 payload can hold '/'). 22-case test table. net/text_codec (internal) — percent-decode, UTF-8 validation, Latin-1-> UTF-8, base64, RFC 2047 — shared by the CD parser and the URL splitter. net/url — a small total URL splitter (scheme/userinfo/host/port/path/ query/fragment, http(s) validity) and url_filename() for the last path segment; used for the filename fallback. net/probe — HEAD then a ranged GET bytes=0-0 that PROVES resumability (206 + matching Content-Range + a validator), rather than trusting Accept-Ranges which servers lie about; the ranged GET is also the HEAD- refused (403/405/501) fallback. 401/407 -> success result with requires_auth, not an error. Runs on its own pool (max_concurrent, default 4) outside the segment budget per ADR 0011 §5. suggest_filename() does the resolution order (explicit -> disposition -> URL -> download.bin) with a light strip; rules/ (stage 9) owns the authoritative sanitize. tools/fuzz — libFuzzer targets for the CD parser and the URL splitter, compiling the parser sources directly so they're fully instrumented; self-guards on VELOX_BUILD_FUZZ + Clang (the top-level CMake adds every tools/* unconditionally). Seed corpora included. Fixed on the way: a p -> Transfer -> State -> cbs -> p reference cycle in Prober that leaked every probe (drop the stored Transfer; the worker keeps State alive). Tests green under ASan/UBSan and TSan. Co-Authored-By: Claude Sonnet 5 <[email protected]> Claude-Session: https://claude.ai/code/session_01HPPSGhiArbvQgwC2DNiURS
43 lines
1.6 KiB
CMake
43 lines
1.6 KiB
CMake
# libFuzzer targets for CORE parsers. Lane CORE owns tools/fuzz.
|
|
#
|
|
# Self-guarding: the top-level CMakeLists.txt add_subdirectory()s every tools/* that has a
|
|
# CMakeLists, unconditionally, so this file must opt out on its own when fuzzing isn't
|
|
# wanted or the compiler can't do libFuzzer.
|
|
#
|
|
# Each target compiles the parser sources directly (not the whole libveloxcore) so the
|
|
# code under test is fully fuzzer-instrumented without a second build of the library.
|
|
|
|
if(NOT VELOX_BUILD_FUZZ)
|
|
return()
|
|
endif()
|
|
if(NOT CMAKE_CXX_COMPILER_ID MATCHES "Clang")
|
|
message(STATUS "tools/fuzz: libFuzzer needs Clang (have ${CMAKE_CXX_COMPILER_ID}); "
|
|
"skipping fuzz targets.")
|
|
return()
|
|
endif()
|
|
|
|
set(_core ${CMAKE_SOURCE_DIR}/core)
|
|
set(_fuzz_flags -g -O1 -fsanitize=fuzzer,address,undefined -fno-omit-frame-pointer)
|
|
|
|
function(vdm_add_fuzzer name)
|
|
add_executable(${name} ${ARGN})
|
|
target_include_directories(${name} PRIVATE ${_core}/include ${_core}/src)
|
|
target_compile_features(${name} PRIVATE cxx_std_23)
|
|
target_compile_options(${name} PRIVATE ${_fuzz_flags})
|
|
target_link_options(${name} PRIVATE ${_fuzz_flags})
|
|
endfunction()
|
|
|
|
vdm_add_fuzzer(fuzz_content_disposition
|
|
content_disposition_fuzz.cpp
|
|
${_core}/src/net/content_disposition.cpp
|
|
${_core}/src/net/text_codec.cpp)
|
|
|
|
vdm_add_fuzzer(fuzz_url
|
|
url_fuzz.cpp
|
|
${_core}/src/net/url.cpp
|
|
${_core}/src/net/text_codec.cpp)
|
|
|
|
# Seed corpora live next to the harnesses.
|
|
file(GLOB _cd_seeds ${CMAKE_CURRENT_SOURCE_DIR}/corpus/content_disposition/*)
|
|
file(GLOB _url_seeds ${CMAKE_CURRENT_SOURCE_DIR}/corpus/url/*)
|