Ned Williamson | 3d55bbb | 2017-11-07 22:58:13 | [diff] [blame] | 1 | // Copyright 2017 The Chromium Authors. All rights reserved. |
| 2 | // Use of this source code is governed by a BSD-style license that can be |
| 3 | // found in the LICENSE file. |
| 4 | |
Ryan Hamilton | a3ee93a7 | 2018-08-01 22:03:08 | [diff] [blame] | 5 | #include "net/quic/quic_stream_factory.h" |
Ned Williamson | 3d55bbb | 2017-11-07 22:58:13 | [diff] [blame] | 6 | |
| 7 | #include "base/test/fuzzed_data_provider.h" |
| 8 | |
Avi Drissman | 4365a478 | 2018-12-28 19:26:24 | [diff] [blame^] | 9 | #include "base/stl_util.h" |
Ned Williamson | 3d55bbb | 2017-11-07 22:58:13 | [diff] [blame] | 10 | #include "net/base/test_completion_callback.h" |
Ryan Sleevi | 8a9c9c1 | 2018-05-09 02:36:23 | [diff] [blame] | 11 | #include "net/cert/ct_policy_enforcer.h" |
Ryan Sleevi | 987d2d9 | 2017-12-19 19:22:14 | [diff] [blame] | 12 | #include "net/cert/do_nothing_ct_verifier.h" |
| 13 | #include "net/cert/mock_cert_verifier.h" |
Ryan Hamilton | e3e592e | 2017-11-16 04:49:09 | [diff] [blame] | 14 | #include "net/cert/x509_certificate.h" |
Ned Williamson | 3d55bbb | 2017-11-07 22:58:13 | [diff] [blame] | 15 | #include "net/dns/fuzzed_host_resolver.h" |
| 16 | #include "net/http/http_server_properties_impl.h" |
| 17 | #include "net/http/transport_security_state.h" |
Ryan Hamilton | a3ee93a7 | 2018-08-01 22:03:08 | [diff] [blame] | 18 | #include "net/quic/mock_crypto_client_stream_factory.h" |
| 19 | #include "net/quic/quic_http_stream.h" |
| 20 | #include "net/quic/test_task_runner.h" |
Ned Williamson | 3d55bbb | 2017-11-07 22:58:13 | [diff] [blame] | 21 | #include "net/socket/fuzzed_datagram_client_socket.h" |
| 22 | #include "net/socket/fuzzed_socket_factory.h" |
Paul Jensen | 8e3c5d3 | 2018-02-19 17:06:33 | [diff] [blame] | 23 | #include "net/socket/socket_tag.h" |
Ryan Sleevi | 987d2d9 | 2017-12-19 19:22:14 | [diff] [blame] | 24 | #include "net/ssl/ssl_config_service_defaults.h" |
Ryan Hamilton | 0a9f0146 | 2017-11-14 01:27:30 | [diff] [blame] | 25 | #include "net/test/gtest_util.h" |
Ryan Hamilton | 56b10c5d | 2018-05-11 13:40:16 | [diff] [blame] | 26 | #include "net/third_party/quic/test_tools/mock_clock.h" |
| 27 | #include "net/third_party/quic/test_tools/mock_random.h" |
Ramin Halavati | a1256c8 | 2018-02-21 06:18:21 | [diff] [blame] | 28 | #include "net/traffic_annotation/network_traffic_annotation_test_helper.h" |
Ned Williamson | 3d55bbb | 2017-11-07 22:58:13 | [diff] [blame] | 29 | |
| 30 | namespace net { |
| 31 | |
| 32 | namespace { |
| 33 | |
Ryan Hamilton | e3e592e | 2017-11-16 04:49:09 | [diff] [blame] | 34 | const char kCertData[] = { |
| 35 | #include "net/data/ssl/certificates/wildcard.inc" |
| 36 | }; |
| 37 | |
Ned Williamson | 3d55bbb | 2017-11-07 22:58:13 | [diff] [blame] | 38 | } // namespace |
| 39 | |
| 40 | namespace test { |
| 41 | |
| 42 | const char kServerHostName[] = "www.example.org"; |
| 43 | const int kServerPort = 443; |
| 44 | const char kUrl[] = "https://www.example.org/"; |
| 45 | // TODO(nedwilliamson): Add POST here after testing |
| 46 | // whether that can lead blocking while waiting for |
| 47 | // the callbacks. |
| 48 | const char kMethod[] = "GET"; |
| 49 | const size_t kBufferSize = 4096; |
| 50 | const int kCertVerifyFlags = 0; |
| 51 | |
| 52 | // Static initialization for persistent factory data |
| 53 | struct Env { |
| 54 | Env() : host_port_pair(kServerHostName, kServerPort), random_generator(0) { |
Ryan Hamilton | 8d9ee76e | 2018-05-29 23:52:52 | [diff] [blame] | 55 | clock.AdvanceTime(quic::QuicTime::Delta::FromSeconds(1)); |
Ryan Sleevi | b8449e0 | 2018-07-15 04:31:07 | [diff] [blame] | 56 | ssl_config_service = std::make_unique<SSLConfigServiceDefaults>(); |
Ned Williamson | 3d55bbb | 2017-11-07 22:58:13 | [diff] [blame] | 57 | crypto_client_stream_factory.set_use_mock_crypter(true); |
Ryan Sleevi | 987d2d9 | 2017-12-19 19:22:14 | [diff] [blame] | 58 | cert_verifier = std::make_unique<MockCertVerifier>(); |
Ryan Sleevi | 987d2d9 | 2017-12-19 19:22:14 | [diff] [blame] | 59 | cert_transparency_verifier = std::make_unique<DoNothingCTVerifier>(); |
Ryan Hamilton | 0a9f0146 | 2017-11-14 01:27:30 | [diff] [blame] | 60 | verify_details.cert_verify_result.verified_cert = |
Avi Drissman | 4365a478 | 2018-12-28 19:26:24 | [diff] [blame^] | 61 | X509Certificate::CreateFromBytes(kCertData, base::size(kCertData)); |
Ryan Hamilton | e3e592e | 2017-11-16 04:49:09 | [diff] [blame] | 62 | CHECK(verify_details.cert_verify_result.verified_cert); |
Ryan Hamilton | 0a9f0146 | 2017-11-14 01:27:30 | [diff] [blame] | 63 | verify_details.cert_verify_result.is_issued_by_known_root = true; |
Ned Williamson | 3d55bbb | 2017-11-07 22:58:13 | [diff] [blame] | 64 | } |
| 65 | |
Ryan Hamilton | 8d9ee76e | 2018-05-29 23:52:52 | [diff] [blame] | 66 | quic::MockClock clock; |
Ryan Sleevi | b8449e0 | 2018-07-15 04:31:07 | [diff] [blame] | 67 | std::unique_ptr<SSLConfigService> ssl_config_service; |
Ryan Hamilton | 0a9f0146 | 2017-11-14 01:27:30 | [diff] [blame] | 68 | ProofVerifyDetailsChromium verify_details; |
Ned Williamson | 3d55bbb | 2017-11-07 22:58:13 | [diff] [blame] | 69 | MockCryptoClientStreamFactory crypto_client_stream_factory; |
| 70 | HostPortPair host_port_pair; |
Ryan Hamilton | 8d9ee76e | 2018-05-29 23:52:52 | [diff] [blame] | 71 | quic::test::MockRandom random_generator; |
Ned Williamson | 3d55bbb | 2017-11-07 22:58:13 | [diff] [blame] | 72 | NetLogWithSource net_log; |
| 73 | std::unique_ptr<CertVerifier> cert_verifier; |
Ned Williamson | 3d55bbb | 2017-11-07 22:58:13 | [diff] [blame] | 74 | TransportSecurityState transport_security_state; |
Ryan Hamilton | 8d9ee76e | 2018-05-29 23:52:52 | [diff] [blame] | 75 | quic::QuicTagVector connection_options; |
| 76 | quic::QuicTagVector client_connection_options; |
Ned Williamson | 3d55bbb | 2017-11-07 22:58:13 | [diff] [blame] | 77 | std::unique_ptr<CTVerifier> cert_transparency_verifier; |
Ryan Sleevi | 8a9c9c1 | 2018-05-09 02:36:23 | [diff] [blame] | 78 | DefaultCTPolicyEnforcer ct_policy_enforcer; |
Ned Williamson | 3d55bbb | 2017-11-07 22:58:13 | [diff] [blame] | 79 | }; |
| 80 | |
| 81 | static struct Env* env = new Env(); |
| 82 | |
| 83 | extern "C" int LLVMFuzzerTestOneInput(const uint8_t* data, size_t size) { |
| 84 | base::FuzzedDataProvider data_provider(data, size); |
| 85 | |
| 86 | FuzzedHostResolver host_resolver(HostResolver::Options(), nullptr, |
| 87 | &data_provider); |
| 88 | FuzzedSocketFactory socket_factory(&data_provider); |
| 89 | |
| 90 | // Initialize this on each loop since some options mutate this. |
| 91 | HttpServerPropertiesImpl http_server_properties; |
| 92 | |
Ned Williamson | 1000a49 | 2017-11-09 20:40:14 | [diff] [blame] | 93 | bool store_server_configs_in_properties = data_provider.ConsumeBool(); |
Jana Iyengar | 903dec2 | 2017-11-28 00:44:23 | [diff] [blame] | 94 | bool close_sessions_on_ip_change = data_provider.ConsumeBool(); |
Ned Williamson | 1000a49 | 2017-11-09 20:40:14 | [diff] [blame] | 95 | bool mark_quic_broken_when_network_blackholes = data_provider.ConsumeBool(); |
Ned Williamson | 1000a49 | 2017-11-09 20:40:14 | [diff] [blame] | 96 | bool allow_server_migration = data_provider.ConsumeBool(); |
| 97 | bool race_cert_verification = data_provider.ConsumeBool(); |
| 98 | bool estimate_initial_rtt = data_provider.ConsumeBool(); |
Yixin Wang | 079ad54 | 2018-01-11 04:06:05 | [diff] [blame] | 99 | bool headers_include_h2_stream_dependency = data_provider.ConsumeBool(); |
kapishnikov | 7f8dd1e12 | 2018-01-24 06:10:49 | [diff] [blame] | 100 | bool enable_socket_recv_optimization = data_provider.ConsumeBool(); |
Renjie | a0cb4a2c | 2018-09-26 23:37:30 | [diff] [blame] | 101 | bool race_stale_dns_on_connection = data_provider.ConsumeBool(); |
Ned Williamson | 1000a49 | 2017-11-09 20:40:14 | [diff] [blame] | 102 | |
Ryan Hamilton | 0a9f0146 | 2017-11-14 01:27:30 | [diff] [blame] | 103 | env->crypto_client_stream_factory.AddProofVerifyDetails(&env->verify_details); |
| 104 | |
Zhongyi Shi | 63574b7f | 2018-06-01 20:22:25 | [diff] [blame] | 105 | bool goaway_sessions_on_ip_change = false; |
Zhongyi Shi | f4683a3 | 2017-12-01 00:03:28 | [diff] [blame] | 106 | bool migrate_sessions_early_v2 = false; |
Zhongyi Shi | 56e44b2 | 2017-12-02 00:06:33 | [diff] [blame] | 107 | bool migrate_sessions_on_network_change_v2 = false; |
Zhongyi Shi | 8de4383 | 2018-08-15 23:40:00 | [diff] [blame] | 108 | bool retry_on_alternate_network_before_handshake = false; |
Renjie | a5722ccf | 2018-08-10 00:18:49 | [diff] [blame] | 109 | bool go_away_on_path_degrading = false; |
Zhongyi Shi | f4683a3 | 2017-12-01 00:03:28 | [diff] [blame] | 110 | |
Zhongyi Shi | 56e44b2 | 2017-12-02 00:06:33 | [diff] [blame] | 111 | if (!close_sessions_on_ip_change) { |
Zhongyi Shi | 63574b7f | 2018-06-01 20:22:25 | [diff] [blame] | 112 | goaway_sessions_on_ip_change = data_provider.ConsumeBool(); |
| 113 | if (!goaway_sessions_on_ip_change) { |
| 114 | migrate_sessions_on_network_change_v2 = data_provider.ConsumeBool(); |
| 115 | if (migrate_sessions_on_network_change_v2) { |
| 116 | migrate_sessions_early_v2 = data_provider.ConsumeBool(); |
Zhongyi Shi | 8de4383 | 2018-08-15 23:40:00 | [diff] [blame] | 117 | retry_on_alternate_network_before_handshake = |
| 118 | data_provider.ConsumeBool(); |
Zhongyi Shi | 63574b7f | 2018-06-01 20:22:25 | [diff] [blame] | 119 | } |
Zhongyi Shi | 56e44b2 | 2017-12-02 00:06:33 | [diff] [blame] | 120 | } |
Zhongyi Shi | f4683a3 | 2017-12-01 00:03:28 | [diff] [blame] | 121 | } |
Ned Williamson | 1000a49 | 2017-11-09 20:40:14 | [diff] [blame] | 122 | |
Renjie | a5722ccf | 2018-08-10 00:18:49 | [diff] [blame] | 123 | if (!migrate_sessions_early_v2) |
| 124 | go_away_on_path_degrading = data_provider.ConsumeBool(); |
| 125 | |
Ned Williamson | 3d55bbb | 2017-11-07 22:58:13 | [diff] [blame] | 126 | std::unique_ptr<QuicStreamFactory> factory = |
| 127 | std::make_unique<QuicStreamFactory>( |
| 128 | env->net_log.net_log(), &host_resolver, env->ssl_config_service.get(), |
| 129 | &socket_factory, &http_server_properties, env->cert_verifier.get(), |
Nick Harper | ecf319d | 2018-10-16 07:58:54 | [diff] [blame] | 130 | &env->ct_policy_enforcer, &env->transport_security_state, |
| 131 | env->cert_transparency_verifier.get(), nullptr, |
| 132 | &env->crypto_client_stream_factory, &env->random_generator, |
Ryan Hamilton | 8d9ee76e | 2018-05-29 23:52:52 | [diff] [blame] | 133 | &env->clock, quic::kDefaultMaxPacketSize, std::string(), |
Jana Iyengar | 903dec2 | 2017-11-28 00:44:23 | [diff] [blame] | 134 | store_server_configs_in_properties, close_sessions_on_ip_change, |
Zhongyi Shi | 63574b7f | 2018-06-01 20:22:25 | [diff] [blame] | 135 | goaway_sessions_on_ip_change, |
Ned Williamson | 1000a49 | 2017-11-09 20:40:14 | [diff] [blame] | 136 | mark_quic_broken_when_network_blackholes, |
Ryan Hamilton | 8d9ee76e | 2018-05-29 23:52:52 | [diff] [blame] | 137 | kIdleConnectionTimeoutSeconds, quic::kPingTimeoutSecs, |
| 138 | quic::kMaxTimeForCryptoHandshakeSecs, quic::kInitialIdleTimeoutSecs, |
Zhongyi Shi | 6ec9d23 | 2018-05-18 02:20:39 | [diff] [blame] | 139 | migrate_sessions_on_network_change_v2, migrate_sessions_early_v2, |
Zhongyi Shi | 8de4383 | 2018-08-15 23:40:00 | [diff] [blame] | 140 | retry_on_alternate_network_before_handshake, |
Renjie | a0cb4a2c | 2018-09-26 23:37:30 | [diff] [blame] | 141 | race_stale_dns_on_connection, go_away_on_path_degrading, |
Zhongyi Shi | 73f23ca87 | 2017-12-13 18:37:13 | [diff] [blame] | 142 | base::TimeDelta::FromSeconds(kMaxTimeOnNonDefaultNetworkSecs), |
Zhongyi Shi | ee76076 | 2018-08-01 00:54:29 | [diff] [blame] | 143 | kMaxMigrationsToNonDefaultNetworkOnWriteError, |
Zhongyi Shi | 8b1e43f | 2017-12-13 20:46:30 | [diff] [blame] | 144 | kMaxMigrationsToNonDefaultNetworkOnPathDegrading, |
Zhongyi Shi | 73f23ca87 | 2017-12-13 18:37:13 | [diff] [blame] | 145 | allow_server_migration, race_cert_verification, estimate_initial_rtt, |
Yixin Wang | 079ad54 | 2018-01-11 04:06:05 | [diff] [blame] | 146 | headers_include_h2_stream_dependency, env->connection_options, |
Nick Harper | ecf319d | 2018-10-16 07:58:54 | [diff] [blame] | 147 | env->client_connection_options, enable_socket_recv_optimization); |
Ned Williamson | 3d55bbb | 2017-11-07 22:58:13 | [diff] [blame] | 148 | |
| 149 | QuicStreamRequest request(factory.get()); |
| 150 | TestCompletionCallback callback; |
| 151 | NetErrorDetails net_error_details; |
Ryan Hamilton | 8d9ee76e | 2018-05-29 23:52:52 | [diff] [blame] | 152 | request.Request( |
| 153 | env->host_port_pair, |
| 154 | data_provider.PickValueInArray(quic::kSupportedTransportVersions), |
| 155 | PRIVACY_MODE_DISABLED, DEFAULT_PRIORITY, SocketTag(), kCertVerifyFlags, |
Zhongyi Shi | a6b68d11 | 2018-09-24 07:49:03 | [diff] [blame] | 156 | GURL(kUrl), env->net_log, &net_error_details, |
| 157 | /*failed_on_default_network_callback=*/CompletionOnceCallback(), |
| 158 | callback.callback()); |
Ned Williamson | 3d55bbb | 2017-11-07 22:58:13 | [diff] [blame] | 159 | |
| 160 | callback.WaitForResult(); |
Yixin Wang | 7891a39d | 2017-11-08 20:59:24 | [diff] [blame] | 161 | std::unique_ptr<QuicChromiumClientSession::Handle> session = |
| 162 | request.ReleaseSessionHandle(); |
| 163 | if (!session) |
Ned Williamson | 3d55bbb | 2017-11-07 22:58:13 | [diff] [blame] | 164 | return 0; |
Yixin Wang | 7891a39d | 2017-11-08 20:59:24 | [diff] [blame] | 165 | std::unique_ptr<HttpStream> stream(new QuicHttpStream(std::move(session))); |
Ned Williamson | 3d55bbb | 2017-11-07 22:58:13 | [diff] [blame] | 166 | |
| 167 | HttpRequestInfo request_info; |
| 168 | request_info.method = kMethod; |
| 169 | request_info.url = GURL(kUrl); |
Ramin Halavati | a1256c8 | 2018-02-21 06:18:21 | [diff] [blame] | 170 | request_info.traffic_annotation = |
| 171 | MutableNetworkTrafficAnnotationTag(TRAFFIC_ANNOTATION_FOR_TESTS); |
Steven Valdez | b4ff041 | 2018-01-18 22:39:27 | [diff] [blame] | 172 | stream->InitializeStream(&request_info, true, DEFAULT_PRIORITY, env->net_log, |
Bence Béky | a25e3f7 | 2018-02-13 21:13:39 | [diff] [blame] | 173 | CompletionOnceCallback()); |
Ned Williamson | 3d55bbb | 2017-11-07 22:58:13 | [diff] [blame] | 174 | |
| 175 | HttpResponseInfo response; |
| 176 | HttpRequestHeaders request_headers; |
| 177 | if (OK != |
| 178 | stream->SendRequest(request_headers, &response, callback.callback())) |
| 179 | return 0; |
| 180 | |
| 181 | // TODO(nedwilliamson): attempt connection migration here |
Nick Harper | 7ac20cc | 2018-05-08 18:06:04 | [diff] [blame] | 182 | int rv = stream->ReadResponseHeaders(callback.callback()); |
| 183 | if (rv != OK && rv != ERR_IO_PENDING) { |
| 184 | return 0; |
| 185 | } |
Ned Williamson | 3d55bbb | 2017-11-07 22:58:13 | [diff] [blame] | 186 | callback.WaitForResult(); |
| 187 | |
Victor Costan | 9c7302b | 2018-08-27 16:39:44 | [diff] [blame] | 188 | scoped_refptr<net::IOBuffer> buffer = |
| 189 | base::MakeRefCounted<net::IOBuffer>(kBufferSize); |
Nick Harper | 7ac20cc | 2018-05-08 18:06:04 | [diff] [blame] | 190 | rv = stream->ReadResponseBody(buffer.get(), kBufferSize, callback.callback()); |
Ned Williamson | 3d55bbb | 2017-11-07 22:58:13 | [diff] [blame] | 191 | if (rv == ERR_IO_PENDING) |
| 192 | callback.WaitForResult(); |
| 193 | |
| 194 | return 0; |
| 195 | } |
| 196 | |
| 197 | } // namespace test |
| 198 | } // namespace net |