Ned Williamson | 3d55bbb | 2017-11-07 22:58:13 | [diff] [blame] | 1 | // Copyright 2017 The Chromium Authors. All rights reserved. |
| 2 | // Use of this source code is governed by a BSD-style license that can be |
| 3 | // found in the LICENSE file. |
| 4 | |
Ryan Hamilton | a3ee93a7 | 2018-08-01 22:03:08 | [diff] [blame] | 5 | #include "net/quic/quic_stream_factory.h" |
Ned Williamson | 3d55bbb | 2017-11-07 22:58:13 | [diff] [blame] | 6 | |
Max Moroz | a1707f4 | 2019-08-28 21:10:28 | [diff] [blame] | 7 | #include <fuzzer/FuzzedDataProvider.h> |
| 8 | |
Avi Drissman | 4365a478 | 2018-12-28 19:26:24 | [diff] [blame] | 9 | #include "base/stl_util.h" |
Matt Menke | 26e4154 | 2019-06-05 01:09:51 | [diff] [blame] | 10 | #include "net/base/network_isolation_key.h" |
Ned Williamson | 3d55bbb | 2017-11-07 22:58:13 | [diff] [blame] | 11 | #include "net/base/test_completion_callback.h" |
Ryan Sleevi | 8a9c9c1 | 2018-05-09 02:36:23 | [diff] [blame] | 12 | #include "net/cert/ct_policy_enforcer.h" |
Ryan Sleevi | 987d2d9 | 2017-12-19 19:22:14 | [diff] [blame] | 13 | #include "net/cert/do_nothing_ct_verifier.h" |
| 14 | #include "net/cert/mock_cert_verifier.h" |
Ryan Hamilton | e3e592e | 2017-11-16 04:49:09 | [diff] [blame] | 15 | #include "net/cert/x509_certificate.h" |
Eric Orth | 4e55b36 | 2019-05-07 22:00:03 | [diff] [blame] | 16 | #include "net/dns/context_host_resolver.h" |
| 17 | #include "net/dns/fuzzed_host_resolver_util.h" |
Matt Menke | 60916074 | 2019-08-02 18:47:26 | [diff] [blame] | 18 | #include "net/http/http_server_properties.h" |
Ned Williamson | 3d55bbb | 2017-11-07 22:58:13 | [diff] [blame] | 19 | #include "net/http/transport_security_state.h" |
Ryan Hamilton | a3ee93a7 | 2018-08-01 22:03:08 | [diff] [blame] | 20 | #include "net/quic/mock_crypto_client_stream_factory.h" |
| 21 | #include "net/quic/quic_http_stream.h" |
| 22 | #include "net/quic/test_task_runner.h" |
Ned Williamson | 3d55bbb | 2017-11-07 22:58:13 | [diff] [blame] | 23 | #include "net/socket/fuzzed_datagram_client_socket.h" |
| 24 | #include "net/socket/fuzzed_socket_factory.h" |
Paul Jensen | 8e3c5d3 | 2018-02-19 17:06:33 | [diff] [blame] | 25 | #include "net/socket/socket_tag.h" |
Ryan Sleevi | 987d2d9 | 2017-12-19 19:22:14 | [diff] [blame] | 26 | #include "net/ssl/ssl_config_service_defaults.h" |
Ryan Hamilton | 0a9f0146 | 2017-11-14 01:27:30 | [diff] [blame] | 27 | #include "net/test/gtest_util.h" |
Victor Vasiliev | 6bb59d2 | 2019-03-08 21:34:51 | [diff] [blame] | 28 | #include "net/third_party/quiche/src/quic/test_tools/mock_clock.h" |
| 29 | #include "net/third_party/quiche/src/quic/test_tools/mock_random.h" |
Ramin Halavati | a1256c8 | 2018-02-21 06:18:21 | [diff] [blame] | 30 | #include "net/traffic_annotation/network_traffic_annotation_test_helper.h" |
Ned Williamson | 3d55bbb | 2017-11-07 22:58:13 | [diff] [blame] | 31 | |
| 32 | namespace net { |
| 33 | |
| 34 | namespace { |
| 35 | |
Ryan Hamilton | e3e592e | 2017-11-16 04:49:09 | [diff] [blame] | 36 | const char kCertData[] = { |
| 37 | #include "net/data/ssl/certificates/wildcard.inc" |
| 38 | }; |
| 39 | |
Ned Williamson | 3d55bbb | 2017-11-07 22:58:13 | [diff] [blame] | 40 | } // namespace |
| 41 | |
| 42 | namespace test { |
| 43 | |
| 44 | const char kServerHostName[] = "www.example.org"; |
| 45 | const int kServerPort = 443; |
| 46 | const char kUrl[] = "https://www.example.org/"; |
| 47 | // TODO(nedwilliamson): Add POST here after testing |
| 48 | // whether that can lead blocking while waiting for |
| 49 | // the callbacks. |
| 50 | const char kMethod[] = "GET"; |
| 51 | const size_t kBufferSize = 4096; |
| 52 | const int kCertVerifyFlags = 0; |
| 53 | |
| 54 | // Static initialization for persistent factory data |
| 55 | struct Env { |
| 56 | Env() : host_port_pair(kServerHostName, kServerPort), random_generator(0) { |
Ryan Hamilton | 8d9ee76e | 2018-05-29 23:52:52 | [diff] [blame] | 57 | clock.AdvanceTime(quic::QuicTime::Delta::FromSeconds(1)); |
Ryan Sleevi | b8449e0 | 2018-07-15 04:31:07 | [diff] [blame] | 58 | ssl_config_service = std::make_unique<SSLConfigServiceDefaults>(); |
Ned Williamson | 3d55bbb | 2017-11-07 22:58:13 | [diff] [blame] | 59 | crypto_client_stream_factory.set_use_mock_crypter(true); |
Ryan Sleevi | 987d2d9 | 2017-12-19 19:22:14 | [diff] [blame] | 60 | cert_verifier = std::make_unique<MockCertVerifier>(); |
Ryan Sleevi | 987d2d9 | 2017-12-19 19:22:14 | [diff] [blame] | 61 | cert_transparency_verifier = std::make_unique<DoNothingCTVerifier>(); |
Ryan Hamilton | 0a9f0146 | 2017-11-14 01:27:30 | [diff] [blame] | 62 | verify_details.cert_verify_result.verified_cert = |
Avi Drissman | 4365a478 | 2018-12-28 19:26:24 | [diff] [blame] | 63 | X509Certificate::CreateFromBytes(kCertData, base::size(kCertData)); |
Ryan Hamilton | e3e592e | 2017-11-16 04:49:09 | [diff] [blame] | 64 | CHECK(verify_details.cert_verify_result.verified_cert); |
Ryan Hamilton | 0a9f0146 | 2017-11-14 01:27:30 | [diff] [blame] | 65 | verify_details.cert_verify_result.is_issued_by_known_root = true; |
Ned Williamson | 3d55bbb | 2017-11-07 22:58:13 | [diff] [blame] | 66 | } |
| 67 | |
Ryan Hamilton | 8d9ee76e | 2018-05-29 23:52:52 | [diff] [blame] | 68 | quic::MockClock clock; |
Ryan Sleevi | b8449e0 | 2018-07-15 04:31:07 | [diff] [blame] | 69 | std::unique_ptr<SSLConfigService> ssl_config_service; |
Ryan Hamilton | 0a9f0146 | 2017-11-14 01:27:30 | [diff] [blame] | 70 | ProofVerifyDetailsChromium verify_details; |
Ned Williamson | 3d55bbb | 2017-11-07 22:58:13 | [diff] [blame] | 71 | MockCryptoClientStreamFactory crypto_client_stream_factory; |
| 72 | HostPortPair host_port_pair; |
Ryan Hamilton | 8d9ee76e | 2018-05-29 23:52:52 | [diff] [blame] | 73 | quic::test::MockRandom random_generator; |
Ned Williamson | 3d55bbb | 2017-11-07 22:58:13 | [diff] [blame] | 74 | NetLogWithSource net_log; |
| 75 | std::unique_ptr<CertVerifier> cert_verifier; |
Ned Williamson | 3d55bbb | 2017-11-07 22:58:13 | [diff] [blame] | 76 | TransportSecurityState transport_security_state; |
Ryan Hamilton | 8d9ee76e | 2018-05-29 23:52:52 | [diff] [blame] | 77 | quic::QuicTagVector connection_options; |
| 78 | quic::QuicTagVector client_connection_options; |
Ned Williamson | 3d55bbb | 2017-11-07 22:58:13 | [diff] [blame] | 79 | std::unique_ptr<CTVerifier> cert_transparency_verifier; |
Ryan Sleevi | 8a9c9c1 | 2018-05-09 02:36:23 | [diff] [blame] | 80 | DefaultCTPolicyEnforcer ct_policy_enforcer; |
Ned Williamson | 3d55bbb | 2017-11-07 22:58:13 | [diff] [blame] | 81 | }; |
| 82 | |
| 83 | static struct Env* env = new Env(); |
| 84 | |
| 85 | extern "C" int LLVMFuzzerTestOneInput(const uint8_t* data, size_t size) { |
Max Moroz | cfbe47cc | 2019-06-24 17:45:02 | [diff] [blame] | 86 | FuzzedDataProvider data_provider(data, size); |
Ned Williamson | 3d55bbb | 2017-11-07 22:58:13 | [diff] [blame] | 87 | |
Eric Orth | 4e55b36 | 2019-05-07 22:00:03 | [diff] [blame] | 88 | std::unique_ptr<ContextHostResolver> host_resolver = |
| 89 | CreateFuzzedContextHostResolver(HostResolver::ManagerOptions(), nullptr, |
| 90 | &data_provider, |
| 91 | true /* enable_caching */); |
Ned Williamson | 3d55bbb | 2017-11-07 22:58:13 | [diff] [blame] | 92 | FuzzedSocketFactory socket_factory(&data_provider); |
| 93 | |
| 94 | // Initialize this on each loop since some options mutate this. |
Matt Menke | 60916074 | 2019-08-02 18:47:26 | [diff] [blame] | 95 | HttpServerProperties http_server_properties; |
Ned Williamson | 3d55bbb | 2017-11-07 22:58:13 | [diff] [blame] | 96 | |
Nick Harper | 72ade19 | 2019-07-17 03:30:42 | [diff] [blame] | 97 | QuicParams params; |
| 98 | params.max_server_configs_stored_in_properties = |
| 99 | data_provider.ConsumeBool() ? 1 : 0; |
| 100 | params.close_sessions_on_ip_change = data_provider.ConsumeBool(); |
Nick Harper | 72ade19 | 2019-07-17 03:30:42 | [diff] [blame] | 101 | params.allow_server_migration = data_provider.ConsumeBool(); |
| 102 | params.race_cert_verification = data_provider.ConsumeBool(); |
| 103 | params.estimate_initial_rtt = data_provider.ConsumeBool(); |
| 104 | params.headers_include_h2_stream_dependency = data_provider.ConsumeBool(); |
| 105 | params.enable_socket_recv_optimization = data_provider.ConsumeBool(); |
| 106 | params.race_stale_dns_on_connection = data_provider.ConsumeBool(); |
Ned Williamson | 1000a49 | 2017-11-09 20:40:14 | [diff] [blame] | 107 | |
Ryan Hamilton | 0a9f0146 | 2017-11-14 01:27:30 | [diff] [blame] | 108 | env->crypto_client_stream_factory.AddProofVerifyDetails(&env->verify_details); |
| 109 | |
Nick Harper | 72ade19 | 2019-07-17 03:30:42 | [diff] [blame] | 110 | params.goaway_sessions_on_ip_change = false; |
| 111 | params.migrate_sessions_early_v2 = false; |
| 112 | params.migrate_sessions_on_network_change_v2 = false; |
| 113 | params.retry_on_alternate_network_before_handshake = false; |
| 114 | params.migrate_idle_sessions = false; |
| 115 | params.go_away_on_path_degrading = false; |
Zhongyi Shi | f4683a3 | 2017-12-01 00:03:28 | [diff] [blame] | 116 | |
Nick Harper | 72ade19 | 2019-07-17 03:30:42 | [diff] [blame] | 117 | if (!params.close_sessions_on_ip_change) { |
| 118 | params.goaway_sessions_on_ip_change = data_provider.ConsumeBool(); |
| 119 | if (!params.goaway_sessions_on_ip_change) { |
| 120 | params.migrate_sessions_on_network_change_v2 = |
| 121 | data_provider.ConsumeBool(); |
| 122 | if (params.migrate_sessions_on_network_change_v2) { |
| 123 | params.migrate_sessions_early_v2 = data_provider.ConsumeBool(); |
| 124 | params.retry_on_alternate_network_before_handshake = |
Zhongyi Shi | 8de4383 | 2018-08-15 23:40:00 | [diff] [blame] | 125 | data_provider.ConsumeBool(); |
Nick Harper | 72ade19 | 2019-07-17 03:30:42 | [diff] [blame] | 126 | params.migrate_idle_sessions = data_provider.ConsumeBool(); |
Zhongyi Shi | 63574b7f | 2018-06-01 20:22:25 | [diff] [blame] | 127 | } |
Zhongyi Shi | 56e44b2 | 2017-12-02 00:06:33 | [diff] [blame] | 128 | } |
Zhongyi Shi | f4683a3 | 2017-12-01 00:03:28 | [diff] [blame] | 129 | } |
Ned Williamson | 1000a49 | 2017-11-09 20:40:14 | [diff] [blame] | 130 | |
Nick Harper | 72ade19 | 2019-07-17 03:30:42 | [diff] [blame] | 131 | if (!params.migrate_sessions_early_v2) { |
| 132 | params.go_away_on_path_degrading = data_provider.ConsumeBool(); |
| 133 | } |
Renjie | a5722ccf | 2018-08-10 00:18:49 | [diff] [blame] | 134 | |
Ned Williamson | 3d55bbb | 2017-11-07 22:58:13 | [diff] [blame] | 135 | std::unique_ptr<QuicStreamFactory> factory = |
| 136 | std::make_unique<QuicStreamFactory>( |
Eric Orth | 4e55b36 | 2019-05-07 22:00:03 | [diff] [blame] | 137 | env->net_log.net_log(), host_resolver.get(), |
| 138 | env->ssl_config_service.get(), &socket_factory, |
| 139 | &http_server_properties, env->cert_verifier.get(), |
Nick Harper | ecf319d | 2018-10-16 07:58:54 | [diff] [blame] | 140 | &env->ct_policy_enforcer, &env->transport_security_state, |
| 141 | env->cert_transparency_verifier.get(), nullptr, |
| 142 | &env->crypto_client_stream_factory, &env->random_generator, |
Nick Harper | 72ade19 | 2019-07-17 03:30:42 | [diff] [blame] | 143 | &env->clock, params); |
Ned Williamson | 3d55bbb | 2017-11-07 22:58:13 | [diff] [blame] | 144 | |
Nick Harper | 057264a8 | 2019-09-12 23:33:49 | [diff] [blame] | 145 | SetQuicReloadableFlag(quic_supports_tls_handshake, true); |
Ned Williamson | 3d55bbb | 2017-11-07 22:58:13 | [diff] [blame] | 146 | QuicStreamRequest request(factory.get()); |
| 147 | TestCompletionCallback callback; |
| 148 | NetErrorDetails net_error_details; |
Ryan Hamilton | 9ef8c10 | 2019-06-28 03:58:52 | [diff] [blame] | 149 | quic::ParsedQuicVersionVector versions = quic::AllSupportedVersions(); |
| 150 | quic::ParsedQuicVersion version = |
| 151 | versions[data_provider.ConsumeIntegralInRange<size_t>( |
| 152 | 0, versions.size() - 1)]; |
Ryan Hamilton | 8d9ee76e | 2018-05-29 23:52:52 | [diff] [blame] | 153 | request.Request( |
Ryan Hamilton | 9ef8c10 | 2019-06-28 03:58:52 | [diff] [blame] | 154 | env->host_port_pair, version, PRIVACY_MODE_DISABLED, DEFAULT_PRIORITY, |
| 155 | SocketTag(), NetworkIsolationKey(), kCertVerifyFlags, GURL(kUrl), |
| 156 | env->net_log, &net_error_details, |
Zhongyi Shi | a6b68d11 | 2018-09-24 07:49:03 | [diff] [blame] | 157 | /*failed_on_default_network_callback=*/CompletionOnceCallback(), |
| 158 | callback.callback()); |
Ned Williamson | 3d55bbb | 2017-11-07 22:58:13 | [diff] [blame] | 159 | |
| 160 | callback.WaitForResult(); |
Yixin Wang | 7891a39d | 2017-11-08 20:59:24 | [diff] [blame] | 161 | std::unique_ptr<QuicChromiumClientSession::Handle> session = |
| 162 | request.ReleaseSessionHandle(); |
| 163 | if (!session) |
Ned Williamson | 3d55bbb | 2017-11-07 22:58:13 | [diff] [blame] | 164 | return 0; |
Yixin Wang | 7891a39d | 2017-11-08 20:59:24 | [diff] [blame] | 165 | std::unique_ptr<HttpStream> stream(new QuicHttpStream(std::move(session))); |
Ned Williamson | 3d55bbb | 2017-11-07 22:58:13 | [diff] [blame] | 166 | |
| 167 | HttpRequestInfo request_info; |
| 168 | request_info.method = kMethod; |
| 169 | request_info.url = GURL(kUrl); |
Ramin Halavati | a1256c8 | 2018-02-21 06:18:21 | [diff] [blame] | 170 | request_info.traffic_annotation = |
| 171 | MutableNetworkTrafficAnnotationTag(TRAFFIC_ANNOTATION_FOR_TESTS); |
Steven Valdez | b4ff041 | 2018-01-18 22:39:27 | [diff] [blame] | 172 | stream->InitializeStream(&request_info, true, DEFAULT_PRIORITY, env->net_log, |
Bence Béky | a25e3f7 | 2018-02-13 21:13:39 | [diff] [blame] | 173 | CompletionOnceCallback()); |
Ned Williamson | 3d55bbb | 2017-11-07 22:58:13 | [diff] [blame] | 174 | |
| 175 | HttpResponseInfo response; |
| 176 | HttpRequestHeaders request_headers; |
| 177 | if (OK != |
| 178 | stream->SendRequest(request_headers, &response, callback.callback())) |
| 179 | return 0; |
| 180 | |
| 181 | // TODO(nedwilliamson): attempt connection migration here |
Nick Harper | 7ac20cc | 2018-05-08 18:06:04 | [diff] [blame] | 182 | int rv = stream->ReadResponseHeaders(callback.callback()); |
| 183 | if (rv != OK && rv != ERR_IO_PENDING) { |
| 184 | return 0; |
| 185 | } |
Ned Williamson | 3d55bbb | 2017-11-07 22:58:13 | [diff] [blame] | 186 | callback.WaitForResult(); |
| 187 | |
Victor Costan | 9c7302b | 2018-08-27 16:39:44 | [diff] [blame] | 188 | scoped_refptr<net::IOBuffer> buffer = |
| 189 | base::MakeRefCounted<net::IOBuffer>(kBufferSize); |
Nick Harper | 7ac20cc | 2018-05-08 18:06:04 | [diff] [blame] | 190 | rv = stream->ReadResponseBody(buffer.get(), kBufferSize, callback.callback()); |
Ned Williamson | 3d55bbb | 2017-11-07 22:58:13 | [diff] [blame] | 191 | if (rv == ERR_IO_PENDING) |
| 192 | callback.WaitForResult(); |
| 193 | |
| 194 | return 0; |
| 195 | } |
| 196 | |
| 197 | } // namespace test |
| 198 | } // namespace net |