diff options
author | Yu Watanabe <watanabe.yu+github@gmail.com> | 2021-12-31 04:30:43 +0900 |
---|---|---|
committer | Zbigniew Jędrzejewski-Szmek <zbyszek@in.waw.pl> | 2022-05-12 13:31:11 +0200 |
commit | 7593691aadc7e1e9c5f17fd26424abe337d56302 (patch) | |
tree | 679f27ca634c56508788eee6d3809c71c1c48005 /src/resolve | |
parent | 96974ea4a85bee508659f8c36f6a32c6b89646f4 (diff) | |
download | systemd-7593691aadc7e1e9c5f17fd26424abe337d56302.tar.gz |
fuzzers: add input size limits, always configure limits in two ways
Without the size limits, oss-fuzz creates huge samples that time out. Usually
this is because some of our code has bad algorithmic complexity. For data like
configuration samples we don't need to care about this: non-rogue configs are
rarely more than a few items, and a bit of a slowdown with a few hundred items
is acceptable. This wouldn't be OK for processing of untrusted data though.
We need to set the limit in two ways: through .options and in the code. The
first because it nicely allows libFuzzer to avoid wasting time, and the second
because fuzzers like hongfuzz and afl don't support .options.
While at it, let's fix an off-by-one (65535 is the largest offset for a
power-of-two size, but we're checking the size here).
Co-authored-by: Zbigniew Jędrzejewski-Szmek <zbyszek@in.waw.pl>
Diffstat (limited to 'src/resolve')
-rw-r--r-- | src/resolve/fuzz-dns-packet.options | 2 |
1 files changed, 1 insertions, 1 deletions
diff --git a/src/resolve/fuzz-dns-packet.options b/src/resolve/fuzz-dns-packet.options index 0824b19fab..678d526b1e 100644 --- a/src/resolve/fuzz-dns-packet.options +++ b/src/resolve/fuzz-dns-packet.options @@ -1,2 +1,2 @@ [libfuzzer] -max_len = 65535 +max_len = 65536 |