Vitaly Buka | b5c12da | 2016-10-19 13:12:41 -0700 | [diff] [blame] | 1 | // Copyright 2016 Google Inc. All rights reserved. |
| 2 | // |
| 3 | // Licensed under the Apache License, Version 2.0 (the "License"); |
| 4 | // you may not use this file except in compliance with the License. |
| 5 | // You may obtain a copy of the License at |
| 6 | // |
| 7 | // http://www.apache.org/licenses/LICENSE-2.0 |
| 8 | // |
| 9 | // Unless required by applicable law or agreed to in writing, software |
| 10 | // distributed under the License is distributed on an "AS IS" BASIS, |
| 11 | // WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. |
| 12 | // See the License for the specific language governing permissions and |
| 13 | // limitations under the License. |
| 14 | |
Vitaly Buka | f90698f | 2017-03-01 15:46:58 -0800 | [diff] [blame] | 15 | #ifndef SRC_MUTATOR_H_ |
| 16 | #define SRC_MUTATOR_H_ |
Vitaly Buka | b5c12da | 2016-10-19 13:12:41 -0700 | [diff] [blame] | 17 | |
Vitaly Buka | 781853c | 2016-11-21 23:09:35 -0800 | [diff] [blame] | 18 | #include <stddef.h> |
| 19 | #include <stdint.h> |
| 20 | |
Allen-Webb | c4fa591 | 2018-09-07 15:53:30 -0700 | [diff] [blame] | 21 | #include <functional> |
Vitaly Buka | 781853c | 2016-11-21 23:09:35 -0800 | [diff] [blame] | 22 | #include <memory> |
Vitaly Buka | 0e17fd7 | 2016-11-18 10:02:46 -0800 | [diff] [blame] | 23 | #include <random> |
Vitaly Buka | f047a00 | 2017-01-12 23:57:00 -0800 | [diff] [blame] | 24 | #include <string> |
Allen-Webb | c4fa591 | 2018-09-07 15:53:30 -0700 | [diff] [blame] | 25 | #include <unordered_map> |
| 26 | #include <vector> |
Vitaly Buka | 00b6107 | 2016-10-19 16:22:51 -0700 | [diff] [blame] | 27 | |
Vitaly Buka | 35df2e4 | 2017-02-25 01:17:25 -0800 | [diff] [blame] | 28 | #include "port/protobuf.h" |
Vitaly Buka | f62fe47 | 2017-03-01 23:05:15 -0800 | [diff] [blame] | 29 | #include "src/random.h" |
Vitaly Buka | b5c12da | 2016-10-19 13:12:41 -0700 | [diff] [blame] | 30 | |
Vitaly Buka | 432b545 | 2016-12-09 14:42:09 -0800 | [diff] [blame] | 31 | namespace protobuf_mutator { |
| 32 | |
Vitaly Buka | 4af611d | 2016-12-03 18:57:32 -0800 | [diff] [blame] | 33 | // Randomly makes incremental change in the given protobuf. |
| 34 | // Usage example: |
Vitaly Buka | e79e018 | 2017-03-01 16:02:14 -0800 | [diff] [blame] | 35 | // protobuf_mutator::Mutator mutator(1); |
Vitaly Buka | 4af611d | 2016-12-03 18:57:32 -0800 | [diff] [blame] | 36 | // MyMessage message; |
| 37 | // message.ParseFromString(encoded_message); |
Vitaly Buka | 4a6d6fc | 2016-12-16 14:21:37 -0800 | [diff] [blame] | 38 | // mutator.Mutate(&message, 10000); |
Vitaly Buka | 4af611d | 2016-12-03 18:57:32 -0800 | [diff] [blame] | 39 | // |
Vitaly Buka | 432b545 | 2016-12-09 14:42:09 -0800 | [diff] [blame] | 40 | // Class implements very basic mutations of fields. E.g. it just flips bits for |
| 41 | // integers, floats and strings. Also it increases, decreases size of |
| 42 | // strings only by one. For better results users should override |
Vitaly Buka | e79e018 | 2017-03-01 16:02:14 -0800 | [diff] [blame] | 43 | // protobuf_mutator::Mutator::Mutate* methods with more useful logic, e.g. using |
| 44 | // library like libFuzzer. |
| 45 | class Mutator { |
Vitaly Buka | b5c12da | 2016-10-19 13:12:41 -0700 | [diff] [blame] | 46 | public: |
Vitaly Buka | 4af611d | 2016-12-03 18:57:32 -0800 | [diff] [blame] | 47 | // seed: value to initialize random number generator. |
Vitaly Buka | 379f5ab | 2019-08-31 16:11:59 -0700 | [diff] [blame] | 48 | Mutator() = default; |
Vitaly Buka | e79e018 | 2017-03-01 16:02:14 -0800 | [diff] [blame] | 49 | virtual ~Mutator() = default; |
Vitaly Buka | 781853c | 2016-11-21 23:09:35 -0800 | [diff] [blame] | 50 | |
Vitaly Buka | 379f5ab | 2019-08-31 16:11:59 -0700 | [diff] [blame] | 51 | // Initialized internal random number generator. |
| 52 | void Seed(uint32_t value); |
| 53 | |
Vitaly Buka | 4af611d | 2016-12-03 18:57:32 -0800 | [diff] [blame] | 54 | // message: message to mutate. |
Vitaly Buka | baa1329 | 2020-01-25 19:39:28 -0800 | [diff] [blame] | 55 | // max_size_hint: approximate max ByteSize() of resulting message. Method does |
| 56 | // not guarantee that real result will be strictly smaller than value. Caller |
| 57 | // could repeat mutation if result was larger than expected. |
| 58 | void Mutate(protobuf::Message* message, size_t max_size_hint); |
Vitaly Buka | 4af611d | 2016-12-03 18:57:32 -0800 | [diff] [blame] | 59 | |
Vitaly Buka | 9f357ae | 2020-01-26 23:17:11 -0800 | [diff] [blame] | 60 | void CrossOver(const protobuf::Message& message1, protobuf::Message* message2, |
| 61 | size_t max_size_hint); |
Vitaly Buka | b5c12da | 2016-10-19 13:12:41 -0700 | [diff] [blame] | 62 | |
Vitaly Buka | d82b5fb | 2020-07-28 23:41:42 -0700 | [diff] [blame] | 63 | // Makes message initialized and calls post processors to make it valid. |
| 64 | void Fix(protobuf::Message* message); |
| 65 | |
Vitaly Buka | 67387f7 | 2019-08-31 19:34:10 -0700 | [diff] [blame] | 66 | // Callback to postprocess mutations. |
| 67 | // Implementation should use seed to initialize random number generators. |
| 68 | using PostProcess = |
| 69 | std::function<void(protobuf::Message* message, unsigned int seed)>; |
| 70 | |
| 71 | // Register callback which will be called after every message mutation. |
| 72 | // In this callback fuzzer may adjust content of the message or mutate some |
| 73 | // fields in some fuzzer specific way. |
Peter Foley | fe76ed6 | 2019-09-30 17:03:37 -0700 | [diff] [blame] | 74 | void RegisterPostProcessor(const protobuf::Descriptor* desc, |
| 75 | PostProcess callback); |
Allen-Webb | c4fa591 | 2018-09-07 15:53:30 -0700 | [diff] [blame] | 76 | |
Vitaly Buka | 432b545 | 2016-12-09 14:42:09 -0800 | [diff] [blame] | 77 | protected: |
Vitaly Buka | b93a146 | 2017-01-06 17:52:58 -0800 | [diff] [blame] | 78 | // TODO(vitalybuka): Consider to replace with single mutate (uint8_t*, size). |
Vitaly Buka | 4af611d | 2016-12-03 18:57:32 -0800 | [diff] [blame] | 79 | virtual int32_t MutateInt32(int32_t value); |
| 80 | virtual int64_t MutateInt64(int64_t value); |
| 81 | virtual uint32_t MutateUInt32(uint32_t value); |
| 82 | virtual uint64_t MutateUInt64(uint64_t value); |
| 83 | virtual float MutateFloat(float value); |
| 84 | virtual double MutateDouble(double value); |
| 85 | virtual bool MutateBool(bool value); |
| 86 | virtual size_t MutateEnum(size_t index, size_t item_count); |
| 87 | virtual std::string MutateString(const std::string& value, |
Vitaly Buka | 1c91e72 | 2020-01-25 21:56:22 -0800 | [diff] [blame] | 88 | int size_increase_hint); |
Vitaly Buka | 4af611d | 2016-12-03 18:57:32 -0800 | [diff] [blame] | 89 | |
Vitaly Buka | 379f5ab | 2019-08-31 16:11:59 -0700 | [diff] [blame] | 90 | RandomEngine* random() { return &random_; } |
Vitaly Buka | 68e49ad | 2017-02-24 14:24:31 -0800 | [diff] [blame] | 91 | |
Vitaly Buka | b5c12da | 2016-10-19 13:12:41 -0700 | [diff] [blame] | 92 | private: |
Vitaly Buka | 5d01320 | 2017-02-24 16:50:11 -0800 | [diff] [blame] | 93 | friend class FieldMutator; |
Vitaly Buka | e79e018 | 2017-03-01 16:02:14 -0800 | [diff] [blame] | 94 | friend class TestMutator; |
Vitaly Buka | f62086c | 2020-01-29 01:11:23 -0800 | [diff] [blame] | 95 | bool MutateImpl(const std::vector<const protobuf::Message*>& sources, |
| 96 | const std::vector<protobuf::Message*>& messages, |
Vitaly Buka | 9f357ae | 2020-01-26 23:17:11 -0800 | [diff] [blame] | 97 | bool copy_clone_only, int size_increase_hint); |
Vitaly Buka | af8136f | 2017-06-09 16:40:12 -0700 | [diff] [blame] | 98 | std::string MutateUtf8String(const std::string& value, |
Vitaly Buka | 1c91e72 | 2020-01-25 21:56:22 -0800 | [diff] [blame] | 99 | int size_increase_hint); |
Vitaly Buka | 9eaf063 | 2020-01-15 17:30:20 -0800 | [diff] [blame] | 100 | bool IsInitialized(const protobuf::Message& message) const; |
Vitaly Buka | ba12972 | 2016-12-14 17:29:15 -0800 | [diff] [blame] | 101 | bool keep_initialized_ = true; |
Vitaly Buka | d7f943f | 2019-01-31 14:05:33 -0800 | [diff] [blame] | 102 | size_t random_to_default_ratio_ = 100; |
Vitaly Buka | 379f5ab | 2019-08-31 16:11:59 -0700 | [diff] [blame] | 103 | RandomEngine random_; |
Vitaly Buka | 045acda | 2020-01-29 00:26:35 -0800 | [diff] [blame] | 104 | using PostProcessors = |
| 105 | std::unordered_multimap<const protobuf::Descriptor*, PostProcess>; |
| 106 | PostProcessors post_processors_; |
Vitaly Buka | b5c12da | 2016-10-19 13:12:41 -0700 | [diff] [blame] | 107 | }; |
| 108 | |
Vitaly Buka | 432b545 | 2016-12-09 14:42:09 -0800 | [diff] [blame] | 109 | } // namespace protobuf_mutator |
| 110 | |
Vitaly Buka | f90698f | 2017-03-01 15:46:58 -0800 | [diff] [blame] | 111 | #endif // SRC_MUTATOR_H_ |