xref: /aosp_15_r20/external/grpc-grpc/test/core/security/alts_credentials_fuzzer.cc (revision cc02d7e222339f7a4f6ba5f422e6413f4bd931f2)
1 //
2 //
3 // Copyright 2018 gRPC authors.
4 //
5 // Licensed under the Apache License, Version 2.0 (the "License");
6 // you may not use this file except in compliance with the License.
7 // You may obtain a copy of the License at
8 //
9 //     http://www.apache.org/licenses/LICENSE-2.0
10 //
11 // Unless required by applicable law or agreed to in writing, software
12 // distributed under the License is distributed on an "AS IS" BASIS,
13 // WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
14 // See the License for the specific language governing permissions and
15 // limitations under the License.
16 //
17 //
18 
19 #include <string.h>
20 
21 #include <grpc/grpc.h>
22 #include <grpc/grpc_security.h>
23 #include <grpc/support/alloc.h>
24 #include <grpc/support/log.h>
25 #include <grpc/support/string_util.h>
26 
27 #include "src/core/lib/gprpp/crash.h"
28 #include "src/core/lib/gprpp/env.h"
29 #include "src/core/lib/security/credentials/alts/alts_credentials.h"
30 #include "src/core/lib/security/credentials/alts/check_gcp_environment.h"
31 #include "src/core/lib/security/credentials/alts/grpc_alts_credentials_options.h"
32 #include "test/core/util/fuzzer_util.h"
33 
34 using grpc_core::testing::grpc_fuzzer_get_next_byte;
35 using grpc_core::testing::grpc_fuzzer_get_next_string;
36 using grpc_core::testing::input_stream;
37 
38 // Logging
39 bool squelch = true;
40 bool leak_check = true;
41 
dont_log(gpr_log_func_args *)42 static void dont_log(gpr_log_func_args* /*args*/) {}
43 
44 // Add a random number of target service accounts to client options.
read_target_service_accounts(input_stream * inp,grpc_alts_credentials_options * options)45 static void read_target_service_accounts(
46     input_stream* inp, grpc_alts_credentials_options* options) {
47   size_t n = grpc_fuzzer_get_next_byte(inp);
48   for (size_t i = 0; i < n; i++) {
49     char* service_account = grpc_fuzzer_get_next_string(inp, nullptr);
50     if (service_account != nullptr) {
51       grpc_alts_credentials_client_options_add_target_service_account(
52           options, service_account);
53       gpr_free(service_account);
54     }
55   }
56   // Added to improve code coverage.
57   grpc_alts_credentials_client_options_add_target_service_account(options,
58                                                                   nullptr);
59   grpc_alts_credentials_client_options_add_target_service_account(
60       nullptr, "this is service account");
61 }
62 
LLVMFuzzerTestOneInput(const uint8_t * data,size_t size)63 extern "C" int LLVMFuzzerTestOneInput(const uint8_t* data, size_t size) {
64   if (squelch && !grpc_core::GetEnv("GRPC_TRACE_FUZZER").has_value()) {
65     gpr_set_log_function(dont_log);
66   }
67   input_stream inp = {data, data + size};
68   grpc_init();
69   bool is_on_gcp = grpc_alts_is_running_on_gcp();
70   while (inp.cur != inp.end) {
71     bool enable_untrusted_alts = grpc_fuzzer_get_next_byte(&inp) & 0x01;
72     char* handshaker_service_url =
73         grpc_fuzzer_get_next_byte(&inp) & 0x01
74             ? grpc_fuzzer_get_next_string(&inp, nullptr)
75             : nullptr;
76     if (grpc_fuzzer_get_next_byte(&inp) & 0x01) {
77       // Test ALTS channel credentials.
78       grpc_alts_credentials_options* options =
79           grpc_alts_credentials_client_options_create();
80       read_target_service_accounts(&inp, options);
81       grpc_channel_credentials* cred = grpc_alts_credentials_create_customized(
82           options, handshaker_service_url, enable_untrusted_alts);
83       if (!enable_untrusted_alts && !is_on_gcp) {
84         GPR_ASSERT(cred == nullptr);
85       } else {
86         GPR_ASSERT(cred != nullptr);
87       }
88       grpc_channel_credentials_release(cred);
89       grpc_alts_credentials_options_destroy(options);
90     } else {
91       // Test ALTS server credentials.
92       grpc_alts_credentials_options* options =
93           grpc_alts_credentials_server_options_create();
94       grpc_server_credentials* cred =
95           grpc_alts_server_credentials_create_customized(
96               options, handshaker_service_url, enable_untrusted_alts);
97       if (!enable_untrusted_alts && !is_on_gcp) {
98         GPR_ASSERT(cred == nullptr);
99       } else {
100         GPR_ASSERT(cred != nullptr);
101       }
102       grpc_server_credentials_release(cred);
103       grpc_alts_credentials_options_destroy(options);
104     }
105     gpr_free(handshaker_service_url);
106   }
107   grpc_shutdown();
108   return 0;
109 }
110