Coverage Report

Created: 2026-09-15 16:03

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/root/bitcoin/src/test/fuzz/process_message.cpp
Line
Count
Source
1
// Copyright (c) 2020-present The Bitcoin Core developers
2
// Distributed under the MIT software license, see the accompanying
3
// file COPYING or http://www.opensource.org/licenses/mit-license.php.
4
5
#include <addrman.h>
6
#include <banman.h>
7
#include <kernel/chainparams.h>
8
#include <net.h>
9
#include <net_processing.h>
10
#include <primitives/block.h>
11
#include <primitives/transaction.h>
12
#include <protocol.h>
13
#include <sync.h>
14
#include <test/fuzz/FuzzedDataProvider.h>
15
#include <test/fuzz/fuzz.h>
16
#include <test/fuzz/util.h>
17
#include <test/fuzz/util/net.h>
18
#include <test/util/net.h>
19
#include <test/util/random.h>
20
#include <test/util/setup_common.h>
21
#include <test/util/time.h>
22
#include <test/util/validation.h>
23
#include <uint256.h>
24
#include <util/check.h>
25
#include <util/time.h>
26
#include <validation.h>
27
#include <validationinterface.h>
28
29
#include <algorithm>
30
#include <array>
31
#include <cstdlib>
32
#include <functional>
33
#include <iostream>
34
#include <memory>
35
#include <optional>
36
#include <string>
37
#include <string_view>
38
#include <utility>
39
#include <vector>
40
41
namespace {
42
TestingSetup* g_setup;
43
std::string_view LIMIT_TO_MESSAGE_TYPE{};
44
45
} // namespace
46
47
extern void MakeRandDeterministicDANGEROUS(const uint256& seed) noexcept;
48
49
void initialize_process_message()
50
0
{
51
0
    FakeNodeClock init_clock{}; // Uses the existing mock time
52
0
    if (const auto val{std::getenv("LIMIT_TO_MESSAGE_TYPE")}) {
  Branch (52:20): [True: 0, False: 0]
53
0
        LIMIT_TO_MESSAGE_TYPE = val;
54
0
        Assert(std::count(ALL_NET_MESSAGE_TYPES.begin(), ALL_NET_MESSAGE_TYPES.end(), LIMIT_TO_MESSAGE_TYPE)); // Unknown message type passed
55
0
    }
56
57
0
    static const auto testing_setup{
58
0
        MakeNoLogFileContext<TestingSetup>(
59
0
            /*chain_type=*/ChainType::REGTEST,
60
0
            {}),
61
0
    };
62
0
    g_setup = testing_setup.get();
63
0
    ResetChainmanAndMempool(*g_setup, init_clock);
64
0
}
65
66
FUZZ_TARGET(process_message, .init = initialize_process_message)
67
0
{
68
0
    SeedRandomStateForTest(SeedRand::ZEROS);
69
0
    FuzzedDataProvider fuzzed_data_provider(buffer.data(), buffer.size());
70
71
0
    auto& node{g_setup->m_node};
72
0
    auto& connman{static_cast<ConnmanTestMsg&>(*node.connman)};
73
0
    connman.Reset();
74
0
    auto& chainman{static_cast<TestChainstateManager&>(*node.chainman)};
75
0
    const auto block_index_size{WITH_LOCK(chainman.GetMutex(), return chainman.BlockIndex().size())};
76
0
    const auto initial_sequence{WITH_LOCK(node.mempool->cs, return node.mempool->GetSequence())};
77
0
    FakeNodeClock node_clock{1610000000s}; // 2021-01-07, arbitrary
78
0
    FakeSteadyClock steady_clock;
79
0
    chainman.ResetIbd();
80
0
    chainman.DisableNextWrite();
81
82
    // Reset, so that dangling pointers can be detected by sanitizers.
83
0
    node.banman.reset();
84
0
    node.addrman.reset();
85
0
    node.peerman.reset();
86
0
    node.addrman = std::make_unique<AddrMan>(*node.netgroupman, /*deterministic=*/true, /*consistency_check_ratio=*/0);
87
0
    node.peerman = PeerManager::make(connman, *node.addrman,
88
0
                                     /*banman=*/nullptr, chainman,
89
0
                                     *node.mempool, *node.warnings,
90
0
                                     PeerManager::Options{
91
0
                                         .reconcile_txs = true,
92
0
                                         .deterministic_rng = true,
93
0
                                     });
94
95
0
    connman.SetMsgProc(node.peerman.get());
96
0
    connman.SetAddrman(*node.addrman);
97
0
    LOCK(NetEventsInterface::g_msgproc_mutex);
98
99
0
    const std::string random_message_type{fuzzed_data_provider.ConsumeBytesAsString(CMessageHeader::MESSAGE_TYPE_SIZE).c_str()};
100
0
    if (!LIMIT_TO_MESSAGE_TYPE.empty() && random_message_type != LIMIT_TO_MESSAGE_TYPE) {
  Branch (100:9): [True: 0, False: 0]
  Branch (100:43): [True: 0, False: 0]
101
0
        return;
102
0
    }
103
104
0
    node.validation_signals->RegisterValidationInterface(node.peerman.get());
105
106
0
    CNode& p2p_node = *ConsumeNodeAsUniquePtr(fuzzed_data_provider, steady_clock).release();
107
108
0
    connman.AddTestNode(p2p_node);
109
0
    FillNode(fuzzed_data_provider, connman, p2p_node);
110
111
0
    node_clock.set(ConsumeTime(fuzzed_data_provider));
112
113
0
    CSerializedNetMsg net_msg;
114
0
    net_msg.m_type = random_message_type;
115
0
    net_msg.data = ConsumeRandomLengthByteVector(fuzzed_data_provider, MAX_PROTOCOL_MESSAGE_LENGTH);
116
117
0
    connman.FlushSendBuffer(p2p_node);
118
0
    (void)connman.ReceiveMsgFrom(p2p_node, std::move(net_msg));
119
120
0
    if (fuzzed_data_provider.ConsumeBool()) {
  Branch (120:9): [True: 0, False: 0]
121
0
        chainman.JumpOutOfIbd();
122
0
    }
123
124
0
    bool more_work{true};
125
0
    while (more_work) {
  Branch (125:12): [True: 0, False: 0]
126
0
        p2p_node.fPauseSend = false;
127
0
        try {
128
0
            more_work = connman.ProcessMessagesOnce(p2p_node);
129
0
        } catch (const std::ios_base::failure&) {
130
0
        }
131
0
        node.peerman->SendMessages(p2p_node);
132
0
    }
133
0
    node.validation_signals->SyncWithValidationInterfaceQueue();
134
0
    node.validation_signals->UnregisterValidationInterface(node.peerman.get());
135
0
    node.connman->StopNodes();
136
0
    const auto end_sequence{WITH_LOCK(node.mempool->cs, return node.mempool->GetSequence())};
137
0
    if (block_index_size != WITH_LOCK(chainman.GetMutex(), return chainman.BlockIndex().size()) || initial_sequence != end_sequence) {
  Branch (137:9): [True: 0, False: 0]
  Branch (137:9): [True: 0, False: 0]
  Branch (137:100): [True: 0, False: 0]
138
        // Reuse the global chainman and mempool, but reset them when dirty.
139
0
        MakeRandDeterministicDANGEROUS(uint256::ZERO);
140
0
        ResetChainmanAndMempool(*g_setup, node_clock);
141
0
    }
142
0
}