mirror of
https://github.com/meshtastic/firmware.git
synced 2026-08-01 02:48:49 -04:00
* first pass tests * more tests * Fix two crafted-admin-packet crashes found by the E5 fuzzer Both are reachable from an authorized admin (local from==0, admin channel, or PKC) - remote DoS: 1. SIGFPE in LoRa config validation. A set_config LoRaConfig with use_preset=false and bandwidth=0 makes freqSlotWidth 0, so numFreqSlots is 0 and `hash(name) % numFreqSlots` (RadioInterface.cpp) divides by zero. Guard the modulo; the existing channel_num check then rejects/ clamps the config. 2. Stack overflow in Channels::getKey. A SECONDARY channel at the primary slot with an empty PSK recursed into getKey(primaryIndex) forever. Skip the primary-key borrow when chIndex == primaryIndex. Re-enable the E5 admin fuzzer to hit both triggers again (use_preset both ways incl. bandwidth 0, plus the set_channel tag) as regression guards. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Correct fuzz-test invariants after the crash fixes - E5 admin fuzz: node eviction under a filling NodeDB is legitimate, so assert only the bounded-count invariant, not that a specific seed node survives 6000 mutating ops. - TMM blitz: scope off the nodeinfo direct-response send path (it needs a fully-wired MeshService/phone queue the fixture doesn't provide; the deterministic directResponse tests cover it). The crafted-nodenum rate/unknown/position cache stress is unchanged. clod helped too * realistic tests * test: dedup fuzz RNG into shared test/support/DeterministicRng.h The four in-tree fuzz suites (test_fuzz_decode, test_fuzz_packets, test_hop_scaling, test_traffic_management) each carried a byte-identical copy of the seeded 64-bit LCG (rngSeed/rngNext/rngByte/rngRange). Hoist it into one shared header so there is a single generator to reason about and no risk of the copies drifting. static inline keeps per-suite state per translation unit and avoids -Wunused-function for suites that don't use every helper. Also corrects a stale comment in test_traffic_management (the blitz's nodeinfo direct-response path is intentionally left off). No behavioral change: same constants, same per-suite seeds. clod helped too * test: fuzz uncovered ProtobufModule handlers and the MQTT downlink ingress Extend the in-tree fuzz coverage to packet sources that previously had none: - test_fuzz_packets E8/E9/E10: drive PositionModule, DeviceTelemetryModule and NeighborInfoModule at handleReceivedProtobuf directly (via using-shims, bypassing the ProtobufModule reply/send path so no router is needed). The fixture already stands up nodeDB/service/channels, and nodeStatus/powerStatus are auto-initialized in main.cpp, so no new globals are required. Adds a shared fuzzRxHeader() helper for crafting adversarial RX packet headers. - test_fuzz_decode: add meshtastic_KeyVerification to the decode table. The KeyVerification and StoreForward handler paths are documented as decode-level only, with the concrete reason each is intrinsic (private-state gating / PSRAM + self-pointer wiring), not a fixture gap. - test_mqtt: test_receiveFuzzServiceEnvelope blitzes the non-RF broker-push ingress (onReceiveProto) two ways - raw garbage bytes that must fail envelope decode cleanly, and a well-formed ServiceEnvelope wrapping a crafted inner MeshPacket over crafted channel_id/gateway_id - exercising the channel match, isFromUs, XEdDSA receive policy and perhapsDecode chain. Adds a deliverRaw() passthrough to MQTTUnitTest. All under the coverage env (ASan/LSan). No firmware/src changes. Full sweep GREEN 27/27, 544 cases. clod helped too * Harden LoRa/channel config against crafted admin messages; consolidate test helpers Production (review findings on the hot-fuzz crash fixes): - Clamp bandwidth at the source (clampBandwidthKHz) in checkOrClampConfigLora and applyModemConfig so numFreqSlots can never be 0 for any consumer; a bandwidth-0 set_config previously passed validation and re-armed the SIGFPE on the next applyModemConfig. - Guard applyModemConfig's hash % numFreqSlots (the validator's sibling modulo was fixed earlier but this one was still unguarded). - Enforce the primary-channel invariant in Channels::onConfigChanged: a config demoting every slot now re-promotes the stale SECONDARY slot (keeping its key) or restores the default channel if the slot is DISABLED, instead of leaving every getPrimaryIndex() reader on a non-primary slot. The getKey recursion guard stays as defense-in-depth. Tests: - New test/support/MockMeshService.h and AdminModuleTestShim.h replace four byte-identical mocks and three divergent admin shims (test_mqtt's capturing mock is genuinely different and stays). - DeterministicRng.h: add rngFill() (replaces 14 hand-rolled fill loops) and rngEdgeNodeNum() (unifies the three NodeNum boundary pools). - Extract fuzzChannelSettings() shared by the set_channel case and fuzzBeacon. - fuzzBeacon: the un-terminated branch now fills the whole buffer with non-NUL bytes so the strnlen bound is actually stressed (~50% of iterations, not ~4%). - E6 beacon fuzz: replace the TEST_ASSERT_TRUE(true) tautology with real invariants (handler never consumes; offers land in lastReceivedOffer keyed to the sender). - Trim the seven over-long comment blocks flagged against the 1-2 line rule; the FINDINGS trailer moves to this commit message (see production notes). Full native suite GREEN 27/27 under the coverage (ASan/LSan) env. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Clamp UTF-8 char length in the emote walkers; add test_fuzz_emotes A TEXT_MESSAGE payload is opaque protobuf bytes, so PB_VALIDATE_UTF8 never screens it - invalid UTF-8 and truncated multi-byte lead bytes reach the emote/width render path verbatim. EmoteRenderer's walkers advanced by utf8CharLen(lead) without clamping to the bytes actually remaining, so a truncated lead (e.g. a lone 0xF0, which claims 4 bytes) near the end of the buffer made getUtf8ChunkWidth's memcpy read past the string. ASan confirms a heap-buffer-overflow READ from measureStringWithEmotes. Add utf8CharLenClamped() and use it at every walk site (width measure, truncation cut-loop, and the draw-path text-run/chunk builders); the one already-guarded site (matchAtIgnoringModifiers) is unchanged. New test/test_fuzz_emotes drives measureStringWithEmotes and truncateToWidth over adversarial byte strings (biased to embed/end in truncated multi-byte leads) in exact-sized heap buffers so any over-read is a hard ASan fault. Its headless display uses a synthetic font (firstChar 0, fontData centered in a large buffer) so the stock OLEDDisplay::getStringWidth - which indexes the font jump table with a signed char and over-reads for any byte >= 0x80 - does not mask the finding. native-suite-count bumped 27 -> 28. Full native suite GREEN 28/28 under the coverage (ASan/LSan) env. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Keep emote width measurement in-bounds for non-ASCII bytes OLEDDisplay::getStringWidth (the utf8=false path EmoteRenderer uses on default builds) indexes the font jump table by (c - firstChar) with a signed char and no bounds check, so any byte outside printable ASCII - high bytes from UTF-8 text, but also a stray control byte like 0x0A - reads outside the font array. On-device this reads adjacent flash and returns a garbage width; under ASan the test_fuzz_emotes fuzzer flags it as a global-buffer-overflow, and it made the non-ASCII width measurement meaningless either way. The OLED driver is a pinned upstream dependency, so guard it firmware-side in EmoteRenderer's getStringWidth helper: measure a sanitized copy where any byte outside [0x20, 0x7E] counts as a '?' placeholder. Printable ASCII is unchanged and the UA/RU lookup path is untouched. test_fuzz_emotes now drives a real ArialMT font instead of the synthetic in-bounds font it needed before this fix, so the suite exercises the true production width path (utf8CharLen clamp + this sanitizer) end to end. The same fuzzer tripped the global-buffer-overflow before this change. Full native suite GREEN 28/28 under the coverage (ASan/LSan) env. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> --------- Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
131 lines
4.4 KiB
C++
131 lines
4.4 KiB
C++
// Adversarial fuzzing of the emote/UTF-8 width+truncation walkers - the render path a TEXT_MESSAGE
|
|
// payload reaches AFTER decode. Text payloads are opaque protobuf `bytes`, so PB_VALIDATE_UTF8 never
|
|
// screens them: invalid UTF-8, control bytes and truncated multi-byte lead bytes reach these walkers
|
|
// verbatim. The walkers advance by utf8CharLen(lead), which for a 0xC0/0xE0/0xF0 lead near the end of
|
|
// the buffer claims more bytes than remain - so an unclamped copy reads past the string.
|
|
//
|
|
// Each input is placed in an EXACT-sized heap buffer (content + NUL, no slack) so any read past the
|
|
// content is a hard heap-buffer-overflow that AddressSanitizer flags. Runs under the coverage env.
|
|
|
|
#include "TestUtil.h"
|
|
#include "configuration.h"
|
|
#include <unity.h>
|
|
|
|
#if HAS_SCREEN
|
|
|
|
#include "graphics/EmoteRenderer.h"
|
|
#include <OLEDDisplay.h>
|
|
#include <OLEDDisplayFonts.h>
|
|
#include <cstdlib>
|
|
#include <cstring>
|
|
|
|
#include "support/DeterministicRng.h"
|
|
static constexpr uint64_t BASE_SEED = 0x00E3070EULL;
|
|
|
|
// Headless display with a REAL font, so the fuzz exercises the production width path end to end:
|
|
// EmoteRenderer's getUtf8ChunkWidth memcpy (guarded by the utf8CharLen clamp) AND the getStringWidth
|
|
// helper's byte sanitizer (which keeps the stock library's signed-char font indexing in bounds for
|
|
// bytes outside printable ASCII). getStringWidth only walks the font jump table, never a frame buffer.
|
|
class FakeDisplay : public OLEDDisplay
|
|
{
|
|
public:
|
|
FakeDisplay() { setFont(ArialMT_Plain_10); }
|
|
void display() override {}
|
|
int getBufferOffset() override { return 0; }
|
|
size_t write(uint8_t) override { return 1; }
|
|
};
|
|
|
|
// Drive both walkers over a NUL-terminated exact-sized copy of [bytes, bytes+len).
|
|
static void exercise(FakeDisplay &d, const uint8_t *bytes, size_t len)
|
|
{
|
|
char *buf = (char *)malloc(len + 1); // exactly content + NUL: reads past index len are OOB
|
|
memcpy(buf, bytes, len);
|
|
buf[len] = '\0';
|
|
|
|
(void)graphics::EmoteRenderer::measureStringWithEmotes(&d, buf); // analyzeLineInternal walk
|
|
char out[64];
|
|
(void)graphics::EmoteRenderer::truncateToWidth(&d, buf, out, sizeof(out), 40); // cut-loop walk
|
|
|
|
free(buf);
|
|
}
|
|
|
|
// A byte that begins a multi-byte UTF-8 sequence (so utf8CharLen returns 2/3/4).
|
|
static uint8_t multibyteLead()
|
|
{
|
|
static const uint8_t leads[] = {0xC0, 0xE0, 0xF0, 0xE2}; // 0xE2/0xF0 are also emote leads
|
|
return leads[rngRange(sizeof(leads))];
|
|
}
|
|
|
|
void test_emote_utf8_fuzz(void)
|
|
{
|
|
printf(" seed=0x%llx\n", (unsigned long long)BASE_SEED);
|
|
rngSeed(BASE_SEED);
|
|
|
|
FakeDisplay d;
|
|
|
|
for (unsigned k = 0; k < 20000; k++) {
|
|
uint8_t bytes[300];
|
|
size_t len = 1 + rngRange(sizeof(bytes)); // 1..300, includes >MAX_MESSAGE_SIZE
|
|
|
|
// Non-zero fill so strlen() == len (an embedded NUL would just shorten the effective string).
|
|
for (size_t i = 0; i < len; i++)
|
|
bytes[i] = (uint8_t)(1 + rngRange(255));
|
|
|
|
// Sprinkle multi-byte leads (some truncated) through the body to reach findEmoteAt / the
|
|
// modifier skippers as well as the plain width path.
|
|
unsigned sprinkles = rngRange(6);
|
|
for (unsigned s = 0; s < sprinkles; s++)
|
|
bytes[rngRange(len)] = multibyteLead();
|
|
|
|
// Half the time, force the LAST byte to a lead: a truncated sequence with no continuation left,
|
|
// the exact shape that makes an unclamped walker step past the buffer end.
|
|
if (rngRange(2))
|
|
bytes[len - 1] = multibyteLead();
|
|
|
|
exercise(d, bytes, len);
|
|
}
|
|
TEST_ASSERT_TRUE(true); // reaching here = no ASan fault across all iterations
|
|
}
|
|
|
|
// Fixed regressions for the truncated-lead shape, independent of the RNG.
|
|
void test_emote_truncated_lead_edges(void)
|
|
{
|
|
FakeDisplay d;
|
|
const uint8_t loneF0[] = {0xF0};
|
|
const uint8_t tailE0[] = {'h', 'i', 0xE0};
|
|
const uint8_t tailC0[] = {'a', 'b', 'c', 0xC0};
|
|
uint8_t allF0[64];
|
|
memset(allF0, 0xF0, sizeof(allF0));
|
|
|
|
exercise(d, loneF0, sizeof(loneF0));
|
|
exercise(d, tailE0, sizeof(tailE0));
|
|
exercise(d, tailC0, sizeof(tailC0));
|
|
exercise(d, allF0, sizeof(allF0));
|
|
TEST_ASSERT_TRUE(true);
|
|
}
|
|
|
|
void setup()
|
|
{
|
|
initializeTestEnvironment();
|
|
UNITY_BEGIN();
|
|
RUN_TEST(test_emote_truncated_lead_edges);
|
|
RUN_TEST(test_emote_utf8_fuzz);
|
|
exit(UNITY_END());
|
|
}
|
|
|
|
void loop() {}
|
|
|
|
#else // !HAS_SCREEN
|
|
|
|
void setUp(void) {}
|
|
void tearDown(void) {}
|
|
void setup()
|
|
{
|
|
initializeTestEnvironment();
|
|
UNITY_BEGIN();
|
|
exit(UNITY_END());
|
|
}
|
|
void loop() {}
|
|
|
|
#endif
|