2020-12-08 10:16:00 +00:00
|
|
|
/*
|
|
|
|
This file is part of solidity.
|
|
|
|
|
|
|
|
solidity is free software: you can redistribute it and/or modify
|
|
|
|
it under the terms of the GNU General Public License as published by
|
|
|
|
the Free Software Foundation, either version 3 of the License, or
|
|
|
|
(at your option) any later version.
|
|
|
|
|
|
|
|
solidity is distributed in the hope that it will be useful,
|
|
|
|
but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
|
|
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
|
|
GNU General Public License for more details.
|
|
|
|
|
|
|
|
You should have received a copy of the GNU General Public License
|
|
|
|
along with solidity. If not, see <http://www.gnu.org/licenses/>.
|
|
|
|
*/
|
|
|
|
|
|
|
|
#include <test/tools/ossfuzz/abiV2FuzzerCommon.h>
|
|
|
|
|
|
|
|
#include <test/tools/ossfuzz/protoToAbiV2.h>
|
|
|
|
|
|
|
|
#include <src/libfuzzer/libfuzzer_macro.h>
|
|
|
|
#include <abicoder.hpp>
|
|
|
|
|
|
|
|
using namespace solidity::test::abiv2fuzzer;
|
|
|
|
using namespace solidity::test;
|
2020-12-14 13:27:05 +00:00
|
|
|
using namespace solidity::util;
|
|
|
|
using namespace solidity;
|
2020-12-08 10:16:00 +00:00
|
|
|
using namespace std;
|
|
|
|
|
|
|
|
static constexpr size_t abiCoderHeapSize = 1024 * 512;
|
2020-12-14 13:27:05 +00:00
|
|
|
static evmc::VM evmone = evmc::VM{evmc_create_evmone()};
|
|
|
|
/// Expected output value is decimal 0
|
|
|
|
static vector<uint8_t> const expectedOutput(32, 0);
|
2020-12-08 10:16:00 +00:00
|
|
|
|
2020-12-10 11:43:46 +00:00
|
|
|
DEFINE_PROTO_FUZZER(Contract const& _contract)
|
2020-12-08 10:16:00 +00:00
|
|
|
{
|
2020-12-10 11:43:46 +00:00
|
|
|
ProtoConverter converter;
|
|
|
|
string contractSource = converter.contractToString(_contract);
|
|
|
|
|
|
|
|
if (const char* dump_path = getenv("PROTO_FUZZER_DUMP_PATH"))
|
|
|
|
{
|
|
|
|
// With libFuzzer binary run this to generate the solidity source file x.sol from a proto input:
|
|
|
|
// PROTO_FUZZER_DUMP_PATH=x.sol ./a.out proto-input
|
|
|
|
ofstream of(dump_path);
|
|
|
|
of << contractSource;
|
|
|
|
}
|
|
|
|
|
|
|
|
string typeString = converter.isabelleTypeString();
|
|
|
|
string valueString = converter.isabelleValueString();
|
2020-12-08 10:16:00 +00:00
|
|
|
abicoder::ABICoder coder(abiCoderHeapSize);
|
2020-12-14 13:27:05 +00:00
|
|
|
if (!typeString.empty() && converter.coderFunction())
|
2020-12-10 11:43:46 +00:00
|
|
|
{
|
|
|
|
auto [encodeStatus, encodedData] = coder.encode(typeString, valueString);
|
|
|
|
solAssert(encodeStatus, "Isabelle abicoder fuzzer: Encoding failed");
|
2020-12-14 13:27:05 +00:00
|
|
|
|
|
|
|
// Raw runtime byte code generated by solidity
|
|
|
|
bytes byteCode;
|
|
|
|
string hexEncodedInput;
|
|
|
|
|
|
|
|
try
|
|
|
|
{
|
|
|
|
// Compile contract generated by the proto fuzzer
|
|
|
|
SolidityCompilationFramework solCompilationFramework;
|
|
|
|
string contractName = ":C";
|
|
|
|
byteCode = solCompilationFramework.compileContract(contractSource, contractName);
|
|
|
|
Json::Value methodIdentifiers = solCompilationFramework.getMethodIdentifiers();
|
|
|
|
// We always call the second function from the list of alphabetically
|
|
|
|
// sorted interface functions
|
|
|
|
hexEncodedInput = (++methodIdentifiers.begin())->asString() + encodedData.substr(2, encodedData.size());
|
|
|
|
}
|
|
|
|
// Ignore stack too deep errors during compilation
|
|
|
|
catch (solidity::evmasm::StackTooDeepException const&)
|
|
|
|
{
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
|
|
|
|
// We target the default EVM which is the latest
|
|
|
|
solidity::langutil::EVMVersion version;
|
|
|
|
EVMHost hostContext(version, evmone);
|
|
|
|
|
|
|
|
// Deploy contract and signal failure if deployment failed
|
|
|
|
evmc::result createResult = AbiV2Utility::deployContract(hostContext, byteCode);
|
|
|
|
solAssert(
|
|
|
|
createResult.status_code == EVMC_SUCCESS,
|
|
|
|
"Proto ABIv2 Fuzzer: Contract creation failed"
|
|
|
|
);
|
|
|
|
|
|
|
|
// Execute test function and signal failure if EVM reverted or
|
|
|
|
// did not return expected output on successful execution.
|
|
|
|
evmc::result callResult = AbiV2Utility::executeContract(
|
|
|
|
hostContext,
|
|
|
|
fromHex(hexEncodedInput),
|
|
|
|
createResult.create_address
|
|
|
|
);
|
|
|
|
|
|
|
|
// We don't care about EVM One failures other than EVMC_REVERT
|
|
|
|
solAssert(callResult.status_code != EVMC_REVERT, "Proto ABIv2 fuzzer: EVM One reverted");
|
|
|
|
if (callResult.status_code == EVMC_SUCCESS)
|
|
|
|
solAssert(
|
|
|
|
AbiV2Utility::isOutputExpected(callResult.output_data, callResult.output_size, expectedOutput),
|
|
|
|
"Proto ABIv2 fuzzer: ABIv2 coding failure found"
|
|
|
|
);
|
|
|
|
|
2020-12-10 11:43:46 +00:00
|
|
|
}
|
2020-12-08 10:16:00 +00:00
|
|
|
return;
|
2020-12-08 20:06:10 +00:00
|
|
|
}
|