Imported Upstream version 1.23.0
[platform/upstream/grpc.git] / test / core / security / alts_credentials_fuzzer.cc
1 /*
2  *
3  * Copyright 2018 gRPC authors.
4  *
5  * Licensed under the Apache License, Version 2.0 (the "License");
6  * you may not use this file except in compliance with the License.
7  * You may obtain a copy of the License at
8  *
9  *     http://www.apache.org/licenses/LICENSE-2.0
10  *
11  * Unless required by applicable law or agreed to in writing, software
12  * distributed under the License is distributed on an "AS IS" BASIS,
13  * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
14  * See the License for the specific language governing permissions and
15  * limitations under the License.
16  *
17  */
18
19 #include <string.h>
20
21 #include <grpc/grpc.h>
22 #include <grpc/grpc_security.h>
23 #include <grpc/support/alloc.h>
24 #include <grpc/support/log.h>
25 #include <grpc/support/string_util.h>
26 #include "test/core/util/fuzzer_util.h"
27 #include "test/core/util/memory_counters.h"
28
29 #include "src/core/lib/gpr/env.h"
30 #include "src/core/lib/security/credentials/alts/alts_credentials.h"
31 #include "src/core/lib/security/credentials/alts/check_gcp_environment.h"
32 #include "src/core/lib/security/credentials/alts/grpc_alts_credentials_options.h"
33 #include "src/core/lib/security/credentials/credentials.h"
34
35 using grpc_core::testing::grpc_fuzzer_get_next_byte;
36 using grpc_core::testing::grpc_fuzzer_get_next_string;
37 using grpc_core::testing::input_stream;
38
39 // Logging
40 bool squelch = true;
41 bool leak_check = true;
42
43 static void dont_log(gpr_log_func_args* args) {}
44
45 // Add a random number of target service accounts to client options.
46 static void read_target_service_accounts(
47     input_stream* inp, grpc_alts_credentials_options* options) {
48   size_t n = grpc_fuzzer_get_next_byte(inp);
49   for (size_t i = 0; i < n; i++) {
50     char* service_account = grpc_fuzzer_get_next_string(inp, nullptr);
51     if (service_account != nullptr) {
52       grpc_alts_credentials_client_options_add_target_service_account(
53           options, service_account);
54       gpr_free(service_account);
55     }
56   }
57   // Added to improve code coverage.
58   grpc_alts_credentials_client_options_add_target_service_account(options,
59                                                                   nullptr);
60   grpc_alts_credentials_client_options_add_target_service_account(
61       nullptr, "this is service account");
62 }
63
64 extern "C" int LLVMFuzzerTestOneInput(const uint8_t* data, size_t size) {
65   char* grpc_trace_fuzzer = gpr_getenv("GRPC_TRACE_FUZZER");
66   if (squelch && grpc_trace_fuzzer == nullptr) {
67     gpr_set_log_function(dont_log);
68   }
69   gpr_free(grpc_trace_fuzzer);
70   grpc_core::testing::LeakDetector leak_detector(leak_check);
71   input_stream inp = {data, data + size};
72   grpc_init();
73   grpc_test_only_control_plane_credentials_force_init();
74   bool is_on_gcp = grpc_alts_is_running_on_gcp();
75   while (inp.cur != inp.end) {
76     bool enable_untrusted_alts = grpc_fuzzer_get_next_byte(&inp) & 0x01;
77     char* handshaker_service_url =
78         grpc_fuzzer_get_next_byte(&inp) & 0x01
79             ? grpc_fuzzer_get_next_string(&inp, nullptr)
80             : nullptr;
81     if (grpc_fuzzer_get_next_byte(&inp) & 0x01) {
82       // Test ALTS channel credentials.
83       grpc_alts_credentials_options* options =
84           grpc_alts_credentials_client_options_create();
85       read_target_service_accounts(&inp, options);
86       grpc_channel_credentials* cred = grpc_alts_credentials_create_customized(
87           options, handshaker_service_url, enable_untrusted_alts);
88       if (!enable_untrusted_alts && !is_on_gcp) {
89         GPR_ASSERT(cred == nullptr);
90       } else {
91         GPR_ASSERT(cred != nullptr);
92       }
93       grpc_channel_credentials_release(cred);
94       grpc_alts_credentials_options_destroy(options);
95     } else {
96       // Test ALTS server credentials.
97       grpc_alts_credentials_options* options =
98           grpc_alts_credentials_server_options_create();
99       grpc_server_credentials* cred =
100           grpc_alts_server_credentials_create_customized(
101               options, handshaker_service_url, enable_untrusted_alts);
102       if (!enable_untrusted_alts && !is_on_gcp) {
103         GPR_ASSERT(cred == nullptr);
104       } else {
105         GPR_ASSERT(cred != nullptr);
106       }
107       grpc_server_credentials_release(cred);
108       grpc_alts_credentials_options_destroy(options);
109     }
110     gpr_free(handshaker_service_url);
111   }
112   grpc_test_only_control_plane_credentials_destroy();
113   grpc_shutdown();
114   return 0;
115 }