mirror of
https://github.com/nlohmann/json.git
synced 2026-09-27 14:20:19 +01:00
* Check the fuzzers' UBJSON/BJData round-trip invariants in the unit tests The strongest correctness checks for the UBJSON and BJData writers lived only in the OSS-Fuzz drivers: anything from_ubjson()/from_bjdata() returns must serialize with every option combination, parse back, and re-serialize stably. Those checks only run at OSS-Fuzz, so regressions surfaced days later as external reports - the same BJData assert pair was reported five times over three years, and #5494's harness change was followed by OSS-Fuzz 563659413 within a day. Add "UBJSON round-trip invariants" and "BJData round-trip invariants" test cases that run the drivers' checks on a fixed, deterministic corpus (tests/src/round_trip_corpus.hpp): integer and float boundaries, non-finite numbers, strings, binary values, optimized containers, deep nesting, the JData annotated-array matrix, and seeded random containers. They also check two properties the drivers do not: the first round trip preserves the value, and re-serializing reproduces the exact bytes. For BJData both exclude values containing a binary value, which is read back as an array of integers unless it was written as a Draft 3 optimized binary array; this carve-out is now documented in bjdata.md. Run against the headers before #5542, the BJData test fails, including on the shape from OSS-Fuzz 563659413. Also document how OSS-Fuzz reports are handled (reference them as "OSS-Fuzz: <id>", turn the reproducer into a unit test, keep drivers and unit tests in sync) in tests/fuzzing.md, and link it from the PR template and the quality assurance page. Signed-off-by: Niels Lohmann <mail@nlohmann.me> * Add the OSS-Fuzz reproducers for 474400817 and 474480402 as unit tests Following the convention added to tests/fuzzing.md, the reproducers of the two BJData fuzzer asserts tracked since January are now unit tests: - 474400817 (assert(false)): an empty object _ArraySize_ was written as the ND-array header length, which from_bjdata() could not read back. Fixed by #5455. - 474480402 (to_bjdata(j2, false, false) == vec2): a one-byte Draft 3 binary array is written in Draft 2 mode as a uint8 array and then re-serialized with the int8 marker. This is the documented exception to byte stability, not a library bug; OSS-Fuzz closed it after #5494 relaxed the harness to value stability. The test pins the exact bytes so the exception stays deliberate. The 563659413 reproducer is already a unit test (#5542). A comment also ties the existing UBJSON excessive-count test to the timeout OSS-Fuzz reported for that shape (testcase 6347769435193344). OSS-Fuzz: 474400817 OSS-Fuzz: 474480402 Signed-off-by: Niels Lohmann <mail@nlohmann.me> * Fix GCC -Weffc++ and -Wuseless-cast warnings in the round-trip corpus Initialize the atoms in the member initialization list, and drop the cast of the generator's result, which already is std::size_t on 64-bit Linux. Signed-off-by: Niels Lohmann <mail@nlohmann.me> --------- Signed-off-by: Niels Lohmann <mail@nlohmann.me>
95 lines
3.0 KiB
C++
95 lines
3.0 KiB
C++
// __ _____ _____ _____
|
|
// __| | __| | | | JSON for Modern C++ (supporting code)
|
|
// | | |__ | | | | | | version 3.12.0
|
|
// |_____|_____|_____|_|___| https://github.com/nlohmann/json
|
|
//
|
|
// SPDX-FileCopyrightText: 2013-2026 Niels Lohmann <https://nlohmann.me>
|
|
// SPDX-License-Identifier: MIT
|
|
|
|
/*
|
|
This file implements a parser test suitable for fuzz testing. Given a byte
|
|
array data, it performs the following steps:
|
|
|
|
- j1 = from_ubjson(data)
|
|
- vec = to_ubjson(j1)
|
|
- j2 = from_ubjson(vec)
|
|
- assert(j1 == j2)
|
|
- vec2 = to_ubjson(j1, use_size = true, use_type = false)
|
|
- j3 = from_ubjson(vec2)
|
|
- assert(j1 == j3)
|
|
- vec3 = to_ubjson(j1, use_size = true, use_type = true)
|
|
- j4 = from_ubjson(vec3)
|
|
- assert(j1 == j4)
|
|
|
|
The unit tests run the same checks on a fixed corpus (see the "UBJSON round-trip
|
|
invariants" test case), so keep both in sync.
|
|
|
|
The provided function `LLVMFuzzerTestOneInput` can be used in different fuzzer
|
|
drivers.
|
|
*/
|
|
|
|
#include <cassert>
|
|
#include <iostream>
|
|
#include <sstream>
|
|
#include <nlohmann/json.hpp>
|
|
|
|
// the round-trip checks below are assertions; NDEBUG would compile them away
|
|
#ifdef NDEBUG
|
|
#error "the fuzzer drivers must be built without NDEBUG"
|
|
#endif
|
|
|
|
using json = nlohmann::json;
|
|
|
|
// see http://llvm.org/docs/LibFuzzer.html
|
|
extern "C" int LLVMFuzzerTestOneInput(const uint8_t* data, size_t size)
|
|
{
|
|
try
|
|
{
|
|
// step 1: parse input
|
|
std::vector<uint8_t> const vec1(data, data + size);
|
|
json const j1 = json::from_ubjson(vec1);
|
|
|
|
try
|
|
{
|
|
// step 2.1: round trip without adding size annotations to container types
|
|
std::vector<uint8_t> const vec2 = json::to_ubjson(j1, false, false);
|
|
|
|
// step 2.2: round trip with adding size annotations but without adding type annotations to container types
|
|
std::vector<uint8_t> const vec3 = json::to_ubjson(j1, true, false);
|
|
|
|
// step 2.3: round trip with adding size as well as type annotations to container types
|
|
std::vector<uint8_t> const vec4 = json::to_ubjson(j1, true, true);
|
|
|
|
// parse serialization
|
|
json const j2 = json::from_ubjson(vec2);
|
|
json const j3 = json::from_ubjson(vec3);
|
|
json const j4 = json::from_ubjson(vec4);
|
|
|
|
// serializations must match
|
|
assert(json::to_ubjson(j2, false, false) == vec2);
|
|
assert(json::to_ubjson(j3, true, false) == vec3);
|
|
assert(json::to_ubjson(j4, true, true) == vec4);
|
|
}
|
|
catch (const json::parse_error&)
|
|
{
|
|
// parsing a UBJSON serialization must not fail
|
|
assert(false);
|
|
}
|
|
}
|
|
catch (const json::parse_error&)
|
|
{
|
|
// parse errors are ok, because input may be random bytes
|
|
}
|
|
catch (const json::type_error&)
|
|
{
|
|
// type errors can occur during parsing, too
|
|
}
|
|
catch (const json::out_of_range&)
|
|
{
|
|
// out of range errors may happen if provided sizes are excessive
|
|
}
|
|
|
|
// return 0 - non-zero return values are reserved for future use
|
|
return 0;
|
|
}
|