Skip to content

[Fuzzing X64] [MihaZupan] Reduce Kerberos fuzzer duplication #2175

Description

@MihuBot

Job completed in 3 hours 54 minutes (remote runner delay: 1 minute 13 seconds).
dotnet/runtime#135514
Using arguments: fuzz fuzzer -short

// NrbfDecoderFuzzer

D:\runner>D:\runner\runtime\src\libraries\Fuzzing\DotnetFuzzing\deployment\NrbfDecoderFuzzer\/libfuzzer-dotnet.exe --target_path=D:\runner\runtime\src\libraries\Fuzzing\DotnetFuzzing\deployment\NrbfDecoderFuzzer\/DotnetFuzzing.exe --target_arg=NrbfDecoderFuzzer -timeout=60 -timeout=60 -max_total_time=600 NrbfDecoderFuzzer-inputs -exact_artifact_path=NrbfDecoderFuzzer-artifact-1 -print_final_stats=1 D:\runner\runtime\src\libraries\Fuzzing\DotnetFuzzing\deployment\NrbfDecoderFuzzer\/corpus 
WARNING: Failed to find function "__sanitizer_acquire_crash_state".
WARNING: Failed to find function "__sanitizer_print_stack_trace".
WARNING: Failed to find function "__sanitizer_set_death_callback".
INFO: libFuzzer ignores flags that start with '--'
INFO: Running with entropic power schedule (0xFF, 100).
INFO: Seed: 980720905
INFO: Loaded 1 modules   (66 inline 8-bit counters): 66 [00007FF6E5EC4008, 00007FF6E5EC404A), 
INFO: Loaded 1 PC tables (66 PCs): 66 [00007FF6E5E916E0,00007FF6E5E91B00), 
INFO: 65536 Extra Counters
INFO:        0 files found in NrbfDecoderFuzzer-inputs
INFO:        8 files found in D:\runner\runtime\src\libraries\Fuzzing\DotnetFuzzing\deployment\NrbfDecoderFuzzer\/corpus
INFO: -max_len is not provided; libFuzzer will not generate inputs larger than 4096 bytes
INFO: seed corpus: files: 8 min: 36b max: 1382b total: 1971b rss: 28Mb
System.OutOfMemoryException: Exception of type 'System.OutOfMemoryException' was thrown.
   at System.Formats.Nrbf.SZArrayOfRecords.ToArray(Boolean allowNulls)
   at System.Formats.Nrbf.SZArrayOfRecords.GetArray(Boolean allowNulls)
   at System.Formats.Nrbf.SZArrayRecord`1.Deserialize(Type arrayType, Boolean allowNulls)
   at System.Formats.Nrbf.ArrayRecord.GetArray(Type expectedArrayType, Boolean allowNulls)
   at DotnetFuzzing.Fuzzers.NrbfDecoderFuzzer.Consume(HashSet`1 visited, Queue`1 queue) in D:\runner\runtime\src\libraries\Fuzzing\DotnetFuzzing\Fuzzers\NrbfDecoderFuzzer.cs:line 146
   at DotnetFuzzing.Fuzzers.NrbfDecoderFuzzer.Test(Span`1 testSpan, Stream stream) in D:\runner\runtime\src\libraries\Fuzzing\DotnetFuzzing\Fuzzers\NrbfDecoderFuzzer.cs:line 63
   at DotnetFuzzing.Fuzzers.NrbfDecoderFuzzer.Test(ReadOnlySpan`1 bytes, PoisonPagePlacement poisonPagePlacement) in D:\runner\runtime\src\libraries\Fuzzing\DotnetFuzzing\Fuzzers\NrbfDecoderFuzzer.cs:line 32
   at DotnetFuzzing.Fuzzers.NrbfDecoderFuzzer.FuzzTarget(ReadOnlySpan`1 bytes) in D:\runner\runtime\src\libraries\Fuzzing\DotnetFuzzing\Fuzzers\NrbfDecoderFuzzer.cs:line 23
   at DotnetFuzzing.Program.<>c__DisplayClass1_0.<RunFuzzer>b__0(ReadOnlySpan`1 bytes) in D:\runner\runtime\src\libraries\Fuzzing\DotnetFuzzing\Program.cs:line 103
   at SharpFuzz.Fuzzer.LibFuzzer.Run(ReadOnlySpanAction action, Boolean ignoreExceptions)
==3092== ERROR: libFuzzer: deadly signal
NOTE: libFuzzer has rudimentary signal handlers.
      Combine libFuzzer with AddressSanitizer or similar for better crash reports.
SUMMARY: libFuzzer: deadly signal
MS: 0 ; base unit: 0000000000000000000000000000000000000000
0x0,0x1,0x0,0x0,0x0,0xff,0xff,0xff,0xff,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x7,0x1,0x0,0x0,0x0,0x0,0x1,0x0,0x0,0x0,0xc7,0xff,0xff,0x7f,0x3,0x6e,0x53,0x79,0x73,0x74,0x65,0x6d,0x2e,0x4e,0x75,0x6c,0x6c,0x61,0x62,0x6c,0x65,0x60,0x31,0x5b,0x5b,0x53,0x79,0x73,0x74,0x65,0x6d,0x2e,0x49,0x6e,0x74,0x33,0x32,0x2c,0x20,0x6d,0x73,0x63,0x6f,0x72,0x6c,0x69,0x62,0x2c,0x20,0x56,0x65,0x72,0x73,0x69,0x6f,0x6e,0x3d,0x34,0x2e,0x30,0x2e,0x30,0x2e,0x30,0x2c,0x20,0x43,0x75,0x6c,0x74,0x75,0x72,0x65,0x3d,0x6e,0x65,0x75,0x74,0x72,0x61,0x6c,0x2c,0x20,0x50,0x75,0x62,0x6c,0x69,0x63,0x4b,0x65,0x79,0x54,0x6f,0x6b,0x65,0x6e,0x3d,0x62,0x37,0x37,0x61,0x35,0x63,0x35,0x36,0x31,0x39,0x33,0x34,0x65,0x30,0x38,0x39,0x5d,0x5d,0xe,0xc7,0xff,0xff,0x7f,0xb,
\000\001\000\000\000\377\377\377\377\001\000\000\000\000\000\000\000\007\001\000\000\000\000\001\000\000\000\307\377\377\177\003nSystem.Nullable`1[[System.Int32, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089]]\016\307\377\377\177\013
artifact_prefix='./'; Test unit written to NrbfDecoderFuzzer-artifact-1
Base64: AAEAAAD/////AQAAAAAAAAAHAQAAAAABAAAAx///fwNuU3lzdGVtLk51bGxhYmxlYDFbW1N5c3RlbS5JbnQzMiwgbXNjb3JsaWIsIFZlcnNpb249NC4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0Ox///fws=
// SslStreamClientHelloFuzzer
System.NotSupportedException: The server mode SSL must use a certificate with the associated private key.
   at System.Net.Security.SslStream.AcquireServerCredentials(Byte[]& thumbPrint)
   at System.Net.Security.SslStream.TryNextMessageViaTlsSession(ReadOnlySpan`1 incomingBuffer, ProtocolToken& token, Int32& consumed)
   at System.Net.Security.SslStream.NextMessage(ReadOnlySpan`1 incomingBuffer, Int32& consumed)
   at System.Net.Security.SslStream.ProcessTlsFrame(Int32 frameSize)
   at System.Net.Security.SslStream.ForceAuthenticationAsync[TIOAdapter](Boolean receiveFirst, Byte[] reAuthenticationData, CancellationToken cancellationToken)
   at DotnetFuzzing.Fuzzers.SslStreamClientHelloFuzzer.FuzzTarget(ReadOnlySpan`1 bytes) in D:\runner\runtime\src\libraries\Fuzzing\DotnetFuzzing\Fuzzers\SslStreamClientHelloFuzzer.cs:line 24
   at DotnetFuzzing.Program.<>c__DisplayClass1_0.<RunFuzzer>b__0(ReadOnlySpan`1 bytes) in D:\runner\runtime\src\libraries\Fuzzing\DotnetFuzzing\Program.cs:line 103
   at SharpFuzz.Fuzzer.LibFuzzer.Run(ReadOnlySpanAction action, Boolean ignoreExceptions)
==12140== ERROR: libFuzzer: deadly signal
NOTE: libFuzzer has rudimentary signal handlers.
      Combine libFuzzer with AddressSanitizer or similar for better crash reports.
SUMMARY: libFuzzer: deadly signal
MS: 2 ShuffleBytes-ChangeBinInt-; base unit: e64ba7edd4532eff9b608d6877c63eb35d3bb65e
0x0,0x0,0x1,0x3,0xa,
\000\000\001\003\012
artifact_prefix='./'; Test unit written to SslStreamClientHelloFuzzer-artifact-2
Base64: AAABAwo=

Code coverage reports:

Artifacts:

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions