Skip to content

JSON fuzzer: use options for handling invalid UTF-8 and big strings - #23877

Open
DanielEScherzer wants to merge 1 commit into
php:PHP-8.6from
DanielEScherzer:fuzzer-json-options
Open

DanielEScherzer wants to merge 1 commit into
php:PHP-8.6from
DanielEScherzer:fuzzer-json-options

Conversation

@DanielEScherzer

Copy link
Copy Markdown
Member

Previously, the fuzzer only used the default options (0) and the PHP_JSON_OBJECT_AS_ARRAY option (1). After running the fuzzer on its existing corpus with -reduce_inputs=0, -runs=100000, and -seed=1, it failed to reach the code paths for handling big integers and strings, or for dealing with invalid UTF8, within the allotted 100,000 runs. Those 100,000 runs resulted in coverage of roughly 2,020 code blocks or edges, and roughly 5,400 "features".

Expand the fuzzer to also run with options that include the PHP_JSON_BIGINT_AS_STRING, PHP_JSON_INVALID_UTF8_IGNORE, and PHP_JSON_INVALID_UTF8_SUBSTITUTE flags. The two flags for handling UTF-8 are not applied used together, since invalid UTF-8 can only be handled one way, but other than that all combinations of these flags and PHP_JSON_OBJECT_AS_ARRAY are now tested. Repeating the same fuzzing as earlier with the expanded options results in roughly 2,150 code blocks or edges, and roughly 5,700 "features", being covered.

Previously, the fuzzer only used the default options (`0`) and the
`PHP_JSON_OBJECT_AS_ARRAY` option (`1`). After running the fuzzer on its
existing corpus with `-reduce_inputs=0`, `-runs=100000`, and `-seed=1`, it
failed to reach the code paths for handling big integers and strings, or for
dealing with invalid UTF8, within the allotted 100,000 runs. Those 100,000 runs
resulted in coverage of roughly 2,020 code blocks or edges, and roughly 5,400
"features".

Expand the fuzzer to also run with options that include the
`PHP_JSON_BIGINT_AS_STRING`, `PHP_JSON_INVALID_UTF8_IGNORE`, and
`PHP_JSON_INVALID_UTF8_SUBSTITUTE` flags. The two flags for handling UTF-8 are
not applied used together, since invalid UTF-8 can only be handled one way, but
other than that all combinations of these flags and `PHP_JSON_OBJECT_AS_ARRAY`
are now tested. Repeating the same fuzzing as earlier with the expanded options
results in roughly 2,150 code blocks or edges, and roughly 5,700 "features",
being covered.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants