Logging interface
[rust-lightning] / fuzz / fuzz_targets / full_stack_target.rs
1 extern crate bitcoin;
2 extern crate crypto;
3 extern crate lightning;
4 extern crate secp256k1;
5
6 use bitcoin::blockdata::block::BlockHeader;
7 use bitcoin::blockdata::transaction::{Transaction, TxOut};
8 use bitcoin::blockdata::script::Script;
9 use bitcoin::network::constants::Network;
10 use bitcoin::network::serialize::{serialize, BitcoinHash};
11 use bitcoin::util::hash::Sha256dHash;
12
13 use crypto::sha2::Sha256;
14 use crypto::digest::Digest;
15
16 use lightning::chain::chaininterface::{BroadcasterInterface,ConfirmationTarget,ChainListener,FeeEstimator,ChainWatchInterfaceUtil};
17 use lightning::chain::transaction::OutPoint;
18 use lightning::ln::channelmonitor;
19 use lightning::ln::channelmanager::ChannelManager;
20 use lightning::ln::peer_handler::{MessageHandler,PeerManager,SocketDescriptor};
21 use lightning::ln::router::Router;
22 use lightning::util::events::{EventsProvider,Event};
23 use lightning::util::reset_rng_state;
24 use lightning::util::logger::Logger;
25
26 mod utils;
27
28 use utils::test_logger;
29
30 use secp256k1::key::{PublicKey,SecretKey};
31 use secp256k1::Secp256k1;
32
33 use std::cell::RefCell;
34 use std::collections::HashMap;
35 use std::hash::Hash;
36 use std::sync::Arc;
37 use std::sync::atomic::{AtomicUsize,Ordering};
38
39 #[inline]
40 pub fn slice_to_be16(v: &[u8]) -> u16 {
41         ((v[0] as u16) << 8*1) |
42         ((v[1] as u16) << 8*0)
43 }
44
45 #[inline]
46 pub fn slice_to_be24(v: &[u8]) -> u32 {
47         ((v[0] as u32) << 8*2) |
48         ((v[1] as u32) << 8*1) |
49         ((v[2] as u32) << 8*0)
50 }
51
52 #[inline]
53 pub fn slice_to_be32(v: &[u8]) -> u32 {
54         ((v[0] as u32) << 8*3) |
55         ((v[1] as u32) << 8*2) |
56         ((v[2] as u32) << 8*1) |
57         ((v[3] as u32) << 8*0)
58 }
59
60 #[inline]
61 pub fn be64_to_array(u: u64) -> [u8; 8] {
62         let mut v = [0; 8];
63         v[0] = ((u >> 8*7) & 0xff) as u8;
64         v[1] = ((u >> 8*6) & 0xff) as u8;
65         v[2] = ((u >> 8*5) & 0xff) as u8;
66         v[3] = ((u >> 8*4) & 0xff) as u8;
67         v[4] = ((u >> 8*3) & 0xff) as u8;
68         v[5] = ((u >> 8*2) & 0xff) as u8;
69         v[6] = ((u >> 8*1) & 0xff) as u8;
70         v[7] = ((u >> 8*0) & 0xff) as u8;
71         v
72 }
73
74 struct InputData {
75         data: Vec<u8>,
76         read_pos: AtomicUsize,
77 }
78 impl InputData {
79         fn get_slice(&self, len: usize) -> Option<&[u8]> {
80                 let old_pos = self.read_pos.fetch_add(len, Ordering::AcqRel);
81                 if self.data.len() < old_pos + len {
82                         return None;
83                 }
84                 Some(&self.data[old_pos..old_pos + len])
85         }
86 }
87
88 struct FuzzEstimator {
89         input: Arc<InputData>,
90 }
91 impl FeeEstimator for FuzzEstimator {
92         fn get_est_sat_per_1000_weight(&self, _: ConfirmationTarget) -> u64 {
93                 //TODO: We should actually be testing at least much more than 64k...
94                 match self.input.get_slice(2) {
95                         Some(slice) => slice_to_be16(slice) as u64 * 250,
96                         None => 0
97                 }
98         }
99 }
100
101 struct TestChannelMonitor {}
102 impl channelmonitor::ManyChannelMonitor for TestChannelMonitor {
103         fn add_update_monitor(&self, _funding_txo: OutPoint, _monitor: channelmonitor::ChannelMonitor) -> Result<(), channelmonitor::ChannelMonitorUpdateErr> {
104                 //TODO!
105                 Ok(())
106         }
107 }
108
109 struct TestBroadcaster {}
110 impl BroadcasterInterface for TestBroadcaster {
111         fn broadcast_transaction(&self, _tx: &Transaction) {}
112 }
113
114 #[derive(Clone)]
115 struct Peer<'a> {
116         id: u8,
117         peers_connected: &'a RefCell<[bool; 256]>,
118 }
119 impl<'a> SocketDescriptor for Peer<'a> {
120         fn send_data(&mut self, data: &Vec<u8>, write_offset: usize, _resume_read: bool) -> usize {
121                 assert!(write_offset < data.len());
122                 data.len() - write_offset
123         }
124         fn disconnect_socket(&mut self) {
125                 assert!(self.peers_connected.borrow()[self.id as usize]);
126                 self.peers_connected.borrow_mut()[self.id as usize] = false;
127         }
128 }
129 impl<'a> PartialEq for Peer<'a> {
130         fn eq(&self, other: &Self) -> bool {
131                 self.id == other.id
132         }
133 }
134 impl<'a> Eq for Peer<'a> {}
135 impl<'a> Hash for Peer<'a> {
136         fn hash<H : std::hash::Hasher>(&self, h: &mut H) {
137                 self.id.hash(h)
138         }
139 }
140
141 #[inline]
142 pub fn do_test(data: &[u8]) {
143         reset_rng_state();
144
145         let input = Arc::new(InputData {
146                 data: data.to_vec(),
147                 read_pos: AtomicUsize::new(0),
148         });
149         let fee_est = Arc::new(FuzzEstimator {
150                 input: input.clone(),
151         });
152
153         macro_rules! get_slice {
154                 ($len: expr) => {
155                         match input.get_slice($len as usize) {
156                                 Some(slice) => slice,
157                                 None => return,
158                         }
159                 }
160         }
161
162         let secp_ctx = Secp256k1::new();
163         macro_rules! get_pubkey {
164                 () => {
165                         match PublicKey::from_slice(&secp_ctx, get_slice!(33)) {
166                                 Ok(key) => key,
167                                 Err(_) => return,
168                         }
169                 }
170         }
171
172         let our_network_key = match SecretKey::from_slice(&secp_ctx, get_slice!(32)) {
173                 Ok(key) => key,
174                 Err(_) => return,
175         };
176
177         let logger: Arc<Logger> = Arc::new(test_logger::TestLogger::new());
178         let monitor = Arc::new(TestChannelMonitor{});
179         let watch = Arc::new(ChainWatchInterfaceUtil::new(Arc::clone(&logger)));
180         let broadcast = Arc::new(TestBroadcaster{});
181
182         let channelmanager = ChannelManager::new(our_network_key, slice_to_be32(get_slice!(4)), get_slice!(1)[0] != 0, Network::Bitcoin, fee_est.clone(), monitor.clone(), watch.clone(), broadcast.clone(), Arc::clone(&logger)).unwrap();
183         let router = Arc::new(Router::new(PublicKey::from_secret_key(&secp_ctx, &our_network_key).unwrap(), Arc::clone(&logger)));
184
185         let peers = RefCell::new([false; 256]);
186         let handler = PeerManager::new(MessageHandler {
187                 chan_handler: channelmanager.clone(),
188                 route_handler: router.clone(),
189         }, our_network_key, Arc::clone(&logger));
190
191         let mut should_forward = false;
192         let mut payments_received = Vec::new();
193         let mut payments_sent = 0;
194         let mut pending_funding_generation: Vec<([u8; 32], u64, Script)> = Vec::new();
195         let mut pending_funding_signatures = HashMap::new();
196         let mut pending_funding_relay = Vec::new();
197
198         loop {
199                 match get_slice!(1)[0] {
200                         0 => {
201                                 let mut new_id = 0;
202                                 for i in 1..256 {
203                                         if !peers.borrow()[i-1] {
204                                                 new_id = i;
205                                                 break;
206                                         }
207                                 }
208                                 if new_id == 0 { return; }
209                                 peers.borrow_mut()[new_id - 1] = true;
210                                 handler.new_outbound_connection(get_pubkey!(), Peer{id: (new_id - 1) as u8, peers_connected: &peers}).unwrap();
211                         },
212                         1 => {
213                                 let mut new_id = 0;
214                                 for i in 1..256 {
215                                         if !peers.borrow()[i-1] {
216                                                 new_id = i;
217                                                 break;
218                                         }
219                                 }
220                                 if new_id == 0 { return; }
221                                 peers.borrow_mut()[new_id - 1] = true;
222                                 handler.new_inbound_connection(Peer{id: (new_id - 1) as u8, peers_connected: &peers}).unwrap();
223                         },
224                         2 => {
225                                 let peer_id = get_slice!(1)[0];
226                                 if !peers.borrow()[peer_id as usize] { return; }
227                                 peers.borrow_mut()[peer_id as usize] = false;
228                                 handler.disconnect_event(&Peer{id: peer_id, peers_connected: &peers});
229                         },
230                         3 => {
231                                 let peer_id = get_slice!(1)[0];
232                                 if !peers.borrow()[peer_id as usize] { return; }
233                                 match handler.read_event(&mut Peer{id: peer_id, peers_connected: &peers}, get_slice!(get_slice!(1)[0]).to_vec()) {
234                                         Ok(res) => assert!(!res),
235                                         Err(_) => { peers.borrow_mut()[peer_id as usize] = false; }
236                                 }
237                         },
238                         4 => {
239                                 let value = slice_to_be24(get_slice!(3)) as u64;
240                                 let route = match router.get_route(&get_pubkey!(), None, &Vec::new(), value, 42) {
241                                         Ok(route) => route,
242                                         Err(_) => return,
243                                 };
244                                 let mut payment_hash = [0; 32];
245                                 payment_hash[0..8].copy_from_slice(&be64_to_array(payments_sent));
246                                 let mut sha = Sha256::new();
247                                 sha.input(&payment_hash);
248                                 sha.result(&mut payment_hash);
249                                 for i in 1..32 { payment_hash[i] = 0; }
250                                 payments_sent += 1;
251                                 match channelmanager.send_payment(route, payment_hash) {
252                                         Ok(_) => {},
253                                         Err(_) => return,
254                                 }
255                         },
256                         5 => {
257                                 let peer_id = get_slice!(1)[0];
258                                 if !peers.borrow()[peer_id as usize] { return; }
259                                 let their_key = get_pubkey!();
260                                 let chan_value = slice_to_be24(get_slice!(3)) as u64;
261                                 if channelmanager.create_channel(their_key, chan_value, 0).is_err() { return; }
262                         },
263                         6 => {
264                                 let mut channels = channelmanager.list_channels();
265                                 let channel_id = get_slice!(1)[0] as usize;
266                                 if channel_id >= channels.len() { return; }
267                                 channels.sort_by(|a, b| { a.channel_id.cmp(&b.channel_id) });
268                                 if channelmanager.close_channel(&channels[channel_id].channel_id).is_err() { return; }
269                         },
270                         7 => {
271                                 if should_forward {
272                                         channelmanager.process_pending_htlc_forwards();
273                                         handler.process_events();
274                                         should_forward = false;
275                                 }
276                         },
277                         8 => {
278                                 for payment in payments_received.drain(..) {
279                                         let mut payment_preimage = None;
280                                         for i in 0..payments_sent {
281                                                 let mut payment_hash = [0; 32];
282                                                 payment_hash[0..8].copy_from_slice(&be64_to_array(i));
283                                                 let mut sha = Sha256::new();
284                                                 sha.input(&payment_hash);
285                                                 sha.result(&mut payment_hash);
286                                                 for i in 1..32 { payment_hash[i] = 0; }
287                                                 if payment_hash == payment {
288                                                         payment_hash = [0; 32];
289                                                         payment_hash[0..8].copy_from_slice(&be64_to_array(i));
290                                                         payment_preimage = Some(payment_hash);
291                                                         break;
292                                                 }
293                                         }
294                                         channelmanager.claim_funds(payment_preimage.unwrap());
295                                 }
296                         },
297                         9 => {
298                                 for payment in payments_received.drain(..) {
299                                         channelmanager.fail_htlc_backwards(&payment);
300                                 }
301                         },
302                         10 => {
303                                 for funding_generation in  pending_funding_generation.drain(..) {
304                                         let mut tx = Transaction { version: 0, lock_time: 0, input: Vec::new(), output: vec![TxOut {
305                                                         value: funding_generation.1, script_pubkey: funding_generation.2,
306                                                 }] };
307                                         let funding_output = OutPoint::new(Sha256dHash::from_data(&serialize(&tx).unwrap()[..]), 0);
308                                         channelmanager.funding_transaction_generated(&funding_generation.0, funding_output.clone());
309                                         pending_funding_signatures.insert(funding_output, tx);
310                                 }
311                         },
312                         11 => {
313                                 if !pending_funding_relay.is_empty() {
314                                         let mut txn = Vec::with_capacity(pending_funding_relay.len());
315                                         let mut txn_idxs = Vec::with_capacity(pending_funding_relay.len());
316                                         for (idx, tx) in pending_funding_relay.iter().enumerate() {
317                                                 txn.push(tx);
318                                                 txn_idxs.push(idx as u32 + 1);
319                                         }
320
321                                         let mut header = BlockHeader { version: 0x20000000, prev_blockhash: Default::default(), merkle_root: Default::default(), time: 42, bits: 42, nonce: 42 };
322                                         channelmanager.block_connected(&header, 1, &txn[..], &txn_idxs[..]);
323                                         txn.clear();
324                                         txn_idxs.clear();
325                                         for i in 2..100 {
326                                                 header = BlockHeader { version: 0x20000000, prev_blockhash: header.bitcoin_hash(), merkle_root: Default::default(), time: 42, bits: 42, nonce: 42 };
327                                                 channelmanager.block_connected(&header, i, &txn[..], &txn_idxs[..]);
328                                         }
329                                 }
330                                 pending_funding_relay.clear();
331                         },
332                         _ => return,
333                 }
334                 for event in handler.get_and_clear_pending_events() {
335                         match event {
336                                 Event::FundingGenerationReady { temporary_channel_id, channel_value_satoshis, output_script, .. } => {
337                                         pending_funding_generation.push((temporary_channel_id, channel_value_satoshis, output_script));
338                                 },
339                                 Event::FundingBroadcastSafe { funding_txo, .. } => {
340                                         pending_funding_relay.push(pending_funding_signatures.remove(&funding_txo).unwrap());
341                                 },
342                                 Event::PaymentReceived { payment_hash, .. } => {
343                                         payments_received.push(payment_hash);
344                                 },
345                                 Event::PaymentSent {..} => {},
346                                 Event::PaymentFailed {..} => {},
347
348                                 Event::PendingHTLCsForwardable {..} => {
349                                         should_forward = true;
350                                 },
351                                 _ => panic!("Unknown event"),
352                         }
353                 }
354         }
355 }
356
357 #[cfg(feature = "afl")]
358 extern crate afl;
359 #[cfg(feature = "afl")]
360 fn main() {
361         afl::read_stdio_bytes(|data| {
362                 do_test(&data);
363         });
364 }
365
366 #[cfg(feature = "honggfuzz")]
367 #[macro_use] extern crate honggfuzz;
368 #[cfg(feature = "honggfuzz")]
369 fn main() {
370         loop {
371                 fuzz!(|data| {
372                         do_test(data);
373                 });
374         }
375 }
376
377 extern crate hex;
378 #[cfg(test)]
379 mod tests {
380         #[test]
381         fn duplicate_crash() {
382                 super::do_test(&::hex::decode("00").unwrap());
383         }
384 }